National Cyber Incident Response Plan (NOKI): Slovenia has adopted a National Cyber Incident Response Plan (NOKI), which establishes incident classification, reporting procedures, escalation mechanisms, communication arrangements and response phases including preparation, detection, containment, mitigation and recovery.
Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/Datoteke/Dokumenti/2022-03-NOKI.pdf
https://pisrs.si/pregledPredpisa?id=ZAKO8934
National CSIRT Capability (SI-CERT and SIGOV-CERT): Slovenia operates dedicated CSIRT capabilities through SI-CERT and SIGOV-CERT, which receive incident reports, provide technical assistance, support incident management and coordinate response activities. SI-CERT serves organisations and the wider public, while SIGOV-CERT supports public administration entities.
Sources: https://www.cert.si/prijava-incidenta/
https://www.gov.si/en/state-authorities/government-offices/government-information-security-office/about-the-office/sigov-cert-division/
Incident Response Plans and CSIRT Notification Protocol Templates: URSIV provides model documentation including a dedicated “Incident Response Plan with CSIRT Notification Protocol”. The template supports organisations in defining response teams, roles, responsibilities, escalation procedures, detection mechanisms and communication processes.
Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/Datoteke/Vzorcna-dokumentacija/6_NACRT-ODZIVANJA-NA-INCIDENTE_ver_1.0.pdf
Training on Incident Preparedness and Response Planning: URSIV conducts workshops and training programmes on incident preparedness, response planning and development of documented incident response systems. Training covers detection, classification, notification, response procedures, responsibilities and post-incident analysis.
Sources: https://www.gov.si/assets/vladne-sluzbe/URSIV/Datoteke/Dogodki/Seminarji-z-ENISO/M8-Nacrti-odzivanja-in-pripravljenost.pdf
SI-CERT Incident Handling and Technical Support Service: SI-CERT provides operational support during incidents, including assistance with investigation, incident analysis, malware analysis and mitigation advice. Organisations can submit incidents along with logs, malicious files and technical evidence for analysis.
Sources: https://www.cert.si/prijava-incidenta/