Risk management and situation assessment regulatory measures are taken. On the one hand, CI face increasing regulatory requirements. For example, it is recommended that if possible all CI operators (particularly those responsible for the protection of critical information infrastructure) be legally obliged to take risk management and information security measures. On the other hand, the private sector itself often addresses questions relating to its duty to report cyber attacks, as in many instances CI operators were prevented from “voluntary reporting” for reasons of data protection. Human Sensor Project: ICT system administrators receive gradual ICT security training and are taught to detect anomalies in their ICT systems and report them to their ICT security officers. The data thus obtained are forwarded to the Cyber Situation Centre and the Cyber Competence Centre, where they are processed to gain a more profound insight into the situation. : Initial situation Today’s digital society has led to a high penetration of ICT in all areas and ICT now plays a major role in traditional sectors such as energy supply, transport and industry. Exclusively ICT-based sectors take advantage of networks of extensive services and infrastructures controlled through ICT components and processes. Links between individual sectors resulting from the interdependence of services and products leads to a chain reaction in security-relevant scenarios. Based on these considerations, risk and situation assessments must cover all sectors, although the sectors of information infrastructures, telecommunications, energy, healthcare, transport, monetary transactions and public administration will need to be examined more closely. Each individual sector has a well-developed risk management system. However, the main risks are identified in areas outside the control of individual enterprises. This suggests that the level of interconnectedness among sectors and beyond organisational units is extremely high and that an overarching risk assessment is required. Due to the strong interdependence of sectors, ICT risks are embedded in the context of upstream or downstream risk situations. It is therefore understandable that a considerable number of risks cannot be managed and tackled by an individual enterprise but only collectively or with the support of the state. It is of vital importance that non-ICT risks and scenarios are covered by up-todate emergency and crisis management plans. This is an important requirement for avoiding overlapping risks and scenarios in interlinked systems. The issue of risk and security management in individual enterprises is another relevant aspect. It will be necessary to resort to best practices in this area, and to create suitable framework conditions. In many cases, it may even become necessary to define minimum standards for these core 17

Select target paragraph3