of activities of the institutions carrying out the tasks imposed by the Policy, organization of regular meetings, recommending the proposed solutions for the security of CRP. It is assumed that as for the implementation of tasks related to the security of CRP in the area of government administration and the civil area, the role of the main CERT is performed by the Governmental Computer Security Incident Response Team CERT. GOV.PL. Similarly, in the military this role is performed by “Departmental Centre for Security Management of ICT Networks and Services.” 3.4.2. The safety management system in organizational unit In each organizational unit of government administration, as a part of ensuring the cyberspace security, the head of the unit should establish an information security management system, in accordance with the applicable provisions and best practice. It is assumed that the public body will develop and modify according to the needs, and implement a security policy for ICT systems used by it for the execution of public tasks. While developing the security policy a public body includes obligations arising from the Act of 17 February 2005 on the informatization of entities performing public tasks (OJ No. 64, item 565, as amended) concerning the minimum requirements for ICT systems in the field of information security. In order to ensure consistency of information security policies of organizational units, it is assumed that the minister responsible for informatization in consultation with the Minister of National Defence and the Head of the Internal Security Agency may prepare guidelines for information security management systems. 3.4.3. The role of plenipotentiaries for cyberspace security The organizational units of government administration should define the role of a plenipotentiary for cyberspace security (hereinafter referred to as PCS). The tasks of a plenipotentiary within the scope of cyberspace security shall include in particular: 1) implementation of the obligations arising from the provisions of legal acts relevant to ensure cyberspace security; 2) development and implementation of procedures for responding to computer incidents which will apply in the organization; 3) identification and conducting periodic risk analyses; 4) preparation of emergency plans and testing them; 5) development of procedures to ensure information of appropriate CERTs about: a) the occurrence of computer incidents, b) the relocation of an organizational unit, contact information, etc. The Policy does not indicate the location of a plenipotentiary for cyberspace security in the structure of an organizational unit, however, the role of a plenipotentiary should be assigned to the person responsible for carrying out the process of ICT security. Page 12 of 24 Ministry of Administration and Digitisation, Internal Security Agency

Select target paragraph3