Objective 5: ICT security research as a basis of national competence Objective 6: Covering ICT security to a greater extent in applied ICT research Hypothesis: State-of-the-art competence must be ensured in the sensitive area of ICT security at national level to prepare decision-making processes and consequently to engage in development. Hypothesis: ICT security is an integral part of IT products, systems and solutions. Security aspects must therefore also become an integral part of ICT research projects. On the other hand, findings of other scientific disciplines (e.g. biology or psychology) should be taken into account in ICT security research to a greater extent than in the past. Strategic objective: to promote the establishment of security research institutes as well as to strengthen networking among research organisations. Measures National know-how in ICT security research: to strengthen national competence centres active in ICT security research, to establish new ones, to create facilities complementing comprehensive security research programmes such as KIRAS (with a “communication and information” research sector) with a view to optimising resources; to promote a broad approach to security research and foster measures enhancing the national thematic priority of “protection of critical infrastructures”; to establish new research topics (e.g. development of robust applications and systems, improvement of network resilience as well as social and political resilience in the event of ICT-based attacks); to develop “common terms of reference” jointly with standardisation initiatives. Promoting networking between individual research organisations: to make greater use of existing networking instruments, e.g. Security Research Map or KIRAS Innovation Platforms. Coordination and exchange of experience between ICT security research stakeholders to bundle the measures required to implement the findings of security research. Strategic objective: Applied ICT research as well as other research areas should increasingly cover ICT security issues; this will strengthen ties with other scientific disciplines and promote practical application. Measures Security aspects in applied ICT research: to examine, if possible, in all ICT research projects which aspects relevant to ICT security have to be taken into account, e.g. by establishing additional evaluation criteria (similar to gender aspects, aspects of humanities, social and cultural sciences in KIRAS projects or security considerations involving RFCs). Cooperation between political decision-makers and research institutions active in technology assessment may be institutionalised, similarly to TAB in Germany or POST in England. Promoting interdisciplinary approaches in security research and practical implementation: Findings and technologies from other areas (e.g. biology) are applied to ICT security research. To develop creative solutions to security problems, a research line on ICT security should be established in which other research disciplines participate on a mandatory basis. An institution responsible for evaluating and implementing findings of security research projects must be set up. Measures must be taken to improve the implementation of findings from security research in industry as well as in concrete projects. An “incentive system” (based on the model of the “Innovation 23

Select target paragraph3