-
drafting a proposal for the organisation and content of trainings;
-
draft training programme;
c) preparation of a pilot project for the information security training of lay users/IT
specialists from public administration.
4. To draft an action plan to the National Strategy for Information Security in the Slovak
Republic for the 2008-2013 period;
5. To prepare an overview of standardisation activities in the field of information
security. The aim of this task is to summarise all information security norms which
Slovakia might find useful, both the existing ones and those under preparation; what is
the situation with information security norms and standards in Slovakia; who is
responsible for their publication. Outcomes of this project could serve as a basis for
updating STN applicable to information security; aligning and improving publication
of norms and standards in Slovakia; as well as for Slovak activities in international
standardisation organisations. The output will be an analytical study with the
following content:
-
a summary of relevant international standardisation organisations and Slovak
representation therein;
-
a summary of competences of Slovak organisations in standardisation
activities;
-
a summary of existing Slovak norms (currently applicable as well as to be
cancelled);
-
a list of norms which need be included into STN;
-
a summary of useful standards which, however, are impossible to be included
into STN;
-
an analysis of the current state of play, shortcomings and a proposal on how to
address the existing situation in standard-setting in the field of information
security in Slovakia.
Based on this overview, a proposal could be made on the allocation of competences in
standardisation activities and coordination of updates to existing and/or publication of
new norm and standards.
6. To analyse the situation in information security in Slovakia. Four basic sources of
information may help to characterise the situation in information security:
12
-
published studies, statistics, analyses from domestic and foreign sources;
-
internal analytical studies (focused either on an system or product analysis or
on a survey into situation in selected NICI segments);
-
data from security incident monitoring;
-
obligatory reports, for example on the computer programmes used, security
solutions, security incidents, etc. 12
this source of information could be used at least in the state segment of the NICI
18