standards for connecting to government information infrastructure; conditions and activities
necessary to launch, implement, develop and monitor projects related to government
information infrastructure; management, development and other elements necessary for the
functioning of government information infrastructure will be continuously evaluated through
the coordination of the competent bodies, including security authorities.
Objective B.3 Establishing criteria for use of certain authentication levels among eGovernment service providers and credentials providers.
The standard single-factor authentication, i.e. level 2 credentials according to the document
“The criteria for determining the level of authentication quality assurance for NIAS” 2, is not
at a satisfactory security level for access to sensitive information. A satisfactory solution, in
terms of reducing security risks, which is also acceptable for use in the framework of eGovernment services, is using the credentials of higher (level 3) or highest (level 4) security
levels. The competent authorities will conduct an analysis and work in a coordinated manner
in order to establish the criteria for use of certain authentication levels among the eGovernment service providers and credentials providers. The analysis will also include an
assessment of possibilities of using the e-Citizens ID card for the purposes of e-Government
and other public and financial services. It will also cover other aspects related to national
possibilities to establish the appropriate accreditation and certification capabilities in the area
of qualified electronic signatures, in accordance with the EU requirements.
5.1.3 Electronic financial services (C)
Information technology and its benefits are also widely used in the area of providing financial
services. Achieving satisfactory levels of security is the goal of every modern state, and the
basic goals of the Republic of Croatia related to cyber security in the field of electronic
financial services are:
Objective C.1 Undertaking activities and measures for increasing the security, resilience and
reliability of cyberspace, with the aim of stimulating the development of electronic financial
services.
Continually stimulate the providers of electronic financial services to introduce new
mechanisms of protection against malicious activities and improve the existing ones, in
accordance with current threats and risk assessments. In doing so, special attention has to be
given to the identification and authentication of the users of electronic financial services,
authorization of financial transactions and timely detection and limitation of the impact of
unauthorized activity.
2
https://www.gov.hr/UserDocsImages//e-Gradjani_dok//NIAS%20%20Kriteriji%20za%20odredjivanje%20razine%20osiguranja%20kvalitete%20autentifikacije%20u%20sustavu
%20NIAS%20(Ver.%201.2).pdf (in Croatian)
12 of 31