for overarching coordination. The cyber partnership comprises: –– Public Cyber Crisis Management –– a Cyber Security Steering Group –– an information exchange centre for cyber security Establishing a Cyber Situation Centre: In order to obtain an overview of the cyber situation, the available information will need to be collected, bundled and evaluated on an ongoing basis. In Austria these tasks are to a large extent carried out by different institutions, in particular CERTs. No centrally managed Cyber Situation Centre has been established to date in Austria. For further information on standardisation see chapters ‘Critical infrastructure’ and ‘Education and research’. Creating structures for standards, certification and quality assessment: The constant availability of reliable ICT systems and components may be ensured by using components (especially in sectors deemed critical for security) subject to certification (“supply chain security”). Austria plans to establish a certification body for cyber security products and cyber security assessors. A centralised body will therefore be established which will be responsible for coordinating the publication of quality standards for cyber security in Austria and of minimum requirements for conducting reviews of cyber security quality standards. The significant structural measures in Austria are described in greater detail below. 8 Public cyber partnership The cyber partnership must extend to crisis-coordinating, strategic-political and advisory-operational level. A central contact for public cyber security matters will be created by establishing the position of a Chief Cyber Security Officer in Austria, who will act in close cooperation with the Chief Information Officer of the Federal Republic. Public Cyber Crisis Management (crisis-coordinating level) A Cyber Security Crisis Management appropriate for all cyber incidents will be defined for Austria by taking into account existing cyber structures (e.g. CERTs). Cyber Crisis Management will consist of representatives of the state and the critical infrastructures. Rules and procedures will have to be agreed upon to facilitate cooperation between public and private crisis centres. In the event of a cyber incident with potentially harmful local effects, institutions of the relevant ministries or private entities will be responsible for crisis management in cooperation with CERTs. These facilities have to be closely geared to the specific requirements of cyber security threats. To be suitably prepared for such emergencies, crisis management bodies and CERTs conduct joint exercises on a regular basis. Crisis management in the event of cyber incidents affecting various sectors and posing a severe threat to the security of supply in Austria is based on existing crisis and civil protection structures (Krisen- und Katastrophenschutzstrukturen/SKKM). Through complementary cooperation with crisis and civil protection structures correlation of cyber security expertise (serving as Austria’s national cyber crisis management) has to be ensured to tackle any cyber issue. In Austria cyber security

Select target paragraph3