involvement of police units. This leads to an increased need for forensic capabilities, a greater flow of information and the strengthening of the exchange of information with CI operators and the private sector. Additional capabilities and capacities are created by means of systematic cooperation with relevant ICT service providers and system suppliers. Measure 14 In the event of a specific threat, active measures are foreseen for identifying the perpetrators and their intentions, as well as for investigating the perpetrators' abilities and compromising their infrastructure. (DDPS, FDJP) Implementation The Federal Intelligence Service is to cover the cyber aspects of its mandate in order to manage and follow up on incidents relating to ICT resources that are relevant to state security. This is accomplished with the inclusion of the AFCSO as the FIS technical service provider and the MIS as interface with military partner services, international military alliances and their agencies. This should be provided for in the relevant legislation (primarily the Intelligence Service Act) and submitted to the political decision-makers. The findings of the threat situation analysis by MELANI and the possibilities for investigating and convicting the perpetrators inherent in the legal remit regarding prosecution influence the measures. Measure 15 It is to be ensured that cyber aspects are factored into management procedures and processes within existing structures that serve to increase the management pace in order to achieve timely problem solving in the event of a crisis. This occurs in agreement with the national strategy for the protection of critical infrastructure and the departments. (FCh) Implementation If the Federal Chancellery (FCh) is instructed by the Federal Council to provide it with proposals relating to "early crisis identification" and "crisis management" within the scope of government reform, it must involve the responsible partners in cyber risk issues. 4.3.7 Sphere of action 7: Legal basis Identification, analysis and evaluation Myriad federal acts and ordinances currently form the legal basis for cyberspace. The problem is that there is almost no coordination of these legal provisions, and in some cases they are still incomplete. Within the scope of implementing the measures, the administration's options for issuing binding stipulations beyond its units concerning the reduction of cyber risks are to be clarified if need be. Performance targets and planning The legal foundations in existence reflect the cyber aspects of existing tasks and responsibilities. Accordingly, a solution in the form of a single cyber-specific act for the whole of Switzerland is inappropriate. The existing body of laws therefore has to be adapted on an 40/42

Select target paragraph3