Communication and information systems that run the critical infrastructure or are essential for
its functioning represent critical communication and information infrastructure, regardless of
which critical infrastructure sector they belong to.
It is therefore necessary that the identification of critical communication and information
infrastructure and prescription of mandatory technical and organizational measures, including
procedures of reporting about computer security incidents, be carried out in a coordinated
manner by central state bodies responsible for certain critical infrastructure sectors, critical
infrastructure owners/operators and competent technical and security-related state authorities.
In addition, establishing a cyber crisis management system that will ensure a timely and
efficient reaction/response to a threat and the recovery of infrastructure or service is of
particular interest to the Republic of Croatia in terms of security.
The system of cyber crisis management in Croatia needs to be established in accordance with
the following requirements:
1.
2.
3.
4.
Harmonisation with the national crisis management solutions,
Inclusion of the protection of critical national communication and information
infrastructure,
Harmonisation with international cyber crisis management systems of the EU and
NATO,
Harmonisation with national competences of the bodies legally responsible for the
coordination of the prevention of and the response to computer threats to the security
of information systems.
In that sense, it is necessary to:
Objective D.1 Determine criteria for identifying critical communication and information
infrastructure.
The criteria for identifying critical communication and information infrastructure must follow
and further elaborate the methodology of approach envisaged by the Act on Critical
Infrastructures. Critical communication and information infrastructure is determined in the
framework of the sectors designated by the aforementioned Decision of the Croatian
Government on designation of sectors from which central state administration bodies identify
critical national infrastructures and critical infrastructures sector sequence list. The criteria
defined for designating critical communication and information infrastructure must arise from
the methodology applied by the Act on Critical Infrastructures. If the situation analysis proves
it necessary, they can be further elaborated and prescribed by the appropriate subordinate
legislation.
Objective D.2 Determine binding security measures to be applied by owners/operators of
designated critical communication and information infrastructure.
It is necessary to determine a set of security measures to be applied systematically by all the
designated owners/operators of critical communication and information infrastructure, as well
as the necessary relation to the general information security regulations, in segments such as
14 of 31