French NATIONAL DIGITAL SECURITY STRATEGY — objective 4
will also support the enhancement and perpetuation of
these offers through public contracting that chooses security products and services qualified at the right level,
as well as by communication and educational measures
for the private sector.
In addition, the State services will endeavour to
disseminate the results of research and development
which they finance for high-level security equipment
in order to raise the security level of products for businesses and the general public.
Finally, France will endeavour to take full advantage of leverage offered by the European Union to support, promote and defend French scientific, technological and industrial competences in the cybersecurity
fields. It will also discourage the EU from limiting itself
to the role of consumer, and will incite it rather to stand
out as an indispensable global stakeholder for the offer
in this sector.
> Transferring acquired knowledge to the private
sector to contribute to the handling of its cybersecurity.
For five years now France has equipped itself with
the capacity to detect and respond to cyberattacks, as
announced in the 2008 White Paper on Defence and
National Security. Although this effort should be pursued, notably by ANSSI, it is up to the private sector to
ensure its own security in the field of information technology as is the case in other fields, since the State services are only required to intervene in case of serious
crisis.
Supported by the transfer of this knowledge acquired by the administrations to the private sector,
labelling of competent and trustworthy service providers should enable the detection and treatment of the
inevitable growth in the number of cyberattacks that
businesses are subjected to.
>
Preparing a safer digital world through better
anticipation of uses, adapted support and stakeholders’ information.
For the next five years, the priority for the competent information systems security authorities should be
anticipation and prevention.
This will entail ensuring that the digital products
and services or those that involve digital technology,
which are designed, developed and produced in France,
are among the safest in the world. To achieve this objective, the competent authorities should direct their
communication efforts towards the public and private
scientific community, and the innovation centres; competitive clusters, technological research institutes, incubators and «fab labs»; by devoting specific means to
these areas as needed, as is the case with the Ministry
of Defence, and more recently, the Ministry of the Interior.
When digital products and services store personal
data or are intended for the business sectors of vital importance, the State services will provide the elements
that are useful for risk analysis or the recommendations required to obtain the level of security that corresponds to the use of the product or the service being
designed or developed. For uses that justify it, they will
also contribute to establishing systems to independently evaluate the level of security and trustworthiness
of these products and services, and to providing their
potential users with adapted guarantees through labelling.
In parallel, the legal environment to accommodate
new products and services should be anticipated. For
example, the imminent arrival of autonomous cars
should incite the regulator to prepare the conditions
to ensure the security of their circulation. Cybersecurity should be taken into account in the international
working groups that define the framework and control
technical procedures.
For other types of products or services, an adapted
identification system should inform the consumer of
their essential digital features and notably the processing of the data that is collected. For certain sectors
such as the health sector, systematic labelling of digital
products and services will be considered.
France will endeavour to include other EU Member
States in the implementation of these practices in order
33