1 Section 1 – Introduction
1.1 Overview
Section 1 defines the foundations for and objectives of ICT
security, sets out what this comprehensive topic covers and what
it does not, and explains how the Minimum ICT Standard is to
be used.
A number of internationally recognised cybersecurity standards
already exist. Most of these extend well beyond the present document (see section 1.4.1). This Minimum Standard explicitly does
not seek to compete with the existing international standards.
Rather, it is compatible with them while being more reduced in
scope. It is intended to provide a more entry-level introduction
to the issues, and yet ensure a high degree of protection.
1.2 Legal foundations
The following underlying laws form the basis for NES action.1
• Federal Act on the National Economic Supply
(National Economic Supply Act, NESA; SR 531)
• Ordinance on the Organisation of National Economic Supply
(Organisation of National Economic Supply Ordinance;
SR 531.11)
• Ordinance on Preparatory Measures for National
Economic Supply (SR 531.12)
As a complement to the present Minimum ICT Standard, NES
has drafted further, sector-specific standards,2 which go into
greater (technical) detail. It is recommended that, as soon as
they become available, operators of critical infrastructures base
their actions on these detailed, sector-specific requirements in
addition to this Minimum Standard.
If a sector already has its own standards, or if international
standards such as ISO or NIST are used, businesses can use the
checklist in Section 3, ‘Assessment’ to determine whether or not
they already meet this Minimum Standard.
1.3 Background and objectives
1.4.1 Foundation documents and standards
Cybersecurity demands a risk-based approach and the use of
secure systems within the individual operator’s own area of
responsibility. Many cyber attacks can be repelled at reasonable
cost simply by taking the tried-and-tested precautions set out
in this Minimum ICT Standard. Its aim is to give businesses and
organisations a versatile tool that enables them to take independent action to improve the resilience of their ICT infrastructures. By taking a risk-based approach, the standard permits the
implementation of different levels of defence, adjusted to the
particular needs of the organisation.
1.4 Scope
This Minimum ICT Standard has been drawn up by the National
Economic Supply (NES) organisation in cooperation with external
cybersecurity experts.
1
All of these legal texts can be found in the classified compilation of
federal law. They can be found online at:
There are many different standards and sources of information
around the world on dealing with cyber risks. Some of these
are already recognised by businesses and are in use. The present Minimum ICT Standard is based on the NIST Cybersecurity
Framework Core.3 It has been supplemented with other internationally recognised industry standards where appropriate. The
most important of these are the following:
1. NIST Guide to Industrial Control Systems (ICS) Security
This guide is also issued and updated by the National
Institute of Standards and Technology, and extends the
NIST Cybersecurity Core Framework by specific requirements
for handling industrial control systems (ICS), in particular,
NIST Special Publication 800-82, revision 2, May 2015.4
2
These are currently available for the power supply and food supply
sectors. Standards for other sectors are in progress and will be published
https://www.admin.ch/gov/en/start/federal-law.html.
upon completion.
The National Economic Supply Act is available in English. The ordinances
3
https://www.nist.gov/cyberframework
are available in German, French and Italian
4
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf
Minimum ICT standard 2018
4