CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012 Action 3 - Phase A/B – Formation of working groups, with representatives from the public and private sectors (as necessary), to implement the Strategy Actions. 3.4 Legal Framework Legislation in the Republic of Cyprus already covers a large number of areas relating to network and information security, as well as cybercrime (and other electronic crime) matters. However, it is still considered necessary to identify all relevant laws in Cyprus and to update them where needed, and also to promote the creation of new primary and secondary legislation to cover all of the provisions of this Strategy. This legislation (whether new or updated) must cover processes for the prevention, deterrence and dynamic response to all forms of cybercrime, and also be harmonised with the relevant law and directives of the European Union. International cooperation with other member states of the European Union, as well as third countries, will be required in the areas of network and information security and the protection of critical information infrastructures. As such, specific legal issues may arise regarding the processing and handling of electronic threats whose sources could be outside of the boundaries of the Republic of Cyprus. It is thus considered necessary to create an appropriate legal infrastructure also regarding the effective cooperation with entities outside Cyprus to solve related problems as they arise. Action 4 - Phase B – Creation of an appropriate legal framework to fully support the provisions of the Cybersecurity Strategy. All relevant laws of the competent authorities must be assessed for any updated needs. 3.5 Cooperation between the State and the Private Sector The State will make significant efforts in the area of network and information security, and especially on the topic of critical information infrastructure protection within Cyprus. The strategic initiative in these areas can only come from the State, which is responsible for ensuring the cooperation between relevant stakeholders on a national and international level. The State recognises that the role of the private sector in the security and protection of critical information infrastructures is extremely important, for the following reasons:  The private sector (including the semi-governmental electronic communications provider) operates the majority of the critical communications infrastructure of the government, e.g. the 18

Select target paragraph3