CYBERSECURITY STRATEGY OF THE REPUBLIC OF CYPRUS 2012
countries. The Council has also asked to be updated, together with the European Parliament, on an
annual basis by member states and the European Commission regarding their actions in these matters.
After the meeting of the Telecommunications Ministerial Council on the 27th of May 2011, in which
these matters were discussed, the European Commission announced the actions that it expects the
member states of the European Union to undertake, asking for the commitment of all those involved for
the promotion of common goals. Specifically, the European Commission is requesting that member
states and the Council state their strong commitment to the improvement and strengthening of national
security in cyberspace to the best of their abilities, with the target of securing a high level of protection
within the European Union and more effective collaboration on the international level.
As such, the European Commission is planning to monitor the performance of the member states
closely, as regards meeting the three basic targets that are being promoted on the European level:
(a) The operation of national / governmental Computer Emergency Response Teams (CERTs) in
each member state and the creation of a common and functional network of national / governmental
CERTs in Europe by 2012, which will be supported by effective national cybersecurity strategies.
(b) The organisation of regular national and pan-European exercises for security in cyberspace
(with CERTs participating as a prerequisite), in which a pan-European cyber exercise which has been
scheduled for the second half of 2012 is included.
(c) The development of national contingency plans for network and information security, and
incidents in cyberspace, and the contribution of all member states to the development of a European
contingency plan for emergencies in cyberspace within 2012. Based on national experiences, such a
plan must lay the foundation and define appropriate processes for effective communications between
member states in situations where common threats and malicious attacks affect a number of member
states.
On a national level, the actions described in points (b) and (c) above form part of the actions that are
included in this Strategy. The action referred to in point (a) above is already in progress in the Republic
of Cyprus and is regulated by separate secondary legislation that is published by the Commissioner for
Electronic Communications and Postal Regulation, while the correct operation of CERTs/CSIRTs in Cyprus
is a basic precondition for the development of the strategic planning that is described in this document.
These same points were the subject of a special Ministerial Conference that took place in Hungary in
April 2011, in the context of the work plans of the Presidency of the Council and of the European
Commission during the first half of 2011. All member states were represented at this conference, which
was under the auspices of the Telecommunications Ministerial Council and under the area of network
and information security. The conference conclusions cover the duties of the member states in detail,
as described in this section. Specifically regarding the matters related to CERTs, the conference
conclusions state that:
9