EU NIS direktiva. Uroš Majcen

Similar documents
COMMISSION OF THE EUROPEAN COMMUNITIES. Draft. COMMISSION REGULATION (EU) No /2010

COMMISSION REGULATION (EU) No 255/2010 of 25 March 2010 laying down common rules on air traffic flow management

COMMISSION IMPLEMENTING REGULATION (EU)

Terms of Reference for a rulemaking task

PRESENT SIMPLE TENSE

Official Journal of the European Union L 146/7

Official Journal of the European Union L 59/1. (Non-legislative acts) REGULATIONS

COUNCIL OF THE EUROPEAN UNION. Brussels, 2 June 2014 (OR. en) 10171/14 OJ CONS 30 TRANS 282 TELECOM 122 ENER 193 PROVISIONAL AGENDA

Donosnost zavarovanj v omejeni izdaji

Official Journal of the European Union L 7/3

Proposal for a COUNCIL DECISION

ANNEX TO EASA OPINION No 03/2015. COMMISSION REGULATION (EU) No /.. of XXX

(Non-legislative acts) REGULATIONS

ANNEX TO EASA OPINION 09/2013. COMMISSION REGULATION (EU) No /.. of XXX

PRIVACY POLICY KEY DEFINITIONS. Aquapark Wrocław Wrocławski Park Wodny S.A. with the registered office in Wrocław, ul. Borowska 99, Wrocław.

Official Record Series 5

COMMISSION OF THE EUROPEAN COMMUNITIES. Draft. COMMISSION REGULATION (EU) No /

DECISION OF THE COUNCIL NO 1 OF 2014 AMENDMENT TO THE APPENDIX TO ANNEX Q TO THE CONVENTION AIR TRANSPORT

DECISION TO DESIGNATE DUBLIN AIRPORT AS A COORDINATED AIRPORT

CROSS-BORDER TRADE IN SERVICES

Continuing Airworthiness

Frequently Asked Questions. Free allocation from the Special Reserve (Art 3f ETS Directive 1 )

This document is meant purely as a documentation tool and the institutions do not assume any liability for its contents

The EU Ecolabel: Good for you, Good for the Environment!

Delegations will find attached document D042244/03.

Official Journal of the European Union

Official Record Series 5

TWINNING EGYPT ITALY STRENGTHENING THE AVIATION OVERSIGHT STANDARDS OF THE EGYPTIAN CIVIL AVIATION AUTHORITY

ANNEX. to the. Proposal for a Regulation of the European Parliament and of the Council

REGULATION (EC) No 1107/2006 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL. of 5 July 2006

CIVIL AVIATION (AVIATION SECURITY) (APPLICATION) ORDER 2017

Terms of reference for a rulemaking task

Maritime Passenger Rights

Council of the European Union Brussels, 27 March 2018 (OR. en)

EUROPEAN COMMISSION DIRECTORATE-GENERAL MOBILITY AND TRANSPORT

L 342/20 Official Journal of the European Union

PRIVACY POLICY 3. What categories of data we process 1. Administrator of personal data 2. How we collect your data

KAKO GA TVORIMO? Tvorimo ga tako, da glagol postavimo v preteklik (past simple): 1. GLAGOL BITI - WAS / WERE TRDILNA OBLIKA:

COMMISSION IMPLEMENTING REGULATION (EU)

ARTICLE 29 Data Protection Working Party

Official Journal L 362. of the European Union. Legislation. Non-legislative acts. Volume December English edition. Contents REGULATIONS

Terms of Reference for rulemaking task RMT.0704

COUNCIL OF THE EUROPEAN UNION. Brussels, 3 October 2013 (OR. en) 13408/13 Interinstitutional File: 2013/0020 (NLE) TRANS 466 MAR 126

Athens International Airport

DaHar Danube Inland Harbour Development

Screening Chapter 14 Transport. Single European Sky (SES) 18 December Transport

Terms of Reference for a rulemaking task. Review of provisions for examiners and instructors

SAMPLE. If your competent authority requires you to hand in a signed paper copy of the report, please use the space below for signature:

LIMITE EN COUNCIL OF THE EUROPEAN UNION. Brussels, 10 February /11 LIMITE GENVAL 8 CATS 10 AVIATION 21 DATAPROTECT 9

The possibility of extending the EU Ecolabel to Green Financial Products

Terms of Reference for a rulemaking task

Proposal for a COUNCIL DECISION

ANA Traffic Growth Incentives Programme Terms and Conditions

SSP progress in Latvia. Overview

Acceptable Means of Compliance and Guidance Material to Part-DTO 1

Operations Specifications

Development of RBMP s In Republic of Macedonia

Dott.ssa Benedetta Valenti

Project acronym Project full title. Project No

LIMITE EN COUNCIL OF THE EUROPEAN UNION. Brussels, 1 August /08 LIMITE CRIMORG 124 AVIATION 162 DATAPROTECT 55

EU ECOLABEL LOGO GUIDELINES

EN Official Journal of the European Union. (Acts whose publication is obligatory)

Conference: FOOD CHAIN IN THE DIGITAL SINGLE MARKET Organised jointly with the Slovak Presidency of the Council

ADQ Regulators Working Group

ANNEX II to EASA Opinion No 09/2017. COMMISSION REGULATION (EU) No /.. of XXX

COMMISSION REGULATION (EU)

Official Journal of the European Union L 335/13

BETWEEN THE BELGIAN CIVIL AVIATION AUTHO THE AUSTRIAN CIVIL AVIATION AUTHORITY ABOUT THE SUPERVISION OF AIRCRAFT

ICAO Regulatory Framework and Universal Safety Oversight Audit Programme

APAT Italian National Agency for the Protection of the Environment and for Technical Services CAMPING SITE SERVICE EU ECO-LABEL AWARD SCHEME

ARTWEI ARTWEI ARTWEI

WRITTEN STATEMENT BY THE WELSH GOVERNMENT

ACI EUROPE POSITION. A level playing field for European airports the need for revised guidelines on State Aid

REGULATIONS. REGULATION (EC) No 216/2008 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL. of 20 February 2008

Programme initiative.pt 2.0 Regulations

(Non-legislative acts) REGULATIONS

ANNEX TO EASA OPINION No 03/2013. COMMISSION REGULATION (EU) No /.. of XXX

Alternative Dispute Resolution

for HUB MSMEs IX Meeting of the Executive Steering Committee of IX Meeting of the Executive Steering Committee of IIRSA

ANNUAL SAFETY REVIEW

Single European Sky II

1/2 July Draft Commission Implementing Regulation amending Regulation (EU) No 1207/2011 (Surveillance Performance and Interoperability SPI)

Regulative Baseline for the Implementation of IFR Operations at Uncontrolled Aerodromes in the Czech Republic / CZCAA IFR Study.

The European Commission's Proposal to Amend EU Regulation 261/2004. by Arpad Szakal

United Kingdom Civil Aviation Authority

RPAS/UAS Challenges in ATM. Peter Tannhäuser. Head of Legal Service 15 July 2015

B COUNCIL REGULATION (EEC) No 95/93 of 18 January 1993 on common rules for the allocation of slots at Community airports. (OJ L 14, , p.

Official Journal of the European Union L 8/3 DIRECTIVES

Welcome. Workshop on New Basic Regulation. Module TT

Press Release Athens, 2 June 2014

ASSEMBLY 35TH SESSION

Opportunities and Challenges for an Enhanced Cooperation between Regulators and Auditors

MINISTRY OF MARITIME AFFAIRS, TRANSPORT AND INFRASTRUCTURE

ANNEX ANNEX. to the COMMISSION IMPLEMENTING REGULATION

REGULATION (EU) No 1177/2010 COPY FOR FREE CONSULTATION

Official Journal of the European Union. (Non-legislative acts) REGULATIONS

Draft Agenda. 7-8 March 2013, Ljubljana (Slovenia) Hosted by APEK

Requirements for wildlife control at aerodromes

Part 145 CONTINUATION TRAINING General Overview and introduction to the regulations

Applicant: EUROWINGS LUFTVERKEHRS AG (Eurowings) Date Filed: July 16, 2014

Transcription:

EU NIS direktiva Uroš Majcen

Kaj je direktiva na splošno? DIREKTIVA Direktiva je za vsako državo članico, na katero je naslovljena, zavezujoča glede rezultata, ki ga je treba doseči, vendar prepušča državnim organom izbiro oblike in metode. (249. člen PES) 2

EU NIS direktiva Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union http://eur-lex.europa.eu/legalcontent/en/txt/?uri=uriserv:oj.l_.2016.194.01.0001.01.eng&toc=oj:l:2016: 194:TOC Gre za prva EU pravila glede kibernetske varnosti Naslavlja se na EU strategijo glede kibernetske varnosti iz leta 2013 Objavljena 19.07.2016 v Official Journal of the European Union Vstopila v veljavo 08.08.2016 Prenos v lokalno zakonodajo do 09.05.2018 3

Namen direktive 1. Izboljšanje zmožnosti kibernetske varnosti na nacionalnem nivoju 2. Povečanje sodelovanja na nivoju EU 3. Operatorji ključne infrastrukture in ponudniki digitalnih storitev morajo zagotavljati: 1.- Risk Management 2.- Incident Reporting 4

Izboljšanje zmožnosti kibernetske varnosti na nacionalnem nivoju 1. Vsaka država članica mora sprejeti nacionalno strategijo kibernetske varnosti. 2. Vsaka država članica mora določiti vsaj eno državno kompetenčno ustanovo za NIS direktivo, ki bo nadzorovala sprejetje in izvajanje direktive na državnem nivoju 3. Vsaka država članica mora določiti enotno kontaktno točko za sodelovanje, izmenjavo informacijo 4. Vsaka država članica mora določiti vsaj en CSIRT (Computer Security incident Response Team). CSIRT bo zadolžen za: 1.- nadzor nad incidenti na državnem nivoju 2.- podajanje zgodnjih opozoril, alarmov, najav in podrobnosti vsem deležnikom glede rizikov in incidentov 3.- izvajanje aktivnosti glede na incidente 4.- zagotavljanje dinamične risk in incident analize in podajanje stanja situational awareness 5.- sodelovanje v mreži nacionalnih CSIRT 5

Povečanje sodelovanja na nivoju EU 1. Glede na NIS direktivo se ustanovi Cooperation Group 1.- sestavljena iz držav članic, EU komisije in ENISA 2.- delovanje na 4 področjih: planiranje, steering, sharing, reporting 2. Glede na NIS direktivo se ustanovi mreža nacionalnih CSIRT 1.- izmenjava informacij med CSIRT 2.- izmenjava informacij o incidentih 3.- zagotavljanje koordiniranega odgovora na incidente 4.- zagotavljanje zmožnosti delovanja preko meja države (cross border incident handling) 5.- obveščanje Cooperation Group glede svojih dejavnosti 6.- ozaveščanje glede rezultatov NIS vaj 7.- spremljanje delovanja nacionalnih CSIRT 8.- objava smernic glede sodelovanja 9.2 leti po sprejetju direktive in vsakih 18 mesecev po tem datumu bo mreža CSIRT podala poročilo glede svojega delovanja. 6

Risk Management in Incident Reporting operaterji ključne infrastrukture in ponudniki digitalnih storitev 1. Operaterji/ponudniki ključne infrastrukture so javne ali zasebne institucije, ki imajo pomembno vlogo v družbi in gospodarstvu 2. Identificirani ponudniki ključne infrastrukture morajo izvajati določene naloge za izboljšanje varnosti in zagotoviti obveščanje o varnostnih incidentih nacionalnim institucijam 3. Naloge za izboljšanje varnosti so: 1.- tehnični in organizacijski koraki za preprečitev rizikov 2.- zagotavljanje varnosti mrežne in informacijske infrastrukture. 3.- obdelovanje incidentov 7

Risk Management in Incident Reporting operaterji ključne infrastrukture in ponudniki digitalnih storitev 1. Vsaka država članica mora določiti ponudnike ključne infrastrukture 1.- to so entitete, ki zagotavljajo storitve, ključne za družbene in gospodarske aktivnosti 2.- zagotavljanje teh storitev temelji tudi na mrežni in informacijski infrastrukturi 3.- varnostni incident bi imel velik vpliv na zagotovitev teh storitev 2. Katere sektorje pokriva direktiva 1.- energetika: elektrika, plin, nafta 2.- transport: zrak, tiri, voda in ceste 3.- bančni sektor 4.- finančni sektor 5.- zdravje 6.- voda: 8

9

Časovnica 1. Julij 2016 sprejetje v EU parlamentu 2. Avgust 2016 direktiva stopi formalno v veljavo 3. Februar 2017 Cooperation Group začne delovati 4. Avgust 2017 sprejetje zahtev, ki jih morajo izpolnjevati DSPji 5. Februar 2018 Cooperation Group sprejme program 6. Maj 2018 direktiva mora biti prenesena v lokalno zakonodajo 7. November 2018 članice identificirajo ponudnike ključne infrastrukture 8. Maj 2019 EU komisija preveri članice glede ključne infrastrukture 9. Maj 2021 EU komisija preveri članice glede izpolnjevanja direktive v celoti 10

EU NIS Direktiva - deležniki EUROPEAN UNION PUBLIC OR PRIVATE ENTITY EUROPEAN COMMISSION EUROPEAN NETWORK AND INFORMATION SECURITY AGENCY COMPETENT AUTHORITY MEMBER STATE COOPERATION GROUP COMPUTER SECURITY INCIDENT RESPONSE TEAM NETWORK AND INFORMATION SECURITY COMMITTEE OPERATORS OF ESSENTIAL SERVICES PURSUANT TO ART. 14 2 and 2ac + ANNEX II 1. Energy 2. Transport 3. Banking 4. Financial market infrastructures 5. Health sector 6. Drinking water supply and distribution 7. Digital Infrastructure THIRD PARTY DIGITAL SERVICE PROVIDERS PURSUANT TO ART. 15a 2 + ANNEX III 1. Online marketplace 2. 3. Online search engine 4. Cloud computing service REPRESENTATIVE FOR A DIGITAL SERVICE PROVIDER PUBLIC ELECTRONIC COMMUNICATION NETWORKS OR PUBLICLY AVAILABLE ELECTRONIC COMMUNICATION SERVICE PROVIDERS UNDER EU DIRECTIVE 2002/21/EC TRUST SERVICE PROVIDERS UNDER = excluded from the Directive QUALIFIED AUDITOR PUBLIC OTHERS NOT IDENTIFIED MICRO AND SMALL ENTERPRISES 08 Feb 2016 11

COMPETENT AUTHORITY OR COMPUTER SECURITY INCIDENT RESPONSE TEAM Public CA/ CSIRT CA/ CSIRT Other Members CA/ CSIRT CA/ CSIRT Other Members EU NIS Direktiva krogotok informaij *Processing of personal data pursuant to this Directive shall be carried out in accordance with Directive 95/46/EC; processing of personal data by Union institutions and bodies pursuant to this Directive shall be carried out in accordance with Regulation (EC) No 45/2001 [Article 1a] Required Voluntary ESSENTIAL SERVICES PROVIDERS Monitor & defend information system Privacy processing* DIGITAL SERVICE PROVIDERS [OR REPRESENTATIVE] Monitor & defend information system Privacy processing* PUBLIC ELECTRONIC COMMUNICATION NETWORKS OR PUBLICLY AVAILABLE ELECTRONIC COMMUNICATION SERVICE OR TRUST PROVIDERS Monitor & defend information system Privacy processing* OTHER ENTITIES VOLUNTARY NOTIFICATION ESP-CA/CSIRT defensive measures cyber security risks incidents DSP-CA/CSIRT interfaces PECN-CA/CSIRT Other-CA/CSIRT CA/CSIRT-CA/CSIRT CA/CSIRT-CA/CSIRT CA/CSIRT-PUBLIC Monitor & defend information system Privacy processing* 08 Feb 2016 12

S&T Slovenija d.d. Leskoškova 6 1000 Ljubljana info@snt.si www.snt.si