Part Three
The Strategy
1. Goal: Establish a governance framework
operational nature. This entails ensuring consolidation
of a top level National CSIRT10. It also implies close
communication and coordination of the CSIRT with
the proposed strategy implementation function,
given that it would need to be involved on:
The
governance
framework
covers
the
necessary key functions and corresponding roles
and responsibilities, as well as policies and
processes necessary9 to constitute a robust
foundation for an effective national cyber
security strategy.
• Real-time information sharing and response to
calls
• Longer term planning11. Communication and
coordination, as the need arises, with other
CSIRTS existing in Malta would also be necessary.
i. Establish the necessary key coordination
structures
It is envisaged that the following functions
(involving
multiple
stakeholders)
shall
be
required to ensure sustainability of the National
Cyber Security Strategy:
a.
The structure12 and responsibilities of these functions
is subject to further reference and alignment to the
relevant European Union legal requirements13 as well
as to further consultation.
At the strategic level:
i. A function for the articulation and periodic review
of the National Cyber Security Strategy. The
creation of this function is required in the short
term. This body would need to work in close
cooperation with the strategy implementation
function(s) referred to below
ii. Foster the coordination to protect national
critical information infrastructure
Measures
of
preparedness,
response
and
recovery, including cooperation and ongoing
coordination
mechanisms
are
particularly
necessary to protect national critical information
infrastructure. It is thus necessary to ensure that
such
national
coordination
between
all
stakeholders concerned14 is fostered.
ii. A strategy implementation function to oversee
implementation of the strategy and monitor cyber
security operations. Such function needs to have
the necessary funding, resources and mandate to:
iii. Ensure clear delineation and communication
of roles and responsibilities
• take a leading, active role in the implementation
of the National Cyber security strategy, keeping
in view of policy and planning developments
within the realm of Malta’s digital economy
and society as well as further cyber security
related developments on a national, EU and
international perspective
Cyber related roles and responsibilities - such
as those identified above and potentially those
arising from the proposed measures, as well as
those
resulting
from
relevant
EU
legal
requirements15, need to be clearly delineated
and agreed upon accordingly.
Communication
of their establishment further ensures the
effective coordination that may be necessary
between the effected stakeholders themselves.
• ensure security preparedness of the public and
private sector of their ICT, in line with established
security requirements. This implies driving for
effective engagement and ongoing high level
coordination across Malta’s public and private
sector.
iv. Ensure the conduct of a national cyber risk
assessment exercise
b. At the operational level, function(s) for the
national coordination of cyber detection and
response. Computer Security Incident Response
Teams (CSIRTs) tend to be of such technical and
A National Cyber Risk Assessment exercise
shall need to identify the major national cyber
threats and risks, assess respective impacts and
17
MALTA CYBER SECURITY STRATEGY 2016