2. Conditions and problems of the cyberspace area
Functioning of the State and the implementation of its constitutional obligations
is increasingly dependent on the development of modern technology, information
society and uninterrupted functioning of cyberspace. Currently, the safe functioning of
cyberspace largely depends on the security of ICT infrastructure, which allows the use of
cyberspace, information resources and services gathered in it, operating thanks to it. The
infrastructure functioning in CRP allows the State to fulfil its constitutional obligation
to the citizen, ensures continuity and effectiveness of government administration as well
as uninterrupted and efficient development of the economy of the Republic of Poland.
Polish government sees the need to introduce measures aimed at ensuring the
security of the State ICT infrastructure, namely ensuring the correctness and continuity
of functioning of ICT systems, facilities and installations used to implement the
constitutional duties of the State to the citizens and its internal security. For this purpose
it is necessary to determine the minimum security standard which will allow for the
implementation of this objective and will reduce to the minimum potential damage
which may be entailed by attack on individual elements of cyberspace of RP. The
Policy is the basis for developing the concept of management of infrastructure security
functioning within CRP and developing guidelines for the creation of the legal basis
serving the implementation of tasks in this regard by the government administration.
The principles of ensuring cyberspace security developed under the cooperation referred
to in point 4.4, within the infrastructure of CRP are also recommended to entrepreneurs.
The actions concerning the security of ICT infrastructure will be complementary
to the efforts aimed at protection of the critical infrastructure of the State. In this
respect, the Policy does not affect the provisions contained in the National Critical
Infrastructure Protection Programme.
The Policy indicates the need to develop the concept of ensuring security of
infrastructure functioning within CRP and prepare legal basis for performance of
tasks in this regard by the government administration.
The ICT infrastructure of CRP must be protected against attacks from cyberspace,
destruction, damage or unauthorized access.
As a part of actions connected with the implementation of the Policy a risk assessment
is carried out with regard to the identification of resources, sub-systems, functions and
dependencies on other systems relevant to the functioning of CRP. At the same time,
the implementation of the Policy will allow for the development of target guidelines for
performance of risk estimates and model of reports containing general data on types of
risks, threats and vulnerabilities identified in each of the sectors of the Polish economy
in relation to the constitutional tasks carried out on the basis of CRP.
There is a need to develop, on the basis of the conducted risk analysis, the minimum
safety standards according to which the identified resources and systems will be
protected, thanks to which the constitutional obligations of the State are fulfilled.
Ministry of Administration and Digitisation, Internal Security Agency
Page 9 of 24