Spheres of action and measures that should help reduce cyber risks are subsequently
defined. These spheres of action are described over a risk management and protection
cycle 31. While the risk management and protection cycle comprises five sub-processes
(identification, analysis and evaluation; performance target and planning; measures;
implementation; checking and verification), this strategy addresses only the first three steps
for each sphere of action (identification, analysis and assessment; performance target and
planning; measures).
Identification,
analysis and
evaluation
Checking and
verification
(4.3.8)
Implementation
Performance
target and
planning
Measures
The measures are implemented by the competent players in administration, the private
sector and society. Insofar as the implementation steps concern federal units, they are
described. These are primarily initial implementation steps at the federal level in order to
initiate implementation planning at all levels in cooperation with the relevant partners from
administration, the private sector and society.
The coordination unit which has to be created is responsible for checking and verifying the
measures implemented, in close cooperation with the responsible units.
4.3.1 Sphere of action 1: Research and development
Identification, analysis and evaluation
New risks in connection with cyber crime are to be researched so that informed decisions
can be made at an early stage in the private sector and political and research circles.
Research focuses on technological, social, political and economic trends that could affect
cyber risks. Research and development processes are initiated or conducted independently
by players in the area of science, the private sector, society and authorities.
31
The risk management and protection cycle leans heavily on the protection cycle that is used in the national
strategy for the protection of critical infrastructure (at the FOCP) and applied to national economic supply
31/42