Awareness Initial situation Security studies and situation reports on ICT security illustrate very clearly that human error facilitates or even causes a substantial proportion of all security-related incidents. Though incomprehensible at first glance, many issues can be explained when ICT security is examined more closely. It is based on three key pillars: technology, organisation and the human factor. Human factor: Despite security-related progress and organisational rules which emerged in the industry and as a result of standardisation in the past few years, the human factor is still an important— probably the most important pillar—of ICT security. Ultimately, all technical and organisational security measures taken must be accepted and supported by human beings. After all it is the individual—the ICT user—who should be at the centre of all activities. ICT security culture: A future-oriented ICT security approach must therefore be human-centred and based on strengthening ICT security culture. The ICT security culture will determine the perception, understanding, personal attitude and knowledge necessary for security-conscious action. Despite all technical and organisational security measures available, sensitisation and awareness-raising as well as the knowledge of all target groups are crucial requirements determining the benefits and success of ICT security. Three main goals of awareness-related measures: •• to strengthen the perception of ICT security as an important issue, to arouse personal interest in and attract attention to ICT security (sensitisation of the target group), •• to create positive personal attitudes and develop an understanding of the need for ICT security (raising awareness at different levels) and •• to promote knowledge about securityconscious action and the responsible use of information and ICT through concrete and specific recommendations for action for each target group. Awareness-related measures have to be differentiated on the basis of action fields (such as citizens, economy, administration, education and research, CI) and target groups (in any case users, developers and operators of ICT). Pillars of ICT security ICT security Technology Human factor Organisation (ICT security culture) 25

Select target paragraph3