Incidents of national importance and of particular relevance are to be identified, evaluated
and analysed. The ensuing findings are to be processed at the appropriate level and made
available to the respective areas of responsibility.
Performance targets and planning
The players from political circles, the private sector and society must have the means and
capabilities to be able to identify, evaluate and analyse the threat situation in close
cooperation with those responsible. If necessary, a reporting authorisation for the responsible
units, CI operators and the private sector should be examined.
Measures
Measure 4
Intelligence, police, forensic and technical information about cyber threats and the risk
situation is obtained from open and classified sources and then evaluated and analysed.
Within the scope of MELANI's public private partnership model, these findings are to be
collected, globally evaluated, analysed and merged to portray and give updates on the
situation, as well as be combined with scenarios for how the situation could possibly develop.
These results are made available to the responsible players concerned. (FDF, DDPS)
Implementation
The Federal Intelligence Service will have to cover the cyber aspects of its mandate in order
to manage and follow up on incidents relating to ICT resources that are relevant to state
security. This is accomplished with the inclusion of the AFCSO as the FIS technical service
provider and, where appropriate, the MIS. The findings flow via MELANI into the overall
analysis of the threat situation.
The technical capacities for 24/7 surveillance of federal networks are to be built up within the
service providers (CERTs) by the end of 2015. The findings flow via MELANI into the overall
analysis of the threat situation.
MELANI strengthens the voluntary exchange of information with CI operators and its
international partners. This leads to an increase in the need for forensic capabilities, a
greater flow of information and an enhancement of the exchange of information with CI
operators and the private sector. Additional capabilities and capacities are created by means
of systematic cooperation with relevant ICT service providers and system suppliers.
Measure 5
The Confederation, the cantons and CI operators are to follow up on relevant incidents and
examine possibilities for developing their own measures for dealing with incidents in relation
to cyber risks. This generally occurs individually within the framework of their own mandate.
Within the scope of MELANI's public private partnership, these findings are to be collected,
globally evaluated, analysed and made available to the players concerned, particularly those
responsible for risk and vulnerability analyses. (FDF, DDPS)
Implementation
MELANI strengthens the voluntary exchange of information between CI operators, relevant
ICT service providers and system suppliers, and supports the follow-up of relevant incidents.
34/42