National strategic framework for cyberspace security Such vulnerabilities can cause service unavailability, or they can compromise the integrity of the information stored and provided by the DNS. In both cases, the exploitation of such vulnerabilities has extremely serious consequences, possibly resulting in a grave malfunctioning of fundamental control nodes of the infrastructure. In order to prevent these vulnerabilities from being exploited, we must first of all set up a risk assessment, mitigation and management plan, which must take into account physical, logic and procedural cybersecurity measures, and raise awareness among the personnel through training and education. In principle, key requirements of the cyber security policy should extend to: • Control of the access to physical installations: in order to minimize the risk of damage, tampering or theft of hardware assets, only traceable and authorized personnel should be granted access to the installations warehouse; • Exclusive use of certified products in order to exclude from the supply chain foreign retailers considered “at risk”; use of up-to-date antivirus software; encryption of data and digital signature; identification and authentication of connected users; monitoring and logging of instances; updating of the access privileges of every user (logical measures); • Norms and procedures instructing all phases and aspects of the security processes; definition of roles, tasks and responsibilities within the risk assessment, mitigation and management plan; adoption of specific measures that complete and reinforce the technological preparedness; recurring controls on the consistency and reliability of the ICT assets (procedural measures). CYBER SECURITY USER TRAINING, AWARENESS AND EMPOWERMENT PHYSICAL LOGICAL MEASURES PROCEDURAL ANALYSIS T MANAGEMEN MITIGATION 18 RISK

Select target paragraph3