National Cyber Security Centre

National Cyber Security Centre

8.39 The National Cyber Security Centre performs a critical “whole-of-government” function. However, the level of resourcing in the first four years was significantly less than that initially envisaged.

Recommendation 8.1

It is recommended that the Department conducts a review of the resourcing of the National Cyber Security Centre in order to ensure that it is adequate to meet its obligations and development objectives.

Accounting Officer response

Agreed.

Reviews of the resourcing (people and ICT) of the National Cyber Security Centre have been conducted on a regular basis as part of the annual estimates process and most recently in 2017 as part of the assessment of requirements for the implementation of EU Directive on the Security of Network and Information Systems. Additional staff were recruited to the National Cyber Security Centre in 2017, and in line with the Department’s 2018 Workforce Plan, a further significant cohort of staff, including a Director and Chief Technology Officer, will be recruited in 2018/2019. The issue of resourcing will be examined again in the context of the 2018 National Cyber Security Strategy.

8.40 The overall strategic direction of the National Cyber Security Centre is not clear. There is no strategic plan currently in place. Not all objectives in the previous strategy were achieved. The new timelines for delivery of these objectives and the relative priorities have not been set down. Where resources are limited, such clarity is particularly important.

Recommendation 8.2

It is recommended that an updated strategy document be finalised, which sets out objectives and related key performance indicators aligning them to planned and available resources.

Accounting Officer response

Agreed.

The context in which the 2015 Strategy was drafted ceased to apply very quickly. In the first instance, while the Strategy anticipated the Network and Information Systems Directive itself, the finalised Directive was substantially different from the draft that existed in mid-2015, both in terms of how critical infrastructure was to be treated and critically, due to the inclusion of the DSPs components.

The National Cyber Security Centre has always sought to benchmark itself against international best practice. The model outlined in the 2015 Strategy represented best practice given the threat environment at the time, but this changed substantially thereafter. Nationally, we have been involved in responding to incidents that were entirely unanticipated at the time of drafting; it was clearly not possible to ignore these. Entities such as the National Cyber Security Centre have to remain flexible and adaptive in order to remain effective. This reflects international experience also — in the global CSIRT community, focus has shifted significantly in the last number of years and we have followed suit to target our resources at the most pertinent threats.

Within the international CSIRT community, there is large-scale adoption of open-source technology and in-house tool development, at least in part due to the need to avoid vendor risk. While other areas of the public sector can incur significant expenditure on consultancy and software licencing and support, the National Cyber Security Centre has adopted a policy of using open-source technology, where possible. The traditional notion that increased current or capital spending correlates directly with output or capacity does not hold true for CSIRTs and National Cyber Security Centres in general.

As such, the strategic direction of the National Cyber Security Centre is entirely clear, and the general thrust of the 2015 strategy holds — to build capacity and to prepare for the entry into force of the Network and Information Systems Directive. However, circumstances have required that the roles and functions of the National Cyber Security Centre develop in somewhat different ways to that envisaged in the 2015 strategy. A National Cyber Security Strategy is one of the requirements of the Network and Information Systems Directive, and work is already underway on a revised strategy which is expected to be completed by the end of 2018. A steering group will be established to bring all relevant stakeholders together in order to fully inform the process. This strategy will capture developments in the cyber security area, and within the National Cyber Security Centre, and will set out governance arrangements for the centre, including how the National Cyber Security Centre functions with regard to the Government’s Cabinet Committee F.

The memorandum of understanding with An Garda Síochána envisioned in the National Cyber Security Strategy remains outstanding. Clarification regarding the roles of each entity should facilitate effective and efficient investigation of cyber crimes and national security incidents.

Measures relating to national cyber security

Recommendation 8.3

It is recommended that the Department agree a memorandum of understanding with An Garda Síochána in order to ensure that resources and capabilities can be deployed in a targeted and efficient manner.

Accounting Officer response

Agreed.

A draft memorandum of understanding was sent by the Department to An Garda Síochána in 2017, and discussions are ongoing with a view to its finalisation as soon as possible.

However, operational effectiveness is not impeded, in any way, by the absence of a formal memorandum of understanding and there is ongoing and positive engagement with An Garda Síochána, particularly in the areas of cyber crime and national security. There is also ongoing shared training and a member of An Garda Síochána is currently on secondment to the National Cyber Security Centre, with a second member to be seconded in the near future.

Pages 11–13 · View in original PDF