microentrepreneurs mid-sized enterprises small enterprises large enterprises authorities / critical public information administration infrastructures secure web applications (online banking, e-government) Minimum security standards for ICT security and data protection Existing norms, standards and manuals (ISO/IEC 27001 et seq., “Austrian Security Manual”, “IT Security Manual for SMEs”, “IT Security Manual for Employees”, etc. Standardisation: Clear minimum security standards for ICT security and data protection have to be developed and published to ensure effective security and, in particular, to reach a common understanding of present requirements. In accordance with different threat potentials, minimum security standards at different levels must be defined, e.g. based on company size and sector. The development of standards will be based on the Information Security Manual and take into account other existing norms, standards, frameworks and manuals. Voluntary security peer review programmes Minimum security standards for ICT security and data protection by recognised Austrian universities and research institutions have to be set up and promoted. In evaluating the quality and security of their ICT services and ICT products, Austrian enterprises and organisations may be supported by external quality testing procedures. Such a certificate will allow them to demonstrate (competitive advantage) and prove (tender procedures) to the public (their customers) that their ICT security has been tested and conforms to security standards. The participating (recognised) institutions of the security peer review programmes will be published on the ICT security portal. Examples of using existing structures and synergy potential Awareness campaigns •• Articles/documentaries (educational mandate) in existing formats (e.g. Newton, Thema, Konkret das Servicemagazin, ATV report, etc.) –– broadcasting (e.g. ORF and ATV channels) as well as print and online media •• Information and communication (active reference to the theme ICT security, distribution of brochures and providing information on websites) by –– PP partners in the public administration with office hours for the public (police services, Advisory Service of Criminal Police, finance and customs offices, federal army, regional administration, district commissions, schools, municipal offices, etc.) –– PP partners in the area of interest representations (WKO, AK, VKI, etc.) –– PP partners in the business sector with customer service points (banks, Internet service providers, ICT retail store chains, ICT service providers, etc.) 29

Select target paragraph3