Resolution: Advancing the National Preparedness for Cyber Security

Similar documents
Government Resolution No of February 15, Resolution: Advancing National Regulation and Governmental Leadership in Cyber Security

State of Israel Prime Minister's Office National Cyber Bureau. Unclassified

ISRAEL NATIONAL CYBER SECURITY STRATEGY IN BRIEF

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

COUNCIL OF THE EUROPEAN UNION. Brussels, 24 May /13. Interinstitutional File: 2013/0027 (COD)

Israel and ICS Cyber Security

Cyber Security Strategy

V{ xy Éy à{x Vtu Çxà Éy ` Ç áàxüá

Country Report : Bhutan. Organization: Disaster Management Division, Ministry of Home and Cultural Affairs. Minister. Secretary

10025/16 MP/mj 1 DG D 2B

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

300 Riverview Plaza Odysseus Marcopolus, Chief Operating Officer Trenton, NJ POLICY NO: SUPERSEDES: N/A VERSION: 1.0

STRENGTHENING THE CYBERSECURITY OF FEDERAL NETWORKS AND CRITICAL INFRASTRUCTURE

DHS Cybersecurity: Services for State and Local Officials. February 2017

Accreditation Services Council Governing Charter

Cyber Security in Europe

National Policy and Guiding Principles

UN General Assembly Resolution 68/243 GEORGIA. General appreciation of the issues of information security

ISACA National Cyber Security Conference 8 December 2017, National Bank of Romania

Directive on security of network and information systems (NIS): State of Play

Special Action Plan on Countermeasures to Cyber-terrorism of Critical Infrastructure (Provisional Translation)

Emergency Support Function #2 Communications Annex INTRODUCTION. Purpose. Scope. ESF Coordinator: Support Agencies: Primary Agencies:

THE CYBER SECURITY ENVIRONMENT IN LITHUANIA

Section I. GENERAL PROVISIONS

Japan s Cyber Diplomacy

OAS Cybersecurity Capacity Building Efforts

Section One of the Order: The Cybersecurity of Federal Networks.

NATIONAL CYBER SECURITY STRATEGY. - Version 2.0 -

RESOLUTION 130 (REV. BUSAN, 2014)

79th OREGON LEGISLATIVE ASSEMBLY Regular Session. Senate Bill 90

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

THE WHITE HOUSE. Office of the Press Secretary EXECUTIVE ORDER

NATIONAL DEFENSE INDUSTRIAL ASSOCIATION Homeland Security Symposium

THE WHITE HOUSE Office of the Press Secretary EXECUTIVE ORDER

STRUCTURAL MATERIALS DIVISION BYLAWS

Presidential Executive Order on Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

MEETINGS OF MINISTERS OF JUSTICE OR OEA/Ser.K/XXXIV

Hazard Management Cayman Islands

HPH SCC CYBERSECURITY WORKING GROUP

TURNING STRATEGIES INTO ACTION DISASTER MANAGEMENT BUREAU STRATEGIC PLAN

The EU Cybersecurity Package: Implications for ENISA Dr. Steve Purser Head of ENISA Core Operations Athens, 30 th January 2018

PIPELINE SECURITY An Overview of TSA Programs

Overview of the Federal Interagency Operational Plans

Cyber Security Strategic Level Landscape in Poland. Krzysztof Silicki NASK Institute, Poland ENISA MB, EB

Executive Order on Coordinating National Resilience to Electromagnetic Pulses

ASSEMBLY, No STATE OF NEW JERSEY. 217th LEGISLATURE INTRODUCED FEBRUARY 4, 2016

Zambia National Standardization Organization Audit

Cybersecurity & Privacy Enhancements

PD 7: Homeland Security Presidential Directive 7: Critical Infrastructure Identification, Prioritization, and Protection

13967/16 MK/mj 1 DG D 2B

Regulating Cyber: the UK s plans for the NIS Directive

Electricity Sub-Sector Coordinating Council Charter FINAL DISCUSSION DRAFT 7/9/2013

CYBERSECURITY FEDERAL UPDATE. NCSL Cybersecurity Task Force

ENISA s Position on the NIS Directive

Data Protection System of Georgia. Nina Sarishvili Head of International Relations Department

U.S. Japan Internet Economy Industry Forum Joint Statement October 2013 Keidanren The American Chamber of Commerce in Japan

Reviewed by ADM(RS) in accordance with the Access to Information Act. Information UNCLASSIFIED.

Resolution adopted by the General Assembly on 14 December [without reference to a Main Committee (A/61/L.44 and Add.1)]

Response to Wood Buffalo Wildfire KPMG Report. Alberta Municipal Affairs

CERT.LV activities, role in Latvia and globally. Baiba Kaskina, CERT.LV , Sofia, Bulgaria

Cybersecurity governance in Europe. Sokratis K. Katsikas Systems Security Laboratory Dept. of Digital Systems University of Piraeus

How Cybersecurity Initiatives May Impact Operators. Ross A. Buntrock, Partner

OF ELECTRICAL AND ELECTRONICS ENGINEERS POWER & ENERGY SOCIETY

COUNTERING IMPROVISED EXPLOSIVE DEVICES

Translation. Notification of the Department of Business Development Re: Qualifications and Requirements of Bookkeepers B.E.

THE WHITE HOUSE. Office of the Press Secretary. EMBARGOED UNTIL DELIVERY OF THE PRESIDENT'S February 12, 2013 STATE OF THE UNION ADDRESS

Office of the Minister of Broadcasting, Communications and Digital Media Chair, Cabinet Appointments and Honours Committee

European Directives and reglements for Information security

The Republic of Korea. economic and social benefits. However, on account of its open, anonymous and borderless

PRC Cyber Security Law --- How does it affect a UK business? Xun Yang Of Counsel, Commercial IP and Technology

Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013

Resolution adopted by the General Assembly. [without reference to a Main Committee (A/62/L.30 and Add.1)]

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management

DHS Cybersecurity. Election Infrastructure as Critical Infrastructure. June 2017

History of NERC December 2012

ASEAN COOPERATION ON DISASTER MANAGEMENT. Disaster Management & Humanitarian Assistance Division, ASEAN Secretariat

UN FREEDOM OF INFORMATION POLICIES INTERNATIONAL TELECOMMUNICATION UNION (ITU)

IAEA Perspective: The Framework for the Security of Radioactive Material and Associated Facilities

Overview on the Project achievements

The Interim Report on the Revision of the Guidelines for U.S.-Japan Defense Cooperation

ASEAN s Cyber Confidence Building Measures

Critical Information Infrastructure Protection. Role of CIRTs and Cooperation at National Level

KISH REMARKS APEC CBPR NOV 1 CYBER CONFERENCE KEIO Page 1 of 5 Revised 11/10/2016

Exploring the European Commission s Network and Information Security Directive (NIS) What every CISO should know

POSITION DESCRIPTION

Draft Resolution for Committee Consideration and Recommendation

Presidential Documents

ECB-PUBLIC OPINION OF THE EUROPEAN CENTRAL BANK. of 18 May 2018

TSA/FTA Security and Emergency Management Action Items for Transit Agencies

Cyber Security Technologies

REGULATION OF THE MINISTER OF COMMUNICATION AND INFORMATION TECHNOLOGY. NUMBER: 12/Per/M.KOMINFO/02/2006 ON THE TERMS OF

THE VALUE OF INTERNATIONAL COOPERATION IN CYBERSPACE: LESSONS FROM THE UNGGE PROCESS

Thailand Country Report 2008

Critical Infrastructure Protection & Resilience Europe / Asia. Conference Discussion Reviews

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

NATIONAL DISASTER PREPAREDNESS IN TURKEY

National Counterterrorism Center

COUNTERING IMPROVISED EXPLOSIVE DEVICES

E-Signature Law of Iraq no. ( 78) of 2012

Cybersecurity for ALL

Transcription:

Government Resolution No. 2444 of February 15, 2015 33 rd Government of Israel Benjamin Netanyahu Resolution: Advancing the National Preparedness for Cyber Security It is hereby resolved: Further to Government Resolution No. 3611 of August 7, 2011, regarding "Advancing the National Capacity in Cyberspace" (hereinafter: Resolution No. 3611), and specifically Article E of Addendum B of Resolution No. 3611: Definition: Cyber security The range of actions for the prevention, mitigation, investigation and handling of cyber threats and incidents, and for the reduction of their effects and of the damage caused by them prior, during and after their occurrence. 1. To determine that protecting the proper and safe functioning of cyberspace is an essential national security interest for the State and an essential governmental interest for national security. A National Cyber Security Authority 2. To establish in the Prime Minister's Office a National Cyber Security Authority (hereinafter: the Authority), with the mission of defending cyberspace and carrying out the following primary tasks: a. To conduct, operate and implement, as needed, all the operational defensive efforts in cyberspace at the national level, from a holistic perspective, for the purpose of providing a complete and continuous defensive response to cyber attacks, including handling cyber threats and incidents in real time, formulating an ongoing situational awareness, consolidating and analyzing intelligence, and working with the defense community, as detailed in Addendum B *, Article 2. * Addendum B of this resolution is classified "Secret" and can be found at the Cabinet Secretariat. 1

b. To operate an assistance center for handling cyber threats (hereinafter: the National CERT) for the entire market including working to improve cyber resilience, providing assistance in handling cyber threats and incidents, consolidating and sharing relevant information with all the organizations in the market; and to serve as a central point of interface between the defense community and the organizations in the market. The National CERT will act in accordance with principles to be determined by the National Cyber Bureau (hereinafter: the Bureau) in coordination with the Attorney General within 90 days of the passing of this Resolution. c. To build and strengthen the cyber resilience of the entire market through preparedness, training and regulation, including increasing the readiness of sectors and organizations in the market, instructing the market in the field of cyber security, regulating the cyber security services sector, licensing, standardization, conducting exercises and training, and providing incentives and other necessary tools. d. To design, apply and implement a national cyber security doctrine. e. To execute any other task determined by the prime minister in accordance with the Authority's mission. 3. To establish the National Cyber Directorate which includes the Authority and the Bureau as two independent auxiliary units in the Prime Minister's Office (hereinafter: the Directorate), as detailed in Addendum A, Article 1, Clause 1. The Head of the Authority will bear the full responsibility for executing the Authority's mission and tasks, including its operational activities and administering its assignments and staff. The Head of the Bureau will continue leading the policy and strategy in the cyber field at the national level, building the national capacity and strengthening the State of Israel as a global leader in the cyber field, in accordance with the Bureau's roles as outlined in Resolution No. 3611 and Article 11 of this Resolution. The Head of the Bureau will serve as Head of the Directorate and will be charged with approving the Authority's work plans. In addition, an advisory committee for the prime minister will be established and entrusted with fundamental policy decisions related to the Authority's activity. The advisory committee will comprise at most five members to be appointed by the prime minister. 2

4. To charge the Bureau, in coordination with the Ministry of Finance and the Civil Service Commission, with the task of establishing the Authority in the framework of a multi-year plan for 2015-2017 in a manner that will allow for proper implementation of its mission as a body with both civilian and defensive-operational characteristics, as detailed in this Resolution, and specifically in Addendum A, Article 1 and Addendum B Article 1. At the end of this period, based on the experience accumulated, the advisory committee will present its recommendations to the prime minister regarding the long-term structure of the Directorate. National activity for cyber security 5. To charge the Bureau with the task of establishing in the Authority a national technological and organizational infrastructure for early warning, analysis, alert and sharing of information, in order to expose and identify cyber attacks on the State of Israel. This will be in accordance with the recommendations to be formulated as specified below with regard to aspects related to the establishment of this infrastructure, which may affect basic rights, including the scope of information to be collected, the format of its use, and how it is to be protected and shared. These recommendations will be formulated by the Bureau while balancing cyber security needs with protecting basic rights as aforementioned, and will be brought to the Attorney General for approval within 90 days of the passing of this Resolution. The aforementioned does not limit in any manner the identification and analysis activities conducted by the defense community. 6. To charge the defense community with the task of working with the Authority on cyber security, each organization in the framework of and according to its legal responsibilities and in accordance with their mission and authorities, as detailed in Addendum B, Article 2. 7. To establish a cyber security forum, led by the Head of the Authority, which is tasked with coordinating, supervising and regularizing the joint activities of the Authority and the defense community, as detailed in Addendum B, Article 3. 3

8. To instruct the Ministry of Foreign Affairs and the Authority to work in coordination, cooperation and consultation on relevant aspects vis-à-vis the international arena, at the discretion of the authorized parties and in accordance with a procedure regularizing the work between the Authority and the Ministry of Foreign Affairs to be formulated within nine months. This procedure will include, inter alia, joint participation in relevant forums. 9. To charge the Bureau with the task of presenting to the prime minister within six months, in coordination with the Head of the National Security Council, an outline to transfer the area of activity in the field of securing essential computerized systems as defined in the Law for Regularizing Security in Public Bodies of 1998 (hereinafter: essential computerized systems) from the Israeli Security Agency to the Authority within three years of its establishment, while taking into account Addendum A, Article 2. In addition, to charge the Bureau and the legal department of the Prime Minister's Office, together with the Ministry of Justice, with the task of preparing a memorandum of legislative amendments needed to implement the outline, which will be brought to the prime minister for approval at the same time. 10. In cases of contradictions between this Resolution and the resolution of the Ministerial Committee for National Security Issues of December 11, 2002, this Resolution will take precedence. 11. Further to the establishment of the Authority and in accordance with its tasks, to change Addendum A of Resolution No. 3611 so that the tasks of the Bureau will be amended as follows: a. To annul the following Articles: 2(i), 2(j), 2(k), 2(l), 2(m). b. To delete Article 2(f) and replace it with: "To advance research and development in the cyber field via the professional parties, or in an independent manner as required for cyber security needs at the national level." c. To delete Article 2(n) and replace it with: "To formulate a national strategy for the development of human capital in the cyber field, in coordination with the professional parties, and to advance national projects to implement it." 4

12. It should be clarified that this Resolution does not authorize the Authority or the Bureau to handle matters under the statutory authority of the Israeli Security Agency. 13. To charge the Bureau and the legal department of the Prime Minister's Office, in cooperation with the Ministry of Justice, with the task of preparing a memorandum for a cyber security law, in accordance with the principles of this Resolution, including examining the need for legislative amendments, and to bring it to the prime minister for approval within six months of the passing of this Resolution. 14. To allocate budgets and human resources in order to implement this Resolution, as detailed in Addendum B, Article 4. The above is a translation of Government Resolution No. 2444 of February 15, 2015. The binding language of this Government Resolution is the draft held by the Government Secretariat in Hebrew. The binding language of draft legislation and law memoranda mentioned in this Resolution is the draft published on the record. Budgetary decisions are subject to the Annual Budget Law. 5