Part Three
The Strategy
national and EU research projects and initiatives
on cyber security. Essentially, it entails participation
not only from Government but also from the private
sector and the academia.
• Ingraining a culture of cyber security awareness
on the potential misuse, vulnerabilities and risks
potentially arising from the ICTs and concepts
applied (particularly those emerging); whilst
embracing the opportunities arising from their
use
v. A Strategic, target-oriented national awareness
and advice campaign
• Imparting the key message that it is ultimately
in everyone’s interest and responsibility to take
the necessary relevant cyber security safeguards;
keeping in view of the inherent interconnectedness of individuals and organisations
alike in cyber-space.
It is highly recommended that a concerted, ongoing
strategic approach is undertaken, potentially through
a nationwide Communications strategy for cyber
security53; aimed at addressing the various strata of
society, business and public sector along with their
corresponding needs, expectations, and potential
ICTs and concepts applied54.
Most measures highlighted within Goals 4 and 5 of
this strategy as well as any established national way of
sharing related knowledge, experience and insight as
referred to in Measure 3 (i)56 may potentially serve as
key sources for the establishment and maintenance
of such a concerted strategic campaign.
Such an approach may ensure:
• Avoiding
piecemeal,
potentially
approaches to awareness campaigns
one-off
• No duplication of effort
• Maximisation of cyber security related financial
and human resources
vi. Encourage ‘cyber hygiene’ and personal
responsibility
• Identification and engagement of all potential
sources of dissemination of the awareness
campaigns
Ultimately, citizens are expected to apply at least
some form of basic ‘cyber hygiene’ in using ICT,
such as through careful disposition and use of
personal information on-line, installing software
updates and anti-virus software, using basic security
controls such as strong passwords and, as much as
possible, seeking to be more wary of any suspicious
activity related to their personal on-line accounts.
The national awareness campaign, as highlighted in
Measure 5 (v), should help in reaching this objective.
• Imparting effective awareness and knowledge
on cyber security patterns and measures that is
commensurate to the specific target audience
and to the medium used55
• A measure of the extent of national awareness
and understanding of cyber security over time
• That cyber security is not simply a concern of
ICT professionals.
Furthermore, the possibility of a national responsible
disclosure policy framework that enables wellintentioned system users to safely inform
Government, businesses or institutions about
detected vulnerabilities in their ICT systems or
services may also be explored. The framework would
need to establish the right parameters and conditions
so as to ensure its effectiveness57.
Ultimately, the key factors that need to be borne in
mind in the establishment of such campaign is:
• Finding the right way to raise awareness,
keeping in view of the target audience
• Ensuring motivation to learn and pay particular
attention to various signals of fake
communications on a day to day basis
(particularly to counter social engineering
threats)
26
MALTA CYBER SECURITY STRATEGY 2016