- The federal government can restrict competition in its own procurements, but cannot impose licensing requirements for foreign providers on private/cantonal operators.
- The influence of foreign suppliers can hardly be reduced in the short term; risks can be minimized through education, analyses, certifications and operational safety procedures.
- Security of fixed and mobile infrastructures depends primarily on correct configuration by users; independent testing is required.
- The proposed Information Security Act enables operational security procedures and risk assessments including nationality, but remains primarily limited to federal contracts.
Submitted text
In the discussion about the IT security of critical infrastructures, the Increased focus on industrial espionage lie. The advancing digitalization of our society will lead to a massive increase in sensitive data. Our industries are becoming more and more networked and automated. The corresponding data flow cannot be controlled or can only be controlled to a limited extent. The IT infrastructure of these companies thus becomes an ideal point of attack for industrial espionage. As a result, knowledge and innovation and, as a consequence, jobs can be lost. Against this backdrop and the close integration of foreign companies with the state and military of their countries of origin, central questions arise that affect our prosperity and our national security. Other industrialized nations, such as Germany, the USA, Australia and recently also Japan, partially prohibit suppliers or purchases from individual countries. A discussion on how Switzerland should behave in view of these dangers is urgently indicated and appropriate measures should be examined. Against this background, I ask the Federal Council to comment on the following questions:
1. what options does the federal government have, based on current legislation, to counter the influence of foreign providers on critical IT infrastructure?
2. what additional measures are conceivable against the increasing influence of foreign companies on parts of our critical IT infrastructure?
3. to what extent are our fixed and mobile network infrastructures protected against white-collar crime, especially since the current network equipment suppliers are all foreign providers?
4 Within the revision of the Telecommunications Act, mobile communications providers will be obliged to combat unauthorized manipulation of telecommunications equipment. How is the corresponding control to be ensured?
Does it have sufficient resources in hand to ensure IT security at all times when procuring and operating critical IT infrastructures, or does it need new legal foundations for this?
Statement of the Federal Council
1. the federal government may, in the case of own procurements based on Article 3 paragraph 2 letter a of the Federal Law on Public Procurement (BöB; SR 172.056.1) restrict competition on an exceptional basis if their own safety is at risk. With regard to private and cantonal operators of critical infrastructures, the Federal Council cannot, on the basis of the current legal situation, make any stipulations regarding the admission of foreign providers.
2. The influence of foreign providers on Switzerland’s ICT infrastructure cannot be significantly reduced in the foreseeable future. Domestic alternatives are lacking for most products. However, the risk of abuse of this influence can be contained. It is important to clarify the existing risks, as is done by the Federal Intelligence Service (FIS) and the Reporting and Analysis Center for Information Assurance (MELANI). They rely on their own analyses as well as those of other federal agencies such as armasuisse or the FUB command support base, which investigate the risk of misuse of ICT in cooperation with research and industry and develop measures to reduce it. It is also conceivable to define security requirements for critical infrastructures via certifications and standardizations or to require the implementation of operational security procedures for critical services.
3. the fixed and mobile infrastructure itself is typically not the target of white-collar criminals, but the means they use to steal information. The level of security when using fixed and mobile infrastructures depends directly on the Configuration of these technologies by the users ab. With the appropriate effort, it is possible to achieve a high level of protection. It is important to check the security of the ICT used carefully and independently and not to rely exclusively on the information provided by the providers.
4. The revision of the Telecommunications Act (TCA; SR 784.10) creates an obligation for all telecommunications providers to combat unauthorized manipulation of telecommunications equipment by means of telecommunications transmissions. Supervision is the responsibility of the Federal Office of Communications (OFCOM). Providers are obliged to provide it with all information necessary for the enforcement of the law. Should there be reason to suspect that providers are insufficiently protecting their equipment against unauthorized manipulation by telecommunications transmissions, OFCOM would intervene within the scope of its supervisory powers. In addition, telecommunications secrecy applies.
5. with the Information Security Act (ISG, 17.028), the Federal Council is proposing new legal foundations for improving the ICT security of federally owned infrastructures. Companies that provide critical IT services for the federal government are to be subject to a Operational safety procedures be assumed. In such a case, the Nationality of the company as a risk factor be assessed. The ISG does not provide a basis for a priori exclusion of foreign providers, but would create the possibility to verify their trustworthiness and also security during the execution of the contract. According to the draft law, the scope of the ISG remains limited in principle to contracts awarded by the Confederation, but could also be extended to contracts awarded by operators of critical infrastructures by means of special legislation pursuant to Art. 2(5) of the draft law.