CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012    development of the necessary skills, training and awareness in security topics, for those that are directly involved and also for the public, productive collaboration between the public and private sector, on both the national and international level, creation or adaptation of the necessary structures and instruments within the competent authorities and the more generally the Cyprus Government, to secure the demands and capabilities of immediate incident response. 3.2 Splitting the Actions – Phases A and B The rest of this chapter presents the actions that have been identified for the implementation of the strategic plan. Current organisational structures and available resources are not at a level that would allow an immediate start to all of the actions that have been identified, and as such each action description that follows also indicates the phase in which it will be executed:   Phase A o Phase A includes all of the actions that OCECPR is in a position to start in the immediate future with the resources that are currently available to it. Phase B o Phase B includes the actions that OCECPR will be in a position to coordinate once a new organisational structure has been developed, with the necessary resources to carry out the implementation of this Strategy in its entirety. Each action description mentions the phase in which it will be executed and the actions that mention both phases will be partly completed in each phase. It is noted that this does not mean that actions implemented in Phase A will necessarily be completed within that phase. The majority of the actions of this Strategy will continue to be executed on a long-term basis for the continued protection of cyberspace in Cyprus. 3.3 Organisational Structure The area of network and information security is a very large and complicated subject, and one which involves a number of stakeholders, as shown in section 2.3. Each competent or relevant authority has its own areas of responsibility and it is important to uphold these differences. However, due to this multi-stakeholder approach to security matters, it is vital for all involved to understand and accept that the maintenance of acceptable levels of security in the electronic world can be accomplished only via cooperation between the different stakeholders involved, within a framework of coordinated response to the various threats that have already been mentioned. It follows that the coordination of the competent or relevant governmental authorities is absolutely necessary. This coordination activity is productive when performed by an entity which is in a position to organise and coordinate the various actions of the Republic of Cyprus for correct response to the threats that are around today, as well as rising and new threats in cyberspace. This entity must have: 15

Select target paragraph3