CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012 1. INTRODUCTION 1.1 Network and Information Security Information and communications technologies and systems are one of the most important drivers of social and economical development today, whilst undoubtedly being necessary tools for the operation of functional and social structures in any country. As cyberspace develops, the protection of the electronic systems present in organisations of all kinds becomes all the more important, so that any activity conducted through these systems is safe and secure. A basic security system must cover the confidentiality, integrity and high availability of infrastructure and information, while allowing the operation of the infrastructure to be reliable, flexible and controlled. Infrastructure security refers to the capability and resilience of the infrastructure against threats and malfunctions that may afflict its constituent parts. Relevant security measures that are taken mainly target the increase of readiness levels and the strengthening of preventative mechanisms, the identification and response to potential risks (including malicious actions or attacks), as well as putting in place measures for mitigation and recovery from malfunctions, failures and the availability of services that are offered, covering also emergency or crisis situations. In this document, the terms ‘network and information security’ and ‘cybersecurity’ are used. ‘Network and information security’ refers to the preservation of the principles of confidentiality, integrity and availability, as they are described below. ‘Cybersecurity’ refers to the broader security of networked systems that operate in cyberspace, i.e. in most cases connected to the Internet, and this term also covers the safe and secure usage of these systems by end users. It is clarified that the applicable level of information security must be guided through the determination of the value of the information to be protected (irrespective of the form of that information, whether it be physical or electronic). The value parameter will be taken into account during the implementation of the actions described in the present document, especially those that are related to informing people regarding security to foster awareness and a security culture. As a general principle, information must be protected appropriately, according to its value. Network and Information Security is a basic and necessary consequence of the development and pervasiveness of new information and communication technologies. Taking into account the globalisation of communications, especially with the use of the Internet but also the continuously increasing dangers that users are faced with at all levels, it has become vital to take adequate protection measures but also to ensure a high level of cooperation between all parts of society, the public and private sectors, on a national, European and international level. Citizens, businesses and governments strongly need to be able to trust the media through which important information and data, personal or otherwise, is transmitted. The safe development of information and communication technologies is important for citizens and societies, for growth in employment (and the economy in general), on the national but also the 5

Select target paragraph3