Risk management and
situation assessment
regulatory measures are taken. On
the one hand, CI face increasing
regulatory requirements. For example,
it is recommended that if possible all CI
operators (particularly those responsible
for the protection of critical information
infrastructure) be legally obliged to take
risk management and information security
measures. On the other hand, the private
sector itself often addresses questions
relating to its duty to report cyber attacks,
as in many instances CI operators were
prevented from “voluntary reporting” for
reasons of data protection.
Human Sensor Project: ICT system
administrators receive gradual ICT security
training and are taught to detect anomalies
in their ICT systems and report them to
their ICT security officers. The data thus
obtained are forwarded to the Cyber
Situation Centre and the Cyber Competence
Centre, where they are processed to gain a
more profound insight into the situation. :
Initial situation
Today’s digital society has led to a high
penetration of ICT in all areas and ICT
now plays a major role in traditional
sectors such as energy supply, transport and
industry. Exclusively ICT-based sectors take
advantage of networks of extensive services
and infrastructures controlled through ICT
components and processes. Links between
individual sectors resulting from the
interdependence of services and products
leads to a chain reaction in security-relevant
scenarios.
Based on these considerations, risk
and situation assessments must cover all
sectors, although the sectors of information
infrastructures, telecommunications,
energy, healthcare, transport, monetary
transactions and public administration will
need to be examined more closely. Each
individual sector has a well-developed
risk management system. However, the
main risks are identified in areas outside
the control of individual enterprises. This
suggests that the level of interconnectedness
among sectors and beyond organisational
units is extremely high and that an
overarching risk assessment is required.
Due to the strong interdependence
of sectors, ICT risks are embedded in the
context of upstream or downstream risk
situations. It is therefore understandable
that a considerable number of risks cannot
be managed and tackled by an individual
enterprise but only collectively or with the
support of the state.
It is of vital importance that non-ICT
risks and scenarios are covered by up-todate emergency and crisis management
plans. This is an important requirement for
avoiding overlapping risks and scenarios in
interlinked systems.
The issue of risk and security
management in individual enterprises is
another relevant aspect. It will be necessary
to resort to best practices in this area, and
to create suitable framework conditions. In
many cases, it may even become necessary
to define minimum standards for these core
17