CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012   help to set ambitious but feasible targets for the realising the vision of the Strategy, cooperate with PPPs in other member states of the European Union in the same area, via active participation in related working groups. Action 6 - Phase B – Investigate the possibility of creating a dynamic PPP (Public-Private Partnership) in the area of critical information infrastructure protection in the Republic of Cyprus and promote active cooperation with international entities through participation in international fora. The use of the PPP to foster trust between the State and private sector will be of primary importance. 3.6 Identification of Critical Information Infrastructures The need for the protection of critical information infrastructures, as highlighted and explained in this document, is necessary to minimize the negative impacts and possible catastrophic consequences of malicious acts or natural disasters on infrastructure, on a national level within the Republic of Cyprus but also because of potential negative effects to other countries, as a consequence of the high levels of interconnection and interdependence between international communications networks. The question is raised as to which particular infrastructures should be considered (and designated) as ‘critical’. Each stakeholder (electronic communications companies, governmental departments and services, security forces, armed forces, hospitals, financial institutions, energy and water providers, etc.) will consider their infrastructure as vitally important and the ideal situation would be the complete and total protection of all information infrastructures in the Republic of Cyprus, without exception. However, given that such an approach is not feasible, it is necessary to identify and assess the truly critical infrastructures within the Republic of Cyprus and to target them for the best possible protection. These critical infrastructures will be identified and assessed based on a number of predetermined criteria. For the determination of these criteria, as well as national conditions, related activities of the European Commission and ENISA (European Network and Information Security Agency) will also be taken into consideration, with the appropriate adaptation for Cyprus. The public sector, as well as the private sector, must contribute to the determination and assessment of critical information infrastructures, within the boundaries of the relevant working group(s). The steps that will be followed for the identification of critical information infrastructures will include the following:    Determination of services that will be targeted (e.g. voice communications, data communications, data storage, data processing), that could be classed as critical, Identification of infrastructures that are technically indispensable for the operation of these services, Introduction of objective criteria for the level of protection that each infrastructure element needs, with categorisation of infrastructures and the use of criteria such as the number of 20

Select target paragraph3