1. INTRODUCTION
Nowhere has technological development been more dynamic and comprehensive than in the
area of communication and information technology. The focus has always been on the rapid
development and introduction of new services and products, while the security-related aspects
usually had little influence on the broad acceptance of new technologies.
The life cycles of modern-day information systems, from the process of planning,
introduction and usage to their withdrawal from use are very short, which often makes their
systematic testing impossible and is most commonly applied as an exception, in expressly
prescribed cases.
Users usually have minimal knowledge of the technology they are using, and the technology
is applied in such a way that makes it very hard to estimate the security characteristics of the
majority of commercial products regarding the protection of user data confidentiality and
privacy. Due to that, users’ attitude towards the communication and information technology is
based almost exclusively on blind confidence.
Modern societies are deeply imbued with communication and information technology. People
are nowadays connected using various technologies for the transmission of text, image and
sound, including the increasing Internet of Things (IoT) trend.
While a deviation in the normal functioning of a certain kind of communication and
information system could go unnoticed, improper operation of some other systems could have
harsh consequences for the functioning of the State; it can cause loss of life, damage to health,
great material damage, pollution of the environment and the disturbance of other
functionalities essential for the proper functioning of the society as a whole.
From the beginning of the development of communication and information technologies until
the present day, deviations in their proper functioning have occurred due to different reasons,
from human error or malicious action to technological error or organizational omission.
The creation of the Internet and connecting a number of communication and information
systems of the public, academic and economic sectors, as well as citizens, created the
contemporary cyberspace composed not only of this interconnected infrastructure, but also of
the ever growing amounts of available information, and users communicating increasingly
among themselves using a growing number of different services - some completely new,
some traditional, but in a new, virtual form.
Deviations in the proper operation of these interconnected systems or their parts are no longer
merely technical difficulties; they pose a danger with a global security impact. Modern
societies counter them with a range of activities and measures collectively called “cyber
security”.
The term “cyber” entered the Croatian legal system upon the ratification of the Budapest
Convention on Cybercrime1 back in 2002. Following from that, the term “cyber” is most
1
Act on the Ratification of the Convention on Cybercrime (Official Gazette No 09/02) and Act on the
Ratification of the Additional Protocol to the Convention on Cybercrime, concerning criminalisation of acts of a
racist and xenophobic nature committed through computer systems (Official Gazette No 04/08).
3 of 31