2. PRINCIPLES Comprehensive nature of the approach to cyber security by covering cyberspace, infrastructure and users under the Croatian jurisdiction (citizenship, registration, domain, address); Integration of activities and measures arising from different cyber security areas and their interconnection and supplementation in order to create a safer cyberspace; Proactive approach through constant adjustment of activities and measures, and adequate periodic adaptation of the strategic framework they stem from; Strengthening resilience, reliability and adjustability by applying universal criteria of confidentiality, integrity and availability of certain groups of information and recognised social values, in addition to complying with the appropriate obligations related to the protection of privacy, as well as confidentiality, integrity and availability for certain groups of information, including the implementation of appropriate certification and accreditation of different kinds of devices and systems, and also business processes in which such information is used; Application of basic principles as basis of the organisation of modern society in the area of cyberspace as the society’s virtual dimension: 1. Application of law to protect human rights and liberties, especially privacy, ownership and all other essential characteristics of an organized contemporary society; 2. Developing a harmonised legal framework through continued improvement of all the segments of regulatory mechanisms of state and sector levels, and through harmonised initiatives of all the sectors of the society, that is, bodies and legal entities that are stakeholders in this Strategy; 3. Application of the principle of subsidiarity through a systematically elaborated transfer of power to make decisions and report on cyber security issues to the appropriate authority whose competences are closest to the matter being resolved in areas important for cyber security, from organization through coordination and cooperation to the technical issues of responding to computer threats to certain communication and information infrastructure; 4. Application of the principle of proportionality to make the level of protection increase and related costs in each area proportional to the related risks and abilities in limiting the threats causing them. 6 of 31

Select target paragraph3