Spheres of action and measures that should help reduce cyber risks are subsequently defined. These spheres of action are described over a risk management and protection cycle 31. While the risk management and protection cycle comprises five sub-processes (identification, analysis and evaluation; performance target and planning; measures; implementation; checking and verification), this strategy addresses only the first three steps for each sphere of action (identification, analysis and assessment; performance target and planning; measures). Identification, analysis and evaluation Checking and verification (4.3.8) Implementation Performance target and planning Measures The measures are implemented by the competent players in administration, the private sector and society. Insofar as the implementation steps concern federal units, they are described. These are primarily initial implementation steps at the federal level in order to initiate implementation planning at all levels in cooperation with the relevant partners from administration, the private sector and society. The coordination unit which has to be created is responsible for checking and verifying the measures implemented, in close cooperation with the responsible units. 4.3.1 Sphere of action 1: Research and development Identification, analysis and evaluation New risks in connection with cyber crime are to be researched so that informed decisions can be made at an early stage in the private sector and political and research circles. Research focuses on technological, social, political and economic trends that could affect cyber risks. Research and development processes are initiated or conducted independently by players in the area of science, the private sector, society and authorities. 31 The risk management and protection cycle leans heavily on the protection cycle that is used in the national strategy for the protection of critical infrastructure (at the FOCP) and applied to national economic supply 31/42

Select target paragraph3