information, guidelines of the Croatian central bank for credit institutions, rules of the
national telecommunications regulatory authority for public electronic service providers). The
competent sectoral authorities and the competent authorities for the defined groups of
protected information should analyse the possibility of unifying the approach and adopting the
positive experiences and best practices in the application of the same set of standards in a
different application context, but with very similar application goals. This will provide more
cost-effective solutions for all the entities obliged to implement regulations and, at the same
time, ensure a better understanding of the best security practice and provide national-level
solutions which will be much more efficient in terms of security.
6.2 Technical coordination in the treatment of computer security incidents
(G)
Technical coordination is one of the primary functions to be applied in the treatment of
computer security incidents which resulted in the disruption of availability, confidentiality or
integrity of information, in order to return to the pre-incident state. Considering the technical
sophistication of modern-day attacks, a high level of technical capability of the CERTs7
personnel is crucial, as they are the bodies in charge of preventing and responding to
computer security incidents. Further enhancement of inter-sectoral organisation and
information sharing regarding computer security incidents represent the necessary conditions
for efficient technical coordination, keeping in mind the protection of sensitive information
(statistics, anonymization) for the purposes of incident treatment or regular reporting, and in
order to get a clearer picture of the state of security in cyberspace at the national level in
Croatia. The mentioned national level includes the consolidation of statistical indicators of
society sectors through the competent CERTs for the national and sectoral levels. The
services and user base of each CERT have to be clearly defined, in accordance with the
principle of subsidiarity in responding. This principle refers to the activities of one or more
CERTs responsible for communication and information infrastructure in which the computer
security incident occurred and in which it is being treated. Especially important are the
prevention activities requiring a small investment but offering the possibility of achieving
significant effects and preventing major damage.
Technical coordination plays an important role in the treatment and resolution of computer
security incidents and the following is necessary for its improvement:
Objective G.1 Continuous enhancement of existing systems for collecting, analysing and
storing information about computer security incidents and making sure that other information
essential for quick and efficient treatment of such incidents is up-to-date.
Collecting, analysing and storing information about computer security incidents is very
important for monitoring the trends and situation in national cyberspace. Information about
7
In the context of the Strategy, the term CERT refers to every organisational unit (or subunit including
individuals) responsible for coordination, prevention of and protection against computer threats.
21 of 31