Establishing a Cyber Situation Centre: see
chapter ‘takeholders and structures’.
Establishing a viable crisis communication
system: Communication with the
organisations and companies responsible
for operating key networks needs to be
strengthened. A functioning and properly
secured communication system with public
and private stakeholders abroad has to be
ensured in acute cases. The establishment of
an “emergency network” (e.g. with the aid
of DVB-T technology) should be guaranteed
at any time. Other options of fail-safe
communication (e.g. VHF radio) will also
have to be taken into consideration. In a
crisis situation, it is also essential to verify
the identity of participants. A suitable legal
basis is required, especially for passing on
information.
Protection
of critical
information
infrastructures
Protection
of critical
infrastructure
Cyber
security
Cyber
crisis
management
Facility
protection
Special
cyber
situations
Public crisis
and civil protection management
Objective 2: Risk management and
information security
Hypothesis: One of the most effective
methods of promoting cyber security and
facilitating day-to-day operations is to
encourage self-protection by proactive risk
minimisation at the level of the enterprise
or organisation (risk management and
information security).
Strategic objective:
To ensure that risk management and
information security methods are applied
are as far-reaching and differentiated as
possible within the critical infrastructures
identified. Services of special general interest
require a higher level of protection.
Measures
Promoting risk management within CI:
The establishment of ICT-related risk
management (generally also referred to as
“information security”) is regarded as one
of the most important measures which CI
operators can take to protect themselves.
In the context of national cyber security
it is of fundamental importance that all
stakeholders responsible take information
security or ICT-related risk management
measures in their respective sphere of
responsibility. The government supports
them by providing information on joint
risk analysis, accreditation of different risk
management methods, harmonisation of
training measures as well as technology
assessment analyses. Sanctions and
incentives promote the use of risk
management methods in the private sector.
For further information on
Cyber crisis management see
chapter ‘Stakeholders and
structures’.
Establishing a Cyber Competence Centre:
The Cyber Competence Centre is part of the
Cyber Security Platform and is the central
point of contact for all operators of critical
infrastructure and also for enterprises
interested in risk management/information
security management (RM/ISM). It
provides information on different RM/ISM
approaches and accreditation procedures,
e.g. based on the Security Manual 2010
or ISO 27000. Together with the Cyber
Situation Centre, quantitative information
is processed for specific cyber security risk
analysis.
15