Measure 10 Switzerland cooperates at the international security policy level so as to counteract the threat in cyberspace together with other countries and international organisations. It monitors the respective developments at diplomatic level and promotes political exchanges within the framework of international conferences and other diplomatic initiatives. (FDFA, DDPS) Implementation In collaboration with the DDPS, the FDFA represents Switzerland at the diplomatic level and defends the security policy interests of our country vis-à-vis international organisations and other states. It champions initiatives under international law aimed at keeping cyberspace free from conflicts. Measure 11 Operators, associations and authorities coordinate their efforts to influence these bodies within the scope of private and state initiatives, conferences and standardisation processes related to security and safety. (DETEC, FDFA, DDPS, FDF) Implementation MELANI and DETEC reinforce the exchange of information on international approaches and initiatives among CI operators, ICT service providers, system suppliers and associations. MELANI and DETEC thus promote the coordinated inclusion of Switzerland as a business location in these international bodies. If desired, MELANI and DETEC ensure participation in agreement with the departments, particularly the FDFA. 4.3.6 Sphere of action 6: Continuity and crisis management Identification, analysis and evaluation The activities of the various players are to be coordinated across all levels. Civilian everyday life is characterised by normal operation of the entire ICT infrastructure. In this situation, the Federal Administration, society as well as the private sector and CI operators are the permanent targets of attacks that must be recognised or detected and warded off with countermeasures. The focus is on preventive measures in terms of infrastructure and operations, with regular reactive interventions without relevant consequences. A crisis is characterised by a successful attack or sustained disruption with grave consequences that can affect the entire country in extreme cases. Depending on its intensity, a crisis increases the management rhythm within existing crisis and continuity management structures. The focus is on the interplay of actions which, depending on the circumstances, have to be accompanied at the national level by politically motivated technical measures. In this regard, determining the cause of a crisis is part of crisis management. CI operators and relevant ICT service providers and system suppliers are integrated into the decision-making process on the basis of agreements. Performance targets and planning Individual and sector-based risk analyses are to serve as a basis for sectoral agreements and continuity planning. These are to be prepared or coordinated in close cooperation with 38/42

Select target paragraph3