Maintaining and updating the Information
Security Manual to ensure basic
protection: The “Austrian Information
Security Manual” (Österreichisches
Informationssicherheitshandbuch/SIHA)
was revised and reorganised in 2012. The
Manual describes and supports procedures
for the establishment of comprehensive
information security management system in
enterprises and the public administration.
SIHA 2010 has been tailored to the needs
of small and medium-sized enterprises
implementing ISM measures. Complying
with international requirements, its
structure and content facilitate the
implementation of the ISO/IEC 27000 series
of standards. The internationally recognised
manual makes an important contribution to
ensuring a minimum level of protection, and
is updated on a regular basis.
See also chapter ‘Education
and research’.
Conducting technology assessments: Radical
technology changes are likely to occur
every two to three years in the field of cyber
security. It is therefore necessary to monitor
present and future technology trends, and
to assess their possible impact on the social
and economic life. Technology assessment
must be tackled within the framework of a
research programme which may be linked
with existing initiatives (e.g. KIRAS).
Voluntary registration system: Like
voluntary fire services, ICT specialists
may sign up via a registration system (of
the Cyber Competence Centre), providing
information on their technical skills, identity
and certificates and/or quality certification
(e.g. security screening pursuant to the
Security Police Act [Sicherheitspolizeigesetz/
SPG]). Organisations and enterprises have
fast and unbureaucratic access to qualified
personnel in an emergency with due regard
for legal requirements.
Objective 3: Information exchange of
public and private stakeholders
Hypothesis: Information exchange is
regarded as the most important element
of national cyber security. Since the wide
diversity of stakeholders coupled with
the growing importance of the private
sector make a purely public centralised
management impracticable, a continuous
exchange of information (particularly
threat-related) is necessary to strengthen
the self-protection of different stakeholders.
The major goal in this context is to ensure
consistency with the Austrian Programme
for Critical Infrastructure Protection
(APCIP).
Strategic objectives:
The exchange of information takes place
between governmental stakeholders,
between non-governmental stakeholders
and between governmental and nongovernmental stakeholders. One of the
crucial goals of all programmes protecting
critical infrastructures is to support publicprivate partnerships (PPPs) as a general
organisational framework for cooperation
between governmental and nongovernmental stakeholders. The need for
information exchange must be reconciled
with confidentiality and data protection
requirements.
Measures
Supporting public-private partnerships
(PPPs): To an increasing extent, the
protection of critical information
infrastructures and cyber security is
coordinated by “trusted” public-private
partnerships (PPPs). Examples of existing
PPPs are CERT.at as a “community-based
PPP” and the Austrian Trust Circle, which
exchanges information between private
bodies.
Legal certainty with respect to reporting
duty: Operators of critical infrastructures
have a special responsibility which must
receive due consideration whenever
16