Performance targets and planning
It is essential for each area of responsibility to have the ability to identify, evaluate and
analyse risks associated with cyber issues in their own area. This is to be achieved in
cooperation with those responsible for the Federal Council's strategy for an information
society in Switzerland (DETEC-OFCOM), the national strategy for the protection of critical
infrastructure (DDPS-FOCP) and federal risk management.
Measures
Measure 1
The responsible federal units discuss both current developments regarding cyber risks and
those to be researched with one another as well as with players outside the Federal
Administration, and when needed they carry out research internally or issue research
mandates.
Implementation
The individual federal units are responsible for departmental research in their area of
responsibility. The education, research and technology steering committee (ERT steering
committee) instructs the agencies to prepare multi-year trans-sectoral programmes for
departmental research in their policy areas (research concepts). These research concepts
provide information on the planned focus areas of departmental research. They specifically
take into account the existing research priorities of the universities, the support programmes
carried out by the Swiss National Science Foundation on behalf of the Confederation, as well
as the activity of the Innovation Promotion Agency.
4.3.2 Sphere of action 2: Risk and vulnerability analysis
Identification, analysis and evaluation
All competent public authority units, CI operators, ICT service providers, system suppliers
and associations (in terms of a merging of branches) must identify at their level the risks
arising from cyber aspects, and evaluate and analyse their probability of occurrence and
potential implications.
Performance targets and planning
The responsible players from political circles, the private sector and society must have the
means and capabilities to be able to identify cyber risks at an early stage, assess the threat
situation and examine the implications for their area in the form of joint risk analyses.
Implementation takes place in cooperation with those in charge of federal risk management,
the "national strategy for the protection of critical infrastructure" and work relating to the
"Switzerland's risks" study.
Measures
32/42