Part Three The Strategy suggest risk mitigation and management strategies accordingly. The exercise entails participation and coordination between all stakeholders involved16 and it needs to be updated on a regular basis, so as to ensure its currency with: data. The legislation demands a risk-based approach with the development of appropriate controls. vi. Encourage cyber risk assessments by other organisations not falling within the scope of Measure 1 (v) • The cyber threat landscape The emphasis on individual risk assessment made to specific organisations with respect to network and information security, in Measure 1 (v) should not however construe that other organisations need not adopt similar activities. Indeed, data protection legislation, also referred to in Measure 1 (v) is applicable to all organisations processing personal data. • Evolution in the adoption of existing and emerging ICT. One key deliverable of the National Cyber Risk Assessment is a strategic plan that includes cooperation and communication processes needed to ensure prevention, detection, response, repair and recovery (including communication), that are modulated according to the alert level are to be ensured. An assessment of financial risks related to cyberrelated incidents could possibly also indicate a market in cyber insurance, which may in turn contribute to information sharing among its participants, apart from availability of financial coverage to mitigate consequential losses. Such processes also refer to national incident cyber handling procedures and business continuity plans to ensure resilience. Furthermore, it is understood that such processes need to be subject to a schedule of regular testing and validation exercises17, with the resulting outcome (including lessons learnt) used as a basis for any related updates. Ultimately, however, it needs to be borne in mind that cyber insurance coverage alone is not a panacea to cyber security threats. It needs to be carried out with in conjunction with consideration and applicability of cyber security measures in line with the risks assessed. v. Ensure necessary measures in line with individual cyber risks assessments by key Public and Private sector organisations falling within the scope of related EU legal requirements vii. Consolidate the Information Framework within the Public Sector The conduct of a National Cyber Risk Assessment does not exclude the conduct of individual cyber risk assessments particularly by the public and private sector organisations falling within the scope of related EU legal requirements on network and information security18. Security The Government of Malta Information Security Policy is expected to come into force in the near future. It is based upon ISO 27001 Information Security international standard and applies to all of the Public Sector. viii. Ensure classification of data within the Public Sector and encourage it within the private sector Data Protection Regulation (EU) 2016/679 and other Directives coming into force by June 2018 across the EU, also call for all organisations to ensure regular risk assessments by organisations to understand the degree of threat imposed on them when processing personal The classification of electronic data within the Public Sector and the application of security controls commensurate to the security marking assigned is one area, among others, referred to 18 MALTA CYBER SECURITY STRATEGY 2016

Select target paragraph3