Annex no. 1: Interpretation of Selected Practically Used Terms “Asset”21 is anything of value for an individual, organization, or public administration. “Asymmetric Threat”22 is a threat resulting from the potential use of different means or methods to avoid and/or supress the strengths of the enemy while using their weaknesses to reach an inadequate result. “Attack”23 is an attempt to destroy, endanger, modify, put out, steal, or gain any benefit by unauthorized access and/or unauthorized use. It is the performance of an offensive action against a set target6. “Critical Information and Communication Infrastructure”21 is the set of systems, infrastructures, networks and services of information and communication technologies that would, if disturbed, damaged, or unavailable, seriously impact the operation of other sectors of critical infrastructure and of social functions of vital importance, including national, economic and public security. “Critical Infrastructure”21 means the systems and services whose failure and/or incorrect operation would significantly impact the security of the state, its economy, public administration and as a consequence, the coverage of basic life needs of the population. The following 5 sectors are often defined in critical infrastructure: sector of information and communication technologies, energy sector, banking and finance sector, physical distribution (i.e. mainly transport systems) and sector of services significant for people. “Cyber Space”24 is a virtual space without borders, comprising worldwide interconnected networks of hardware, software and data. “Cyber Security”24 is a set of legal, organizational and technical measures protecting cyber space. “Cyber Attack”25 is an attack against an ICT infrastructure in order to damage it, destroy it, obtain sensitive or strategically important information, or influence the decision-making processes of the victim. Cyber attacks influence all operating domains and are most frequently used in the context of those with political and/or military motivation. “Cyber Defence”25 is a set of active and passive measures aimed at prevention of cyber attacks and mitigation of their consequences. Also the resistance of an entity against attack and the ability of efficient defence. “Incident”21 in the environment of information and communication technologies (hereinafter referred to as “ICT”) means each circumstance and/or event that is normally linked to outage of a network, services, or reduction of the quality thereof. “Incident Resolution”26 reactions to incidents. means all procedures supporting the analysis, monitoring and “Information Environment” is the sum of individuals, organizations and systems that collect, process, distribute and/or work with information. “Information Security”23 is a set of measures to ensure the integrity, confidentiality and accessibility of information, networks and information and communications systems. 21 Interpretation dictionary of Cyber Security, Second updated edition under the auspices of the National Cyber Security Centre of the Czech Republic and the National Security Authority of the Czech Republic, © Jirásek, Novák, Požár, Praha 2013. 22 Dictionary of Military Terminology of the Armed Forces of the Slovak Republic, Bratislava, 2007. 23 ISO IEC 27000:2014 Information technology-Security techniques – Information security management systems – Overview and vocabulary 24 https://ccdcoe.org/cyber-definitions.html 25 National Security Authority. 21 26 Directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security in the Union, COM (2013) 48 FINAL, Brussels, 2013.

Select target paragraph3