Difference between revisions of "Critical Information Infrastructure"

From CIPedia
Jump to navigation Jump to search
(Norway)
Line 10: Line 10:
 
=== National Definitions ===
 
=== National Definitions ===
 
==== Australia ====
 
==== Australia ====
{{definition|The ICT component of Critical Infrastructure is referred to as Critical Information Infrastructure (CII). <ref>[http://www.digital.vic.gov.au/wp-content/uploads/2014/07/SEC-STD-02-Critical-Information-Infrastructure-Risk-Management1.pdf Critical Information Infrastructure Risk Management, VICTORIAN GOVERNMENT CIO COUNCIL, 2012 ]</ref>}}
+
{{definition|The ICT component of Critical Infrastructure is referred to as Critical Information Infrastructure (CII). <ref>[http://www.digital.vic.gov.au/wp-content/uploads/2014/07/SEC-STD-02-Critical-Information-Infrastructure-Risk-Management1.pdf Critical Information Infrastructure Risk Management, VICTORIAN GOVERNMENT CIO COUNCIL, 2012 ]</ref>}}<br />
<br />
 
 
==== Austria ====
 
==== Austria ====
 
{{definition|Critical information infrastructures are those infrastructures or parts thereof which are of crucial importance for ensuring important social functions. Their failure or destruction has severe effects on the health, security or the economic and social wellbeing of the population or the functioning of governmental institutions. <ref>[http://www.bmi.gv.at/cms/BMI_Service/cycer_security/130415_strategie_cybersicherheit_en_web.pdf Austrian Cyber Security Strategy, Federal Chancellery of the Republic of Austria, Vienna (2013)]</ref>}}<br />
 
{{definition|Critical information infrastructures are those infrastructures or parts thereof which are of crucial importance for ensuring important social functions. Their failure or destruction has severe effects on the health, security or the economic and social wellbeing of the population or the functioning of governmental institutions. <ref>[http://www.bmi.gv.at/cms/BMI_Service/cycer_security/130415_strategie_cybersicherheit_en_web.pdf Austrian Cyber Security Strategy, Federal Chancellery of the Republic of Austria, Vienna (2013)]</ref>}}<br />
 +
==== Brazil ====
 +
{{definition|Infraestruturas Críticas da Informação: subconjunto de ativos de informação que afetam diretamente a consecução e a continuidade da missão do Estado e a segurança da sociedade. <ref>[http://www.biblioteca.presidencia.gov.br/publicacoes-oficiais-1/catalogo/orgao-essenciais/gabinete-de-seguranca-institucional/guia-de-referencia-para-seguranca-de-infraestruturas-criticas-da-informacao/at_download/file GUIA DE REFERÊNCIA PARA A SEGURANÇA DAS INFRAESTRUTURAS CRÍTICAS DA INFORMAÇÃO Versão 01 (Nov. 2010)/ Portaria Nº 34, de 5 de agosto de 2009. Conselho de Defesa Nacional, Secretaria Executiva (2009).]</ref><br />Critical information Infrastructures are the subset of information [[Asset|assets]] that directly affect the achievement and continuity of state mission and the safety of society.}}<br />
 
==== Colombia ====
 
==== Colombia ====
{{definition|Critical Infrastructure is the set of computers, computer systems, telecommunication networks, data and information, the destruction or interference may weaken or impact the safety of the economy, public health, or combination thereof, in a nation (Infraestructura crítica: Es el conjunto de computadores, sistemas computacionales, redes de telecomunicaciones, datos e información, cuya destrucción o interferencia puede debilitar o impactar en la seguridad de la economía, salud pública, o la combinación de ellas, en una nación). <ref>[http://www.mintic.gov.co/portal/604/articles-3510_documento.pdf  Lineamientos de política para la Ciberseguridad y Ciberdefensa, Conpes 3701 (2011) based on Resolución CRC 2258 from 2009.]</ref>}}
+
{{definition|Critical Infrastructure is the set of computers, computer systems, telecommunication networks, data and information, the destruction or interference may weaken or impact the safety of the economy, public health, or combination thereof, in a nation (Infraestructura crítica: Es el conjunto de computadores, sistemas computacionales, redes de telecomunicaciones, datos e información, cuya destrucción o interferencia puede debilitar o impactar en la seguridad de la economía, salud pública, o la combinación de ellas, en una nación). <ref>[http://www.mintic.gov.co/portal/604/articles-3510_documento.pdf  Lineamientos de política para la Ciberseguridad y Ciberdefensa, Conpes 3701 (2011) based on Resolución CRC 2258 from 2009.]</ref>}}<br />
<br />
 
 
 
 
==== Czech Republic ====
 
==== Czech Republic ====
 
{{definition|Within the field of cyber security, a critical infrastructure means an element or system of elements of the critical infrastructure in the sector of communication and information systems. <ref>[http://www.govcert.cz/download/nodeid-1143/ Act  No. 181 of 23 July 2014 On Cyber Security and Change of Related Acts (Act on Cyber Security)]</ref>}}
 
{{definition|Within the field of cyber security, a critical infrastructure means an element or system of elements of the critical infrastructure in the sector of communication and information systems. <ref>[http://www.govcert.cz/download/nodeid-1143/ Act  No. 181 of 23 July 2014 On Cyber Security and Change of Related Acts (Act on Cyber Security)]</ref>}}
 
Zákonem jasně vymezený komplex informačních systémů, jejichž nefunkčnost by měla závažný dopad na bezpečnost státu, ekonomiku, veřejnou správu a zabezpečení základních životních potřeb obyvatelstva.<br />
 
Zákonem jasně vymezený komplex informačních systémů, jejichž nefunkčnost by měla závažný dopad na bezpečnost státu, ekonomiku, veřejnou správu a zabezpečení základních životních potřeb obyvatelstva.<br />
 
 
==== Estonia ====
 
==== Estonia ====
{{definition|Critical information infrastructure ([CII]) means information and communication [[system|systems]] whose maintenance, [[reliability]] and [[safety]] are essential for the proper functioning of a country. The critical information infrastructure is a part of the [[Critical Infrastructure|critical infrastructure]]. <ref> [https://www.ria.ee/CIIP/ Critical Information Infrastructure Protection Estonia]</ref>}}
+
{{definition|Critical information infrastructure ([CII]) means information and communication [[system|systems]] whose maintenance, [[reliability]] and [[safety]] are essential for the proper functioning of a country. The critical information infrastructure is a part of the [[Critical Infrastructure|critical infrastructure]]. <ref> [https://www.ria.ee/CIIP/ Critical Information Infrastructure Protection Estonia]</ref>}}<br />
<br />
 
 
 
 
==== Finland ====
 
==== Finland ====
{{definition|Critical information infrastructure refers to the structures and functions behind the information systems of the vital functions of society which electronically transmit, transfer, receive, store or otherwise process information (data). <ref>[http://www.enisa.europa.eu/activities/Resilience-and-CIIP/national-cyber-security-strategies-ncsss/FinlandsCyberSecurityStrategy.pdf Finlands' Cyber Security Strategy]</ref>}}
+
{{definition|Critical information infrastructure refers to the structures and functions behind the information systems of the vital functions of society which electronically transmit, transfer, receive, store or otherwise process information (data). <ref>[http://www.enisa.europa.eu/activities/Resilience-and-CIIP/national-cyber-security-strategies-ncsss/FinlandsCyberSecurityStrategy.pdf Finlands' Cyber Security Strategy]</ref>}}<br />
<br />
 
 
==== Indonesia ====
 
==== Indonesia ====
{{definition|ICT Critical National Infrastructures are assets, services, objects in the form of physical or logical that involving the livelihood of many people, national interests and/or revenue of country that are strategic, in case of threats and attacks cause more loss of lives, destabilizing political, social, cultural and national economy as well as the sovereignty of the nation. <ref>[http://www.slideshare.net/ditkaminfo/iisf-indonesia-national-cyber-security-strategy-v2 Indonesia's National Cyber Security Strategy]</ref>}}
+
{{definition|ICT Critical National Infrastructures are assets, services, objects in the form of physical or logical that involving the livelihood of many people, national interests and/or revenue of country that are strategic, in case of threats and attacks cause more loss of lives, destabilizing political, social, cultural and national economy as well as the sovereignty of the nation. <ref>[http://www.slideshare.net/ditkaminfo/iisf-indonesia-national-cyber-security-strategy-v2 Indonesia's National Cyber Security Strategy]</ref>}}<br />
<br />
 
 
==== Lithuania ====
 
==== Lithuania ====
{{definition|Critical information infrastructure shall mean an electronic communications network, information system or a group of information systems where an [[Incident|incident]] that occurs causes or may cause grave [[damage]] to national security, national economy or social well-being. <ref>[http://www.ird.lt/doc/teises_aktai_en/EIS%28KS%29PP_796_2011-06-29_EN_PATAIS.pdf GOVERNMENT OF THE REPUBLIC OF LITHUANIA RESOLUTION NO 796 of 29 June 2011 ON THE APPROVAL OF THE PROGRAMME FOR THE DEVELOPMENT OF ELECTRONIC INFORMATION SECURITY (CYBER-SECURITY) FOR 2011–2019]</ref>}}  
+
{{definition|Critical information infrastructure shall mean an electronic communications network, information system or a group of information systems where an [[Incident|incident]] that occurs causes or may cause grave [[damage]] to national security, national economy or social well-being. <ref>[http://www.ird.lt/doc/teises_aktai_en/EIS%28KS%29PP_796_2011-06-29_EN_PATAIS.pdf GOVERNMENT OF THE REPUBLIC OF LITHUANIA RESOLUTION NO 796 of 29 June 2011 ON THE APPROVAL OF THE PROGRAMME FOR THE DEVELOPMENT OF ELECTRONIC INFORMATION SECURITY (CYBER-SECURITY) FOR 2011–2019]</ref>}} <br />
<br />
 
 
 
 
==== Norway ====
 
==== Norway ====
 
{{definition|Critical ICT infrastructure is defined as [[Critical Infrastructure|critical infrastructure]] for electronic communications. <ref>[https://www.regjeringen.no/globalassets/upload/fad/vedlegg/ikt-politikk/cyber_security_strategy_norway.pdf Cyber Security Strategy for Norway (2012)]</ref><br />Kritisk IKT-infrastruktur defineres som kritisk infrastruktur for elektronisk kommunikasjon. <ref>[https://www.regjeringen.no/globalassets/upload/fad/vedlegg/ikt-politikk/nasjonal_strategi_infosikkerhet.pdf Nasjonal strategi for informasjonssikkerhet (2012)]</ref>}}<br />
 
{{definition|Critical ICT infrastructure is defined as [[Critical Infrastructure|critical infrastructure]] for electronic communications. <ref>[https://www.regjeringen.no/globalassets/upload/fad/vedlegg/ikt-politikk/cyber_security_strategy_norway.pdf Cyber Security Strategy for Norway (2012)]</ref><br />Kritisk IKT-infrastruktur defineres som kritisk infrastruktur for elektronisk kommunikasjon. <ref>[https://www.regjeringen.no/globalassets/upload/fad/vedlegg/ikt-politikk/nasjonal_strategi_infosikkerhet.pdf Nasjonal strategi for informasjonssikkerhet (2012)]</ref>}}<br />
 
 
==== Republic of Trinidad & Tobago ====
 
==== Republic of Trinidad & Tobago ====
{{definition|Critical (information) infrastructure means computer systems, devices, networks, computer programs, computer data, so vital to the country that the incapacity or destruction of or interference with such systems and assets would have a debilitating impact on [[security]], defence or international relations of the State; or provision of services directly related to national or economic security, banking and financial services, communications infrastructure, national public health and safety, public transportation, public key infrastructure or any combination of those matters. <ref>[http://www.nationalsecurity.gov.tt/Portals/0/Pdf%20Files/National_Cyber_Security%20Strategy_Final.pdf Government of the Republic of Trinidad & Tobago, National Cyber Security Strategy (December 2012)]</ref>}}  
+
{{definition|Critical (information) infrastructure means computer systems, devices, networks, computer programs, computer data, so vital to the country that the incapacity or destruction of or interference with such systems and assets would have a debilitating impact on [[security]], defence or international relations of the State; or provision of services directly related to national or economic security, banking and financial services, communications infrastructure, national public health and safety, public transportation, public key infrastructure or any combination of those matters. <ref>[http://www.nationalsecurity.gov.tt/Portals/0/Pdf%20Files/National_Cyber_Security%20Strategy_Final.pdf Government of the Republic of Trinidad & Tobago, National Cyber Security Strategy (December 2012)]</ref>}} <br />
<br />
 
 
 
 
==== South Africa ====
 
==== South Africa ====
{{definition|Critical Information Infrastructure means all ICT systems, data systems, data bases, networks (incl. people, buildings, facilities and processes), that are fundamental to the effective operation of the State. <ref> [http://pmg-assets.s3-website-eu-west-1.amazonaws.com/docs/100219cybersecurity.pdf South Africa Cyber Security Policy, Staatskoerant No. 32963, 10 Feb 2010]</ref>.}}
+
{{definition|Critical Information Infrastructure means all ICT systems, data systems, data bases, networks (incl. people, buildings, facilities and processes), that are fundamental to the effective operation of the State. <ref> [http://pmg-assets.s3-website-eu-west-1.amazonaws.com/docs/100219cybersecurity.pdf South Africa Cyber Security Policy, Staatskoerant No. 32963, 10 Feb 2010]</ref>.}}<br />
<br />
 
 
 
 
==== Turkey ====
 
==== Turkey ====
{{definition|Critical (information) infrastructure is defined as the infrastructures which host the information systems that can cause: loss of lives, large scale economic damages, or security vulnerabilities and disturbance of public order at national level when the [[confidentiality]], [[integrity]] or [[accessibility]] of the information they process is compromised. <ref> [http://www.enisa.europa.eu/activities/Resilience-and-CIIP/national-cyber-security-strategies-ncsss/TUR_NCSS.pdf Turkey's National Cyber Security Strategy and 2013-2014 Action Plan]</ref>}}
+
{{definition|Critical (information) infrastructure is defined as the infrastructures which host the information systems that can cause: loss of lives, large scale economic damages, or security vulnerabilities and disturbance of public order at national level when the [[confidentiality]], [[integrity]] or [[accessibility]] of the information they process is compromised. <ref> [http://www.enisa.europa.eu/activities/Resilience-and-CIIP/national-cyber-security-strategies-ncsss/TUR_NCSS.pdf Turkey's National Cyber Security Strategy and 2013-2014 Action Plan]</ref>}}<br />  
<br />  
 
 
<!--===Standard Definition===
 
<!--===Standard Definition===
  
Line 68: Line 54:
 
[[Category:Information]]
 
[[Category:Information]]
 
[[Category:Infrastructure]]
 
[[Category:Infrastructure]]
{{#set:defined by=OECD|defined by=Australia|defined by=Austria|defined by=Colombia|defined by=Czech Republic|defined by=Estonia|defined by=Finland|defined by=Indonesia|defined by=Lithuania|defined by=Norway|defined by=Republic of Trinidad & Tobago|defined by=South Africa|defined by=Turkey}}
+
{{#set:defined by=OECD|defined by=Australia|defined by=Austria|defined by=Brazil|defined by=Colombia|defined by=Czech Republic|defined by=Estonia|defined by=Finland|defined by=Indonesia|defined by=Lithuania|defined by=Norway|defined by=Republic of Trinidad & Tobago|defined by=South Africa|defined by=Turkey}}

Revision as of 00:53, 19 June 2015

Definitions

European Definitions

Council Communication COM(2011)163 final

No definition provided [1]

Other International Definitions

OECD

Critical information infrastructures (“CII”) should be understood as referring to those interconnected information systems and networks, the disruption or destruction of which would have serious impact on the health, safety, security, or economic well-being of citizens, or on the effective functioning of government or the economy. [2]

National Definitions

Australia

The ICT component of Critical Infrastructure is referred to as Critical Information Infrastructure (CII). [3]


Austria

Critical information infrastructures are those infrastructures or parts thereof which are of crucial importance for ensuring important social functions. Their failure or destruction has severe effects on the health, security or the economic and social wellbeing of the population or the functioning of governmental institutions. [4]


Brazil

Infraestruturas Críticas da Informação: subconjunto de ativos de informação que afetam diretamente a consecução e a continuidade da missão do Estado e a segurança da sociedade. [5]
Critical information Infrastructures are the subset of information assets that directly affect the achievement and continuity of state mission and the safety of society.


Colombia

Critical Infrastructure is the set of computers, computer systems, telecommunication networks, data and information, the destruction or interference may weaken or impact the safety of the economy, public health, or combination thereof, in a nation (Infraestructura crítica: Es el conjunto de computadores, sistemas computacionales, redes de telecomunicaciones, datos e información, cuya destrucción o interferencia puede debilitar o impactar en la seguridad de la economía, salud pública, o la combinación de ellas, en una nación). [6]


Czech Republic

Within the field of cyber security, a critical infrastructure means an element or system of elements of the critical infrastructure in the sector of communication and information systems. [7]

Zákonem jasně vymezený komplex informačních systémů, jejichž nefunkčnost by měla závažný dopad na bezpečnost státu, ekonomiku, veřejnou správu a zabezpečení základních životních potřeb obyvatelstva.

Estonia

Critical information infrastructure ([CII]) means information and communication systems whose maintenance, reliability and safety are essential for the proper functioning of a country. The critical information infrastructure is a part of the critical infrastructure. [8]


Finland

Critical information infrastructure refers to the structures and functions behind the information systems of the vital functions of society which electronically transmit, transfer, receive, store or otherwise process information (data). [9]


Indonesia

ICT Critical National Infrastructures are assets, services, objects in the form of physical or logical that involving the livelihood of many people, national interests and/or revenue of country that are strategic, in case of threats and attacks cause more loss of lives, destabilizing political, social, cultural and national economy as well as the sovereignty of the nation. [10]


Lithuania

Critical information infrastructure shall mean an electronic communications network, information system or a group of information systems where an incident that occurs causes or may cause grave damage to national security, national economy or social well-being. [11]


Norway

Critical ICT infrastructure is defined as critical infrastructure for electronic communications. [12]
Kritisk IKT-infrastruktur defineres som kritisk infrastruktur for elektronisk kommunikasjon. [13]


Republic of Trinidad & Tobago

Critical (information) infrastructure means computer systems, devices, networks, computer programs, computer data, so vital to the country that the incapacity or destruction of or interference with such systems and assets would have a debilitating impact on security, defence or international relations of the State; or provision of services directly related to national or economic security, banking and financial services, communications infrastructure, national public health and safety, public transportation, public key infrastructure or any combination of those matters. [14]


South Africa

Critical Information Infrastructure means all ICT systems, data systems, data bases, networks (incl. people, buildings, facilities and processes), that are fundamental to the effective operation of the State. [15].


Turkey

Critical (information) infrastructure is defined as the infrastructures which host the information systems that can cause: loss of lives, large scale economic damages, or security vulnerabilities and disturbance of public order at national level when the confidentiality, integrity or accessibility of the information they process is compromised. [16]


See also

Notes

  1. COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS on Critical Information Infrastructure Protection ‘Achievements and next steps: towards global cyber-security’
  2. [1] OECD Recommendation of the Council on the Protection of Critical Information Infrastructures C(2008)35]
  3. Critical Information Infrastructure Risk Management, VICTORIAN GOVERNMENT CIO COUNCIL, 2012
  4. Austrian Cyber Security Strategy, Federal Chancellery of the Republic of Austria, Vienna (2013)
  5. GUIA DE REFERÊNCIA PARA A SEGURANÇA DAS INFRAESTRUTURAS CRÍTICAS DA INFORMAÇÃO Versão 01 (Nov. 2010)/ Portaria Nº 34, de 5 de agosto de 2009. Conselho de Defesa Nacional, Secretaria Executiva (2009).
  6. Lineamientos de política para la Ciberseguridad y Ciberdefensa, Conpes 3701 (2011) based on Resolución CRC 2258 from 2009.
  7. Act No. 181 of 23 July 2014 On Cyber Security and Change of Related Acts (Act on Cyber Security)
  8. Critical Information Infrastructure Protection Estonia
  9. Finlands' Cyber Security Strategy
  10. Indonesia's National Cyber Security Strategy
  11. GOVERNMENT OF THE REPUBLIC OF LITHUANIA RESOLUTION NO 796 of 29 June 2011 ON THE APPROVAL OF THE PROGRAMME FOR THE DEVELOPMENT OF ELECTRONIC INFORMATION SECURITY (CYBER-SECURITY) FOR 2011–2019
  12. Cyber Security Strategy for Norway (2012)
  13. Nasjonal strategi for informasjonssikkerhet (2012)
  14. Government of the Republic of Trinidad & Tobago, National Cyber Security Strategy (December 2012)
  15. South Africa Cyber Security Policy, Staatskoerant No. 32963, 10 Feb 2010
  16. Turkey's National Cyber Security Strategy and 2013-2014 Action Plan