CSIRT continually monitors the ICT resources of the Federal Administration for attack
patterns and has very substantial experience in dealing with extensively designed attacks on
the Confederation's infrastructure. However, if the number of tasks or the intensity of attacks
or potential for damage increases, the FOITT does not have the necessary human resources
for service provision.
Risk management in the Confederation
Risk management was introduced in the Confederation in 2005. Today, the objectives and
principles of risk management and the various risk management functions in the
Confederation are set out in the directives on the Confederation's risk policy of 24 September
2010 11. To ensure uniform implementation of risk management in the Federal Administration,
the Federal Finance Administration (FFA) set out the details in a uniform and binding manner
in guidelines of 21 November 2011.
Risks refer to events and developments that have a certain likelihood of occurring and would
have significant negative financial and non-financial repercussions for the Federal
Administration in terms of fulfilling its objectives and performing its tasks. The specialist units
in the administrative units and departments are responsible for the early detection of these
risks. Identified risks are analysed and evaluated. Based on the identified risk exposure, the
necessary measures are taken in order to prevent risks insofar as possible, or at least to
reduce them. Such task-related federal risk management is essentially implemented in a
decentralised manner in the administrative units and departments.
The specialist units in the administrative units and departments are tasked with the early
recognition of and defence against cyber attacks on the Federal Administration. As all federal
departments and administrative units are affected, the risk of "cyber attacks on the
Confederation's ICT systems" is managed as an interdisciplinary risk at the level of the
Federal Council.
Federal Department of the Environment, Transport, Energy and Communications (DETEC)
Federal Office of Communications (OFCOM)
OFCOM deals with telecommunications issues among other things. In this area, OFCOM
carries out all sovereign and regulatory tasks. In particular, it supervises telecommunications
in general, including Internet service providers (ISP). It is also responsible for address
elements in the telecommunications sector, including the contract under administrative law
with the register operator Switch for the administration of the .ch domain, as well as the
associated supervision and the electronic signature foundations. OFCOM is also extremely
active at the international level, particularly in the area of Internet governance and
international policies. Furthermore, OFCOM coordinates – at the national and international
level – the activities conducted within the scope of the Federal Council's strategy for an
information society in Switzerland.
Swiss Federal Office of Energy (SFOE)
The Swiss Federal Office of Energy SFOE is the competence centre for energy supply and
energy use issues. It creates the prerequisites for sufficient, crisis-resistant, widely
11
Federal Gazette 2010 6549
19/42