Measure 2 Risk and vulnerability analyses are to be carried out at all levels (Confederation, cantons and CI operators) in collaboration with ICT service providers and system suppliers. These include independent and regular examination of systems by operators. The development of (sectoral) risk analyses requires close cooperation with the authorities. (FDEA, FDF, DETEC) Implementation Within the scope of the revision of the NESA 32, the FDEA is adapting its powers in order to be able to carry out needs-oriented risk and vulnerability analyses with all sub-sectors of the Federal Office for National Economic Supply (FONES), involving the competent authorities (primarily DETEC and FDF) depending on the situation. If CI operators are not captured by the national economic supply system, they are to be contacted through the respective competent authorities, which will adapt their sector-specific legislation accordingly if necessary. An approach that is as uniform as possible is to be used for conducting risk and vulnerability analyses. The relevant authorities (primarily in DETEC and FDF) are to be involved when implementing the findings. The results are consolidated in cooperation with MELANI to form a comprehensive analysis of the threat situation. Measure 3 The authorities, CI operators and research institutions examine their ICT infrastructure for vulnerabilities in collaboration with ICT service providers and system suppliers. Vulnerabilities include systemic, organisational and technical weaknesses. The findings are consolidated and evaluated, and published in corresponding reports if they are of public interest 33. (FDEA, FDF, DDPS, DETEC) Implementation Together with ICT service providers, the Federal IT Steering Unit (FITSU) in the FDF will compile an evaluation concept by mid-2015 for the periodic examination of the Federal Administration's ICT infrastructure with regard to systemic, organisational and technical weaknesses. This will be implemented by the competent service providers and those responsible in the departments' general secretariats. The evaluation concept can be given as a recommendation or to support the private sector and CI operators in their own evaluations. The results are consolidated in cooperation with MELANI to form a comprehensive analysis of the threat situation. 4.3.3 Sphere of action 3: Analysis of the threat situation Identification, analysis and evaluation 32 SR 531 Federal Act of 8 October 1982 on the National Economic Supply 33 In accordance with the Information Protection Ordinance, cryptographic measures and products for the protection of classified (CONFIDENTIAL / SECRET) information must be authorised by the Specialist Unit for Cryptology of the DDPS 33/42

Select target paragraph3