11.07.2015 Views

syssec_red_book

syssec_red_book

syssec_red_book

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

24. Cyber Security Strategy• All relevant actors (public authorities, private sector and individualcitizens) share responsibilities to protect themselves and strengthen cybersecurity.24.2 Strategic PrioritiesIn order to achieve the goal of a safer EU online environment, the EuropeanCommission identified the following five strategic priorities:1. Achievement of Cyber Resilience. Progress in this area has alreadybeen made based on voluntary commitments. The EU proposes to closegaps when it comes to national capabilities and coordination in the caseof incidents across borders or in terms of private sector involvementand prepa<strong>red</strong>ness. The strategy includes a proposal for legislation to(i) establish requirements and strategies for Network and InformationSecurity (NIS) at the national level and the need to set up a ComputerEmergency Response Team (CERT) in each member state, (ii) fosterthe coordination of cyber security measures and information sharingamongst national NIS authorities, and (iii) improve the prepa<strong>red</strong>nessand engagement of the private sector by increasing incentives for privateactors to embrace a cyber security culture.Furthermore, the strategy details the need to raise end users’ awarenessof cyber security by publishing reports, organizing expert workshopsand developing public-private partnerships.Proposed Actions: The EC should continue to identify vulnerabilities ofcritical infrastructure. The EC will also launch a pilot project for fighting botnetsand malware via cooperation between member states, the private sector andinternational partners. ENISA should assist member states in building securityexpertise and improving the resilience of critical infrastructures. The industryshould invest in cyber security and develop best practices and informationsharingmechanisms with public authorities. In order to raise awareness, theEC proposes, amongst other things, to increase national efforts towards NISeducation and training. Finally, the industry should also promote cyber securityawareness and reflect on the accountability for ensuring cyber security.2. Drastic Reduction of Cybercrime. Law enforcement should adopt across-border approach to respond to cybercrime through: (i) passinglegislation such as the Council of Europe Convention of Cybercrime(Budapest Convention) and a Directive on attacks against informationsystems, especially through the use of botnets; (ii) enhancing operationalcapabilities to combat cybercrime and the use of state-of-the-artoperational tools; and (iii) improving coordination at EU level.142

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!