In cyber security areas identified by this Strategy there is a great need for information sharing
concerning the information that in most cases represents one of the above mentioned special
groups of protected information.
Each of these protected information groups is regulated by an appropriate package of acts and
subordinate legislation, and the problems encountered so far in practice were in most cases
related to the implementation policies of information protection, especially in legal entities,
and to a broader lack of understanding and awareness in different society sectors of the need
and necessity to develop a culture of handling certain groups of protected information.
The following is required in order to improve the state of security and provide all the
prerequisites for unobstructed information sharing concerning such information among the
different competent stakeholders involved in certain cyber security activities:
Objective F.1 Improvement of national regulations in the area of trade secrets.
It has been detected that there is room for improvement in the area of trade secrets at the
national level, which should be consistent with the ongoing unification of this field started in
2013 by the EU among Member States. The current situation may lead to legal uncertainty
and it is considered necessary to elaborate the criteria for designating and protecting trade
secrets, with mandatory application of the duty of care principles by those responsible in
using this group of protected information.
Objective F.2 Encouraging continuous cooperation of authorities competent for special
groups of protected information in national environment to achieve alignment in
implementation of relevant regulations.
It has been detected that interdepartmental and inter-sectoral coordination of the entire society
is necessary for harmonising certain implementing elements of legal regulations. Emphasis is
placed on the need and importance of exchange of experiences among the national and
international authorities competent for certain groups of protected information in the national
environment, as well as following all the current amendments to the rules regulating access to
information, especially in the EU and NATO environment, and in the scope of the needs and
obligations of Croatia as a member of the EU and NATO. Measures from the Action plan for
the implementation of the Strategy have to focus the attention towards the institutions, namely
all the entities responsible for protected information. The role of the entities responsible for
protected information is to ensure a uniform approach to the implementation of the relevant
regulations on the part of all the protected information processors. This also applies to the
authorised users of such information in the framework of the appropriate internal information
security policies implemented by those processors and users.
Objective F.3 Determining criteria for identifying national electronic registries, which are
critical information resources, and entities responsible for their protection.
Inadequate policies of protecting information in national electronic registries are one of the
important problems that have been detected. The problem lies in the cumulation of a large
19 of 31