Summary The development of modern information and communication technologies (ICT)— and above all the Internet—has led to an unprecedented transformation of social and economic life. In Austria about three quarters of the population currently use the Internet regularly, and one in every two persons does so daily. The economy heavily depends on ICT in order to take advantage of e-commerce and ensure the efficiency of internal procedures. For the public administration ICT is indispensable when it comes to making its services available to a broad public through non-traditional channels. Today the general welfare of the state depends to a considerable extent on the availability and proper functioning of cyberspace. While growth rates in Internet usage, e-commerce and e‑government are significant and cyber crime (in particular hacking and phishing offences) is on the rise, the Internet and computer skills of the users have remained virtually unchanged. This has led to dramatic disparities between actual ICT usage, increasing IT crime, necessary IT knowledge and risk awareness. Attacks from cyberspace pose a direct threat to our safety and security and to the functioning of the state, the economy and our society, and may therefore severely affect our daily lives. One of Austria’s top priorities is to tackle cyberspace security using every means available at national and international level. A first step is to define a strategy to ensure cyberspace security. The ICT Security Strategy is a proactive concept designed to protect cyberspace and human beings in this virtual space by taking into account their fundamental rights and freedoms. This strategy will not only improve the security and resilience of Austrian infrastructures and services in cyberspace but also create awareness and trust among Austrian citizens. The strategy addresses a wide range of issues—from different aspects of creating ICT security knowledge and ICT security awareness to proactive and reactive cyber incident management. The spectrum covers education, research, sensitisation, case law, technical and organisational issues of Austrian enterprises as well as the protection of strategically important Austrian institutions. ICT security is regarded as a common key challenge. As far as an implementation strategy is concerned, a bottom-up approach has been chosen—with a broad base involving all relevant stakeholders. Hence, the strategic objectives and measures for implementation of the Austrian concept may be divided into five key areas: •• •• •• •• •• Stakeholders and structures Critical infrastructures Risk management and status quo Education and research Awareness In order to achieve the Austrian goals, the Action Plan described below will increase the effectiveness of both sector-specific and trans-sectoral measures, which will be implemented by taking into account timelines and responsibilities. 4

Select target paragraph3