CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012
help to set ambitious but feasible targets for the realising the vision of the Strategy,
cooperate with PPPs in other member states of the European Union in the same area, via active
participation in related working groups.
Action 6 - Phase B – Investigate the possibility of creating a dynamic PPP (Public-Private
Partnership) in the area of critical information infrastructure protection in the Republic of
Cyprus and promote active cooperation with international entities through participation in
international fora. The use of the PPP to foster trust between the State and private sector will
be of primary importance.
3.6
Identification of Critical Information Infrastructures
The need for the protection of critical information infrastructures, as highlighted and explained in this
document, is necessary to minimize the negative impacts and possible catastrophic consequences of
malicious acts or natural disasters on infrastructure, on a national level within the Republic of Cyprus
but also because of potential negative effects to other countries, as a consequence of the high levels of
interconnection and interdependence between international communications networks. The question
is raised as to which particular infrastructures should be considered (and designated) as ‘critical’. Each
stakeholder (electronic communications companies, governmental departments and services, security
forces, armed forces, hospitals, financial institutions, energy and water providers, etc.) will consider
their infrastructure as vitally important and the ideal situation would be the complete and total
protection of all information infrastructures in the Republic of Cyprus, without exception.
However, given that such an approach is not feasible, it is necessary to identify and assess the truly
critical infrastructures within the Republic of Cyprus and to target them for the best possible protection.
These critical infrastructures will be identified and assessed based on a number of predetermined
criteria. For the determination of these criteria, as well as national conditions, related activities of the
European Commission and ENISA (European Network and Information Security Agency) will also be
taken into consideration, with the appropriate adaptation for Cyprus. The public sector, as well as the
private sector, must contribute to the determination and assessment of critical information
infrastructures, within the boundaries of the relevant working group(s).
The steps that will be followed for the identification of critical information infrastructures will include
the following:
Determination of services that will be targeted (e.g. voice communications, data
communications, data storage, data processing), that could be classed as critical,
Identification of infrastructures that are technically indispensable for the operation of these
services,
Introduction of objective criteria for the level of protection that each infrastructure element
needs, with categorisation of infrastructures and the use of criteria such as the number of
20