The organization must establish and document a formal procedure for ongoing collaboration and information exchange with external security bodies such as the sectoral authority, the Directorate General Crisis Centre (DGCC), the Coordination Unit for Threat Analysis (OCAM) and police services.
This procedure should outline the specific types of security information to be shared, the designated communication channels, contact points and the responsibilities for this exchange.
Key steps for formalizing and implementing ongoing security collaboration and information exchange include the following:
- List all relevant external security bodies (e.g., sectoral authority, DGCC, OCAM, police services) and their specific roles concerning critical infrastructure security.
- Specify the types of security information to be shared (e.g., threat intelligence, incident reports, vulnerability advisories), frequency, and classification levels.