2015-12-16
National Audit Office: cyber security in public sector is ensured acceptably

Having conducted an audit of cyber security the National Audit Office characterises the level of cyber security in public sector in Lithuania acceptable. In Lithuania State institutions apply on average one fourth of the recommended organisational measures and implement less than a half of the recommended technical measures in the area of cyber security. Main shortcomings of cyber security organisational measures are related to creation of security management systems, incident management, ensuring sustainability of implementation, staff development and external communication. Institutions are also at threat due to insufficiently implemented technical measures - inappropriate identification of secure configurations, management of electronic communication networks, management of mobile and other technologies.
In 2015 the Law on Cyber Security came into force, however it is not sufficient for the State to systematically regulate strategically important areas of cyber security and electronic information safety. Those areas are separated at the level of law, however it is not easy to implement those laws and overall security situation in the State in the mentioned areas is not yet improving. Moreover, other relating legal acts regulating cyber security have not been drafted in time, partial duplication of activities exists in responsible institutions, and there is a lack of separation of competences in formation and implementation of cyber security and electronic information safety policies.
At present in Lithuania greatest attention is paid to response to and prevention of incidents in cyber environment, however traditional aspects of management of electronic information safety (confidentiality, integrity, accessibility) are being forgotten and insufficient attention is paid to the development of the said area in 2015. Programme for Development of Electronic Information Safety (Cyber Security) for 2011–2019 which envisaged to reach the most significant results in this area is implemented inefficiently (the overall implementation of programme objectives reached one-fifth in September 2015).
Auditors also draw attention to the fact that allocation and use of resources for cyber security and information safety (15.6 million EUR is planned for 2015–2020) is not based on the established priorities and criteria, without having data about actual situation of cyber security and information safety in institutions, expenditure (20.6 million EUR in 2011-2014) and their impact.
The National Audit Office provided recommendations to the Government to assist in ensuring cyber security and increasing its resilience, to improve the existing planning, legal regulation and financial management. Recommendations given to the Ministry of Defence and Ministry of the Interior should improve the quality and effectiveness of cyber security regulation.
Summary of Audit Report “The Cyber Security Environment in Lithuania”