Governance and oversight
8.30 The Government decision in July 2011 approving the National Cyber Security Centre also approved the setting up of an interdepartmental committee to set and implement policy in relation to addressing the challenges of cyber security in Ireland. The group first met in December 2013. Minutes of only one meeting, dated February 2014 (noted as the third meeting) were available for review. The Department has indicated that its records suggest that the group met five times.
8.31 The National Cyber Security Centre Strategy Implementation Plan (2015) states that the overarching governance structure for the National Cyber Security Centre will remain the interdepartmental high level steering group, indicating the group would be reoriented to function as the oversight mechanism for all the work of the National Cyber Security Centre. The Department states that the committee has not met since the strategy was published in 2015.
8.32 The Department states that the committee consisted of an Assistant Secretary from the Department and the Department of the Taoiseach, an Assistant Commissioner from An Garda Síochána, a Principal Officer of the Department of Justice and Equality, a Colonel from the Defence Forces and a Counsellor from the Department of Foreign Affairs and Trade.
8.33 The Department stated that the Assistant Secretary with responsibility for telecommunications has policy and operational responsibility for the National Cyber Security Centre. The Secretary General is also briefed regularly on developments. There were no minutes or other evidence provided as to the regularity of briefings.
8.34 The Department stated that its Management Board considers cyber security from time to time. The Department provided the relevant extracts from the minutes of Management Board meetings (summarised in Figure 8.8).
Figure 8.8 Summary of Management Board minutes 2015 — June 2018
Meeting dates Points recorded as having being discussed
| 2015 — June | Memo for Government relating to publishing the cyber security | ||
|---|---|---|---|
| strategy. Delivery of the associated implementation plan. |
2016 — January Update provided on attacks on Government websites
| 2017 — Jan, | Update from HR on progress with recruitment competitions for | ||||
|---|---|---|---|---|---|
| Feb, Mar, May | cyber security functions |
2018 — April Strategic priorities were discussed and agreed that the next presentation in May would cover cyber security
| — May | Detailed presentation on the National Cyber Security Centre | ||
|---|---|---|---|
| (NCSC) and its operations to date |
— June Update on accommodation and reference to additional NCSC staff
Source: Department of Communications, Climate Action and Environment
Measures relating to national cyber security
8.35 The Department further stated that a component for the next strategy will be the governance and oversight arrangements for the unit, based on international best practice and a draft organisation structure has already been considered by the Department.
8.36 The National Cyber Security Strategy Implementation Plan commits to publishing an annual report and to conducting a formal impact assessment of their work in late 2017. These are outstanding, though the work of the Centre is outlined in the Department’s annual report.
8.37 The Department’s Strategy Statement 2016 — 2019 outlines two performance indicators related to the work of the National Cyber Security Centre
implementation of the EU Network and Information Systems Directive
services response capacity developed to be able to engage in cyber security actions.
8.38 An assessment of the Centre’s performance was formally requested from the Department. No evidence of an assessment having been carried out was provided. The Department stated that performance assessment of the work of the National Cyber Security Centre formed part of the normal performance management and corporate governance of the Department.
Pages 10–11 · View in original PDF