Take-Aways (AI)
  • The fede­ral govern­ment can rest­rict com­pe­ti­ti­on in its own pro­cu­re­ments, but can­not impo­se licen­sing requi­re­ments for for­eign pro­vi­ders on private/cantonal operators.
  • The influence of for­eign sup­pliers can hard­ly be redu­ced in the short term; risks can be mini­mi­zed through edu­ca­ti­on, ana­ly­ses, cer­ti­fi­ca­ti­ons and ope­ra­tio­nal safe­ty procedures.
  • Secu­ri­ty of fixed and mobi­le infras­truc­tures depends pri­ma­ri­ly on cor­rect con­fi­gu­ra­ti­on by users; inde­pen­dent test­ing is required.
  • The pro­po­sed Infor­ma­ti­on Secu­ri­ty Act enables ope­ra­tio­nal secu­ri­ty pro­ce­du­res and risk assess­ments inclu­ding natio­na­li­ty, but remains pri­ma­ri­ly limi­t­ed to fede­ral contracts.

Inter­pel­la­ti­on Was­ser­fal­len (18.4197): IT secu­ri­ty of cri­ti­cal infras­truc­tures – What means and mea­su­res is the Fede­ral Coun­cil taking?

Sub­mit­ted text

In the dis­cus­sion about the IT secu­ri­ty of cri­ti­cal infras­truc­tures, the Increa­sed focus on indu­stri­al espio­na­ge lie. The advan­cing digi­ta­lizati­on of our socie­ty will lead to a mas­si­ve increa­se in sen­si­ti­ve data. Our indu­stries are beco­ming more and more net­work­ed and auto­ma­ted. The cor­re­spon­ding data flow can­not be con­trol­led or can only be con­trol­led to a limi­t­ed ext­ent. The IT infras­truc­tu­re of the­se com­pa­nies thus beco­mes an ide­al point of attack for indu­stri­al espio­na­ge. As a result, know­ledge and inno­va­ti­on and, as a con­se­quence, jobs can be lost. Against this back­drop and the clo­se inte­gra­ti­on of for­eign com­pa­nies with the sta­te and mili­ta­ry of their count­ries of ori­gin, cen­tral que­sti­ons ari­se that affect our pro­spe­ri­ty and our natio­nal secu­ri­ty. Other indu­stria­li­zed nati­ons, such as Ger­ma­ny, the USA, Austra­lia and recent­ly also Japan, par­ti­al­ly pro­hi­bit sup­pliers or purcha­ses from indi­vi­du­al count­ries. A dis­cus­sion on how Switz­er­land should behave in view of the­se dan­gers is urgen­tly indi­ca­ted and appro­pria­te mea­su­res should be exami­ned. Against this back­ground, I ask the Fede­ral Coun­cil to com­ment on the fol­lo­wing questions:

1. what opti­ons does the fede­ral govern­ment have, based on cur­rent legis­la­ti­on, to coun­ter the influence of for­eign pro­vi­ders on cri­ti­cal IT infrastructure?

2. what addi­tio­nal mea­su­res are conceiva­ble against the incre­a­sing influence of for­eign com­pa­nies on parts of our cri­ti­cal IT infrastructure?

3. to what ext­ent are our fixed and mobi­le net­work infras­truc­tures pro­tec­ted against white-col­lar crime, espe­ci­al­ly sin­ce the cur­rent net­work equip­ment sup­pliers are all for­eign providers?

4 Within the revi­si­on of the Tele­com­mu­ni­ca­ti­ons Act, mobi­le com­mu­ni­ca­ti­ons pro­vi­ders will be obli­ged to com­bat unaut­ho­ri­zed mani­pu­la­ti­on of tele­com­mu­ni­ca­ti­ons equip­ment. How is the cor­re­spon­ding con­trol to be ensured?

Does it have suf­fi­ci­ent resour­ces in hand to ensu­re IT secu­ri­ty at all times when pro­cu­ring and ope­ra­ting cri­ti­cal IT infras­truc­tures, or does it need new legal foun­da­ti­ons for this?

State­ment of the Fede­ral Council

1. the fede­ral govern­ment may, in the case of own pro­cu­re­ments based on Artic­le 3 para­graph 2 let­ter a of the Fede­ral Law on Public Pro­cu­re­ment (BöB; SR 172.056.1) rest­rict com­pe­ti­ti­on on an excep­tio­nal basis if their own safe­ty is at risk. With regard to pri­va­te and can­to­nal ope­ra­tors of cri­ti­cal infras­truc­tures, the Fede­ral Coun­cil can­not, on the basis of the cur­rent legal situa­ti­on, make any sti­pu­la­ti­ons regar­ding the admis­si­on of for­eign providers.

2. The influence of for­eign pro­vi­ders on Switzerland’s ICT infras­truc­tu­re can­not be signi­fi­cant­ly redu­ced in the fore­seeable future. Dome­stic alter­na­ti­ves are lack­ing for most pro­ducts. Howe­ver, the risk of abu­se of this influence can be con­tai­ned. It is important to cla­ri­fy the exi­sting risks, as is done by the Fede­ral Intel­li­gence Ser­vice (FIS) and the Report­ing and Ana­ly­sis Cen­ter for Infor­ma­ti­on Assu­rance (MELANI). They rely on their own ana­ly­ses as well as tho­se of other fede­ral agen­ci­es such as arma­su­i­s­se or the FUB com­mand sup­port base, which inve­sti­ga­te the risk of misu­se of ICT in coope­ra­ti­on with rese­arch and indu­stry and deve­lop mea­su­res to redu­ce it. It is also conceiva­ble to defi­ne secu­ri­ty requi­re­ments for cri­ti­cal infras­truc­tures via cer­ti­fi­ca­ti­ons and stan­dar­dizati­ons or to requi­re the imple­men­ta­ti­on of ope­ra­tio­nal secu­ri­ty pro­ce­du­res for cri­ti­cal services.

3. the fixed and mobi­le infras­truc­tu­re its­elf is typi­cal­ly not the tar­get of white-col­lar cri­mi­nals, but the means they use to ste­al infor­ma­ti­on. The level of secu­ri­ty when using fixed and mobi­le infras­truc­tures depends direct­ly on the Con­fi­gu­ra­ti­on of the­se tech­no­lo­gies by the users ab. With the appro­pria­te effort, it is pos­si­ble to achie­ve a high level of pro­tec­tion. It is important to check the secu­ri­ty of the ICT used careful­ly and inde­pendent­ly and not to rely exclu­si­ve­ly on the infor­ma­ti­on pro­vi­ded by the providers.

4. The revi­si­on of the Tele­com­mu­ni­ca­ti­ons Act (TCA; SR 784.10) crea­tes an obli­ga­ti­on for all tele­com­mu­ni­ca­ti­ons pro­vi­ders to com­bat unaut­ho­ri­zed mani­pu­la­ti­on of tele­com­mu­ni­ca­ti­ons equip­ment by means of tele­com­mu­ni­ca­ti­ons trans­mis­si­ons. Super­vi­si­on is the respon­si­bi­li­ty of the Fede­ral Office of Com­mu­ni­ca­ti­ons (OFCOM). Pro­vi­ders are obli­ged to pro­vi­de it with all infor­ma­ti­on neces­sa­ry for the enforce­ment of the law. Should the­re be rea­son to suspect that pro­vi­ders are insuf­fi­ci­ent­ly pro­tec­ting their equip­ment against unaut­ho­ri­zed mani­pu­la­ti­on by tele­com­mu­ni­ca­ti­ons trans­mis­si­ons, OFCOM would inter­ve­ne within the scope of its super­vi­so­ry powers. In addi­ti­on, tele­com­mu­ni­ca­ti­ons sec­re­cy applies.

5. with the Infor­ma­ti­on Secu­ri­ty Act (ISG, 17.028), the Fede­ral Coun­cil is pro­po­sing new legal foun­da­ti­ons for impro­ving the ICT secu­ri­ty of fede­ral­ly owned infras­truc­tures. Com­pa­nies that pro­vi­de cri­ti­cal IT ser­vices for the fede­ral govern­ment are to be sub­ject to a Ope­ra­tio­nal safe­ty pro­ce­du­res be assu­med. In such a case, the Natio­na­li­ty of the com­pa­ny as a risk fac­tor be asses­sed. The ISG does not pro­vi­de a basis for a prio­ri exclu­si­on of for­eign pro­vi­ders, but would crea­te the pos­si­bi­li­ty to veri­fy their trust­wort­hi­ness and also secu­ri­ty during the exe­cu­ti­on of the con­tract. Accor­ding to the draft law, the scope of the ISG remains limi­t­ed in prin­ci­ple to con­tracts award­ed by the Con­fe­de­ra­ti­on, but could also be exten­ded to con­tracts award­ed by ope­ra­tors of cri­ti­cal infras­truc­tures by means of spe­cial legis­la­ti­on pur­su­ant to Art. 2(5) of the draft law.