CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012
«put in place well-functioning and operational national/governmental CERTs as soon as possible;
provide technical support to the EU institutions in setting up their own CERT by 2012; establish a wellfunctioning network of CERTs at EU level, which will include the CERT for the EU institutions;».
In summary, the European Union, in recent years, has been planning, preparing and executing actions to
strengthen its position in relation to cybersecurity. Its aim is to effectively handle the rapidly increasing
rates of crimes and attacks in cyberspace, and the European Commission is asking from member state
governments to seriously examine the issue of security in cyberspace.
The statement of Neelie Kroes, Vice-President of the European Commission for the Digital Agenda on
the EU website is indicative:
"Cyber-attacks are a very real and ever-increasing threat. Whether against individual countries,
companies or most recently against the European Commission, they can paralyse key infrastructure and
cause huge long-term damage”. She also added that: “Setting up this CERT pre-configuration team is a
further demonstration of how seriously the EU Institutions take the cyber-security threat."
2.2
Network and Information Security in the Republic of Cyprus
The Republic of Cyprus and especially the Ministry of Communications and Works (MCW), and the
competent coordinating authority2 for Network and Information Security in Cyprus, which is the Office
of the Commissioner of Electronic Communications and Postal Regulation (OCECPR), have recognised
the essential role of security topics in the promotion of new communications services, the use of new
technologies and more generally in the development of an information society. Towards this end, a
number of specific actions and policies have been promoted on the national level:
(a) In 2006, the Ministry of Communications and Works (MCW) approved a policy document3,
through which a number of specific actions in the area of network and information security are
promoted, via OCECPR: the formation of Computer Emergency Response Teams (CERTs / CSIRTs), the
creating of an institutional framework for the security and integrity of information infrastructures, and
the raising of awareness of all stakeholders and Cypriot society about relevant security matters.
(b) In 2010, upon recommendations by OCECPR which were received favourably by ENISA, MCW
also approved a detailed policy document4 regarding the operation of a governmental and an academic
CERT. The Cypriot CERTs are being formed with the extension potential to cover the private business
sector at a later stage. The founding of the CERTs has been formalised via secondary legislation
P.I.358/2010.
2
Based on the provisions of the legislation that pervades its operations, OCECPR is responsible for the security of
electronic communications infrastructures, as well as for the information that is transmitted through or stored
within them.
3
Policy Document on Network and Information security 2006
4
Policy Document on the Formation of Emergency Response Teams for Incidents related to Network and
Information Security (CSIRT/CERT) 2010
10