National strategic framework for cyberspace security
Such vulnerabilities can cause service
unavailability, or they can compromise
the integrity of the information stored
and provided by the DNS. In both cases,
the exploitation of such vulnerabilities has
extremely serious consequences, possibly
resulting in a grave malfunctioning
of fundamental control nodes of the
infrastructure.
In order to prevent these vulnerabilities
from being exploited, we must first of all
set up a risk assessment, mitigation and
management plan, which must take into
account physical, logic and procedural
cybersecurity measures, and raise
awareness among the personnel through
training and education.
In principle, key requirements of the
cyber security policy should extend to:
• Control of the access to physical
installations: in order to minimize the
risk of damage, tampering or theft
of hardware assets, only traceable
and authorized personnel should be
granted access to the installations
warehouse;
• Exclusive use of certified products
in order to exclude from the supply
chain foreign retailers considered
“at risk”; use of up-to-date antivirus
software; encryption of data and
digital signature; identification and
authentication of connected users;
monitoring and logging of instances;
updating of the access privileges of
every user (logical measures);
• Norms and procedures instructing
all phases and aspects of the security
processes; definition of roles, tasks
and responsibilities within the
risk assessment, mitigation and
management plan; adoption of
specific measures that complete
and reinforce the technological
preparedness; recurring controls on
the consistency and reliability of the
ICT assets (procedural measures).
CYBER SECURITY
USER TRAINING, AWARENESS
AND EMPOWERMENT
PHYSICAL
LOGICAL
MEASURES
PROCEDURAL
ANALYSIS
T
MANAGEMEN
MITIGATION
18
RISK