Establishing a Cyber Situation Centre: see chapter ‘takeholders and structures’. Establishing a viable crisis communication system: Communication with the organisations and companies responsible for operating key networks needs to be strengthened. A functioning and properly secured communication system with public and private stakeholders abroad has to be ensured in acute cases. The establishment of an “emergency network” (e.g. with the aid of DVB-T technology) should be guaranteed at any time. Other options of fail-safe communication (e.g. VHF radio) will also have to be taken into consideration. In a crisis situation, it is also essential to verify the identity of participants. A suitable legal basis is required, especially for passing on information. Protection of critical information infrastructures Protection of critical infrastructure Cyber security Cyber crisis management Facility protection Special cyber situations Public crisis and civil protection management Objective 2: Risk management and information security Hypothesis: One of the most effective methods of promoting cyber security and facilitating day-to-day operations is to encourage self-protection by proactive risk minimisation at the level of the enterprise or organisation (risk management and information security). Strategic objective: To ensure that risk management and information security methods are applied are as far-reaching and differentiated as possible within the critical infrastructures identified. Services of special general interest require a higher level of protection. Measures Promoting risk management within CI: The establishment of ICT-related risk management (generally also referred to as “information security”) is regarded as one of the most important measures which CI operators can take to protect themselves. In the context of national cyber security it is of fundamental importance that all stakeholders responsible take information security or ICT-related risk management measures in their respective sphere of responsibility. The government supports them by providing information on joint risk analysis, accreditation of different risk management methods, harmonisation of training measures as well as technology assessment analyses. Sanctions and incentives promote the use of risk management methods in the private sector. For further information on Cyber crisis management see chapter ‘Stakeholders and structures’. Establishing a Cyber Competence Centre: The Cyber Competence Centre is part of the Cyber Security Platform and is the central point of contact for all operators of critical infrastructure and also for enterprises interested in risk management/information security management (RM/ISM). It provides information on different RM/ISM approaches and accreditation procedures, e.g. based on the Security Manual 2010 or ISO 27000. Together with the Cyber Situation Centre, quantitative information is processed for specific cyber security risk analysis. 15

Select target paragraph3