Foundations of Cybersecurity Policy and Governance in Italy
摘要
This chapter critically analyzes the historical trajectory of the Italian cybersecurity governance and policymaking foundations. The content of the chapter offers insights into the Italian regulatory and governance evolution in the field of cybersecurity, critical information infrastructure protection (CIIP) and attribution of competencies among different governmental and institutional bodies. The analysis spans a period marked by the issuance of the first ministerial decree protecting information critical infrastructure in 2005 up to the reform of intelligence services in 2007. It addresses the challenge of capturing the fluidity of cybersecurity within a static and bureaucratic timeline. The chapter begins by outlining the early stages of Italy’s cybersecurity initiatives, which were significantly influenced by international variables: events such as terrorist attacks in US (9/11) and Europe (Madrid 2004 and London 2005) and decision made by actors such as NATO and subsequent EU regulations. It discusses the pivotal reforms and policy shifts that have shaped Italy’s national cybersecurity architecture, highlighting the move from a fragmented approach focused on CIIP under law enforcement, to a more centralized intelligence-driven national security strategy. This transition is examined through various legislative actions and strategic decisions that, progressively, integrated cybersecurity into national security concerns, under the direct responsibility of the Prime Minister.