Policy Paper on Cyber Security 2015 - 2017 objective, another very important aspect in addition to the protection of these critical systems, is the “resilience”, which will ensure continuity of business activities in cases of force majeure or different cyber attacks. The protection and resilience capacity of critical infrastructure and encouraging operators that own them to implement a full security architecture (including risk management and emergencies) will ensure effectivity, reliability and continuity of services that are provided by them. c) Defining the legal/regulatory basis, based on which the providers of critical infrastructures should report about serious cyber incidents. An analysis should be conducted for every case (which is reported or not) as cyber crime, the reasons why did it happened and actions that should be generated and reflected into laws, regulations or procedures, in order to avoid the recurrance of the incident. Developing and implementation of the minimum requirements on cyber security The increase of the security in the state administration, the increase in the use of ICT systems in the public administration and also ensuring their security is one of the priorities of this Document. a) Standards, guidelines and procedures based on the best international practices will be aligned and approved in order to be implemented in the public administration. b) It is a priority to develop and approve risk analysis procedures concerning security for the systems that are used and electronic services that are provided by institutions. The risk analysis will be an ongoing process and it will be conducted periodically. The implementation of these procedures will be one of the key elements to increase the level of cyber security. c) Further development of procedures to coordinate investments in order to analyse security and harmonize projects at the design stage will be assessed. d) Important systems will be identified in the state administration and institutions will invest in automated hardware and software as proactive and reactive ensure these systems they administer. e) The BCC (Business Continuity Center) and DRC (Disaster Recovery Center) will be set up for networks / state systems. 24

Select target paragraph3