– greater confidence of the citizens in the proper protection of the state services provided by electronic means, – greater public awareness as to the methods of the safe use of systems available electronically and ICT networks. 6.2. Effectiveness of actions The measure of effectiveness of actions undertaken as a part of the Policy will be the assessment of the created regulations, institutions and relationships which will enable the actual existence of an effective cyberspace security system. One of the basic methods of influencing the effectiveness of the planned activities performed by many institutions is to establish the scope of tasks of each of the entities and to determine the responsibility for their implementation. 6.3. Monitoring the effectiveness of actions as a part of the adopted Policy Reports on the progress of implementation of the Policy will be sent by the bodies mentioned in point 1.4 to the minister responsible for informatization. 6.4. Consequences of violating the provisions of the Policy Each government administration entity shall apply the provisions of this Policy, regardless of liability specified in the provisions of generally applicable law. Violation of the rules set out in this Policy may result in the exclusion of the entity from the information society and emergence of barriers in access to public information. Adequate protection, security of the processed data and reliability of the ICT systems are the highest values faced by the modern systems. Entities implementing the Policy in question should indicate ways for securing information systems, procedures for the ICT security breach in information systems in security policies of these systems. The implementation of the provisions of this document is to provide an adequate response, evaluation and documentation of cases of the system security breaches and ensure an appropriate way of responding to incidents in order to restore an acceptable level of security. An important obligation is to immediately inform an administrator or an appropriate CERT about detected incidents and take or refrain from actions aimed at handling them. Page 24 of 24 Ministry of Administration and Digitisation, Internal Security Agency

Select target paragraph3