computer security incidents is collected in the competent CERTs according to the principle of
subsidiarity, and it is consolidated and monitored in central sectoral authorities. Bearing in
mind the particularities of the different society sectors and selected cyber security areas, types
of information about computer security incidents will be defined, as well as the ways of and
prerequisites for exchanging such information among the central sectoral authorities. Central
sectoral authorities will submit periodical reports to the National Cyber Security Council8
about the trends, situation and important incidents in the recent period. Central sectoral
authorities will submit appropriate reports to sectoral stakeholders on computer security
incidents. Special attention will be paid to the improvement of the existing systems for
collecting, analysing and storing incident-related information.
Objective G.2 Regular implementation of measures for improving security by issuing
warnings and recommendations.
The centrally collected information about computer security incidents has to be analysed,
exchanged and shared with the competent national regulatory authority and other relevant
stakeholders. Based on the analyses of that information and information collected in other
ways, bodies responsible for the security of public information systems and bodies
responsible for the security of government information systems will apply measures for
improving the security by defining warnings and recommendations.
Objective G.3 Establishing constant information sharing regarding computer security
incidents, as well as relevant information and expertise in solving specific cybercrime cases.
Information that becomes known to criminal prosecution authorities and the security and
intelligence system bodies in solving cybercrime cases significantly contributes to the overall
picture of cyber security in Croatia but also to better prevention. It is therefore necessary that
those bodies and the competent CERTs constantly exchange the appropriate information to
the extent possible considering the competences and needs of certain stakeholders. Other than
exchanging technical information, cooperation is necessary in the area of expertise, especially
in solving more complex cybercrime cases.
6.3 International cooperation (H)
Cyberspace and the related technologies and knowledge have an increasing role in the overall
development of the society, including the political, security, economic and social dimensions.
It is quite clear how necessary it is to apply the same principles of security, rule of law and
guarantees of established rights and freedoms to all individuals and legal entities in this field
of human activity, too, in the same way they are applied out of cyberspace. Considering the
fact that the international aspect is self-evident in the development, production and use of
8
See chapter 7.
22 of 31