involvement of police units. This leads to an increased need for forensic capabilities, a
greater flow of information and the strengthening of the exchange of information with CI
operators and the private sector. Additional capabilities and capacities are created by means
of systematic cooperation with relevant ICT service providers and system suppliers.
Measure 14
In the event of a specific threat, active measures are foreseen for identifying the perpetrators
and their intentions, as well as for investigating the perpetrators' abilities and compromising
their infrastructure. (DDPS, FDJP)
Implementation
The Federal Intelligence Service is to cover the cyber aspects of its mandate in order to
manage and follow up on incidents relating to ICT resources that are relevant to state
security. This is accomplished with the inclusion of the AFCSO as the FIS technical service
provider and the MIS as interface with military partner services, international military
alliances and their agencies. This should be provided for in the relevant legislation (primarily
the Intelligence Service Act) and submitted to the political decision-makers.
The findings of the threat situation analysis by MELANI and the possibilities for investigating
and convicting the perpetrators inherent in the legal remit regarding prosecution influence the
measures.
Measure 15
It is to be ensured that cyber aspects are factored into management procedures and
processes within existing structures that serve to increase the management pace in order to
achieve timely problem solving in the event of a crisis. This occurs in agreement with the
national strategy for the protection of critical infrastructure and the departments. (FCh)
Implementation
If the Federal Chancellery (FCh) is instructed by the Federal Council to provide it with
proposals relating to "early crisis identification" and "crisis management" within the scope of
government reform, it must involve the responsible partners in cyber risk issues.
4.3.7 Sphere of action 7: Legal basis
Identification, analysis and evaluation
Myriad federal acts and ordinances currently form the legal basis for cyberspace. The
problem is that there is almost no coordination of these legal provisions, and in some cases
they are still incomplete.
Within the scope of implementing the measures, the administration's options for issuing
binding stipulations beyond its units concerning the reduction of cyber risks are to be clarified
if need be.
Performance targets and planning
The legal foundations in existence reflect the cyber aspects of existing tasks and
responsibilities. Accordingly, a solution in the form of a single cyber-specific act for the whole
of Switzerland is inappropriate. The existing body of laws therefore has to be adapted on an
40/42