ENDNOTES
1.
Particular reference is made to the:
•
Directive 95/46/EC and the Data Protection Act (Chapter 440) of the Laws of Malta, – Both Directives
shall be repealed by the Data Protection Regulation (EU) 2016/679, which shall come into force by June 2018.
•
Network and Information Security - NIS Directive (i.e. The Directive of the European Parliament and of he Council
concerning measures for a high common level of security of network and information systems across the Union) which is
expected to enter into force in August 2016 for transposition into local legislation within 21 months.
2.
https://www.mca.org.mt/general/national-ecommerce-strategy-2014-2020
3.
Adapted from the definition cited by the Cyber security Strategy of the European Union.
4.
Ross(2015)
5.
Puricelli (2015)
6.
Global Cyber Security Capacity Centre, (2014), Cyber Security Capability Maturity Model (CMM)- Pilot, Oxford Martin School,
University of Oxford, http://www.intgovforum.org/cms/wks2015/uploads/proposal_background_paper/Cyber-Security-CapacityMaturity-Model.pdf
7.
Refer to Note 1.
8.
Ibid.
9.
Taking into particular consideration of the Network and Information Security (NIS) Directive. Reference is made to Note 1.
10.
A top level national CSIRT that acts as the key technical/operational function. Among the responsibilities of such CSIRT are:
•
Monitoring incidents at a national level
• Providing early warning, alerts, announcements and dissemination of information to relevant stakeholders about risks and
incidents
•
Providing dynamic risk and incident analysis and situational awareness
•
Establish cooperative relationships with the private sector
•
Facilitate cooperation through use of common or standardised practices for incident and risk handling procedures
11.
European Commission (2015), DSI Maturity Study, p.29
12.
Which could take the form of (i) a centralised approach – whereby a national authority has in-house responsibilities with all
authorities reporting to it; OR (ii) a decentralised approach whereby roles and responsibilities are spread across a variety of actors
who coordinate together to share information and exchange on a voluntary basis OR (iii) a semi-centralised (hybrid) approach
whereby a central ministry coordinates implementation of the strategy with designated authorities having the necessary roles and
responsibilities over operators and other stakeholders and who report to the central ministry on a periodic basis.
13.
Reference is made to Note 1.
14.
Refers to Critical Information Infrastructure (CII) operators
15.
One of which specifically includes the Network and Information Security – NIS – Directive, referred to in Note 1.
16.
Refers to CII operators, Critical Infrastructure (CI) operators, Digital service providers and other potential stakeholders
17.
Potentially enabled by National cyber simulation exercises as referred to in Measure 3.1
18.
Reference is particularly made to the NIS Directive, referred to in Note 1.
19.
European Agenda on Security: Questions and Answers, Strasbourg, 28 April 2015 - European Commission-Fact Sheet.
20.
European Commission, Countering hybrid threats: EU Response – Cybersecurity, Presentation, Brussels, 19th February 2016
21.
One example of such an arrangement is the Cyber-security Information sharing Partnership, part of CERT-UK; www.cert.gov.uk
cisp/
22.
Organisation for Security and Cooperation in Euroope (OSCE), Decision No. 102, OSCE Confidence Building Measures to reduce
the risks of conflict stemming from the use of ICTs, PCOEW6464, 10 March 2016, Confidence Buidling Measure No. 14. This CBM
refers to best practices of responses to common security challenges stemming from the use of ICTs.
23.
Areas that could potentially be looked into may include risk assessment and apportioning security practices to risk levels,
information security planning, processes, roles and assesments of preparedness.
24.
Reference is made in particular to Note 1.
25.
Article 2(4) of the UN states that “All Members shall refrain in their international relations from the threat or use of force against the
territorial integrity or political independence of any state, or in any other manner inconsistent with the Purposes of the United
Nation”. This Article prohibits any state from attacking another state however in Article 51 of the same charter states that “Nothing
in the present Charter shall impair the inherent right of individual or collective self defence if an armed attack occurs against
a Member of the United Nations, until the Security Council has taken the measures necessary to maintain international peace and
security.”
26.
Reference is made to ‘Developing a Joint EU diplomatic response against coercive cyber operations’, Council of the European
34
MALTA CYBER SECURITY STRATEGY 2016