Measure 2
Risk and vulnerability analyses are to be carried out at all levels (Confederation, cantons and
CI operators) in collaboration with ICT service providers and system suppliers. These include
independent and regular examination of systems by operators. The development of
(sectoral) risk analyses requires close cooperation with the authorities. (FDEA, FDF,
DETEC)
Implementation
Within the scope of the revision of the NESA 32, the FDEA is adapting its powers in order to
be able to carry out needs-oriented risk and vulnerability analyses with all sub-sectors of the
Federal Office for National Economic Supply (FONES), involving the competent authorities
(primarily DETEC and FDF) depending on the situation. If CI operators are not captured by
the national economic supply system, they are to be contacted through the respective
competent authorities, which will adapt their sector-specific legislation accordingly if
necessary. An approach that is as uniform as possible is to be used for conducting risk and
vulnerability analyses. The relevant authorities (primarily in DETEC and FDF) are to be
involved when implementing the findings.
The results are consolidated in cooperation with MELANI to form a comprehensive analysis
of the threat situation.
Measure 3
The authorities, CI operators and research institutions examine their ICT infrastructure for
vulnerabilities in collaboration with ICT service providers and system suppliers.
Vulnerabilities include systemic, organisational and technical weaknesses. The findings are
consolidated and evaluated, and published in corresponding reports if they are of public
interest 33. (FDEA, FDF, DDPS, DETEC)
Implementation
Together with ICT service providers, the Federal IT Steering Unit (FITSU) in the FDF will
compile an evaluation concept by mid-2015 for the periodic examination of the Federal
Administration's ICT infrastructure with regard to systemic, organisational and technical
weaknesses. This will be implemented by the competent service providers and those
responsible in the departments' general secretariats.
The evaluation concept can be given as a recommendation or to support the private sector
and CI operators in their own evaluations.
The results are consolidated in cooperation with MELANI to form a comprehensive analysis
of the threat situation.
4.3.3 Sphere of action 3: Analysis of the threat situation
Identification, analysis and evaluation
32
SR 531 Federal Act of 8 October 1982 on the National Economic Supply
33
In accordance with the Information Protection Ordinance, cryptographic measures and products for the protection of classified (CONFIDENTIAL / SECRET) information must be authorised by the Specialist Unit for Cryptology of the DDPS
33/42