of activities of the institutions carrying out the tasks imposed by the Policy, organization
of regular meetings, recommending the proposed solutions for the security of CRP.
It is assumed that as for the implementation of tasks related to the security of CRP
in the area of government administration and the civil area, the role of the main CERT
is performed by the Governmental Computer Security Incident Response Team CERT.
GOV.PL. Similarly, in the military this role is performed by “Departmental Centre for
Security Management of ICT Networks and Services.”
3.4.2. The safety management system in organizational unit
In each organizational unit of government administration, as a part of ensuring
the cyberspace security, the head of the unit should establish an information security
management system, in accordance with the applicable provisions and best practice.
It is assumed that the public body will develop and modify according to the needs,
and implement a security policy for ICT systems used by it for the execution of public
tasks. While developing the security policy a public body includes obligations arising
from the Act of 17 February 2005 on the informatization of entities performing public
tasks (OJ No. 64, item 565, as amended) concerning the minimum requirements for
ICT systems in the field of information security.
In order to ensure consistency of information security policies of organizational
units, it is assumed that the minister responsible for informatization in consultation
with the Minister of National Defence and the Head of the Internal Security Agency
may prepare guidelines for information security management systems.
3.4.3. The role of plenipotentiaries for cyberspace security
The organizational units of government administration should define the role of a
plenipotentiary for cyberspace security (hereinafter referred to as PCS).
The tasks of a plenipotentiary within the scope of cyberspace security shall include
in particular:
1) implementation of the obligations arising from the provisions of legal acts
relevant to ensure cyberspace security;
2) development and implementation of procedures for responding to computer
incidents which will apply in the organization;
3) identification and conducting periodic risk analyses;
4) preparation of emergency plans and testing them;
5) development of procedures to ensure information of appropriate CERTs about:
a) the occurrence of computer incidents,
b) the relocation of an organizational unit, contact information, etc.
The Policy does not indicate the location of a plenipotentiary for cyberspace security
in the structure of an organizational unit, however, the role of a plenipotentiary should
be assigned to the person responsible for carrying out the process of ICT security.
Page 12 of 24
Ministry of Administration and Digitisation, Internal Security Agency