for overarching coordination. The cyber
partnership comprises:
–– Public Cyber Crisis Management
–– a Cyber Security Steering Group
–– an information exchange centre for
cyber security
Establishing a Cyber Situation Centre: In
order to obtain an overview of the cyber
situation, the available information will
need to be collected, bundled and evaluated
on an ongoing basis. In Austria these tasks
are to a large extent carried out by different
institutions, in particular CERTs. No
centrally managed Cyber Situation Centre
has been established to date in Austria.
For further information on
standardisation see chapters
‘Critical infrastructure’
and ‘Education and research’.
Creating structures for standards,
certification and quality assessment: The
constant availability of reliable ICT systems
and components may be ensured by using
components (especially in sectors deemed
critical for security) subject to certification
(“supply chain security”). Austria plans
to establish a certification body for cyber
security products and cyber security
assessors. A centralised body will therefore
be established which will be responsible
for coordinating the publication of quality
standards for cyber security in Austria and
of minimum requirements for conducting
reviews of cyber security quality standards.
The significant structural measures in
Austria are described in greater detail below.
8
Public cyber partnership
The cyber partnership must extend to
crisis-coordinating, strategic-political
and advisory-operational level. A central
contact for public cyber security matters
will be created by establishing the position
of a Chief Cyber Security Officer in
Austria, who will act in close cooperation
with the Chief Information Officer of the
Federal Republic.
Public Cyber Crisis Management
(crisis-coordinating level)
A Cyber Security Crisis Management
appropriate for all cyber incidents will be
defined for Austria by taking into account
existing cyber structures (e.g. CERTs).
Cyber Crisis Management will
consist of representatives of the state
and the critical infrastructures. Rules and
procedures will have to be agreed upon to
facilitate cooperation between public and
private crisis centres.
In the event of a cyber incident
with potentially harmful local effects,
institutions of the relevant ministries or
private entities will be responsible for crisis
management in cooperation with CERTs.
These facilities have to be closely geared
to the specific requirements of cyber
security threats. To be suitably prepared
for such emergencies, crisis management
bodies and CERTs conduct joint exercises
on a regular basis.
Crisis management in the event
of cyber incidents affecting various
sectors and posing a severe threat
to the security of supply in Austria
is based on existing crisis and civil
protection structures (Krisen- und
Katastrophenschutzstrukturen/SKKM).
Through complementary cooperation
with crisis and civil protection structures
correlation of cyber security expertise
(serving as Austria’s national cyber crisis
management) has to be ensured to tackle
any cyber issue. In Austria cyber security