information, guidelines of the Croatian central bank for credit institutions, rules of the national telecommunications regulatory authority for public electronic service providers). The competent sectoral authorities and the competent authorities for the defined groups of protected information should analyse the possibility of unifying the approach and adopting the positive experiences and best practices in the application of the same set of standards in a different application context, but with very similar application goals. This will provide more cost-effective solutions for all the entities obliged to implement regulations and, at the same time, ensure a better understanding of the best security practice and provide national-level solutions which will be much more efficient in terms of security. 6.2 Technical coordination in the treatment of computer security incidents (G) Technical coordination is one of the primary functions to be applied in the treatment of computer security incidents which resulted in the disruption of availability, confidentiality or integrity of information, in order to return to the pre-incident state. Considering the technical sophistication of modern-day attacks, a high level of technical capability of the CERTs7 personnel is crucial, as they are the bodies in charge of preventing and responding to computer security incidents. Further enhancement of inter-sectoral organisation and information sharing regarding computer security incidents represent the necessary conditions for efficient technical coordination, keeping in mind the protection of sensitive information (statistics, anonymization) for the purposes of incident treatment or regular reporting, and in order to get a clearer picture of the state of security in cyberspace at the national level in Croatia. The mentioned national level includes the consolidation of statistical indicators of society sectors through the competent CERTs for the national and sectoral levels. The services and user base of each CERT have to be clearly defined, in accordance with the principle of subsidiarity in responding. This principle refers to the activities of one or more CERTs responsible for communication and information infrastructure in which the computer security incident occurred and in which it is being treated. Especially important are the prevention activities requiring a small investment but offering the possibility of achieving significant effects and preventing major damage. Technical coordination plays an important role in the treatment and resolution of computer security incidents and the following is necessary for its improvement: Objective G.1 Continuous enhancement of existing systems for collecting, analysing and storing information about computer security incidents and making sure that other information essential for quick and efficient treatment of such incidents is up-to-date. Collecting, analysing and storing information about computer security incidents is very important for monitoring the trends and situation in national cyberspace. Information about 7 In the context of the Strategy, the term CERT refers to every organisational unit (or subunit including individuals) responsible for coordination, prevention of and protection against computer threats. 21 of 31

Select target paragraph3