French NATIONAL DIGITAL SECURITY STRATEGY — objective 1
issues related to the reinforcement of the security of information systems is taken into account in the steering
of the normative process.
>
Preparing France and the multilateral organisations to which it belongs to face major cybersecurity
crises.
Reinforcement of the security of the most sensitive
information systems of operators of vital importance,
which was announced in the 2013 White Paper on Defence and National Security, was the subject of legislative measures (Articles 21 and 22 of law n° 2013-1168 of
18 December 2013). The work started with these operators will continue over the long term, notably by routine updating of regulatory texts. This work will be progressively extended, as is specified by the law, to public
and private operators who participate in these sensitive
information systems.
This choice made by France will have made it possible to actively participate in the development of the
orientations of the European Directive concerning
measures to ensure a high common level of network
and information systems security across the Union and
to anticipate its transposition. At the right moment,
France will specify the operators who are essential to
its economy according to the orientations of the Directive and will participate in the European initiatives intended to reinforce their digital security.
Over time, cybersecurity crises management exercises carried out at the national level will progressively
concern the entire territory and vitally important activity sectors. The Ministry of Defence, in collaboration
with the National Authority on Information Systems
Security, will continue to implement a cyberdefence
reserve for operational purposes to face major information technology crises.
In parallel, France will continue to contribute to the
emergence of an environment of voluntary cooperation
for cybernetic crisis management at the European level,
by supporting the work of the European agency ENISA
(European Union Agency for Network and Information
Security) in particular.
It is up to the CERT-EU (Computer Emergency Response Team of the European Union (EU) institutions,
bodies and agencies) and to the NCIRC (Computer Incidence Response Capability) within the North Atlantic
Treaty Organization (NATO) to ensure the cyberdefence of their respective institutions. France, which is
active during cybersecurity crisis management exercises organised by these organisations, and which is
highly represented in proceedings that orient EU and
NATO choices concerning secured digital technologies,
will continue to provide its support to these institutions
and their members according to their respective competences.
France will also contribute to reinforcing the cybersecurity of other international organisations to which it
belongs, on a political and technical level, notably those
hosted on the national territory that benefit from the
national technical environment.
> Developing an autonomous way of thinking that
is in line with our values.
The strategic choices made by France immediately
after the Second World War led to the emergence of an
autonomous way of thinking and the development of a
doctrine that gave France a unique place on the international scene and today still permeates its diplomacy
and the concepts behind the use of its armed forces.
Although digital technology fundamentally changes
our societies, its impact on other realities such as those
of sovereignty, national territory, currency or the fundamental interests of the Nation is yet to be measured
and the organisation and means of public action to
make the law apply to it or to ensure their protection
must be reconsidered. A discussion, coordinated by the
General Secretary of Defence and National Security,
will be held to develop an intellectual corpus related to
cyberspace.
17