Official Gazette, 79/2007 Article 21 CERT and the Information Systems Security Bureau shall cooperate on the prevention and protection from computer threats to information systems security and shall take part in the making of information systems security recommendations and standards in the Republic of Croatia. Article 22 The Director of CARNet shall appoint the Assistant competent for managing CERT. VI INFORMATION SECURITY IMPLEMENTATION Article 23 (1) Bodies and legal persons referred to in Article 1, paragraph 2 of this Act shall apply the information security measures and standards referred to in Article 7 of this Act. (2) In bodies and legal persons who do not have the appropriate computer and technical means the measures and standards referred to in paragraph 1 of this Article shall be applied by the central state administration authority competent for information systems development (Communication and information systems Planning and Implementation Authority). (3) Within the educational and academic sector the measures and standards referred to in paragraph 1 of this Article shall be applied by the central state authority competent for science and education (Communication and Information Systems Planning and Implementation Authority). Article 24 (1) Bodies and legal persons referred to in Article 1, paragraph 2 of this Act shall determine the implementation of information security measures and standards by Ordinance. (2) Central state administration authorities referred to in Article 23, paragraphs 2 and 3 of this Act shall determine the way of implementing information security measures and standards in other bodies by Ordinance. VII INFORMATION SECURITY OVERSIGHT Article 25 (1) The works of information security oversight are the works of oversight of organization, implementation and effectiveness of stipulated information security measures and standards in bodies and legal persons referred to in Article 1, paragraph 2 of this Act. (2) The works of oversight referred to in paragraph 1 of this Article shall be implemented by information security advisors. 7

Select target paragraph3