EU Cyber Security Agency ENISA Launches Guide on How to Build Effective IT Security Public Private Partnerships (PPPs)

Oct 10, 2011, 19:01 ET from ENISA - European Network and Information Security Agency

BRUSSELS and HERAKLION, Greece, October 11, 2011 /PRNewswire/ --

- A New Guide With 36 Recommendations on Successfully Building Effective Public and Private Partnerships for Resilient IT Security was Published Today by the EU's Cyber Security Agency ENISA

Across the EU, most of the Member States' critical infrastructure is in the hands of the private sector. Therefore, industry and governments must work together to provide secure and reliable system access for citizens and business alike. The critical information infrastructures (CII) in Europe are fragmented, both geographically and due to the competition among telecom operators. Increasing CII-Resilience is thus fundamental for Europe. To meet this need, Public Private Partnerships (PPPs) have evolved to protect the digital economy in many Member States, at different times, and under different legal frameworks. This natural evolution means that there is no common definition of what constitutes a PPP. In a world where threats to infrastructure do not respect national borders, the European Network and Information Security Agency ENISA's new PPPs Guide with 36 recommendations on how to successfully build a PPP, underlines the need for a common understanding across Europe. This is of particular importance for the European Public Private Partnership for Resilience (EP3R), a European Union initiative, which is liaising with national PPPs on Critical Information Infrastructure Protection (CIIP) issues.

The Executive Director of ENISA, Professor Udo Helmbrecht, comments: "There is a need for a truly international, global approach to cyber security and Critical Information Infrastructure Protection. No country can create a CIIP strategy in isolation, as there are no national boundaries in cyber-space. PPPs are consequently one of the agenda items for the special EU-US Working Group on Cyber-Security and Cyber-Crime."

PPP taxonomy

The Guide classifies PPPs for security and resilience in three types: Prevention Focused, Response Focused and Umbrella PPPs. The Guide consolidates and validates a PPP-taxonomy, and reveals five main components for advice:

  • Why a PPP should be created? (scope/threats)
  • Who should be involved? (coverage, geographical/focus, interrelated links)
  • How a PPP should be governed?
  • What services and incentives should be offered?
  • When a PPP should be created and other timing questions?

These results derive from 30 questionnaires and 15 in-depth interviews with both public and private sector stakeholders across twenty countries. The Guide also describes and maps PPPs from the USA, Canada and Australia, identifying critical success factors for information sharing, and ways forward for international collaboration.

For full report:

Background: European Commission communication on CIIP and EP3R

SOURCE ENISA - European Network and Information Security Agency