Strategic objective: Risk acceptance in core enterprises is determined at a higher level so as to avoid major harmful effects resulting from a lack of risk prevention for financial considerations. In this context, minimum standards will have to be defined and examined. Other options may be explored so as to achieve the desired risk control effect. Measure To check whether the government’s crisis and emergency plans as well as their procedures for updating and testing them are up-to-date; to establish a connection to the Situation Centre; to review crisis organisations and processes at a public and private level, to interconnect them and, if required, create other appropriate crisis organisations and processes. Measures Discussing risk acceptance in critical core enterprises at a higher level of responsibility and clarifying which is the most appropriate way of defining minimum standards (in laws, directives, standards, etc.), which institution is in charge of verifying compliance, and the extent to which best practices of a specific sector may be applied. Raise this issue at an EU level in order to address matters relating to the distortion of competition. Objective 4: Establishing a crisis and emergency management system in the respective sectors Hypothesis: Due to the high degree of interconnectedness, ICT risks must be examined and assessed comprehensively with a view to identifying strategies for coping with them. Emergency and crisis plans are necessary in ICT-related and nonICT areas. Strategic objective: to review public crisis and emergency management processes, to identify risks arising from the increasing ICT dependence of many core processes; to ensure the availability of crisis organisations and processes at public and private level, including contacts in enterprises (e.g. crisis and business contact managers) as well as emergency and contact lists. Objective 5: Situation assessment and management Hypothesis: All sectors and/or organisational units are currently assessed and appraised individually. A personal network is responsible for trans-sectoral risk evaluation. A permanent institution must be established in order to handle interlinked structures. Strategic objective: to set up a Situation Centre which will optimise collaboration among sectors. Management responsible for reporting will be informed of incidents and pass this information on to enterprises with critical infrastructures. The Situation Centre must never be a “one-way street”, a reciprocal exchange of information is the only way to ensure that information is made available in a timely, comprehensive and targeted manner. The experience gained will be incorporated into long-term awareness measures. Measure Creating a Cyber Situation Centre with appropriate means of situation monitoring, including necessary and relevant processes, e.g. reporting obligation or information requirements of the individual stakeholders. : 19 Furthermore information on the Cyber Situation Centre see chapter ‘Stakeholders and structures’.

Select target paragraph3