b) existing Slovak standards; c) international standardisation organisations; d) international standards that Slovakia should adopt; e) de facto standards11, f) Slovakia’s capacities for competent standardisation activity; g) Slovak representation in international standardisation organisations and initiatives. Based on this overview, a proposal could be made on the allocation of competences in standardisation activities and coordination of updates to existing and/or publication of new norms and standards, as well as a mechanism to control the compliance with the existing norms and standards. 3.4.3 Knowledge building and dissemination Knowledge building and dissemination is a precondition for improving employees’ qualification and level of expertise in information security. This mainly involves production of knowledge, which is a result of a creative, scientific and technical research. Knowledge dissemination, i.e. reproduction, is related to education and training in educational institutions. Knowledge of information security can be categorised as follows: a) general basic knowledge – on a level of a user who needs to know what to do and what not to do, but does not need to understand causes in detail; b) general IT knowledge – on a level of an IT specialist, but not an information security expert, who knows the system, is able to implement and maintain its security mechanisms based on recommendations (security policies) and transform security requirements into system operating rules; c) specialised security knowledge – on a level of an information security expert who can analyse the system and its security environment, perform a risk analysis and propose measures to eliminate risks, or comprehensively assess system security (auditor); The expert is familiar with the existing situation and trends in threats and security solutions, managerial and legal aspects of information security, and is capable of producing conceptual materials; d) application security knowledge – on a level of an expert in a different field (lawyers and investigators in particular) who, when performing his/her tasks, needs to understand the nature of security problems and is able to cooperate with specialists at all levels; e) innovative knowledge – on a level of a research specialist in information security (or some of its sub-fields) enabling him/her to find fundamentally new solutions. Along with IT and expert training, language skills are equally necessary; in Slovakia, due attention should be given to education in all aforementioned categories. 3.4.4 International cooperation 11 generally accepted technical norms which, formally, do not have the status of a standard (e.g. PKCS in the case of electronic signature and cryptology) 15

Select target paragraph3