1 Section 1 – Introduction 1.1 Overview Section 1 defines the foundations for and objectives of ICT security, sets out what this comprehensive topic covers and what it does not, and explains how the Minimum ICT Standard is to be used. A number of internationally recognised cybersecurity standards already exist. Most of these extend well beyond the present document (see section 1.4.1). This Minimum Standard explicitly does not seek to compete with the existing international standards. Rather, it is compatible with them while being more reduced in scope. It is intended to provide a more entry-level introduction to the issues, and yet ensure a high degree of protection. 1.2 Legal foundations The following underlying laws form the basis for NES action.1 • Federal Act on the National Economic Supply (National Economic Supply Act, NESA; SR 531) • Ordinance on the Organisation of National Economic Supply (Organisation of National Economic Supply Ordinance; SR 531.11) • Ordinance on Preparatory Measures for National Economic Supply (SR 531.12) As a complement to the present Minimum ICT Standard, NES has drafted further, sector-specific standards,2 which go into greater (technical) detail. It is recommended that, as soon as they become available, operators of critical infrastructures base their actions on these detailed, sector-specific requirements in addition to this Minimum Standard. If a sector already has its own standards, or if international standards such as ISO or NIST are used, businesses can use the checklist in Section 3, ‘Assessment’ to determine whether or not they already meet this Minimum Standard. 1.3 Background and objectives 1.4.1 Foundation documents and standards Cybersecurity demands a risk-based approach and the use of secure systems within the individual operator’s own area of responsibility. Many cyber attacks can be repelled at reasonable cost simply by taking the tried-and-tested precautions set out in this Minimum ICT Standard. Its aim is to give businesses and organisations a versatile tool that enables them to take independent action to improve the resilience of their ICT infrastructures. By taking a risk-based approach, the standard permits the implementation of different levels of defence, adjusted to the particular needs of the organisation. 1.4 Scope This Minimum ICT Standard has been drawn up by the National Economic Supply (NES) organisation in cooperation with external cybersecurity experts. 1 All of these legal texts can be found in the classified compilation of federal law. They can be found online at: There are many different standards and sources of information around the world on dealing with cyber risks. Some of these are already recognised by businesses and are in use. The present Minimum ICT Standard is based on the NIST Cybersecurity Framework Core.3 It has been supplemented with other internationally recognised industry standards where appropriate. The most important of these are the following: 1. NIST Guide to Industrial Control Systems (ICS) Security This guide is also issued and updated by the National Institute of Standards and Technology, and extends the NIST Cybersecurity Core Framework by specific requirements for handling industrial control systems (ICS), in particular, NIST Special Publication 800-82, revision 2, May 2015.4 2 These are currently available for the power supply and food supply sectors. Standards for other sectors are in progress and will be published https://www.admin.ch/gov/en/start/federal-law.html. upon completion. The National Economic Supply Act is available in English. The ordinances 3 https://www.nist.gov/cyberframework are available in German, French and Italian 4 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf Minimum ICT standard 2018 4

Select target paragraph3