French NATIONAL DIGITAL SECURITY STRATEGY — objective 4 will also support the enhancement and perpetuation of these offers through public contracting that chooses security products and services qualified at the right level, as well as by communication and educational measures for the private sector. In addition, the State services will endeavour to disseminate the results of research and development which they finance for high-level security equipment in order to raise the security level of products for businesses and the general public. Finally, France will endeavour to take full advantage of leverage offered by the European Union to support, promote and defend French scientific, technological and industrial competences in the cybersecurity fields. It will also discourage the EU from limiting itself to the role of consumer, and will incite it rather to stand out as an indispensable global stakeholder for the offer in this sector. > Transferring acquired knowledge to the private sector to contribute to the handling of its cybersecurity. For five years now France has equipped itself with the capacity to detect and respond to cyberattacks, as announced in the 2008 White Paper on Defence and National Security. Although this effort should be pursued, notably by ANSSI, it is up to the private sector to ensure its own security in the field of information technology as is the case in other fields, since the State services are only required to intervene in case of serious crisis. Supported by the transfer of this knowledge acquired by the administrations to the private sector, labelling of competent and trustworthy service providers should enable the detection and treatment of the inevitable growth in the number of cyberattacks that businesses are subjected to. > Preparing a safer digital world through better anticipation of uses, adapted support and stakeholders’ information. For the next five years, the priority for the competent information systems security authorities should be anticipation and prevention. This will entail ensuring that the digital products and services or those that involve digital technology, which are designed, developed and produced in France, are among the safest in the world. To achieve this objective, the competent authorities should direct their communication efforts towards the public and private scientific community, and the innovation centres; competitive clusters, technological research institutes, incubators and «fab labs»; by devoting specific means to these areas as needed, as is the case with the Ministry of Defence, and more recently, the Ministry of the Interior. When digital products and services store personal data or are intended for the business sectors of vital importance, the State services will provide the elements that are useful for risk analysis or the recommendations required to obtain the level of security that corresponds to the use of the product or the service being designed or developed. For uses that justify it, they will also contribute to establishing systems to independently evaluate the level of security and trustworthiness of these products and services, and to providing their potential users with adapted guarantees through labelling. In parallel, the legal environment to accommodate new products and services should be anticipated. For example, the imminent arrival of autonomous cars should incite the regulator to prepare the conditions to ensure the security of their circulation. Cybersecurity should be taken into account in the international working groups that define the framework and control technical procedures. For other types of products or services, an adapted identification system should inform the consumer of their essential digital features and notably the processing of the data that is collected. For certain sectors such as the health sector, systematic labelling of digital products and services will be considered. France will endeavour to include other EU Member States in the implementation of these practices in order 33

Select target paragraph3