6. INTERRELATIONS OF THE AREAS OF CYBER
SECURITY
The interrelations of cyber security areas are defined in accordance with the assessment of
Croatia’s needs at the time of drafting the Strategy and they cover cyber security segments
estimated to be common to all or most of the previously selected cyber security areas. The
selected interrelations of cyber security areas are:
1.
Protection of information;
2.
Technical coordination in the treatment of computer security incidents;
3.
International cooperation, and
4.
Education, research, development and raising security awareness in cyberspace.
The interrelations of cyber security areas are essential for the improvement and more efficient
achievement of the goals and measures in cyber security areas. The Strategy therefore also
defines special objectives, regarding the interrelations, which are considered crucial for
enhancing the level of security in cyberspace, with special reference to the defined society
sectors and the influence of each interrelation of cyber security areas on certain sectors of the
society and forms of cooperation and mutual coordination in the work of cyber security
stakeholders. The elaboration of interrelations of cyber security areas is done according to the
principles defined by the Strategy.
6.1 Protection of information (F)
In the life cycle of a piece of information, as soon as it is generated, it is necessary to
determine whether it belongs to a certain group of protected information and apply the
appropriate set of measures to protect such information. It is the responsibility of every
protected information owner and data controller, but also every protected information
processor and every authorised user of protected information, not only to take care of the
confidentiality and privacy of the information they use in their work, but also to be
accountable for the integrity and availability of the information that is released publicly in
cyberspace (web sites, social networks, etc.).
In order to direct the handling of protected information in an appropriate manner, especially
on the part of the entities responsible for protected information, the following groups of
protected information were identified in drafting this Strategy as the most important special
groups of protected information which require the implementation of adequate protection
policy: classified information, unclassified5 information, personal data and trade secret.
5
Group of information appropriately marked, used only for official purposes in the government sector, which
does not have the characteristic of being secret.
18 of 31