amount of information from a certain group (e.g. data gathered for all citizens at the national level), which makes the vulnerability of such information resources critical for other interconnected information resources, too. It is necessary to analyse this area carefully and determine the criteria for defining national electronic registries which represent critical information resources, as well as the additional requirements for the protection of such critical information resources. This has to be conducted following the possibility of applying regulations on critical national infrastructures on the one hand and, on the other hand, possibly relating to the criteria for determining as classified the registries of information which, when put together in electronic form, become critical at the national level and in the sense described. Objective F.4 Improving the way protected information is handled by entities responsible for protected information, protected information processors and authorised users of protected information. Despite the satisfactory regulations, harmonised with international requirements of the EU and NATO, there is room for practical implementation improvements in the use and information sharing of both classified information and personal data, especially in relation to legal entities and the handling of electronic information, regardless of whether the legal entities appear as protected information processors or users. Special attention must be paid to the specificity of cyberspace and services based on computer infrastructure, software platforms or cloud development applications. It is necessary to develop adjusted contract supplement templates (appendices, annexes, clauses). These templates would be appropriately unified and prepared for various forms of practical application, thereby indicating to the entities obliged to apply legal regulations the details of implementation of all the obligations highly important for information protection. This would refer especially to contracts the implementation or conclusion of which requires access to and use of protected information. The particularities of cyberspace and e-services would also be covered, that is, the conditions of using infrastructure as a service (IaaS), platform as a service (PaaS), or software as a service (SaaS). These issues are viewed in the context of certain groups of protected information and accompanying regulatory requirements, and with regard to the particularities of cyberspace and cloud computing services. The mentioned issues include: problems related to information that is not physically controlled by the owner in the course of transmission, processing or storing; problems related to different legal responsibilities of service providers within various legal frameworks (national, EU, third countries); related issues of the relevant national framework for identification, authentication and authorisation (IAA) of the users of certain electronic services in public and economic sectors. Objective F.5 Unification of approach in using the set of standards ISO/IEC 270006. The set of standards ISO/IEC 27000 is used in several sectors of the society for protecting different groups of information (e.g. protection of personal data, protection of unclassified 6 Set of international standards for the area of information security management, accepted as the Croatian standard “HRN ISO/IEC 27000”. 20 of 31

Select target paragraph3