Introduction
ICT security is a common objective—and
as the challenges faced by ICT security
are of increasing frequency and scope,
a coordinated approach has become
indispensable. However, due to the dynamic
nature of these challenges, conventional
strategies have been subjected to extreme
stress. A more long-term and international
perspective is required in order to stabilise
this situation.
Austria’s ICT Security Strategy
therefore has to define its position within a
European context as an important reference
for further action. It must also give Austria
a stronger voice in the concert of EU
Member States in the field of ICT security.
Hence, Austria’s firm commitment to the
sustainable development of this sector in
Europe is absolutely essential.
Due to general priorities, the “security
poverty line” in the SME sector and private
sphere is low. As Austria is a country with
a particularly high proportion of small
and medium-sized enterprises (SMEs), it is
necessary to focus on the requirements of
these sectors.
Critical information infrastructures
and their protection are core objectives of
ICT security strategies. On this basis, it
is necessary to implement consolidation
measures and plotlines ensuring the
calculability of risks.
Reactive strategies such as cyber
security or cyber defence measures are vital
and integral elements. However, they cannot
be applied effectively unless complemented
by proactive strategy elements on a large
scale. The latter are usually characterised
by a significantly higher cost/effectiveness
factor.
This fact poses special challenges to
formal and non-formal types of education,
preparatory phases of labour market
reintegration as well as to the media,
especially radio and TV. This mandate
must go beyond the scope of current
incident reports since not even the most
fundamental efforts have been made to
realise the potential in this area. Interest
representations such as chambers are
equally challenged to bundle and intensify
their existing activities across sectors.
To ensure the calculability of risks
in all areas, there must be considerably
more cooperation between the economy
and security research. Highly visible best
practices (“lighthouses”) of competent
implementation (e.g. integral security in
Austria’s e-government system) have to be
established in other areas at transnational
level in order to ensure the long-term
viability of the Austrian economy. The aim
of coordinating cooperation with education
and research is to respond to dynamic
developments, to identify new trends in due
course through technology monitoring and
to improve resilience.
To increase general ICT risk awareness
beyond the level of specific incidents, the
public administration will not only have
to take ICT security seriously within its
own purview but also to implement it
in a competent manner. Based on the
useful approach embodied in the ICT
Consolidation Act, there is a need for action
in other areas as well.
CIIP Action Plans define a common
roadmap and establish a comprehensive
and logical sequence of steps to be taken
on the basis of ICT exercises. In line with
these plans, protection profiles will have to
be created for technologies used in critical
infrastructures within the framework
of international cooperation (e.g. by
involving ENISA/CEN/ETSI ...). It will
also be necessary to arrive at a common
understanding of examination/certification
and monitoring processes.
A start has been made by developing a
process-oriented approach. On this basis,
it will be possible to formulate an overall
strategy, to identify the stakeholders and
create an institutional framework for the
continuing commitment and cooperation of
these players with a view to achieving the
goals.
Reinhard Posch,
Chief Information Officer of the Federal
Republic of Austria
3