1.1. Definitions The meaning of terms and abbreviations used in this document: Abuse – a common name of a security department of an internet service provider who manages the computer security incident response process and the examination of complaints of abuse, cyberspace security – a set of organizational and legal, technical, physical and educational projects aimed at ensuring the uninterrupted functioning of cyberspace, CERT (Computer Emergency Response Team), CSIRT (Computer Security Incident Response Team) – a team set up to respond to incidents violating security on the Internet, cyber attack – an intentional disruption of the proper functioning of cyberspace, cybercrime – an offence committed in cyberspace, cyberspace – a space of processing and exchanging information created by the ICT systems, as defined in Article 3 point 3 of the Act of 17 February 2005 on the informatization of entities performing public tasks (OJ No. 64, item 565, as amended), together with links between them and the relations with users; in accordance with Article 2 paragraph 1b of the Act of 29 August 2002 on martial law and the powers of the Supreme Commander of the Armed Forces as well as the Commander’s subordination to the constitutional authorities of the Republic of Poland (OJ No. 156, item 1301, as amended), Article 2 paragraph 1a of the Act of 21 June 2002 on the state of emergency (OJ No. 113, item 985, as amended) and Article 3 paragraph 1 point 4 of the Act of 18 April 2002 on the state of natural disaster (OJ No. 62, item 558, as amended), cyberspace of the Republic of Poland (hereinafter referred to as CRP) –cyberspace within the territory of the Polish state and beyond, in places where the representatives of the RP are functioning (diplomatic agencies, military levies), cyberterrorism – an offence of a terrorist nature committed in cyberspace, computer security incident – a single event or a series of adverse events related to information security which pose a significant likelihood of disruption of business operations and jeopardize the security of information (according to the PN-ISO/IEC 27000 norm series), organizational unit – an organizational unit within the meaning of the Act of 23 April 1964 – Civil Code (OJ No. 16, item 93, as amended), PCS – a plenipotentiary for cyberspace security in organizational units of public administration, entrepreneur – an entrepreneur within the meaning of Article 4 of the Act of 2 July 2004 on freedom of economic activity (OJ of 2010, No. 220, item 1447, as amended) or any other organizational unit, regardless of the form of ownership, risk assessment – means the total risk analysis, which consists of: risk identification Ministry of Administration and Digitisation, Internal Security Agency Page 5 of 24

Select target paragraph3