National Cyber Security Strategy 2015-2017
8.15 The National Cyber Security Strategy (published July 2015) sets out 12 measures to be achieved over the lifetime of the strategy. A National Cyber Security Strategy Implementation Plan was also developed in 2015, setting out key targets and notes that reaching these targets will ensure all measures will be addressed.
8.16 An assessment of progress in achieving the measures set out in the strategy, based on the targets set out in the implementation plan, is summarised in Figure 8.4. As at May 2018, four measures had been completed, four measures had been partially implemented, and four measures had not been implemented.
8.17 The existing strategy covers the period 2015 to 2017. The Department has indicated that it expects to publish a new National Cyber Security Strategy by the end of 2018.
Measures relating to national cyber security
Figure 8.4 Progress assessment of strategy measures, as at May 2018
Establish the National Cyber Security Centre (NCSC) within the Department
Accreditation of the Computer Security Incident Response Team — completed
| Network and information security for public bodies | |||
|---|---|---|---|
| Three specific training programmes were envisaged for key personnel in government | |||
| departments. These programmes had not been rolled out. | |||
| A security incident and event management system was not in place | |||
| Provision of threat information through an ‘alerts and advisory’ mechanism to public | |||
| sector participants was in place |
Coherent international engagement
Contribution to the board of management of European Agency for the Security of Network and Information Systems was in place
Bilateral engagement ongoing. NCSC participates in a number of working groups and workstreams
| Fully implement the EU Directive by primary legislation | |||
|---|---|---|---|
| The deadline for transposition was 9 May 2018. Transposition was achieved on 18 | |||
| September 2018. |
National security and policing
The Strategy committed to a memorandum of understanding with An Garda Síochána — not completed
| Cybercrime | |||
|---|---|---|---|
| The Strategy committed to a memorandum of understanding with An Garda Síochána — | |||
| not completed |
Civil-military cooperation
Service level agreement and a memorandum of understanding in place with the Department of Defence and Defence Forces
| Protection of critical national infrastructure | |||
|---|---|---|---|
| No mandatory reporting obligations as the Directive had not been transposed | |||
| Provision of threat information through an ‘alerts and advisory’ mechanism in place | |||
| The establishment of a Critical Information Infrastructure Initiative — a forum of critical | |||
| system operators — not achieved |
Information sharing
Engagement with industry and public sector bodies through agreed and established information sharing mechanisms
Public engagement delivered by the Department’s Press Office
| Education and training | |||
|---|---|---|---|
| Development of accredited training programmes with academic partners — not delivered | |||
| Structured exercises for critical national infrastructure operators ongoing |
Public awareness
‘Make IT secure’ website was operational during the period from 2012 to early 2018
Further campaigns to raise public awareness — outstanding
| Relationship with third-level institutions | |||
|---|---|---|---|
| A ‘cyber security group’ to be developed to lead interaction within the sector — not | |||
| achieved | |||
| The “use of memoranda of understanding…to support the developing research agenda in | |||
| [the] sector” was envisaged, but had not been provided | |||
| Relationship with UCD Centre for Cyber Crime Investigation not formalised |
Source: National Cyber Security Strategy Implementation Plan 2015. Analysis by the Office of the Comptroller and Auditor General.
Note: Complete Partial progress Not complete
Network and Information Systems Directive
Pages 4–6 · View in original PDF