Critical Information Infrastructure
Critical Information Infrastructure is a complex concept consisting of three elements:
- The critical cross-sector ICT elements of Critical Infrastructures (e.g. same Process Control systems (hardware and software) used in CI (limited number of manufactures globally; same vulnerabilities and threats)
- Critical base-level services supporting the ICT CI (e.g. Top Level Domain services/registries, critical Domain Name services, trust services, internet exchanges, PNT (Position, Navigation and Timing), ...
- Critical applications and services (e.g. critical national information services of government, critical cloud services, critical search engines and social media, ...
Contents
- 1 Abbreviation
- 2 Definitions
- 2.1 European Definitions
- 2.2 Other International Definitions
- 2.3 National Definitions
- 2.3.1 Albania
- 2.3.2 Austria
- 2.3.3 Bangladesh
- 2.3.4 Benin
- 2.3.5 Botswana
- 2.3.6 Brazil
- 2.3.7 Bulgaria
- 2.3.8 Cambodia
- 2.3.9 Chile
- 2.3.10 China
- 2.3.11 Colombia
- 2.3.12 Congo
- 2.3.13 Costa Rica
- 2.3.14 Croatia
- 2.3.15 Czech Republic
- 2.3.16 Denmark
- 2.3.17 Estonia
- 2.3.18 Finland
- 2.3.19 France
- 2.3.20 Iceland
- 2.3.21 India
- 2.3.22 Gambia
- 2.3.23 Ghana
- 2.3.24 Indonesia
- 2.3.25 Islamic Republic of Afghanistan
- 2.3.26 Israel
- 2.3.27 Italy
- 2.3.28 Japan
- 2.3.29 Kenya
- 2.3.30 Kosovo
- 2.3.31 Kuwait
- 2.3.32 Kyrgyztan
- 2.3.33 Lesotho
- 2.3.34 Lithuania
- 2.3.35 Malaysia
- 2.3.36 Mexico
- 2.3.37 Montenegro
- 2.3.38 Mozambique
- 2.3.39 North Macedonia
- 2.3.40 Norway
- 2.3.41 Pakistan
- 2.3.42 Philippines
- 2.3.43 Portugal
- 2.3.44 Qatar
- 2.3.45 Republic of Korea
- 2.3.46 Republic of Trinidad & Tobago
- 2.3.47 Russian Federation
- 2.3.48 Rwanda
- 2.3.49 Singapore
- 2.3.50 South Africa
- 2.3.51 Spain
- 2.3.52 Sri Lanka
- 2.3.53 Türkiye
- 2.3.54 Uganda
- 2.3.55 Ukraine
- 2.3.56 United Arab Emirates
- 2.3.57 United Kingdom
- 2.3.58 United States
- 2.3.59 Uruguay
- 2.3.60 Uzbekistan
- 2.3.61 Zambia
- 2.3.62 Zimbabwe
- 2.4 Regional Definition
- 2.5 Standard Definition
- 3 See also
- 4 Notes
- 5 References
Abbreviation
Definitions
European Definitions
Council Communication COM(2011)163 final
Council Directive 2016/1148
Other International Definitions
African Union
OECD
GFCE-MERIDIAN
National Definitions
Albania
Austria
Bangladesh
(i) public safety or financial security or public health,
(ii) national security or national integrity or sovereignty. [11]
Benin
Botswana
Brazil
Critical information Infrastructures are the subset of information assets that directly affect the achievement and continuity of state mission and the safety of society.
Bulgaria
Критична информационна инфраструктура са както мрежите, каналите и системите за управлението и поддържането им.
Cambodia
Chile
China
The national critical information infrastructure refers to the information facilities concerning the national security, the national economy and the people's livelihood, which may seriously damage the national security and the public interest if the data is divulged, destroyed or lost, including but not limited to providing public communications, broadcasting and television transmission and other services, information networks, energy, finance, transportation, education, scientific research, water conservancy, industrial manufacturing, medical and health, social security, public utilities and other important information systems and important Internet applications.
Colombia
Infraestructura crítica: Es el conjunto de computadores, sistemas computacionales, redes de telecomunicaciones, datos e información, cuya destrucción o interferencia puede debilitar o impactar en la seguridad de la economía, salud pública, o la combinación de ellas, en una nación). [21]
Congo
Costa Rica
Croatia
Kritična komunikacijska i informacijska infrastruktura – komunikacijski i informacijski sustavi čiji bi poremećaj u funkcioniranju bitno poremetio rad pojedine ili više identificiranih nacionalnih kritičnih infrastruktura. [25]
Czech Republic
Critical information infrastructure: Complex of information systems clearly defined by law, whose unfunctionality would result in a serious impact on state security, economy, public administration and provision of the basic daily needs of population. [26]
Within the field of cyber security, a critical infrastructure means an element or system of elements of the critical infrastructure in the sector of communication and information systems. [28]
Zákonem jasně vymezený komplex informačních systémů, jejichž nefunkčnost by měla závažný dopad na bezpečnost státu, ekonomiku, veřejnou správu a zabezpečení základních životních potřeb obyvatelstva.
Denmark
Critical ICT infrastructure: The subset of critical infrastructure that includes the digital infrastructure needed to maintain or restore vital societal functions. [30]
Estonia
The purpose of the critical information infrastructure protection (CIIP) is to maintain a trouble-free functioning of the country's essential information and communication systems under ordinary circumstances and to ensure their continuity on a minimum level during critical situations.
Finland
France
Iceland
The National Commissioner of Police further define those systems considered to be critical infrastructure.
India
Gambia
Ghana
Indonesia
Islamic Republic of Afghanistan
Israel
Italy
Japan
Japan defined the set of 13 Japanese CII sectors as [44], [45]:
- Information and communication services (情報通信)
- Financial services (金融)
- Aviation services (航空)
- Railway services (鉄道)
- Electric power supply services (電力)
- Gas supply services (ガス)
- Government and administrative services (including local public authorities)
(政府・行政サービス(地方公共団体を含む)) - Medical services (医療)
- Water services (水道)
- Logistics services (物流)
- Chemical industries (化学)
- Credit card services (クレジット)
- Petroleum industries (び「石油)
Kenya
Kosovo
a) An entity that provides a service which is essential for the maintenance of critical societal and/or economic activities, and
b) The provision of that service depends on network and information systems
c) An incident would have significant disruptive effects on the provision of that service. [47]
Critical Information Infrastructure (CII): ICT systems that are critical infrastructures for themselves or that are essential for the operation of critical infrastructures (telecommunications, computers/software, Internet, satellites, etc.). [50]
Kuwait
Kyrgyztan
Critical information infrastructure of the Kyrgyz Republic: a set of state information systems, state information and telecommunication networks and automated process control systems operating in the public administration and state electronic services, healthcare, transport, telecommunications and communications, credit and financial sector, defence sector, fuel industry, power generation and distribution, food processing industry and mining industry.
Lesotho
Lithuania
Ypatingos svarbos informacinė infrastruktūra – elektroninių ryšių tinklas ar jo dalis, informacinė sistema ar jos dalis, informacinių sistemų grupė ar pramoninių procesų valdymo sistema ar jos dalis, nepaisant to, ar jos valdytojas yra privatus ar viešojo administravimo subjektas, kuriuose įvykęs kibernetinis incidentas gali padaryti didelę žalą nacionaliniam saugumui, šalies ūkiui, valstybės ir visuomenės interesams. [55]
Malaysia
Mexico
Montenegro
[59]
Mozambique
North Macedonia
Norway
Kritisk IKT-infrastruktur defineres som kritisk infrastruktur for elektronisk kommunikasjon. [64]
Pakistan
Philippines
It covers any type of computer device including devices with data processing capabilities like mobile phones, smart phones, computer networks and other devices connected to the internet.
Portugal
Qatar
Criteria for being critical are:
- Identify the organization’s key core business processes and their dependency on assets owned and managed by the organization (e.g., power plant, refinery, general ledger, etc.);
- Use impact severity table to determine an impact score for the loss/non-functioning of each key asset; and
- Classify all assets as critical when the criticality score is greater than twenty (20) according to the impact criteria table in [72] [73].
Republic of Korea
The term "information and communications infrastructure" means electronic control and management system related to the national security, administration, defense, public security, finance, communications, transportation, energy, etc. and information and communications network under Article 2 (1) 1 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.. [75]
Republic of Trinidad & Tobago
Russian Federation
критическая информационная инфраструктура Российской Федерации - совокупность автоматизированных систем управления КВО и обеспечивающих их взаимодействие информационно- телекоммуникационных сетей, предназначенных для решения задач государственного управления, обеспечения обороноспособности, безопасности и правопорядка, нарушение (или прекращение) функционирования которых может стать причиной наступления тяжких последствий. [77]
Rwanda
Critical information infrastructure: virtual and physical information systems that provide services to the citizens and serve as a backbone of development of the national economic, social and security life.
Infrastructures d’information critiques: systèmes d’informations virtuels et physiques qui fournissent des services aux citoyens et servent de pivot à l’éclosion de la vie économique, sociale et sécuritaire du pays. [78]
Singapore
South Africa
Spain
The Spanish CIP law does not make any kind of distinction between [Critical Infrastructure|CI]] and CII. The law establishes the concept of a comprehensive and integral security approach uniting the physical and cyber security in one single strategy.
Sri Lanka
Türkiye
Kritik altyapılar: İşlediği bilginin gizliliği, bütünlüğü veya erişilebilirliği bozulduğunda, can kaybına, büyük ölçekli ekonomik zarara, ulusal güvenlik açıklarına veya kamu düzeninin bozulmasına, yol açabilecek bilişim sistemlerini barındıran altyapıları. [84] [85]
Uganda
Ukraine
{machine translation} critical information infrastructure - a set of objects of critical information infrastructure; the object of critical information infrastructure - a communication or technological system of the critical infrastructure object, the cyber attack of which will directly affect the sustainable functioning of such an object of critical infrastructure. [87]
United Arab Emirates
United Kingdom
United States
DHS
Uruguay
Uzbekistan
муҳим ахборот инфратузилмаси — муҳим стратегик ва ижтимоий-иқтисодий аҳамиятга эга бўлган автоматлаштирилган бошқарув тизимларининг, ахборот тизимлари ҳамда тармоқлар ва технологик жараёнлар ресурсларининг мажмуи.
(Critical information infrastructure - a complex of automated control systems, information systems and resources of networks and technological processes of great strategic and socio-economic importance) [92]
Zambia
Zimbabwe
Regional Definition
Victoria, Australia
Standard Definition
IETF
See also
- Critical Information Infrastructure Protection
- Critical Infrastructure
- Critical Infrastructure Protection
Notes
References
- Jump up ↑ COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS on Critical Information Infrastructure Protection ‘Achievements and next steps: towards global cyber-security’
- Jump up ↑ Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 (NIS Directive
- Jump up ↑ African Union Convention on Cyber Security and Personal Data Protection, LC12490, Malabo, Guinea, 27th June 2014
- Jump up ↑ Recommendation of the Council on Digital Security of Critical Activities
- Jump up ↑ Recommandation du Conseil sur la sécurité numérique des activités critiques
- Jump up ↑ OECD Recommendation of the Council on the Protection of Critical Information Infrastructures C(2008)35
- Jump up ↑ The GFCE-MERIDIAN Good Practice Guide on Critical Information Infrastructure Protection for governmental policy-makers, November 2016
- Jump up ↑ Dokumenti i Politikave për Sigurinë Kibernetike 2015 - 2017
- Jump up ↑ ENERGY REGULATOR AUTHORITY REGULATION ON CYBER SECURITY OF CRITICAL INFRASTRUCTURES IN THE POWER SECTOR
- Jump up ↑ Austrian Cyber Security Strategy, Federal Chancellery of the Republic of Austria, Vienna (2013)
- Jump up ↑ Digital Security Act (2018) Bangladesh
- Jump up ↑ DÉCRET N° 2023 - 060 DU 22 FEVRIER 2023 portant approbation des règles de politique de protection des infrastructures d’information critiques en République du Bénin
- Jump up ↑ National Cybersecurity Strategy (2021)
- Jump up ↑ GUIA DE REFERÊNCIA PARA A SEGURANÇA DAS INFRAESTRUTURAS CRÍTICAS DA INFORMAÇÃO Versão 01 (Nov. 2010)/ Portaria Nº 34, de 5 de agosto de 2009. Conselho de Defesa Nacional, Secretaria Executiva (2009).
- Jump up ↑ „Кибер устойчива България 2020” - Republic of Bulgaria: national cyber security strategy "Cyber Resilient Bulgaria 2020"(2016)
- Jump up ↑ Understanding of Korean CIIP
- Jump up ↑ BASES PARA UNA POLÍTICA NACIONAL DE CIBERSEGURIDAD, MARZO DE 2015, Chile
- Jump up ↑ Chile Política Nacional de Ciberseguridad (2017)
- Jump up ↑ Chilean National Cybersecurity Policy (2017)
- Jump up ↑ 网络空间安全战略 "National cyberspace security strategy" (full text) December 2016
- Jump up ↑ Lineamientos de política para la Ciberseguridad y Ciberdefensa, Conpes 3701 (2011) based on Resolución CRC 2258 from 2009.
- Jump up ↑ Stratégie nationale de cybersécurité 2022 - 2025 de la République Démocratique de Congo
- Jump up ↑ Estrategia Nacional de Ciberseguridad de Costa Rica (2023-2027)
- Jump up ↑ Estrategia Nacional de Ciberseguridad de Costa Rica (2017)
- Jump up ↑ National Cyber Security Strategy draft (2015)
- ↑ Jump up to: 26.0 26.1 [1]
- Jump up ↑ Zákon č. 181/2014 Sb. o kybernetické bezpečnosti a o změně souvisejících zákonů (zákon o kybernetické bezpečnosti)
- Jump up ↑ Act No. 181 of 23 July 2014 On Cyber Security and Change of Related Acts (Act on Cyber Security)
- Jump up ↑ National strategi for cyber- og informationssikkerhed 2022-2024 (2021)
- Jump up ↑ Danish Cyber and Information Security Strategy (2022-2024)
National strategi for cyber- og informationssikkerhed 2022-2024 (2021) - Jump up ↑ Critical Information Infrastructure Protection Estonia
- Jump up ↑ Finlands' Cyber Security Strategy
- Jump up ↑ ANSSI Glossaire
- Jump up ↑ Network and information security webpage
- Jump up ↑ Section 70(1) of the Information Technology Act Ammendment (2008)
- Jump up ↑ THE GAMBIA NATIONAL CYBERSECURITY STRATEGY (2019)
- Jump up ↑ Directive for the Protection of Critical Information Infrastructure (CII) (2020)
- Jump up ↑ (presentation), 2016
- Jump up ↑ Z.A. Hasibuan, Indonesia National Cyber Security Strategy: Security and Sovereignty in Indonesia Cyberspace (presentation), 2013
- Jump up ↑ National Cyber Security Strategy of Afghanistan (2014)
- Jump up ↑ CERT.IL Glossary
- Jump up ↑ PROTEZIONE DELLE INFRASTRUTTURE CRITICHE INFORMATIZZATE La realtà Italiana (2004)
- Jump up ↑ The Basic Policy of Critical Information Infrastructure Protection (3rd Edition), Japan (2015)
- Jump up ↑ 重要インフラの情報セキュリティ対策に係る 第4次行動計画 (2018)
- Jump up ↑ The Cybersecurity Policy for Critical Infrastructure Protection (4th Edition) / (Tentative Translation) 2018
- Jump up ↑ GUIDELINES ON CYBERSECURITY FOR PAYMENT SERVICE PROVIDERS, AUGUST 2018
- Jump up ↑ National Cyber Security Strategy and Action Plan 2023 – 2026 (2023)
- Jump up ↑ National Cyber Security Strategy and Action Plan 2023 – 2026 (2023)
- Jump up ↑ Strategjia Shtetërore për Sigurinë Kibernetike dhe Plani i Veprimit 2016 – 2019
- Jump up ↑ National Cyber Security Strategy and Action Plan 2016 – 2019 (2016)
- Jump up ↑ Glossary Communication and Information Technology Regulatory
- Jump up ↑ СТРАТЕГИЯ кибербезопасности Кыргызской Республики на 2019-2023 годы
- Jump up ↑ Computer Crime and Cyber Security Bill (2022)
- Jump up ↑ GOVERNMENT OF THE REPUBLIC OF LITHUANIA RESOLUTION NO 796 of 29 June 2011 ON THE APPROVAL OF THE PROGRAMME FOR THE DEVELOPMENT OF ELECTRONIC INFORMATION SECURITY (CYBER-SECURITY) FOR 2011–2019
- Jump up ↑ LIETUVOS RESPUBLIKOS KIBERNETINIO SAUGUMO ĮSTATYMAS 2014 m. gruodžio 11 d. Nr. XII-1428 Vilnius
- Jump up ↑ Malaysia (2009)
- Jump up ↑ Estragia Nacional de Ciberseguridad (November 2017)
- Jump up ↑ Strategija sajber bezbjednosti Crne Gore 2022-2026 (2021)
- Jump up ↑ Стратегија сајбер безбједности Црне Горе 2022-2026
- Jump up ↑ Estratégia Nacional de Segurança Cibernética de Moçambique (2021-2024)
- Jump up ↑ НАЦИОНАЛНА СТРАТЕГИЈА ЗА САЈБЕР БЕЗБЕДНОСТ НА РЕПУБЛИКА МАКЕДОНИЈА 2018 -2022
- Jump up ↑ National Cyber Security Strategy of the Republic of Macedonia (2018)
- Jump up ↑ Cyber Security Strategy for Norway (2012)
- Jump up ↑ Nasjonal strategi for informasjonssikkerhet (2012)
- Jump up ↑ AS PASSED BY THE NATIONAL ASSEMBLY A Bill to make provisions for prevention of electronic crimes
- Jump up ↑ Cyber Security Strategy for Telecom Sector 2023-2028
- Jump up ↑ National Cyber Security Policy 2021
- Jump up ↑ Republic Act No. 10175, 2012
- Jump up ↑ DND GLOSSARY OF CYBER SECURITY TERMS (v.4)
- Jump up ↑ National Cyber Security Plan 2022 (May 2017)
- Jump up ↑ Glossário Centro National de Cibersegurança Portugal
- ↑ Jump up to: 72.0 72.1 QATAR National Cyber Security Strategy (May 2014)
- ↑ Jump up to: 73.0 73.1 الاستراتيجية الوطنية للأمن السيبراني QATAR National Cyber Security Strategy - Arabic version (May 2014)
- Jump up ↑ Act on the protection of information and communications, no. 13590 (2015)
- Jump up ↑ Act on the protection of information and communications, no. 13590 (2015)
- Jump up ↑ Government of the Republic of Trinidad & Tobago, National Cyber Security Strategy (December 2012)
- Jump up ↑ NATIONAL SECURITY OF RUSSIA - Information security (February 3, 2012, № 803)
- Jump up ↑ https://cyber.gov.rw/documentation/ Rwanda cybercrime law
- Jump up ↑ (draft) Cybersecurity Bill 2017
- Jump up ↑ Cybersecurity Code of Practice for Critical Information Infrastructure
- Jump up ↑ South Africa Cyber Security Policy, Staatskoerant No. 32963, 10 Feb 2010
- Jump up ↑ Cyber Security bill 2019
- Jump up ↑ Turkey's National Cyber Security Strategy and 2013-2014 Action Plan
- Jump up ↑ UlUSAL SİBER GÜVENLİk STRATEJİSİ VE
- Jump up ↑ 2016-2019 ULUSAL SİBER GÜVENLİK STRATEJİSİ
- Jump up ↑ National Information Security Policy (2011)
- Jump up ↑ ЗАКОН УКРАЇНИ - Про основні засади забезпечення кібербезпеки України / THE LAW OF UKRAINE: About the basic principles of providing cyber security of Ukraine 2163-19
- Jump up ↑ https://u.ae/en/information-and-services%2Fjustice-safety-and-the-law%2F-%2Fmedia%2FDocuments-2023%2FCritical-Information-Infrastructure-Protection-CIIP-Policy.ashx CRITICAL INFORMATION INFRASTRUCTURE PROTECTION (CIIP) POLICY
- Jump up ↑ Cyber Security in the UK, Postnote Number 389, September 2011
- Jump up ↑ Blueprint for a secure cyber future, DHS Nov 2011
- Jump up ↑ Decreto No. 451/009 item No. 3
- Jump up ↑ Presidential Resolution No. PP-167 dated May 31, 2023, “On additional measures to improve the system of cybersecurity of critical information infrastructure facilities of the Republic of Uzbekistan”
- Jump up ↑ National Cyber Security Policy
- Jump up ↑ Draft Cybercrime and Cyber security bill (2017)
- Jump up ↑ Critical Information Infrastructure Risk Management, VICTORIAN GOVERNMENT CIO COUNCIL, 2012
- Jump up ↑ IETF RFC449 Internet Security Glossary 2