CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012
European and international level. Investments in the area of security serve to increase the trust of users
in new services and contribute to the wider development of the economy and society itself.
Governments, as well as businesses, must evaluate their investments in this area, with the basic
criterion being the costs associated with failures of their information technology or communication
systems against malicious actions or natural causes.
‘Security’, in the information and communications technology world, generally refers to the
preservation of three principles:
confidentiality of information, i.e. to only allow access to information to authorised persons,
integrity of information, i.e. the protection of information from any unwanted modification or
destruction,
availability of information or systems, i.e. for a system to be able to provide service and/or
information when it is requested.
The preservation of the above principles aims to ensure network and information security to the highest
possible degree, in relation to:
the protection of information/data in transit,
the protection of information/data in processing,
the protection of information/data in storage.
Going beyond the protection of infrastructure, systems and information, the preservation of a high level
of security, as per the principles described above, is necessary in order to built trust in information
systems, communications and other electronic services that are offered by the government and other
important organisations in Cyprus. The development of trust on behalf of citizens in these systems and
ensuring secure transactions in cyberspace will contribute to a significant degree to the economic
development of Cyprus and to meeting the targets of the Digital Agenda for Cyprus.
1.2
Critical Information Infrastructures
Information infrastructures have greatly increased in recent years in the Republic of Cyprus, and they
have penetrated into almost every part of the life of the average citizen. These infrastructure are used
not only directly (e.g. through the use of telephony, the Internet, etc.), but also indirectly, since almost
all of the services that are offered by the government and used by citizens are heavily supported by
them. Some of these information infrastructures form a critical part of Cypriot economy and society,
either through the provision of vital goods and services, or forming a supporting platform for other
(critical) infrastructures. These are thus considered to be critical information infrastructures, given that
their disruption or destruction would have severe consequences to vital governmental and societal
functions.
It thus becomes necessary, via a wider framework of a cybersecurity strategy of a country, to place
special emphasis on the protection of such critical information infrastructures. A number of actions that
are described in the present document cover the protection of critical information infrastructures, and
6