Part Three
The Strategy
suggest
risk
mitigation
and
management
strategies accordingly. The exercise entails
participation and coordination between all
stakeholders involved16 and it needs to be
updated on a regular basis, so as to ensure its
currency with:
data. The legislation demands a risk-based
approach with the development of appropriate
controls.
vi. Encourage cyber risk assessments by other
organisations not falling within the scope of
Measure 1 (v)
• The cyber threat landscape
The emphasis on individual risk assessment
made to specific organisations with respect to
network and information security, in Measure 1 (v)
should not however construe that other
organisations need not adopt similar activities.
Indeed, data protection legislation, also referred
to in Measure 1 (v) is applicable to all
organisations processing personal data.
• Evolution in the adoption of existing and emerging
ICT.
One key deliverable of the National Cyber Risk
Assessment is a strategic plan that
includes
cooperation and communication processes needed
to ensure prevention, detection, response, repair
and recovery (including communication), that are
modulated according to the alert level are to be
ensured.
An assessment of financial risks related to cyberrelated incidents could possibly also indicate a market
in cyber insurance, which may in turn contribute to
information sharing among its participants, apart
from availability of financial coverage to mitigate
consequential losses.
Such processes also refer to national incident cyber
handling procedures and business continuity plans
to ensure resilience. Furthermore, it is understood
that such processes need to be subject to a schedule
of regular testing and validation exercises17, with the
resulting outcome (including lessons learnt) used as
a basis for any related updates.
Ultimately, however, it needs to be borne in mind that
cyber insurance coverage alone is not a panacea to
cyber security threats. It needs to be carried out with
in conjunction with consideration and applicability
of cyber security measures in line with the risks
assessed.
v. Ensure necessary measures in line with
individual cyber risks assessments by key Public
and Private sector organisations
falling within
the scope of related EU legal requirements
vii. Consolidate the Information
Framework within the Public Sector
The conduct of a National Cyber Risk
Assessment does not exclude the conduct of
individual cyber risk assessments particularly
by the public and private sector organisations
falling within the scope of related EU legal
requirements
on
network
and
information
security18.
Security
The Government of Malta Information Security Policy
is expected to come into force in the near future.
It is based upon ISO 27001 Information Security
international standard and applies to all of the Public
Sector.
viii. Ensure classification of data within the Public
Sector and encourage it within the private sector
Data Protection Regulation (EU) 2016/679 and
other Directives coming into force by June
2018 across the EU, also call for all organisations
to
ensure
regular
risk
assessments
by
organisations to understand the degree of threat
imposed on them when processing personal
The classification of electronic data within the
Public Sector and the application of security
controls commensurate to the security marking
assigned is one area, among others, referred to
18
MALTA CYBER SECURITY STRATEGY 2016