Summary
The development of modern information
and communication technologies (ICT)—
and above all the Internet—has led to an
unprecedented transformation of social
and economic life. In Austria about three
quarters of the population currently use
the Internet regularly, and one in every two
persons does so daily. The economy heavily
depends on ICT in order to take advantage
of e-commerce and ensure the efficiency
of internal procedures. For the public
administration ICT is indispensable when
it comes to making its services available
to a broad public through non-traditional
channels.
Today the general welfare of the state
depends to a considerable extent on the
availability and proper functioning of
cyberspace. While growth rates in Internet
usage, e-commerce and e‑government are
significant and cyber crime (in particular
hacking and phishing offences) is on the rise,
the Internet and computer skills of the users
have remained virtually unchanged. This has
led to dramatic disparities between actual
ICT usage, increasing IT crime, necessary IT
knowledge and risk awareness.
Attacks from cyberspace pose a direct
threat to our safety and security and to the
functioning of the state, the economy and
our society, and may therefore severely
affect our daily lives. One of Austria’s top
priorities is to tackle cyberspace security
using every means available at national and
international level. A first step is to define a
strategy to ensure cyberspace security.
The ICT Security Strategy is a
proactive concept designed to
protect cyberspace and human
beings in this virtual space
by taking into account their
fundamental rights and freedoms.
This strategy will not only improve
the security and resilience of
Austrian infrastructures and
services in cyberspace but also
create awareness and trust among
Austrian citizens.
The strategy addresses a wide range of
issues—from different aspects of creating
ICT security knowledge and ICT security
awareness to proactive and reactive cyber
incident management. The spectrum
covers education, research, sensitisation,
case law, technical and organisational
issues of Austrian enterprises as well as
the protection of strategically important
Austrian institutions.
ICT security is regarded as a common
key challenge. As far as an implementation
strategy is concerned, a bottom-up
approach has been chosen—with a broad
base involving all relevant stakeholders.
Hence, the strategic objectives and measures
for implementation of the Austrian concept
may be divided into five key areas:
••
••
••
••
••
Stakeholders and structures
Critical infrastructures
Risk management and status quo
Education and research
Awareness
In order to achieve the Austrian goals, the
Action Plan described below will increase
the effectiveness of both sector-specific
and trans-sectoral measures, which will
be implemented by taking into account
timelines and responsibilities.
4