the disruption of which will have an
impact significantly beyond the scope of
the individual enterprise. These need to
be considered in analyses and taken into
account in risk assessments.
Energy sector
Comprehensive
electricity failure
leads to
Objective 2: Comprehensive risk and
security management across sectors
Telecommunications
sector
Loss of
communication services
Transport sector
Disruption of supplies
breakdown of
communication and
services
computing centres are
not supplied with diesel
for emergency power
All sectors
Failure of
computing centres
Hypothesis: ICT risks may not be
considered separately due to global
interconnectedness.
Strategic objective:
A comprehensive risk and security
management system must cover all risks
and address all sectors and core enterprises.
Minimum standards defining organisational
aspects and processes will have to be
defined.
Measures
Example of a failure chain
infrastructures, which will also require
government regulation.
Strategic objectives and measures
Objective 1: Identification of core
enterprises in the sectors
Hypothesis: There are risks that can be
managed by individual enterprises, and
there are risks that need to be addressed
collectively or with the support of the
government. Assessments of the residual
risks to be accepted by an enterprise or of
the economic viability of possible countermeasures must take into account the impact
on other sectors.
Strategic objective:
Core sectors and relevant enterprises must
be identified. There is a small number of
core infrastructures or core enterprises
18
Consolidating the risk catalogue together
with selected sector representatives at expert
level.
Defining minimum standards for risk and
security management taking into account
specificities of the sector and standards as
well as processes in the area of risk and
incident management.
Objective 3: Ensuring minimum standards
and managing risk acceptance in core
enterprises
Hypothesis: Due to growing competition,
the risk to be accepted by core enterprises is
increasingly determined by financial factors.
This could have an impact considerably
exceeding the scope of the enterprise
involved, especially in the case of core
enterprises with major knock-on effects;
this must be taken into account in any
risk assessment. Minimum standards of
risk prevention must be ensured if a major
impact on other sectors is likely.