personnel security clearance requirements or the need to determine a certain type of
information as classified.
Objective D.3 Strengthen prevention and protection through risk management.
The priority is to ensure the implementation of the provisions of the Act on Critical
Infrastructures in segments concerning the sector risk analysis of critical communication and
information infrastructure, sector plans for ensuring the work of critical communication and
information infrastructure, and security plans of owners/operators of critical communication
and information infrastructure.
The sector risk analysis includes:
1.
2.
3.
4.
5.
Identification of critical functions (procedures, information, networks, etc.);
Identification of threats;
Assessment of threats, vulnerabilities and impact;
Analysis and prioritisation of risks;
Determining acceptable risk and risk treatment.
Sector plans for ensuring the work of critical infrastructure and security plans of
owners/operators of this critical infrastructure contain measures and activities for
preparedness, prevention, protection, response and recovery in case of computer security
incidents with adverse impact on the functioning of the critical infrastructure sector, namely
production and delivery of goods and services and other functions of critical infrastructure
owners/operators, the operation or functioning of which is based on critical communication
and information infrastructure. Special attention has to be paid to the professional training of
the individuals who will be involved in the procedure of designating critical communication
and information infrastructure.
Objective D.4 Strengthen public-private partnership and technical coordination in the
treatment of computer security incidents.
Within the sectors of critical infrastructure designated by the aforementioned Decision of the
Croatian Government on designation of sectors from which central state administration bodies
identify critical national infrastructures and critical infrastructures sector sequence list, it is
necessary to encourage public-private partnership through central bodies of state government
competent for certain sectors, in order to ensure unhindered functioning of the business
entities representing the owners/operators of critical infrastructure. It is necessary to
determine the appropriate procedures of oversight, coordination, and information sharing
concerning the necessary security information. Information sharing is conducted among the
competent sectoral entities and owners/operators of critical infrastructures, with bodies in
charge of computer security incidents in areas of public electronic communication and
information infrastructure and services, and with the criminal prosecution authorities.
Technical coordination in the treatment of computer security incidents is undertaken through
the cooperation of the bodies with developed capabilities in responding to such incidents.
15 of 31