I propose to take Questions Nos. 238 and 239 together.
In common with other Government Departments, the Department of the Taoiseach has comprehensive arrangements in place to support cyber security and receives regular advice on these matters from the relevant authorities, including the Office of the Government Chief Information Officer and the National Cyber Security Centre.
Cybersecurity awareness is the responsibility of all staff and cybersecurity awareness training is made available to staff in the Department on an ongoing basis.
The Department's ICT Team have skills across the range of ICT and digital disciplines, including cybersecurity and implementation of the full range of cybersecurity measures is undertaken by the ICT Team in conjunction with appropriate external expertise as required.
The Department actively participates in the Government Cyber Security Coordination & Response (GovCORE) Network, facilitating information sharing and best practice exchange with other public sector bodies.
The Department implements a risk-based approach to the management of its third-party supply chain. All third party suppliers of ICT are appropriately managed via a third party management lifecycle which includes screening; onboarding; ongoing management and monitoring; risk assessment and mitigation; and termination.
The Department is in the process of reviewing its processes and procedures in relation to third-party supply chain management in order to ensure that they meet the requirements of the Network and Information Security (NIS2) Directive.