Communication and information systems that run the critical infrastructure or are essential for its functioning represent critical communication and information infrastructure, regardless of which critical infrastructure sector they belong to. It is therefore necessary that the identification of critical communication and information infrastructure and prescription of mandatory technical and organizational measures, including procedures of reporting about computer security incidents, be carried out in a coordinated manner by central state bodies responsible for certain critical infrastructure sectors, critical infrastructure owners/operators and competent technical and security-related state authorities. In addition, establishing a cyber crisis management system that will ensure a timely and efficient reaction/response to a threat and the recovery of infrastructure or service is of particular interest to the Republic of Croatia in terms of security. The system of cyber crisis management in Croatia needs to be established in accordance with the following requirements: 1. 2. 3. 4. Harmonisation with the national crisis management solutions, Inclusion of the protection of critical national communication and information infrastructure, Harmonisation with international cyber crisis management systems of the EU and NATO, Harmonisation with national competences of the bodies legally responsible for the coordination of the prevention of and the response to computer threats to the security of information systems. In that sense, it is necessary to: Objective D.1 Determine criteria for identifying critical communication and information infrastructure. The criteria for identifying critical communication and information infrastructure must follow and further elaborate the methodology of approach envisaged by the Act on Critical Infrastructures. Critical communication and information infrastructure is determined in the framework of the sectors designated by the aforementioned Decision of the Croatian Government on designation of sectors from which central state administration bodies identify critical national infrastructures and critical infrastructures sector sequence list. The criteria defined for designating critical communication and information infrastructure must arise from the methodology applied by the Act on Critical Infrastructures. If the situation analysis proves it necessary, they can be further elaborated and prescribed by the appropriate subordinate legislation. Objective D.2 Determine binding security measures to be applied by owners/operators of designated critical communication and information infrastructure. It is necessary to determine a set of security measures to be applied systematically by all the designated owners/operators of critical communication and information infrastructure, as well as the necessary relation to the general information security regulations, in segments such as 14 of 31

Select target paragraph3