版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進(jìn)行舉報或認(rèn)領(lǐng)
文檔簡介
GenevaCentre
forSecuritySector
Governance
CybersecurityPolicyDevelopmentandCapacityBuilding–
IncreasingregionalcooperationintheWesternBalkans
Dra?enMaravi?
1
AboutDCAF
DCAF–GenevaCentreforSecuritySectorGovernanceisdedicatedtoimprovingthese-curityofstatesandtheirpeoplewithinaframeworkofdemocraticgovernance,theruleoflaw,respectforhumanrights,andgenderequality.Sinceitsfoundingin2000,DCAFhascontributedtomakingpeaceanddevelopmentmoresustainablebyassistingpartnerstates,andinternationalactorssupportingthesestates,toimprovethegovernanceoftheirsecuritysectorthroughinclusiveandparticipatoryreforms.Itcreatesinnovativeknowledgeprod-ucts,promotesnormsandgoodpractices,provideslegalandpolicyadviceandsupportscapacity-buildingofbothstateandnon-statesecuritysectorstakeholders.
DCAF’sFoundationCounciliscomprisedofrepresentativesofabout60memberstatesandtheCantonofGeneva.Activeinover80countries,DCAFisinternationallyrecognizedasoneoftheworld’sleadingcentresofexcellenceforsecuritysectorgovernance(SSG)andsecuritysectorreform(SSR).DCAFisguidedbytheprinciplesofneutrality,impartiality,lo-calownership,inclusiveparticipation,andgenderequality.Formoreinformationvisitwww.dcaf.chandfollowusonTwitter@DCAF_Geneva.
DCAF-GenevaCentreforSecuritySectorGovernance
MaisondelaPaixCheminEugène-Rigot2E
CH-1202Geneva,Switzerland
Tel:+41227309400
info@dcaf.ch
www.dcaf.ch
Twitter@DCAF_Geneva
2 CybersecurityPolicyDevelopmentandCapacityBuildingintheWesternBalkans
Contents
EXECUTIVESUMMARY 4
INTRODUCTION 5
COUNTRYOVERVIEW 9
Albania 9
BosniaandHerzegovina 10
Kosovo* 11
Montenegro 12
NorthMacedonia 13
Serbia 13
REGIONALOVERVIEW 15
WAYFORWARD 18
ThisdesignationiswithoutprejudicetopositionsonstatusandisinlinewithUNSCR1244(1999)andtheICJOpinionontheKosovodeclarationofindependence.
3
EXECUTIVESUMMARY
TheDeclarationof2020ZagrebSummitbetweentheEuropeanUnion(EU)andWesternBalkanleadernotesthatso-calledhybridactivitiesoriginatingfromthird-stateactors,in-cludingdisinformationaroundCOVID-19,havebecomeincreasinglyprevalentintheWest-ernBalkans.Suchincidentsexposethevulnerabilityofsocietiesandinfrastructuretocy-berattacks,cybercrimeandhybridthreats.TheDeclarationcallsforincreasedcooperationtoaddressdisinformationandotherhybridactivities.
TheDigitalandGreenAgendafortheWesternBalkans,theRegionalCooperationCouncil(RCC),theRegionalSchoolofPublicAdministration(ReSPA)andotherregionalinitiativesprovideageneralframeworkforenhancedcooperation.ManyinternationalactorshavesupportedcybersecurityintheWesternBalkansovertheyears.Countriesoftheregionarealsoawareofthebenefitsofregionalcooperation.Closerregionalcollaborationwillthere-forebebeneficialforresiliencebuilding,enhancingcybersecurityandstrategiccommuni-cation.Thecybersecurityworkforceshortageandskillsgaparealsosignificantconcernsfortheeconomicdevelopmentandnationalsecurity,especiallygiventherapiddigitizationofglobalandregionaleconomies.Besides,slowprogressinpublicadministrationreformsishinderingprogressincybersecuritydevelopment.
Withclearpoliticalsupportandsharedownership,itwouldbepossibletocreatemorevitalregionalcollaboration,facilitatedbyacustomizedjointframeworkintheformofaregionalhub.WesternBalkaneconomiescouldhavearegionalframeworkforcooperationcommit-tedtosupportingandstrengtheningcybersecuritystrategies,policies,andcompetenceatalllevelsofpublicadministration,fromnon-expertstohighlyskilledprofessionals.Besides,thisregionalframeworkcouldsupporteconomiesoftheregioninraisingcitizens’aware-nessofcybersecurityandpotentialcyberthreatsandspeedupaligningcountries’align-mentwiththeEUacquis.
Economiesoftheregioncouldtaskthepotentialregionalcybersecurityhubtooperateacrossareaswhicharewithintheusualpracticesofnationalcybersecurityauthorities,andwithafocuson:
Providingthoughtleadershipandstrategicdevelopmentdirectionandanalysisinthecyber-securityspace.
Raisingcybersecurityawarenessatalllevelsofgovernment.
Sharinginformation,expertise,andknowledge;and
Establishingandpromotingbestpracticesbasedoncommonchallenges.
Finally,jointactivitiesinthisareacouldpotentiallycountonmoreconsiderabledonorsup-portiftheWesternBalkaneconomiesthemselvescontributeandcreategreatersustainabil-ityofregionalcooperationactivities.
4 CybersecurityPolicyDevelopmentandCapacityBuildingintheWesternBalkans
INTRODUCTION
TheCOVID-19pandemicisaglobalshockthathasnotsparedtheWesternBalkans(WB).Thefinalextentofitsfootprintintermsoflossofhumanlivesanddamagetotheeconomyisstilldifficulttoassess.However,earlyestimatesforeseeadropofbetween4%and6%ofgrossdomesticproductintheregion.DuringtheCOVID-19crisis,inclusiveregionalcoop-erationhasprovenessential.1AttheZagrebSummiton6May2020,theEuropeanUnion(EU)andWesternBalkanleadersagreedthatdeepeningregionaleconomicintegrationhastobeaprominentpartoftheWesternBalkansrecoveryefforts.2Suchacommonregion-almarketmustbeinclusive,basedonEUrulesandbuiltontheregionaleconomicareamulti-annualactionplan’sachievements.
TheZagrebSummitDeclarationnotedthathybridactivitiesoriginatingfromthird-stateac-tors,includingdisinformationaroundCOVID-19,havebecomeincreasinglyprevalentintheWesternBalkans(andTurkey).Suchincidentsexposethevulnerabilityofsocietiesandinfrastructuretocyberattacks,cybercrimeandhybridthreats.AsstatedintheZagrebDec-laration,theEUwillincreaseitscooperationwithWesternBalkaneconomiestoaddressdisinformationandotherhybridactivities.Closercollaborationisthereforemuchneededinresiliencebuilding,cybersecurityandstrategiccommunication.Thecybersecuritywork-forceshortageandskillsgapisasignificantconcernforeconomicdevelopmentandnation-alsecurity,especiallyintheglobalandregionaleconomy’srapiddigitization.
Therearedifferentopportunitiesforenhancedregionalcooperation.Thestartingpointforthisdeliberationcouldbetomaintainthestatusquo.OnedimensionistocontinuewiththeusualbilateralexchangeSbetweenthecountriesintheWBregionandthirdcountries.Secondly,existingregionalforumscouldbeusedforjointactivities,mainlyregardingre-searchactivities.Thishasbeenthecasesofarwithinthisfield,particularlybytheRegionalCooperationCouncil.Bilateralandmultilateraldonorscouldcontinuetoprovidesupporttoindividualcountries,butthiscouldleadtoparallelratherthanjointcapacitydevelopment.Also,existingdifferencesbetweenthecountriesandslowpaceofEUintegrationprospectsfortheregionasawhole,couldbereinforcediftheycontinuetodevelopnationalcapaci-tiesforcybersecurityattheirownpace,withoutthe(additional)possibilityofmakinglargerstepstogether.
Whilstmaintainingthestatusquo,itwouldbepossibletocreatemorevitalregionalcol-laboration,facilitatedbyacustomizedjointframework.WesternBalkancountriescouldhavearegionalframeworkforcooperationcommittedtosupportingandstrengtheningtheenhancementofcybersecuritystrategies,policies,andcompetenceatalllevelsofpub-licadministration,fromnon-expertstohighlyskilledprofessionals.Besides,thisregionalframeworkcouldhelpraisecitizens’awarenessofcybersecurityandpotentialcyberthreats(e.g.phishingattacks,botnets,financialandbankingfraud,datafraud).Itwouldbepossibletodesignregionalinformationcampaignsandtosupportpotentialnationalones,asdemon-stratedbytheDCAFregionalproject.Suchaframeworkcouldguideacceptablepracticestopromotesaferonlinebehaviour(e.g.cyberhygieneandcyberliteracy)usingbothgoodandbadexamplesfromanycountryintheregion.
Furthermore,aregionaleffortcouldhelptospeedupaligningcountries’actionswiththeEUacquis,andengageinpromotingandanalysingcybersecurityacademicandprofessionaleducationbydividingeffortsandspecializationsamongthenationsinsomeway.Finally,allcountriesintheregionsufferfromsimilarchallenges,suchasashortfallincybersecurity
1
2
2020CommunicationonEUenlargementpolicy,Brussels,6.10.2020COM(2020)660final.ZagrebDeclaration,6May2020.https://www.consilium.europa.eu/media/43776/zagreb-declara-tion-en-06052020.pdf
5
skills,whichcouldjeopardizebothnationalsecurityandeconomicdevelopment.Sincetherearemultipleeffortstoapproachtheregion’seconomicgrowth,suchasthemini-Schengeninitiative,theGreenAgendafortheWesternBalkansandothers,itisreasonabletocon-cludethatthesameapproachcouldworkforcybersecurityaswell.Regionalcooperationisvitaliftheeconomiesintheregionmovemorerapidlytowardsdigitalizationande-com-merce.Thispolicypaperaimstodocumentthekeyfeaturesofexistingregionalcooperationinpublicpolicydevelopmentandcivilservantcapacitybuilding,focusingoninstitutionsinchargeofcybersecuritypolicydevelopmentandincidentresponse,whilstprovidingpolicyadviceforfutureimprovements.
Publicadministrationreform(PAR)isessentialforimprovinggovernanceatalllevels.3Suchreformincludesincreasedtransparencyandaccountability,soundpublicfinancialmanage-ment,andadministrationofamoreprofessionalnature.Theexistingcapacitiesforgovern-mentalcybersecuritypoliciesarestronglyrelatedtothecountries’generalpublicadminis-trationreformdevelopments.ModesteffectsconcerningPAR(inareassuchaspublicpolicydraftingandimplementation,accountability,humanresourcesmanagement,andprofes-sionaldevelopmentofcivilservants),areinfluencingcybersecuritypolicies,capacitiesofleadinstitutions,andcybersecurityincidenthandlers.
TheannualEUassessment4isthatAlbania,NorthMacedonia,Montenegro,andSerbiaareonlymoderatelypreparedregardingpublicadministrationreform.InSerbianofurtherprog-resshasbeenmade,asthenumberofactingseniormanagerpositionsremainsexcessive,ratherthanbeingreduced.Kosovo*hasachievedsomelevelofpreparation,whileBosniaandHerzegovinaisatanearlystage.Therehasbeensomeprogressinimprovingpolicyplanning,butfurthereffortsareneededinallcountriestoensuresubstantialcentralgov-ernmentqualitycontrol.Montenegrohasstrengthenedandrationalizedpolicyplanningandachievedareductioninthenumberofstrategicdocuments.Policies,legislationandpublicinvestmentsarestilloftenpreparedwithoutimpactassessments.5Managerialaccountabil-ityandprofessionalizationofthecivilservicestillneedtobeensuredinmostcountries,andexcessivepoliticizationhastobeaddressed.Transparentandmerit-basedproceduresforrecruitment,promotion,demotionanddismissalneedtobeembeddedinthelegislativeframeworksandconsistentlyimplementedacrosspublicservices.Thestructureofthestateadministrationshouldensureeffectivelinesofaccountability.Mostcountrieshavemadeeffortstoimproveservicestocitizensandbusinesses,especiallyintheareaofe-servicedelivery.6TheEUhasconcludedthatenhancedinter-institutionalcoordinationisneededtofullyimplementpublicadministrationreformsintheWesternBalkans.
Nationalauthoritiesfocusingoncybersecurityshouldbasetheirworkonstrategiesandactionplansdevelopedinaninclusiveprocessthatbenefitsfrominputfromacademia,thebusinesssectorandcivilsocietyorganizations.Theyshouldhavesignificanthumanresources,bothintermsofnumbersofpersonnelandcompetences,andrelyonasolidretentionpolicytoenablelong-termdevelopmentstobeputinplace.Publicadministrationshavealwaysbeeninformation-processingorganizations.Ingeneral,publicadministrationbodiesmusthaveIT-relatedbusinessprocessesthataresecurebydesignandahighlevelofrelatedknowledgeforallmembersofthepublicadministration.Clearaccountabilityandreportinglinesforstaffareessential,andforallseniormanagersdealingwithsensitivepublicinformationandpersonaldata.Publicorganizationsaredealingwithahighvolumeofsensitivedataandmanyhavevulnerablecyberdefences,whichinsomecasesposesariskforregionalgovernmentorganizationsandthepublicsectoringeneral.
3
4
5
6
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52019DC0260
2020CommunicationonEUenlargementpolicy,Brussels,6.10.2020COM(2020)660FINAL.https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52019DC0260https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52019DC0260
6 CybersecurityPolicyDevelopmentandCapacityBuildingintheWesternBalkans
Furthermore,digitalizationofpublicadministrationservicesisavitalpriorityforWesternBalkancountries.Themoregovernmentorganizationsembracetechnology,themoreex-posedtheyaretothreatsincyberspace.Nowadays,digitalgovernmentagendasworld-wideseektokeepabreastofdigitalnetworkinganddigitalchangesinasocietybasedoninformationtechnology.Ever-increasingdigitalizationleadstofundamentalchangesinthebusinessprocessesofpublicadministrationsastheytrytooffercustomer-friendlyservicestocitizensandbusinesses.
Consideringthis,governmentsneedtoimplementnewsafeguardsintheformofcontinu-ousinformationsecurityandlegallycompliantdataprotection.Cybersecuritymeasuresarecontinuallyimproving.Justascriminalsaredevelopingunknownattackvectors,firewalls,encryptionandothersecuritymeasuresarebecomingmorerobust.Itwouldbeamistake,though,tothinkofthisasaprimarilytechnology-relatedissue.Thegreatestweaknessofpublicorganizationswillalwaysbethehumanfactor.Thebiggestthreatwillusuallycomefromwithin–eitherfromamaliciousactionorafundamentalhumanerror.
Attacksarestillmostlyduetosomeonemakingamistake–eitherrevealinginformationthroughanemailorclickingonasuspiciouslink.7Therefore,themostcrucialtoolforpro-tectinginternalsystemsistoensurethatstaffareadequatelytrained.Thiscanbeinitiatedbydevelopingacomprehensivetrainingprogrammeforeveryonefromtop-levelmanage-menttothemostjuniorofficeassistants.Theymustrealizetheimportanceoffollowingsecurityprotocols.
TheWesternBalkangovernmentsshoulddeveloprobustframeworksforcybersecurity,inlinewithEUstandards,includingadoptingstrategiesandactionplans.SincetheEUprescribesframeworkswhicharecontinuouslybeingdeveloped(forexample,theEUan-nouncedanewcybersecuritystrategy8inDecember2020),countrieswouldbenefitfromfollowingthesedevelopmentsand‘movingtargets’setbytheEU.Theroleoflineminis-triesistoensureafunctionallegalframeworkinlinewithEUlegislationandcybersecuritystrategies.Still,thereisusuallyadelayintheharmonizationprocess,duetotheheavynormativeagenda,politicalprocesses,frequentcallsforearlyelections,andotherchal-lenges,includingthelackofcivilservicemembersskilledincybersecurity.Besides,lineministriesshouldensureanadequatelevelofhumanresourcesforthecompetentauthor-itiestoensureeffectivecybersecurity,suchascomputersecurityincidentresponseteams(CSIRTs).AsdefinedbytheDirectiveonsecurityofnetworkandinformationsystems,thenationalcompetentauthorities,whichmaydifferfromthelineministryinchargeofpublicadministration,shouldensurepropercyberresilienceandcapacitytodealefficientlywiththreatsandattacks.Sincepublicadministrationreformrequiresastrongfocusonmultipledivergentissues(forexample,capacitybuildingvsdownsizingwithinthecivilservice),thiscouldproveademandingtaskfornationaladministrationsstrugglingtoenablebetterhor-izontalcooperationandawhole-of-governanceapproachtoreforms.Reinforcedregionalcooperationcouldproveusefultokeepthemomentumofcapacitybuildingincybersecurity,ifsomecountriesatagivenmomentfocusmoretowardsdownsizingtheiradministrationordecreasingwagesinordertomaintainfiscalstability.Thecompetentauthoritiescouldprovidemoreefficientregionalcooperation,andwiththeEU,whensupportedbyaneworenhancedregionalframeworkforcollaborationwiththelineministries.
ThefunctionofallCSIRTsinthesixWesternBalkancountriesisverysimilar,whichisun-surprising.TheyhaveallbeenstructuredprimarilyinlinewithEuropeanUnionAgencyforCybersecurityguidelines.9Therefore,itseemsthataregionalapproachmakessensebe-
7
8
9
https://www.itsecurityawareness.ie/public-administrationhttps://ec.europa.eu/commission/presscorner/detail/en/IP_20_2391https://www.enisa.europa.eu/
7
causeleadinginstitutionswithsimilarfunctionsandsetupsalreadyexist.Asingleregionaleffortcouldprovidemomentumandqualityassuranceincybersecuritypoliciesandpractic-esinsuchanenvironment.
8 CybersecurityPolicyDevelopmentandCapacityBuildingintheWesternBalkans
COUNTRYOVERVIEW
Albania
Albania10ismoderatelypreparedinthereformofitspublicadministration.Still,itcontinuestomakeeffortsinseveralrelatedareas.Albaniahasachievedprogressinenforcingtheguidelinesonregulatoryimpactassessmentsacrosslineministries,developingthelegisla-tivepackagerelatedtopolicyplanning,increasingthenumberofe-services,andimprovingtransparencyindatacollectionandhumanresourcesmanagementbetweenthecentralandlocallevels.Managerialaccountabilityisnotyetprotectedinthelegislationandinadmin-istrativepractice.Decisionmakingintheinstitutionsiscentralizedand,inpractice,amin-imalnumberofdecisionsaredelegated.Verticalaccountabilityisveryweakbetweenpoli-cy-makingandpolicy-implementingentities.Governancearrangementsensuringstrategicplanswithdefinedobjectives,performanceindicators,andprecisemonitoringandreportinglinesbetweenparentministriesandsubordinatedagencies,arestilllacking.
TheEUspecifiesintheprogressreportfor2020thatAlbaniashould11establishamoreef-fectivelaw-enforcementresponsefocusingonthedetection,traceabilityandprosecutionofcybercriminalsandaddressthegrowingphenomenonofchildpornographyonline.
TheAlbanianSchoolofPublicAdministration’s(ASPA)trainingprogrammescontributetotheprofessionaldevelopmentofcivilservants.However,anintegratedtrainingmanage-mentcyclestillneedstobeestablished.TheASPAhasdevelopedtwotrainingcoursesoncomputersecurity,a3-dayintroductorycourseanda2-dayadvancedlearningcourse.Withinthepublicinstitutions,trainingoncybersecurityissuesforITstaffandgeneralstaffisminimal.Itoftendependsontheinstitution’sindividualmanagementpolicy,todeterminewhetheraspecificstaffmembercanattendanavailablecybersecuritytrainingorcertifica-tioncourse.InternationallyaccreditedITsecurityandgovernancetrainingandcertificationcoursesarebeingofferedinAlbania.Asmentionedbythereviewparticipants,thepercep-tionofcybersecurityheldbytheprivatesectorboardsandCEOsrequiressignificantim-provement.AnotherconcernsharedbytheparticipantsisthechallengeofretainingsecurityprofessionalswithinAlbania,astheyoftenleavethecountrytoseekbetteropportunitiesintheEUorinNorthAmerica.12
TheLaw‘OnCyberSecurity’isonlypartlyalignedwiththeEUDirectiveonsecurityofnetworkandinformationsystems(NISDirective).Albaniahasestablishedalistofcriticalinformationinfrastructuresandthenecessaryimplementinglegislation.In2019,theNa-tionalAuthorityforElectronicCertificationandCyberSecurity(AKCESK)draftedanationalcybersecuritystrategythatstillneedstobeadopted.Albania’scommitmenttocybersecurityandcyberresiliencehasnotablyprogressedafteradoptingvariousnationaldigitaltransfor-mationandnationalsecuritystrategies.
ThreecentralauthoritiesareresponsiblefordifferentpartsofincidentresponseinAlbania.TheMinistryofDefence(MoD)isresponsibleforhandlingcyberincidentsrelatedtotheMoDandtheairforce.TheCybercrimeInvestigationUnitoftheAlbanianStatePoliceandtheprosecutor’sofficeaddressescybercrime.However,theAKCESKservesastheofficialnationalcoordinatingbodytoreportandmanagecybersecurityincidentsforkeyinformationinfrastructuresandcriticalinformationinfrastructureoperators.
10
11
12
Basedonthe2020EUProgressReportforAlbania,https://ec.europa.eu/neighbourhood-enlargement/
sites/near/files/albania_report_2020.pdf,andReportonCybersecurityMaturityLevelinAlbania,https://
.al/Publikime/2019/AlbaniaCMMReport.pdf
https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=SWD:2020:354:FIN
/wp-content/uploads/2019/10/AlbaniaCMMReport.pdf
9
TheLawNo.2/2017‘OnCyberSecurity’definesCriticalInformationInfrastructuresaswellasImportantInformationInfrastructuresandtheirresponsibilityforreportingincidents.
Anationalprogrammeforraisingcybersecurityawareness,ledbydesignatedorganizations(fromanysector)whichaddressesawiderangeofdemographics,isyettobeestablished.Inthelastfewyears,AlbaniahasperiodicallycarriedoutawarenessactivitiesforasaferinternetandparticipatedinactivitiesoninternationalSaferInternetDay.AlbaniacelebratesOctoberascybersecurityawarenessmonth.OnesuccessfulinitiativeistheAlbanianCyberAcademy,whoselast(4th)edition,in2020,wassupportedbyDCAF.13Moreover,thereisaweekinMarchthatisdedicatedtochildcybersecurity.Theofficiallyrecognizedcomputerin-cidentresponseteam–AKCESK–isthelegallymandatedagencycreatedbythedecisionoftheCouncilofMinisterstoorganizeawarenesscampaigns,training,andtopublishinfor-mativematerialsfortheprivateandpublicsectors.AKCESK,inconjunctionwiththeMin-istryofEducation,SportandYouth,andthebankingsector,conductedapilotprogrammeforschoolsonraisingawarenessoncyberbullying.Additionally,theCybercrimeUnitworkswithNGOsvisitingschoolsandprovidingtrainingforchildren.Theprivatesectorisstartingtoconsidercybersecurityawareness;however,itisstillatanearlystage.
BosniaandHerzegovina
TheEUprogressreportfor202014findsthatBosniaandHerzegovina(BiH)isstillatanearlystagewithregardtopublicadministrationreform.AccordingtotheEUreport,therehasbeennosubstantialprogressinensuringaprofessionalanddepoliticizedcivilserviceandacoordinatedcountrywidepolicy-makingapproach.Alllevelsofgovernmenthavead-optedthestrategicframeworkonpublicadministrationreformandnowneedtoembracetherelatedactionplan.Apoliticalbodysteeringthecoordinationofsuchareformhasnotyetbeenestablished.15Professionalcivilserviceproceduresmustbebasedonprinciplesofmeritandfreefrompoliticalinterference.Humanresourcesmanagementremainshighlyfragmented.Civilserviceagenciesandtrainingunitsdonotcoordinateappropriately.Ingeneral,governancestructuresneedtobefullyfunctionaltoprovideatoolforimprovementinanyrelatedarea,suchascybersecurity.
Theadministrativecapacitiesandcoordinationofcivilserviceagenciesandintegratedtrainingunitsneedtobestrengthened.Managerialaccountabilityisnotyetembeddedintheorganizationalcultureofthepublicsector.Acrossgovernmentlevels,basicaccountabilitymechanismsbetweenministriesandsubordinatedagenciesarenotinplace,andeffectivemanagementofsubordinatebodiesisnotensured.
TheBiHCivilServiceAgencyadoptedatrainingplanfor2020withtwocoursesoffered:computernetworkssecurityandweb-basedapplications.Trainingforjudgesandprosecu-torsremainsinsufficient.Significantimprovementsinthedurationandqualityofmandatorytrainingareurgentlyneeded.
BosniaandHerzegovinaneedstoestablishacomputersecurityincidentresponseteam(CSIRT)networktofacilitatestrategiccooperationandinformationexchange.16Ingeneral,thecountryneedstofurtheralignitslegislationoncybercrimewiththeEUacquisanden-surethereareadequatetoolsandenoughwell-trainedstafftodetect,traceandprosecutecybercrimes.Wecouldconcludethatwithoutthesefoundationsasaprecondition,itwould
13
14
15
16
.al/publicAnglisht_html/aktivitete/aca4.html
BosniaandHerzegovina2020ProgressReport,https://ec.europa.eu/neighbourhood-enlargement/sites/near/files/bosnia_and_herzegovina_report_2020.pdfhttps://eur-lex.europa.eu/legal-content/EN/ALL/?uri=SWD:2020:350:FIN
GuidelinesforaStrategicCybersecurityFrameworkinBosniaandHerzegovina,Sarajevo,October2019,/files/f/documents/1/a/438383.pdf
10 CybersecurityPolicyDevelopmentandCapacityBuildingintheWesternBalkans
bedifficultforlawenforcementauthoritiestotakepartinawhole-of-governanceapproachtobuildingresilientcybersecurity.
Unfortunately,BiHlacksanofficialandagreedstrategicapproachandframeworkforre-spondingtocybersecuritythreats.Althoughsomestrategiespartlyaddresscybersecurity,BiHremainstheonlycountryinsouth-easternEuropewithoutanational-levelcybersecuritystrategyandCSIRT.
Inadequatecoordination,aninsufficientlyharmonizedapproach,deficientcapacities,andtheabsenceofastrategicvisionremainissuesofconcern.Moreover,existinglegislationisyettobefullyharmonizedwiththerelevantEUacquis,andthereisnooverarchinglawoninformationsecurity.The2017DecisionoftheCouncilofMinistersofBiHonthedesigna-tionofacomputeremergencyresponseteamforBiH’sinstitutionsstillrequiresinstitutionaloperationalization.Also,keynationalprioritiesinthe2017–2022informationsecurityman-agementpolicyfortheBiHinstitutionsareyettobeoperationalized–namely,establishingmechanismstoadequatelyrespondtothecurrentchallengesofthedigitalage.AllthisleavesthepublicandprivatesectorsinBiH,aswellasindividualcitizens,highlyvulnerabletotheevolvingthreatsofcyberspace,includingcyberattacksandterrorismtargetingc
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時也不承擔(dān)用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。
最新文檔
- 租別人的地方養(yǎng)雞合同(2篇)
- 預(yù)售房轉(zhuǎn)賣合同(2篇)
- 長江 黃河 課件
- 薩克斯教學(xué)課件
- 植物描寫 課件
- 高考地理一輪復(fù)習(xí)第二章宇宙中的地球及其運(yùn)動第四節(jié)地球公轉(zhuǎn)及其地理意義課件
- 西南林業(yè)大學(xué)《C語言程序設(shè)計》2023-2024學(xué)年期末試卷
- 西京學(xué)院《網(wǎng)絡(luò)程序設(shè)計》2023-2024學(xué)年期末試卷
- 課件 孝悌文化
- 6以內(nèi)的加減法練習(xí)
- 新歷史主義文藝思潮
- GB/T 40120-2021農(nóng)業(yè)灌溉設(shè)備灌溉用熱塑性可折疊軟管技術(shù)規(guī)范和試驗方法
- GB/T 3903.2-1994鞋類通用檢驗方法耐磨試驗方法
- GB/T 10801.2-2018絕熱用擠塑聚苯乙烯泡沫塑料(XPS)
- 12J5-1 平屋面建筑標(biāo)準(zhǔn)設(shè)計圖
- 中印邊境爭端
- 品管圈徽SOS圈釋義
- 薩提亞模式家庭治療課件
- 行政事業(yè)單位全面實施預(yù)算績效管理思路和路徑及其評課件
- 《墨梅》課件(省一等獎)
- 國際貿(mào)易之進(jìn)出口流程操作課件
評論
0/150
提交評論