APPENDIX: TERMS AND ACRONYMS Terms Authorised users of protected information - users of protected information whose authorisation, i.e. right of use, is based on legal or contractual basis, but who are not entities responsible for protected information or protected information processors. Computer security incident - one or more computer security events that have disturbed or are disturbing the security of the information system. Credentials - set of information used for introducing the user of electronic service, which serves as proof for electronic identity (e-ID) verification, in order to grant access to electronic services (e-services). Critical communication and information infrastructure - communication and information systems whose disturbed functioning would significantly disturb the work of one or more identified critical national infrastructures. Cyber (computer) crime - criminal offences against computer systems, software support and data; committed in cyberspace using information and communication technologies. Cyber crisis - event or events in cyberspace which could cause or have already caused a significant disturbance in Croatia’s social, political and economic life. Such a situation can eventually affect the security of people, democratic system, political stability, economy, environment and other national values, that is, national security and defence in general. Cyber security - encompasses activities and measures for achieving the confidentiality, integrity and availability of information and systems in cyberspace. Cyberspace - space in which communication among information systems takes place. In the context of the Strategy, it encompasses the Internet and all the systems connected to it. Electronic communication and information infrastructure - includes computer and communication systems and software support used for data transmission, processing, storing. Electronic communication and information services - commercial and non-commercial services provided using information and communication systems. Electronic financial services - financial services provided directly to users by their authorised providers via electronic communication and information infrastructure (e.g. online and mobile banking, ATMs, EFTPOS systems). Electronic financial service providers - subjects authorised by the competent authority to provide electronic financial services. Entities responsible for protected information - protected information owners and information controllers. 29 of 31

Select target paragraph3