2. Conditions and problems of the cyberspace area Functioning of the State and the implementation of its constitutional obligations is increasingly dependent on the development of modern technology, information society and uninterrupted functioning of cyberspace. Currently, the safe functioning of cyberspace largely depends on the security of ICT infrastructure, which allows the use of cyberspace, information resources and services gathered in it, operating thanks to it. The infrastructure functioning in CRP allows the State to fulfil its constitutional obligation to the citizen, ensures continuity and effectiveness of government administration as well as uninterrupted and efficient development of the economy of the Republic of Poland. Polish government sees the need to introduce measures aimed at ensuring the security of the State ICT infrastructure, namely ensuring the correctness and continuity of functioning of ICT systems, facilities and installations used to implement the constitutional duties of the State to the citizens and its internal security. For this purpose it is necessary to determine the minimum security standard which will allow for the implementation of this objective and will reduce to the minimum potential damage which may be entailed by attack on individual elements of cyberspace of RP. The Policy is the basis for developing the concept of management of infrastructure security functioning within CRP and developing guidelines for the creation of the legal basis serving the implementation of tasks in this regard by the government administration. The principles of ensuring cyberspace security developed under the cooperation referred to in point 4.4, within the infrastructure of CRP are also recommended to entrepreneurs. The actions concerning the security of ICT infrastructure will be complementary to the efforts aimed at protection of the critical infrastructure of the State. In this respect, the Policy does not affect the provisions contained in the National Critical Infrastructure Protection Programme. The Policy indicates the need to develop the concept of ensuring security of infrastructure functioning within CRP and prepare legal basis for performance of tasks in this regard by the government administration. The ICT infrastructure of CRP must be protected against attacks from cyberspace, destruction, damage or unauthorized access. As a part of actions connected with the implementation of the Policy a risk assessment is carried out with regard to the identification of resources, sub-systems, functions and dependencies on other systems relevant to the functioning of CRP. At the same time, the implementation of the Policy will allow for the development of target guidelines for performance of risk estimates and model of reports containing general data on types of risks, threats and vulnerabilities identified in each of the sectors of the Polish economy in relation to the constitutional tasks carried out on the basis of CRP. There is a need to develop, on the basis of the conducted risk analysis, the minimum safety standards according to which the identified resources and systems will be protected, thanks to which the constitutional obligations of the State are fulfilled. Ministry of Administration and Digitisation, Internal Security Agency Page 9 of 24

Select target paragraph3