Introduction ICT security is a common objective—and as the challenges faced by ICT security are of increasing frequency and scope, a coordinated approach has become indispensable. However, due to the dynamic nature of these challenges, conventional strategies have been subjected to extreme stress. A more long-term and international perspective is required in order to stabilise this situation. Austria’s ICT Security Strategy therefore has to define its position within a European context as an important reference for further action. It must also give Austria a stronger voice in the concert of EU Member States in the field of ICT security. Hence, Austria’s firm commitment to the sustainable development of this sector in Europe is absolutely essential. Due to general priorities, the “security poverty line” in the SME sector and private sphere is low. As Austria is a country with a particularly high proportion of small and medium-sized enterprises (SMEs), it is necessary to focus on the requirements of these sectors. Critical information infrastructures and their protection are core objectives of ICT security strategies. On this basis, it is necessary to implement consolidation measures and plotlines ensuring the calculability of risks. Reactive strategies such as cyber security or cyber defence measures are vital and integral elements. However, they cannot be applied effectively unless complemented by proactive strategy elements on a large scale. The latter are usually characterised by a significantly higher cost/effectiveness factor. This fact poses special challenges to formal and non-formal types of education, preparatory phases of labour market reintegration as well as to the media, especially radio and TV. This mandate must go beyond the scope of current incident reports since not even the most fundamental efforts have been made to realise the potential in this area. Interest representations such as chambers are equally challenged to bundle and intensify their existing activities across sectors. To ensure the calculability of risks in all areas, there must be considerably more cooperation between the economy and security research. Highly visible best practices (“lighthouses”) of competent implementation (e.g. integral security in Austria’s e-government system) have to be established in other areas at transnational level in order to ensure the long-term viability of the Austrian economy. The aim of coordinating cooperation with education and research is to respond to dynamic developments, to identify new trends in due course through technology monitoring and to improve resilience. To increase general ICT risk awareness beyond the level of specific incidents, the public administration will not only have to take ICT security seriously within its own purview but also to implement it in a competent manner. Based on the useful approach embodied in the ICT Consolidation Act, there is a need for action in other areas as well. CIIP Action Plans define a common roadmap and establish a comprehensive and logical sequence of steps to be taken on the basis of ICT exercises. In line with these plans, protection profiles will have to be created for technologies used in critical infrastructures within the framework of international cooperation (e.g. by involving ENISA/CEN/ETSI ...). It will also be necessary to arrive at a common understanding of examination/certification and monitoring processes. A start has been made by developing a process-oriented approach. On this basis, it will be possible to formulate an overall strategy, to identify the stakeholders and create an institutional framework for the continuing commitment and cooperation of these players with a view to achieving the goals. Reinhard Posch, Chief Information Officer of the Federal Republic of Austria 3

Select target paragraph3