3.3.
Security and resilience of critical information infrastructures to boost
confidence in the information society
In order to ensure that ICT infrastructures are used to their maximum extent, thus fully
realising the economic and social opportunities of the information society, all stakeholders
must have a high level of confidence and trust in them. This depends on various elements, the
most important of which is ensuring their high level of security and resilience. Diversity,
openness, interoperability, usability, transparency, accountability, auditability of the different
components and competition are key drivers for security development and stimulate the
deployment of security-enhancing products, processes and services. As the Commission
already highlighted22, this is a shared responsibility: no single stakeholder has the means to
ensure the security and resilience of all ICT infrastructures and to carry all the related
responsibilities.
Taking up such responsibilities calls for a risk management approach and culture, able to
respond to known threats and anticipate unknown future ones, without over-reacting and
stifling the emergence of innovative services and applications.
3.4.
The challenges for Europe
In addition and complementarily to all the activities related to the implementation of the
Directive on the identification and designation of the European Critical Infrastructures, in
particular the identification of ICT sector-specific criteria, a number of broader challenges
need to be addressed in order to strengthen the security and resilience of CIIs.
3.4.1.
Uneven and uncoordinated national approaches
Although there are commonalities among the challenges and the issues faced, measures and
regimes to ensure the security and resilience of CIIs, as well as the level of expertise and
preparedness, differ across Member States.
A purely national approach runs the risk of producing a fragmentation and inefficiency across
Europe. Differences in national approaches and the lack of systematic cross-border cooperation substantially reduce the effectiveness of domestic countermeasures, inter alia
because, due to the interconnectedness of CIIs, a low level of security and resilience of CIIs in
a country has the potential to increase vulnerabilities and risks in other ones.
To overcome this situation a European effort is needed to bring added value to national
policies and programmes by fostering the development of awareness and common
understanding of the challenges; stimulating the adoption of shared policy objectives and
priorities; reinforcing cooperation between Member States and integrating national policies in
a more European and global dimension.
3.4.2.
Need for a new European governance model for CIIs
Enhancing the security and the resilience of CIIs poses peculiar governance challenges. While
Member States remain ultimately responsible for defining CII-related policies, their
implementation depends on the involvement of the private sector, which owns or controls a
large number of CIIs. On the other hand, markets do not always provide sufficient incentives
22
EN
COM(2006) 251 final
5
EN