The Federal Administration's IT security is only summarily regulated in the Federal
Information Technology Ordinance (FITO) 14. Most principles and security requirements can
be found as directives (directives of the Federal IT Council regarding IT security in the
Federal Administration of 27 September 2004) 15.
The Federal Act on Data Protection (DPA) 16 and the Ordinance to the Federal Act on Data
Protection (DPO) 17 contain generally applicable minimum requirements for data protection
when dealing with personal data. These apply to both the Confederation and the private
sector.
The Federal Act on Measures to Safeguard Internal Security (ISA) 18, which addresses
primarily measures for detecting and combating terrorism, prohibited intelligence, violent
extremism and violence at sports events, also contributes to information security within
federal authorities with its security screening of people.
The Federal Act on Responsibilities in the Area of the Civilian Intelligence Service (CISA) 19
regulates some of the tasks of the Confederation's Civilian Intelligence Service, particularly
the procurement of security policy relevant information from abroad and its evaluation for the
attention of the departments and the Federal Council, as well as the assumption of
intelligence tasks in the area of internal security.
The Armed Forces Act (ArmA, particularly Articles 99 and 100) 20 and the Ordinance on the
Armed Forces Intelligence Service (AFISO, particularly Articles 4, 5, 6) 21 form the basis for
cultivating contact with other military intelligence services working in the area of cyber risks,
among other things. Furthermore, they form the legal basis for preventive and intervention
issues for the Armed Forces Self-Protection Unit which is being created.
With its decree of 12 May 2010, the Federal Council instructed the DDPS to prepare formal
legal foundations for the protection of information and information security. The protection of
information and information security are now to be governed uniformly in a special act. The
act to be passed must not only ensure the confidentiality of information, but also protect its
integrity, availability and traceability, as well as the security of the resources with which this
information is processed.
14
SR 172.010.58 Ordinance of 9 December 2011 on Information Technology and Telecommunications in the
Federal Administration
15
Directives of the Federal IT Council (FITC) on Information Security in the Federal Administration of 27 September 2004 (as at 1 November 2007)
16
SR 235.1 Federal Act of 19 June 1992 on Data Protection (DPA), as at 1 January 2011
17
SR 235.11 Ordinance of 14 June 1993 to the Federal Act on Data Protection (DPO), as at 1 December 2010
18
SR 120 Federal Act of 21 March 1997 on Measures to Safeguard Internal Security
19
SR 121 Federal Act of 3 October 2008 on Responsibilities in the Area of the Civilian Intelligence Service
(CISA), as at 1 January 2010
20
SR 510.10 Federal Act of 3 February 1995 on the Armed Forces and the Military Administration (Armed
Forces Act, ArmA), as at 1 January 2011
21
510.291 Ordinance of 4 December 2009 on the Armed Forces Intelligence Service (AFISO), as at 1 January
2010
24/42