amount of information from a certain group (e.g. data gathered for all citizens at the national
level), which makes the vulnerability of such information resources critical for other
interconnected information resources, too. It is necessary to analyse this area carefully and
determine the criteria for defining national electronic registries which represent critical
information resources, as well as the additional requirements for the protection of such critical
information resources. This has to be conducted following the possibility of applying
regulations on critical national infrastructures on the one hand and, on the other hand,
possibly relating to the criteria for determining as classified the registries of information
which, when put together in electronic form, become critical at the national level and in the
sense described.
Objective F.4 Improving the way protected information is handled by entities responsible for
protected information, protected information processors and authorised users of protected
information.
Despite the satisfactory regulations, harmonised with international requirements of the EU
and NATO, there is room for practical implementation improvements in the use and
information sharing of both classified information and personal data, especially in relation to
legal entities and the handling of electronic information, regardless of whether the legal
entities appear as protected information processors or users. Special attention must be paid to
the specificity of cyberspace and services based on computer infrastructure, software
platforms or cloud development applications. It is necessary to develop adjusted contract
supplement templates (appendices, annexes, clauses). These templates would be appropriately
unified and prepared for various forms of practical application, thereby indicating to the
entities obliged to apply legal regulations the details of implementation of all the obligations
highly important for information protection. This would refer especially to contracts the
implementation or conclusion of which requires access to and use of protected information.
The particularities of cyberspace and e-services would also be covered, that is, the conditions
of using infrastructure as a service (IaaS), platform as a service (PaaS), or software as a
service (SaaS). These issues are viewed in the context of certain groups of protected
information and accompanying regulatory requirements, and with regard to the particularities
of cyberspace and cloud computing services. The mentioned issues include: problems related
to information that is not physically controlled by the owner in the course of transmission,
processing or storing; problems related to different legal responsibilities of service providers
within various legal frameworks (national, EU, third countries); related issues of the relevant
national framework for identification, authentication and authorisation (IAA) of the users of
certain electronic services in public and economic sectors.
Objective F.5 Unification of approach in using the set of standards ISO/IEC 270006.
The set of standards ISO/IEC 27000 is used in several sectors of the society for protecting
different groups of information (e.g. protection of personal data, protection of unclassified
6
Set of international standards for the area of information security management, accepted as the Croatian
standard “HRN ISO/IEC 27000”.
20 of 31