c) to assess the existing competences and determine responsibility/define duties of
state authorities in the area of information security;
d) to harmonize STN (Slovak Technical Norms) with the applicable international
information security standards; coordinate issuing of information security
standards in Slovakia;
e) to create a uniform methodology of non-classified information and information
and communication systems security categorisation;
f) to prepare basic ICT security requirements mandatory for the state ICI, and
optional for other NICI components (mainly for e-Health, e-Government system
and KRIS), compatible with international norms and standards.
g) to prepare and make available methodology materials with a goal to achieve the
required/basic level of information security (guidelines and best practices); to
promote convergence of best-practice based security procedures applied by the
state and private sector;
h) to promote solutions and services based on available (open) standards in order to
improve availability of security solutions to small businesses and individuals;
i) to engage the commercial sector and expert public in the process of drafting and
reviewing conceptual documents, norms and standards; to create room for
knowledge and experience exchange.
3.2.4
Improvement of effectiveness in information security management
In order to achieve and retain the required level of information security it is necessary
to coordinate the protection of organisation’s assets and, at the same time, develop an
effective system of its management. Improving the quality of management requires that
institutions would be provided with not only the methodological assistance while solving
conceptual issues, but also with the support in solution of particular urgent problems
(including preparation of regulations, methodology documents and trainings, as well as advice
and technical assistance). In this respect, security level should be monitored and evaluated,
with respective statistics on security incidents being provided to target groups, in order to
make management more effective. The following tasks should be set in order to resolve the
aforementioned problems:
a) threat monitoring;
b) creation of an early warning system (notification of target groups about existing
threats, warning of possible target groups, alarm signalling);
c) help with security incidents solutions;
d) identification, recording and evaluation of security incidents;
e) monitoring effectiveness of measures proposed to resolve security incidents;
f) coordination of security strategies of individual NICI system to ensure cooperation
in NICI management.
3.2.5
Ensurance of sufficient protection of state ICI and ICI supporting the state
critical infrastructure
11