Objective C.2 Enhance information sharing about computer security incidents among the providers of electronic financial services, regulatory and supervisory bodies and other relevant authorities. Creating the conditions for the implementation of efficient information sharing, which will also improve the process of treating computer security incidents, prevent the occurrence of such incidents in the future or ensure that their impact is limited. Particular attention has to be paid to the protection of personal data and other information covered by legal restrictions related to information use and information sharing, building trust among the parties involved, and establishing protocols and mechanisms that will ensure efficient and secure collection of information and information sharing. Computer security incident related information sharing includes the providers of electronic financial services, regulatory and supervisory bodies, bodies competent for computer security incidents in the area of public electronic communications, and criminal prosecution authorities. 5.2 Critical communication and information infrastructure and cyber crisis management (D) The enactment of the Act on Critical Infrastructures3 and subordinate legislation created the legislative preconditions for successful risk management in the critical communication and information infrastructure, within the designated critical infrastructure sectors, in order to: 1. 2. 3. Increase the resilience/reduce the vulnerability of communication and information systems; Mitigate the consequences of negative events (natural disasters and technicaltechnological accidents) and possible attacks (intentional and unintentional); Enable quick and efficient recovery and resumption of operation. Pursuant to the Decision of the Croatian Government4, the sector of communication and information technology has been designated as one of the sectors from which the central state administration bodies identify critical national infrastructures by applying the appropriate method. Its subsectors have been designated as follows: electronic communications, data transmission, information systems and provision of audio and audio-visual media services. These subsectors are further divided into the following sections: electronic communication networks, infrastructure and the related equipment, information infrastructure and terrestrial radio broadcasting systems. Continuation of activities in the area of critical communication and information infrastructure protection is a strategic interest, for the purpose of making all the necessary conditions for its functioning and continued operation. 3 Published in the Official Gazette, No 56/13. Decision on designation of sectors from which central state administration bodies identify critical national infrastructures and critical infrastructures sector sequence list (Official Gazette 108/13). 4 13 of 31

Select target paragraph3