EXECUTIVE SUMMARY Following the adoption of the Prime Minister’s “Decree Containing Strategic Guidelines for the National Cyber Protection and ICT Security” of the 24th January 2013, the Cybersecurity Working Group was established on the 3rd of April 2013 under the auspices of the Committee for the Security of the Republic, chaired by the Department for Intelligence and Security (DIS), and developed this National Cybersecurity Strategic Framework. The Cybersecurity Working Group saw the active participation of all the Administrations already represented in the Committee for the Security of the Republic (Ministries of Foreign Affairs, Interior, Defence, Justice, Economy and Finance, Economic Development), and included the Agency in charge for the Italian Digital Agenda as well as the Cybersecurity Unit within the Prime Minister’s Office. The point of departure of this National Cybersecurity Strategic Framework is an assessment of today’s cyber threat. The growing importance of services provided through cyberspace in everyday life – from simple online payments to the management of strategic and critical national infrastructures – implies that also the cyber threat is becoming more and more pervasive and subtle, and yet it is still widely unnoticed and underestimated. In the first chapter, “The Nature and the Evolving Trends of the Cyber Threat and of the Vulnerabilities of the National ICT Infrastructures”, the major cyber threats and their actors will be acknowledged – from cybercrime to cyber espionage and cyber terrorism, from hacktivism to cyber sabotage, concluding with cyber warfare – and a brief taxonomy of the cyber organizational, procedural and technical vulnerabilities will be proposed. Cyberspace is a man-made domain essentially composed of ICT nodes and networks, hosting and processing an ever-increasing wealth of data of strategic importance for States, firms, and citizens alike, and for all political, social and economic decision-makers. The second chapter, “Tools and Procedures to Strengthen the National Cyber Defence Capabilities”, identifies six strategic guidelines around which to converge, 9

Select target paragraph3