In cyber security areas identified by this Strategy there is a great need for information sharing concerning the information that in most cases represents one of the above mentioned special groups of protected information. Each of these protected information groups is regulated by an appropriate package of acts and subordinate legislation, and the problems encountered so far in practice were in most cases related to the implementation policies of information protection, especially in legal entities, and to a broader lack of understanding and awareness in different society sectors of the need and necessity to develop a culture of handling certain groups of protected information. The following is required in order to improve the state of security and provide all the prerequisites for unobstructed information sharing concerning such information among the different competent stakeholders involved in certain cyber security activities: Objective F.1 Improvement of national regulations in the area of trade secrets. It has been detected that there is room for improvement in the area of trade secrets at the national level, which should be consistent with the ongoing unification of this field started in 2013 by the EU among Member States. The current situation may lead to legal uncertainty and it is considered necessary to elaborate the criteria for designating and protecting trade secrets, with mandatory application of the duty of care principles by those responsible in using this group of protected information. Objective F.2 Encouraging continuous cooperation of authorities competent for special groups of protected information in national environment to achieve alignment in implementation of relevant regulations. It has been detected that interdepartmental and inter-sectoral coordination of the entire society is necessary for harmonising certain implementing elements of legal regulations. Emphasis is placed on the need and importance of exchange of experiences among the national and international authorities competent for certain groups of protected information in the national environment, as well as following all the current amendments to the rules regulating access to information, especially in the EU and NATO environment, and in the scope of the needs and obligations of Croatia as a member of the EU and NATO. Measures from the Action plan for the implementation of the Strategy have to focus the attention towards the institutions, namely all the entities responsible for protected information. The role of the entities responsible for protected information is to ensure a uniform approach to the implementation of the relevant regulations on the part of all the protected information processors. This also applies to the authorised users of such information in the framework of the appropriate internal information security policies implemented by those processors and users. Objective F.3 Determining criteria for identifying national electronic registries, which are critical information resources, and entities responsible for their protection. Inadequate policies of protecting information in national electronic registries are one of the important problems that have been detected. The problem lies in the cumulation of a large 19 of 31

Select target paragraph3