Critical infrastructure Initial situation The term “critical infrastructure” or “strategic infrastructure” describes those parts of all public or private infrastructures that are of crucial importance for maintaining vital societal functions. Their disruption or destruction has a major impact on the health, security or economic and social wellbeing of the citizens or the effective functioning of state institutions. Today most critical infrastructures increasingly depend on specialised IT systems which are expected to guarantee services as smoothly, reliably and continuously as possible. The ICT sector itself (and its IT and telecommunications networks with their various components and providers) as well as the ICT-based infrastructures of all other sectors not only permit sectoral production, but also keep the trans-sectoral flow of information going. In more general terms, these are also referred to as critical information infrastructures (CII). The protection of critical information infrastructure (CIIP) is therefore not just a task for the ICT sector alone, but has increasingly become a concern of other economic sectors. One particular characteristic of critical information structures is their susceptibility to different types of cyber attacks. This is reflected in the fact that CIIs themselves can be actively abused as “attack channels” against other critical infrastructures. Unlike failures of electricity or water supply, cyber attacks may cause lasting—“sustainable”— damage, e.g. through the targeted destruction or manipulation of machine control data. In Austria cyber security goals pursued to protect critical information infrastructures must be coordinated with the proven Austrian Programme for Critical Infrastructure Protection (APCIP). An overarching objective therefore correlates with this programme as follows: “The APCIP programme must be complemented by cyber security measures within and between the sectors; national 14 capacities to support information security and cope with national crisis and disaster situations have to be built up.” Strategic objectives and measures Objective 1: Cyber crisis management Hypothesis: Cyber crises and disaster situations may have fatal effects on the state, the economy and public life. At international level it has become an established practice to build up special overarching structures for events of this kind to complement existing crisis management structures. Strategic objectives: To further develop reactive tools for a country-wide disaster and crisis management relevant to cyber security (cyber crisis management) to protect the state, economy and public life from harm. National cyber crisis management is an important element of national security. Measures Establishing a structure for national cyber crisis management: The factors distinguishing national cyber security management (“cyber crisis management”) from conventional public disaster and crisis management are, on the one hand, the special requirements and overlapping areas of cyber security, and on the other constant cooperation with programmes protecting critical infrastructures. Another difference between cyber crisis management and conventional public disaster and crisis management is the degree of networking required at national and international level. Cyber crises at a domestic level may be coped with only with the aid of governmental (public) and non-governmental (private) stakeholders and depend on international cooperation in almost all cases.

Select target paragraph3