3.1 Building an Institutional Framework for Cyber Security Administration
The Concept proposes the structure of cyber security administration as shown in Figure no. 1.
Government of the Slovak
Republic, Security Council of
the Slovak Republic,
Committee for Cyber Security
National CERT/CSIRT
Ministry of Finance
Ministry of the Interior
Other central state
authorities
Information systems
of public administration
Information systems
of critical infrastructure
Other information
systems (outside ISPA and CI),
communication systems,
networks, etc.
Government CERT/CSIRT
CERT/CSIRT XY
Sector oriented authority
for cyber security cyber
security
Special units
for resolving incidents
CERT – Computer emergency response team
CSIRT – Computer Security Incident Response Team
Figure no. 1 Proposed framework structure for managing cyber security
Cyber security at a national level belongs to the scope of powers of the relevant central state
administration body, with competences and powers defined in general by the Competence Act and
specifically by a special law (Cyber Security Act). The scope and method of the exercise of public
authority in the area of cyber security by relevant central state administration bodies and other
state bodies in the framework of specific material areas of administration of the state’s socioeconomic environment (hereinafter referred to as “material areas”) will be defined by a special law
(Cyber Security Act).
Complex provision for cyber security within individual material areas must be performed by the
exercise of public authority and exercise of special activities. The Concept foresees that a National
Incident Resolution Unit and several incident resolution units in material areas of special importance
(hereinafter referred to as the “units”) will be formed. To use human capacities rationally and use
the technological equipment of the unit efficiently, the Concept foresees the formation of common
units for other material areas; the National Incident Resolution Unit can hold the authority in
certain material areas. The competences and authority of the National Incident Resolution Unit and
of the units will be defined by the Cyber Security Act.
The Concept proposes the following framework definition of the powers and competences of public
administration bodies in the area of cyber security at a central level:
Central state administration body for cyber security – the authority of an existing non-sectoral
central state administration body18 extended by another segment of state administration. The
Concept recommends that the lawmaker entrusts this authority to the National Security Authority.
11
18 I.e. a state body whose powers do not relate to a specific material area of administration of the state’s socio-economic environment. E.g.:
Office of Government of the SR, National Security Authority.