2. ISO 2700x The International Organization for Standardization (ISO) publishes around a dozen mutually complementary standards on cybersecurity. These are referred to as the ‘2700x family’. The best-known of these is ISO 27001. It specifies the requirements for setting up, implementing, maintaining and continuously improving a documented information security management system compatible with the context of the organisation concerned.5 3. COBIT Control Objectives for Information and Related Technology (COBIT) 6 4. ENISA Good Practice Guide on National Cyber Security Strategies.7 5. Federal Office for Information Security (Germany), BSI 100-2.8 1.5 Introducing the Minimum ICT Standard This section presents the key issues addressed by the Minimum ICT Standard. 1.5.1 Principles of cybersecurity A business must first define its cybersecurity principles before it can put them into effect in its operations. Specifically, it must answer the following questions: • • • • What is to be done? How is it to be done? Who is responsible? How will the outcome be measured? Cybersecurity principles set out the rules, procedures, metrics and organisational structures which are required for effective planning and control. 1.4.2 Principles 1.5.2 Organisation and responsibilities 1. Independent responsibility: operators of critical infrastructures have a fundamental independent responsibility to maintain their critical ICT processes. As a basis for cybersecurity, a business must have a general security organisation which defines clear tasks, responsibilities and authorities. This should also provide the framework for defining and implementing the defence-in-depth strategy. Cyber risks should form part of global risk management. This is key to recognising potential cyber threats and to defining the appropriate action. The security organisation must enable senior management to decide on the necessary resources. This level of management must also equip the security organisation with the proper powers to perform their core tasks without limitation in close cooperation with the various areas of the business. 2. Business continuity management: all aspects of cybersecurity should be integrated into an overarching business continuity management structure. 3. Risk management: those applying these standards must assess possible cyber risks – such as impairments to availability, integrity and confidentiality – on an ongoing basis. The business must judge which risks should be mitigated, and which it is willing to bear. 1.4.3 Measures and references in this document Wherever possible, the authors have avoided duplicating information. Instead, they refer to other cybersecurity standards. Those applying this Standard are advised to consult the stated sources where necessary. 5 https://www.iso.org/standard/66435.html 6 http://www.isaca.org/COBIT/Pages/default.aspx 7 https://www.enisa.europa.eu/topics/national-cyber-security-strategies 8 https://www.bsi.bund.de/EN/TheBSI/thebsi_node.html;jsessionid= 1.5.3 Policy, directives and guidelines Before a cybersecurity strategy (such as a defence-in-depth strategy) can be put into effect, the policy, procedures and working directives of an organisation must be identified, or in some cases defined. Those responsible for cybersecurity must be notified of the business requirements of the various business units. These requirements must also be documented. They might be legal, financial, strategic or operational in nature, for example. 2012D9CA020E153625E39AFEE673D910.1_cid341 Minimum ICT standard 2018 5

Select target paragraph3