“Infrastructure” generally means the group of mutually interconnected components that provide a framework support to the whole, i.e. mutually dependent networks and systems generally interconnected at various levels, including industries, institutions and distribution capacities that provide a flow of products and services. These represent the material and technical facilities of the state, i.e. sectors carrying out economic and social system functions, such as energy, transportation, etc. “Security Event”21 is an event that may cause and/or lead to a violation of information systems and technologies and rules of security policy. “Security Incident”21 is a violation of an imminent threat of violation of security policies, security rules, or standard security rules of operation of an information and communications system or of a network. “Security Measure”21 is a protective measure ensuring security requirements are put into place on the system. These may be of different natures (physical protection of a device and information, personnel security – staff check, organizational measures – operating rules, etc.). “Security of Information System” means the ability of a network or of an information and communication system to resist, at a certain reliability level, random events and/or intentional actions that endanger the availability, integrity and confidentiality of the saved and/or transmitted data and/or of related services provided by the network and information system and/or accessible using the network and the information system. “Security Threat”21 is a potential cause of an unwanted event that may result in damage to system and its assets, e.g. destroying, unwanted accessibility, modification, unavailability of services, etc. “Security Vulnerability”21 is an intentional error or an unintentional defect and/or error of software or hardware of infrastructure facilities that may be misused by potential attackers for damaging activities. These vulnerabilities are either known and published but not yet treated by the producer or hidden and non-discovered. “System Resistance”21 the ability of a system to resist threats and face impacts of outages. “Risk”26 means any circumstance and/or event that has a potentially unfavourable impact on security. “Vulnerability”21 is a weak point of an asset or of a control that can be exploited by a threat. 22

Select target paragraph3