Maintaining and updating the Information Security Manual to ensure basic protection: The “Austrian Information Security Manual” (Österreichisches Informationssicherheitshandbuch/SIHA) was revised and reorganised in 2012. The Manual describes and supports procedures for the establishment of comprehensive information security management system in enterprises and the public administration. SIHA 2010 has been tailored to the needs of small and medium-sized enterprises implementing ISM measures. Complying with international requirements, its structure and content facilitate the implementation of the ISO/IEC 27000 series of standards. The internationally recognised manual makes an important contribution to ensuring a minimum level of protection, and is updated on a regular basis. See also chapter ‘Education and research’. Conducting technology assessments: Radical technology changes are likely to occur every two to three years in the field of cyber security. It is therefore necessary to monitor present and future technology trends, and to assess their possible impact on the social and economic life. Technology assessment must be tackled within the framework of a research programme which may be linked with existing initiatives (e.g. KIRAS). Voluntary registration system: Like voluntary fire services, ICT specialists may sign up via a registration system (of the Cyber Competence Centre), providing information on their technical skills, identity and certificates and/or quality certification (e.g. security screening pursuant to the Security Police Act [Sicherheitspolizeigesetz/ SPG]). Organisations and enterprises have fast and unbureaucratic access to qualified personnel in an emergency with due regard for legal requirements. Objective 3: Information exchange of public and private stakeholders Hypothesis: Information exchange is regarded as the most important element of national cyber security. Since the wide diversity of stakeholders coupled with the growing importance of the private sector make a purely public centralised management impracticable, a continuous exchange of information (particularly threat-related) is necessary to strengthen the self-protection of different stakeholders. The major goal in this context is to ensure consistency with the Austrian Programme for Critical Infrastructure Protection (APCIP). Strategic objectives: The exchange of information takes place between governmental stakeholders, between non-governmental stakeholders and between governmental and nongovernmental stakeholders. One of the crucial goals of all programmes protecting critical infrastructures is to support publicprivate partnerships (PPPs) as a general organisational framework for cooperation between governmental and nongovernmental stakeholders. The need for information exchange must be reconciled with confidentiality and data protection requirements. Measures Supporting public-private partnerships (PPPs): To an increasing extent, the protection of critical information infrastructures and cyber security is coordinated by “trusted” public-private partnerships (PPPs). Examples of existing PPPs are CERT.at as a “community-based PPP” and the Austrian Trust Circle, which exchanges information between private bodies. Legal certainty with respect to reporting duty: Operators of critical infrastructures have a special responsibility which must receive due consideration whenever 16

Select target paragraph3