personnel security clearance requirements or the need to determine a certain type of information as classified. Objective D.3 Strengthen prevention and protection through risk management. The priority is to ensure the implementation of the provisions of the Act on Critical Infrastructures in segments concerning the sector risk analysis of critical communication and information infrastructure, sector plans for ensuring the work of critical communication and information infrastructure, and security plans of owners/operators of critical communication and information infrastructure. The sector risk analysis includes: 1. 2. 3. 4. 5. Identification of critical functions (procedures, information, networks, etc.); Identification of threats; Assessment of threats, vulnerabilities and impact; Analysis and prioritisation of risks; Determining acceptable risk and risk treatment. Sector plans for ensuring the work of critical infrastructure and security plans of owners/operators of this critical infrastructure contain measures and activities for preparedness, prevention, protection, response and recovery in case of computer security incidents with adverse impact on the functioning of the critical infrastructure sector, namely production and delivery of goods and services and other functions of critical infrastructure owners/operators, the operation or functioning of which is based on critical communication and information infrastructure. Special attention has to be paid to the professional training of the individuals who will be involved in the procedure of designating critical communication and information infrastructure. Objective D.4 Strengthen public-private partnership and technical coordination in the treatment of computer security incidents. Within the sectors of critical infrastructure designated by the aforementioned Decision of the Croatian Government on designation of sectors from which central state administration bodies identify critical national infrastructures and critical infrastructures sector sequence list, it is necessary to encourage public-private partnership through central bodies of state government competent for certain sectors, in order to ensure unhindered functioning of the business entities representing the owners/operators of critical infrastructure. It is necessary to determine the appropriate procedures of oversight, coordination, and information sharing concerning the necessary security information. Information sharing is conducted among the competent sectoral entities and owners/operators of critical infrastructures, with bodies in charge of computer security incidents in areas of public electronic communication and information infrastructure and services, and with the criminal prosecution authorities. Technical coordination in the treatment of computer security incidents is undertaken through the cooperation of the bodies with developed capabilities in responding to such incidents. 15 of 31

Select target paragraph3