Measure 10
Switzerland cooperates at the international security policy level so as to counteract the threat
in cyberspace together with other countries and international organisations. It monitors the
respective developments at diplomatic level and promotes political exchanges within the
framework of international conferences and other diplomatic initiatives. (FDFA, DDPS)
Implementation
In collaboration with the DDPS, the FDFA represents Switzerland at the diplomatic level and
defends the security policy interests of our country vis-à-vis international organisations and
other states. It champions initiatives under international law aimed at keeping cyberspace
free from conflicts.
Measure 11
Operators, associations and authorities coordinate their efforts to influence these bodies
within the scope of private and state initiatives, conferences and standardisation processes
related to security and safety. (DETEC, FDFA, DDPS, FDF)
Implementation
MELANI and DETEC reinforce the exchange of information on international approaches and
initiatives among CI operators, ICT service providers, system suppliers and associations.
MELANI and DETEC thus promote the coordinated inclusion of Switzerland as a business
location in these international bodies. If desired, MELANI and DETEC ensure participation in
agreement with the departments, particularly the FDFA.
4.3.6 Sphere of action 6: Continuity and crisis management
Identification, analysis and evaluation
The activities of the various players are to be coordinated across all levels.
Civilian everyday life is characterised by normal operation of the entire ICT infrastructure. In
this situation, the Federal Administration, society as well as the private sector and CI
operators are the permanent targets of attacks that must be recognised or detected and
warded off with countermeasures. The focus is on preventive measures in terms of
infrastructure and operations, with regular reactive interventions without relevant
consequences.
A crisis is characterised by a successful attack or sustained disruption with grave
consequences that can affect the entire country in extreme cases. Depending on its intensity,
a crisis increases the management rhythm within existing crisis and continuity management
structures. The focus is on the interplay of actions which, depending on the circumstances,
have to be accompanied at the national level by politically motivated technical measures. In
this regard, determining the cause of a crisis is part of crisis management. CI operators and
relevant ICT service providers and system suppliers are integrated into the decision-making
process on the basis of agreements.
Performance targets and planning
Individual and sector-based risk analyses are to serve as a basis for sectoral agreements
and continuity planning. These are to be prepared or coordinated in close cooperation with
38/42