Publications

Published decree approving the National Strategy for Cyber Security

Published decree approving the National Strategy for Cyber Security

On February 6, 2020, the Decree No. 10,222/2020 was published, establishing the National Strategy for Cyber Security (E-Ciber). The E-ciber is the first module of implementation of the National Information Security Policy (Decree 9.367/2018) and contains the main actions intended by the federal government in the area of cyber security from 2020 to 2023.

The objectives of E-Ciber are i) to fill gaps in cyber security; ii) to protect the Government itself in view of recent cyber-attacks on government systems with the objective of causing damage to the Government’s image; and iii) to provide cyber protection for companies responsible for critical infrastructure.

To achieve the established goals, the E-Ciber makes recommendations for the public sector, the private sector, and the third sector. Among the recommendations to the public sector, the negotiation of mutual legal assistance treaties (or MLATs, Mutual Legal Assistance Treaties) and the sharing of information for national cooperation stand out.

Critical infrastructures are those that, if interrupted or destroyed, would cause serious social, economic, political, international or national security impact – such as Telecommunications, Transport, Energy, Water and Financial companies. These infrastructures are increasingly dependent on automated information systems and controls, which in turn are the target of several cyber-attacks and therefore need to deploy a high level of security.

The E-Ciber establishes that such infrastructures should consider cyber security as a priority investment action, for example, implementing cyber security policies with assessments, metrics, and review; developing plans for risk management, incident handling, and response; budgeting to combat security incidents; and participating in cyber exercises.

In addition, it highlights the importance of interaction among regulatory agencies in these sectors to deal with cyber security issues; encourages the establishment of Cyber Incident Training and Response Teams – ETIRs and encourages the sending of notifications about cyber incidents to the Government Cyber Incident Response and Treatment Center – CTIR Gov.

Finally, it encourages cyber education in three ways: i) training, ii) education, and iii) awareness and understands that public and private entities should participate in regional and international exercises as a way to support cooperation with strategic partners and that regulatory agencies are relevant in the adoption of cyber security procedures by their regulated entities.

The new initiative offers space for the development of new business models in digital services for risk management, fault prediction and control, and cyber-attacks, mainly because nowadays, companies operating in infrastructure are integrated with applications, intelligent contracts with customers and suppliers, cloud data management and storage contracts, big data analytics, media, and social mobility; the Strategy requires from companies to conduct themselves proactively to comply with legislation, which contributes to reducing liability for security breaches and compliance with reporting obligations in situations involving data leakage.

The Decree nº 10.222/2020 can be accessed at the following link: http://www.planalto.gov.br/ccivil_03/_Ato2019-2022/2020/Decreto/D10222.htm).

Related Posts
Tags