political data, is required for making informed decisions. For example, protection and economic efficiency considerations can get in the way where the establishment of infrastructure redundancies and overcapacity would be beneficial in terms of protection but would run contrary to economic considerations. Moreover, economic liberalisation has changed the initial situation in that a growing number of IC operators (e.g. energy, telecommunications) have been fully or at least partially privatised and are thus primarily bound by market logic. A second area where conflicts of interests can arise is personal rights. Efforts to improve protective mechanisms in cyberspace, e.g. by means of stricter controls or surveillance, must be weighed against the protection of privacy. This strategy also has the task of taking these considerations into account and demonstrating how measures can be taken cautiously. Special crisis management is required if a crisis scenario featuring a successful attack or lasting disruption with serious consequences has arisen. The focus is on the interplay of actions within the existing structures, which have to be conducted with regard to politically directed measures throughout the country and in accordance with the rules of criminal prosecution. Determining the cause and improving the affected infrastructure's resilience are also part and parcel of managing the crisis. For this purpose, CI operators and relevant ICT service providers or system suppliers are integrated into the process on the basis of agreements. The strategy for the protection of Switzerland against cyber risks has interfaces with other projects that, at the federal level, are also concerned with security issues and are thematically related. These activities need to be closely coordinated during implementation. The most important projects are as follows: Federal Council's strategy for an information society in Switzerland The Federal Council's strategy for an information society in Switzerland was adopted by the Federal Council on 9 March 2012. One of the focus areas of the Confederation's activity is "security and confidence". The objectives pursued with this include extending security powers, protecting against cybercrime and increasing the resilience of information and communication technologies (ICT) and of critical infrastructure. The associated concept, which was approved by the Federal Council back in 2010, foresees measures to raise the awareness of the population as well as small and medium-sized enterprises regarding security-conscious and legally compliant use of ICT. National strategy for the protection of critical infrastructure The Federal Office for Civil Protection (FOCP) was instructed by the Federal Council to coordinate work in the area of critical infrastructure protection (CIP). Based on the Federal Council's CIP basic strategy of June 2009, the FOCP is to compile a list of Switzerland's critical infrastructure (SCI inventory), whereby critical ICT infrastructure is also identified. Furthermore, guidelines are to be prepared to improve the integral protection of critical infrastructure. The CIP basic strategy is currently being expanded to form a national CIP strategy and will be submitted to the Federal Council together with this strategy. Legislation on information security in the Confederation With its decree of 12 May 2010, the Federal Council instructed the DDPS to prepare a formal legal basis for information protection and information security in order to ensure and safeguard the confidentiality, availability, integrity and authenticity of data and information. This new legislation should primarily set out the information security principles for all federal authorities and govern responsibilities in a uniform manner. Specifications will thus be 7/42

Select target paragraph3