SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 1 SUBSIDIARY LEGISLATION 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS ORDER* 6th July, 2018 LEGAL NOTICE 216
2018, as amended by Legal Notice 335
2018 and 307
2024. PART I - PRELIMINARY 1.
this order is Measures for High Common Level
Security
Network and Information Systems Order. Citation and scope.
the European Parliament and
the Council
6 July 2016 concerning measures for a high common level
security
network and information systems across the Union. 2. In this order unless the context otherwise requires: "autonomous CSIRT" means a self-organised CSIRT which provides a monitoring function
CSIRT services and alerts to its own business or other agencies, operators
essential services or digital service providers; Interpretation. Amended by: L.N. 307
2024. "CIIP Unit" means the Critical Information Infrastructure Protection Unit as established under article 5
shareable computing resources; "consumer" means any natural person who is acting for purposes which are outside his trade, business, craft or profession; "critical information infrastructure" or "CII" means an information and communication technology asset, system, network or part thereof which is essential for the maintenance
vital societal functions, health, safety, security, economic or social well-being
people, and the disruption or destruction
which would have a significant impact in Malta as a result
the failure to maintain those functions; "critical infrastructure" or "CI" has the same meaning assigned to it by article 2
the Critical Infrastructures and European Critical Infrastructures (Identification, Designation and Protection) Order; *These regulations have been repealed by Legal Notice 71
SECURITY
NETWORK AND INFORMATION SYSTEMS "CSIRT" means computer security incident response team; Cap. 586. "Data Protection Commissioner" means the Information and Data Protection Commissioner as appointed under article 11
the Data Protection Act. S.L. 460.24. "Department" means the Critical Infrastructure Protection Department established by article 3
the Critical Infrastructures and European Critical Infrastructures (Identification, Designation and Protection) Order; S.L. 419.06. "digital service" means a service within the meaning
regulation 2
the Notification Procedure Regulations which is
a type listed in the Third Schedule; "DNS service provider" means an entity which provides DNS services on the internet; "digital service provider" means any legal person that provides a digital service; "domain name system" or "DNS" means a hierarchical distributed naming system in a network which refers queries for domain names; "incident" means any event having an effect on the security
network and information systems; "incident handling" means all procedures supporting the detection, analysis and containment
an incident and the response thereto; "internet exchange point" or "IXP" means a network facility which enables the interconnection
more than two independent autonomous systems, primarily for the purpose
facilitating the exchange
internet traffic; an IXP provides interconnection only for autonomous systems; an IXP does not require the internet traffic passing between any pair
participating autonomous systems to pass through any third autonomous system, nor does it alter or otherwise interfere with such traffic; Cap. 418. "Malta Communications Authority" means the authority established under article 3
the Malta Communications Authority Act; "Member States" means the Member States
the European Union; "Minister" means the Minister responsible for the protection
critical infrastructure and critical information infrastructure protection; MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 "national strategy on the security
network and information systems" means a framework providing strategic objectives and priorities on the security
network and information systems at national level; "network and information system" means: (a) an electronic communications network within the meaning
article 2
the Electronic Communications (Regulation) Act; (b) any device or group
interconnected or related devices, one or more
which, pursuant to a program, perform automatic processing
digital data; or (
their operation, use, protection and maintenance. "online marketplace" means a digital service that allows consumers, traders or both as respectively defined in paragraph (a) and in paragraph (b)
Directive 2013/11/EU
the European Parliament and
the Council to conclude online sales or services contracts with traders either on the online marketplace’s website or on a trader's website that uses computing services provided by the online marketplace; "online search engine" means a digital service that allows users to perform searches
, in principle, all websites or websites in a particular language on the basis
a query on any subject in the form
a keyword, phrase or other input, and returns links in which information related to the requested content can be found; "operator
essential services" means a public or private entity
a type referred to in the Second Schedule, which meets the criteria laid down in article 9
essential services and, or digital service providers, identifying the security solutions and technical measures that exist or are being implemented for their protection and the identification, selection and prioritization
counter measures and procedures; "representative" means any natural or legal person established in the Union explicitly designated to act on behalf
a digital service provider not established in the Union, which may be addressed by a national competent authority or a CSIRT instead
the digital service provider with regard to the obligations
that digital service provider Cap. 399. 3 4 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS under this order; "risk" means any reasonably identifiable circumstance or event having a potential effect on the security
network and information systems and leading to uncertainty on the objectives
an asset, system, network or part thereof. An effect is a deviation from the expected objectives, objectives may have different aspects and may apply at different levels, positive or negative. Objectives can have different aspects (such as financial, health and safety, and environmental goals) and can apply at different levels (such as strategic, organization-wide, project, product and process). Risk is
ten characterized by reference to potential events and consequences, or a combination
these. Risk is
ten expressed in terms
a combination
the consequences
an event, including changes in circumstances, and the associated likelihood
occurrence; "risk assessment" is the overall process
risk identification, risk analysis and risk evaluation, incorporating the identification
risk sources, events, their causes and their potential consequences, comprehending the nature
risk and determining the level
risk, with the ultimate objective
comparing the results
the risk analysis with the risk criteria in order to determine whether the risk and, or its magnitude is acceptable or tolerable; "security
network and information systems" means the ability
network and information systems to resist, at a given level
confidence, any action that compromises the availability, authenticity, integrity or confidentiality
stored or transmitted or processed data or the related services
fered by, or accessible via those network and information systems; "standard" means a standard within the meaning
paragraph
Regulation (EU) No 1025/2012
the European Parliament and
the Council; "specification" means a technical specification within the meaning
paragraph
Regulation (EU) No 1025/ 2012
the European Parliament and
the Council; "top-level domain name registry" means an entity which administers and operates the registration
internet domain names under a specific top-level domain; "trader" means any natural persons, or any legal person irrespective
whether privately or publicly owned, who is acting, including through any person acting in his name or on his behalf, for purposes relating to his trade, business, craft or profession; Cap. 460. "Treaty" shall have the same meaning as in article 2
the European Union Act. MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 3.
this order shall not apply to undertakings which are subject to the requirements
and 13b
Directive 2002/21/EC
the European Parliament and
the Council, or to trust service providers which are subject to requirements
Regulation (EU) No 910/2014
the European Parliament and
the Council. Applicability.
the Europe Parliament and
the Council. S.L. 460.24. 5
this order. The information exchanged shall be limited to that which is relevant and proportionate to the purpose
such exchange. Such exchange
information shall preserve the confidentiality
that information and protect the security and commercial interests
operators
essential services and digital service providers.
which is contrary to the essential interests
the security
Malta, and to maintain law and order, in particular to allow for the investigation, detection and prosecution
criminal
fences.
essential services or digital service providers either to ensure the security
their network and information systems or to notify incidents, provided that such requirements are at least equivalent in effect to the obligations laid down in this order, those provisions
that sector-specific law shall apply. 4. Processing
personal data pursuant to this order shall be carried out in accordance with the Data Protection Act and Regulation 2016/679/EU
the European Parliament and
the Council. Processing
personal data. Cap. 586. PART II – CRITICAL INFORMATION INFRASTRUCTURE PROTECTION UNIT, CSIRTMalta and CSIRTs 5.
this order and shall be the national competent authority The CIIP Unit. Amended by: L.N. 307
2024. 6 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS covering the sectors referred to in the Second Schedule and the services referred to in the Third Schedule.
operators
essential services and digital service providers; (b) identifying and designating operators
essential services within Malta pursuant to article 9; (c) identifying the services provided by operators
essential services and digital service providers; (d) ensuring that a risk assessment is carried out by operators
essential services and digital service providers; (e) ensuring that operators
essential services and digital service providers draw up and maintain an operator security plan; (f) instigating simulated runs
operator security plans by operators
essential services and digital service providers. (g) without prejudice to article 3
Critical Information Infrastructures (CIIs) for information sharing; (h) maintaining a register
CSIRTs, operators
essential services and digital service providers providing services in Malta; (
network and information systems pursuant to article 8; (k) monitoring security measures taken by operators
essential services pursuant to article 11.
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 6.
the First Schedule respectively, covering at least the sectors referred to in the Second Schedule and the services referred to in the Third Schedule. CSIRTMalta shall be responsible for risk and incident handling in accordance with a well-defined process. 7 CSIRTs. Amended by: L.N. 307
2024.
an essential service shall receive CSIRT monitoring services from any
the following CSIRTs which shall comply with the requirements and tasks set out in paragraphs 1 and 3 respectively
the First Schedule: (a) an internal CSIRT providing CSIRT monitoring services and alerts within operators
essential services; (b) an autonomous CSIRT may be contracted to perform CSIRT monitoring services.
essential services which fails to establish a CSIRT as provided for in sub-article
the obligations laid down in this order. 7. The Minister shall ensure that: Resources. (a) the CIIP Unit and CSIRTMalta have adequate resources to carry out in an effective and efficient manner, the tasks assigned to them and thereby to fulfil the objectives
this order; (b) CSIRTMalta shall have access to an appropriate, secure and resilient communication and information infrastructure at national level. PART III– NATIONAL FRAMEWORK ON THE SECURITY
NETWORK AND INFORMATION SYSTEMS 8. The CIIP Unit in collaboration with other entities and stakeholders, shall adopt a national strategy on the security
network and information systems defining the strategic objectives and appropriate policy and regulatory measures with a view to achieving and maintaining a high level
security
network and information systems and covering at least the sectors referred to in the Second Schedule and the services referred to in the Third Schedule. The national strategy on the security
network and information systems National Strategy on the security
network and information systems. 8 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS shall address, in particular, the following issues: (a) the objectives and priorities
the national strategy on the security
network and information systems; (b) a governance framework to achieve the objectives and priorities
the national strategy on the security
network and information systems, including roles and responsibilities
the government bodies and the other relevant actors; (c) the identification
measures relating to preparedness, response and recovery, including cooperation between the public and private sectors; (d) an indication
the education, awareness-raising and training programmes relating to the national strategy on the security
network and information systems; (e) an indication
the research and development plans relating to the national strategy on the security
network and information systems; (
the various actors involved in the implementation
the national strategy on the security
network and information systems. PART IV – SECURITY
NETWORK AND INFORMATION SYSTEMS
OPERATORS
ESSENTIAL SERVICE Identification
operators
essential services. 9.
essential services within Malta.
essential services pursuant to sub-article
critical societal, economic activities or both; (b) the provision
that service depends on network and information systems; and (c) an incident would have significant disruptive effects on the provision
that service.
sub-article
the services referred to in paragraph (a)
sub-article MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35
essential services in Malta shall within twenty
essential services it provides.
essential services whether it has been designated as an operator
essential services pursuant to this article within reasonable time.
essential services shall comply with the designation notification referred to in sub-article
identified operators
essential services. 10.
a disruptive effect as referred to in article 9
users relying on the service provided by the entity concerned; (b) the dependency
other sectors referred to in the Second Schedule on the service provided by that entity; (c) the impact that incidents could have, in terms
degree and duration, on economic and societal activities or public safety; (d) the market share
that entity; (
the entity for maintaining a sufficient level
the service, taking into account the availability
alternative means for the provision
that service; (g) the dependency
a critical infrastructure, critical information infrastructure, or both, on the service provided by that entity.
SECURITY
NETWORK AND INFORMATION SYSTEMS significant disruptive effect, the CIIP Unit shall also, where appropriate, take into account sector-specific factors. Security requirements and incident notification. 11.
essential services: (a) take appropriate and proportionate technical and organisational measures to manage the risks posed to the security
network and information systems which they use in their operations. Having regard to the state
the art, those measures shall ensure a level
security
network and information systems appropriate to the risk posed; (b) take appropriate measures to prevent and minimise the impact
incidents affecting the security
the network and information systems used for the provision
such essential services, with a view to ensuring the continuity
those services; and (c) appoint a security liaison
ficer who shall have the necessary expertise and who shall: (i) facilitate the development, implementation, maintenance and review
an operator
essential services preparedness, processes and solutions; (ii) ensure that an operator
essentials services conducts and maintains appropriate risk assessments; (iii) ensure that the operator
essential services maintains and exercises an operator security plan; and (iv) act as the point
contact for security related issues for ensuring the fulfilment
the obligations laid down in this order between the operator
essential services and the Critical Information Infrastructure Protection (CIIP) Unit.
essential services shall notify the CIIP Unit, without undue delay,
incidents having a significant impact on the continuity
the essential services they provide. Notifications shall include information enabling the CIIP Unit to determine, any local or cross-border impact
the incident. Notification shall not make the notifying party subject to increased liability.
the impact
an incident, the following parameters in particular shall be taken into account: (a) the number
users affected by the disruption
MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 essential service; (b) the duration
the incident; (
essential (e) the dependency
a critical infrastructure, critical information infrastructure, or both, on the disruption
essential services.
the information provided in the notification by the operator
essential services, the CIIP Unit shall, inform the other affected Member States if the incident has a significant impact on the continuity
essential services in that Member State. In so doing, the CIIP Unit, in accordance with law, shall preserve the security and commercial interests
the operator
essential services, as well as the confidentiality
the information provided in its notification. Where the circumstances allow, the CIIP Unit shall provide the notifying operator
essential services with relevant information regarding the follow-up
its notification, such as information that could support the effective incident handling. The CIIP Unit shall forward notifications as referred to in the first paragraph to single points
contact
other affected Member States.
essential services provides a service to an undertaking providing electronic communications networks and, or services in terms
the Electronic Communications (Regulation) Act, any security breach affecting such operator
essential services shall also be notified by the relevant CSIRT to the Malta Communications Authority: Provided that in this context, in exercising their regulatory oversight, the CIIP Unit and the Malta Communications Authority shall consult each other and each shall give due consideration to any advice that the other may give.
essential services, the CIIP Unit may inform the public about individual incidents, where public awareness is necessary in order to prevent an incident or to deal with an ongoing incident.
essential services which fails to comply with the obligations
this article shall be liable to an administrative Cap. 399. 11 12 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS fine in accordance with the procedure under article 19. Implementation and enforcement. 12.
operators
essential services with their obligations under article 11 and the effects thereof on the security
network and information systems.
the CIIP Unit, operators
essential services shall without undue delay provide: (a) the information necessary to assess the security
their network and information systems, including documented security policies; (b) evidence
the effective implementation
security policies, such as the results
a security audit carried out by the CIIP Unit or a qualified auditor and, in the latter case to make the results thereof, including the underlying evidence, available to the CIIP Unit. When requesting such information, the CIIP Unit shall state the purpose
the request and specify what information is needed.
information, evidence or results
security audits referred to in sub-article
essential service to remedy the deficiencies identified.
NETWORK AND INFORMATION SYSTEMS
DIGITAL SERVICE PROVIDERS Security requirements and incident notification. 13.
network and information systems which they use in the context
fering services within Malta referred to in the Third Schedule. Having regard to the state
the art, those measures shall ensure a level
security
network and information systems appropriate to the risk posed, and shall take into account the following elements: (a) the security
systems and facilities; (
SECURITY
NETWORK AND INFORMATION SYSTEMS (e) [ S.L. 460.35 compliance with international standards.
incidents affecting the security
their network and information systems on the services referred to in the Third Schedule that are
fered within Malta, with a view to ensuring the continuity
those services.
any incident having a substantial impact on the provision
a service as referenced in the Third Schedule that they
fer within Malta. Notifications shall include information to enable the CIIP Unit to determine the significance
any local and crossborder impact. Notification shall not make the notifying party subject to increased liability.
an incident is substantial, the following parameters in particular shall be taken into account: (a) the number
users affected by the incident, in particular users relying on the service for the provision
their own services; (b) the duration
the incident; (
the disruption
the functioning
the service; (e) activities; the extent
the impact on economic and societal (f) the importance
the entity for maintaining a sufficient level
the service, taking into account the availability
alternative means for the provision
that service; (g) the dependency
a critical infrastructure, critical information infrastructure, or both, on the service provided by that entity. The obligation to notify an incident shall only apply where the digital service provider has access to the information needed to assess the impact
an incident against the parameters referred to in the first paragraph.
essential services relies on a thirdparty digital service provider for the provision
a service which is 13 14 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS essential for the maintenance
critical societal and economic activities, any significant impact on the continuity
the essential services due to an incident affecting the digital service provider shall be notified in writing and without undue delay by that operator.
the other affected Member States. In so doing, the CIIP Unit shall, in accordance with the law, preserve the digital service provider’s security and commercial interests as well as the confidentiality
the information provided.
the incident is otherwise in the public interest.
an administrative fine in accordance with the procedure under article 19. Implementation and enforcement. 14.
another Member State where the service is provided by the digital service provider itself.
sub-article
their network and information systems, including documented security policies; (b) remedy any failure to meet the requirements laid down in article 13.
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 15 (
other Member States as necessary. Such assistance and cooperation may cover information exchanges between the CIIP Unit and other Member State competent authorities concerned and requests to take supervisory measures referred to in sub-article
the Electronic Communications (Regulation) Act, any security breach affecting such digital service provider shall also be notified by the relevant CSIRT to the Malta Communications Authority: Malta Communications Authority. Cap. 399. Provided that in this context, in exercising their regulatory oversight, the CIIP Unit and the Malta Communications Authority shall consult each other and each shall give due consideration to any advice that the other may give. 16.
this order, a digital service provider shall be deemed to be under the jurisdiction
Malta if it has its main establishment in Malta. A digital service provider shall be deemed to have its main establishment in Malta when it has its head
fice in Malta. Jurisdiction and territoriality.
fers services referred to in the Third Schedule within the Union, shall be deemed to be under the jurisdiction
Malta where its representative is established in Malta.
a representative by the digital service provider shall be without prejudice to legal actions which could be initiated against the digital service provider itself. PART VI - STANDARDISATION AND VOLUNTARY NOTIFICATION 17. In the implementation
article 11
the use
a particular type
technology, encourage the use
European or internationally accepted standards and specifications relevant to the security
network and information systems. Standardisation. 16 [ S.L. 460.35 Voluntary notification. MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS 18.
essential services and are not digital service providers may notify, on a voluntary basis, incidents having a significant impact on the continuity
the services which they provide.
mandatory notifications over voluntary notifications. Voluntary notifications shall only be processed where such processing does not constitute a disproportionate or undue burden on the CIIP Unit. Voluntary notification shall not result in the imposition upon the notifying entity
any obligations to which it would not have been subject had it not given that notification. PART VII – ENFORCEMENT AND SANCTIONS Enforcement. 19.
any undertaking which infringes any provision
this order or
any other law which the CIIP Unit is entitled to enforce, or who fails to comply with any decision given by the CIIP Unit: (a) the imposition
an administrative fine in accordance with the provisions
this article; and (b) order the cessation
any act or omission which is in breach
this order.
the measures under sub-article
the measure that may be taken and the specific reason why it may be taken, requiring it to cease or rectify its acts or omissions and, or to make its submissions thereto within such period not being less than fifteen
sub-article
the infringement impacts negatively the effective exercise by the CIIP Unit
its regulatory functions and, or warrants the immediate intervention
the CIIP Unit: Provided that where the measure is an administrative fine the undertaking concerned shall also be informed
the amount
the fine: Provided further that when issuing a warning under this sub-article, the CIIP Unit may impose such conditions as it may consider reasonable in the circumstances.
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 CIIP Unit may impose, the CIIP Unit may at its discretion desist from proceeding any further, this without prejudice to any regulatory measures that may have already been imposed.
the period mentioned in sub-article
the infringement, stating the measure being taken, and if the measure is an administrative fine, stating the amount
the fine being imposed.
sub-article
reaching a final decision, including ordering the immediate cessation
the act or omission giving cause to the infringement: Provided that the undertaking which is subject to such contemplated measures, shall, thereafter, be given a reasonable opportunity to state its view and propose any remedies: Provided further that the interim measures shall be valid for a maximum
three months, subject to extension for a further period
three months, in circumstances where enforcement procedures have not been completed.
the time limit for appeal therefrom, upon the service
a copy thereof by means
a judicial act on the undertaking indicated in the notice, constitute an executive title for all effects and purposes
Book Second
the Code
Organization and Civil Procedure: Provided that if the undertaking against which the notice has been issued, files an appeal before the Tribunal within the twenty
its appeal requests the Tribunal to suspend the effects
the notice, then the CIIP Unit shall desist from issuing a judicial act as referred to in this sub-article until such time as the request for suspension has been determined, withdrawn or otherwise dealt with: Provided further that the Tribunal shall determine any requests for suspension referred to in this sub-article expeditiously. Before determining any such request the Tribunal shall give the CIIP Unit a reasonable opportunity to reply and make its submissions.
a decision
the CIIP Unit to which an appeal relates shall not, except where the Tribunal so orders, be Cap. 12. 17 18 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS suspended in consequence
the bringing
the appeal. Quantum
an administrative fine. 20.
not less than one thousand euro (€1000) and not more than one hundred thousand euro (€100,000) for each violation and one hundred euro (€100) for each day during which such violation persists, which fine shall be determined and imposed by the CIIP Unit, in accordance with the procedure under article 19: Provided that any daily fine imposed may be backdated to the date
the commission or commencement
the infringement.
this order other than those listed under sub-article
not less than five hundred euro (€500) and not more than fifty thousand euro ((€50,000) for each violation and fifty euro (€50) for each day during which such violation persists, which fine shall be determined and imposed by the CIIP Unit, in accordance with the procedure under article 19: Provided that any daily fine imposed may be backdated to the date
the commission or commencement
the infringement.
an administrative fine, regard shall be had in particular to the nature and extent
the infringement, its duration and the impact on critical societal and economic activities. PART VIII ADMINISTRATIVE REVIEW TRIBUNAL Administrative Review Tribunal. 21.
the CIIP Unit as provided in this order or in any law. MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35
the Administrative Justice Act, in so far as they apply to the Administrative Review Tribunal, shall apply to any proceedings before the said Tribunal and the words ‘public administration’ in the said enactment shall be construed as a reference to the CIIP Unit. Cap. 490. 22.
the CIIP Unit shall be made by application and shall be filed with the Secretary
the Tribunal within twenty
the appeal, and may in whole or in part, confirm or annul the decision appealed from, giving in writing the reasons for its decision and shall cause such decision to be made public and communicated to the parties to the appeal. Decisions
the Tribunal. 20 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS FIRST SCHEDULE REQUIREMENTS AND TASKS
COMPUTER SECURITY INCIDENT RESPONSE TEAMS (CSIRTs) The requirements and tasks
CSIRTs shall be adequately and clearly defined and supported by national policy and, or regulation. Such requirements and tasks shall include the following:
availability
their communications services by avoiding single points
failure and shall have several means for being contacted and for contacting others at all times. Furthermore, the communication channels shall be clearly specified and well known to the constituency and cooperative partners. (
ficers (CSIROs) to ensure availability at all times. (iii) CSIRTs shall rely on an infrastructure the continuity
which is ensured. To that end, redundant systems and backup working space shall be available. (d) CSIRTs shall have the possibility to participate, where they wish to do so, in local, international cooperation networks or both.
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 (ii) providing early warning, alerts, announcements and dissemination
information to relevant stakeholders about risks and incidents; (iii) Coordinating and responding to incidents providing the necessary support and advice to constituents; (
common or standardised practices for: (
assets, systems, or (ii) providing early warning, alerts, announcements and dissemination
information to relevant stakeholders about risks and incidents; (iii) responding to incidents; (iv) providing dynamic risk analysis and situational awareness. and incident 21 22 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 SECOND SCHEDULE TYPES
ENTITIES FOR THE PURPOSES
THE INTERPRETATION
"OPERATOR
ESSENTIAL SERVICES" UNDER ARTICLE 2 Sector Subsector Type
entity MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS 1. Energy (a) Electricity [ S.L. 460.35 Electricity undertakings as defined in point
Directive 2009/72/EC
the European Parliament and
the Council
‘supply’ as defined in point
that Directive Distribution system operators as defined in point
Directive 2009/72/EC Transmission system operators as defined in point
Directive 2009/72/EC (b) Oil Operators
oil transmission pipelines Operators
oil production, refining and treatment facilities, storage and transmission (c) Gas Supply undertakings as defined in point
Directive 2009/73/EC
the European Parliament and
the Council
Directive 2009/73/EC Transmission system operators as defined in point
Directive 2009/73/EC Storage system operators as defined in point
Directive 2009/73/EC LNG system operators as defined in point
Directive 2009/73/EC Natural gas undertakings as defined in point
Directive 2009/ 73/EC Operators
natural gas refining and treatment facilities 23 24 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS 2. Transport (a) Air transport Air carriers as defined in point
Regulation (EC) No 300/ 2008
the European Parliament and
the Council
Directive 2009/ 12/EC
the European Parliament and
the Council
that Directive, including the core airports listed in point 2
Annex II to Regulation (EU) No 1315/2013
the European Parliament and
the Council
Regulation (EC) No 549/ 2004
the European Parliament and
the Council
Directive 2012/ 34/EU
the European Parliament and
the Council
Directive 2012/ 34/EU, including operators
service facilities as defined in point
Directive 2012/34/EU (c) Water transport Inland, sea and coastal passenger and freight water transport companies, as defined for maritime transport in Annex I to Regulation (EC) No 725/2004
the European Parliament and
the Council
ports as defined in point
Directive 2005/ 65/EC
the European Parliament and
the Council
Regulation (EC) No 725/ 2004, and entities operating works and equipment contained within ports Operators
vessel traffic services as defined in point (o)
Directive 2002/59/EC
the European Parliament and
the Council
SECURITY
NETWORK AND INFORMATION SYSTEMS (d) Road transport [ S.L. 460.35 Road authorities as defined in point
Commission Delegated Regulation (EU) 2015/962
Intelligent Transport Systems as defined in point
Directive 2010/40/EU
the European Parliament and
the Council
Regulation (EU) No 575/ 2013
the European Parliament and
the Council
trading venues as defined in point
Directive 2014/65/EU
the European Parliament and
the Council
Regulation (EU) No 648/2012
the European Parliament and
the Council
Directive 2011/24/EU
the European Parliament and
the Council
water intended for human consumption as defined in point
Council Directive 98/83/EC
water for human consumption is only part
their general activity
distributing other commodities and goods which are not considered essential services 7.Digital Infrastructure IXPs DNS service providers TLD name registries 8. Public Administration
the European Parliament and
the Council
13 July 2009 concerning common rules for the internal market in electricity and repealing Directive 2003/54/EC (OJ L 211, 14.8.2009, p. 55). Directive 2009/73/EC
the European Parliament and
the Council
13 July 2009 concerning common rules for the internal market in natural gas and repealing Directive 2003/55/EC (OJ L 211, 14.8.2009, p. 94). 25 26 MEASURES FOR HIGH COMMON LEVEL
SECURITY
NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35
the European Parliament and
the Council
11 March 2008 on common rules in the field
civil aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 9.4.2008, p. 72). Directive 2009/12/EC
the European Parliament and
the Council
11 March 2009 on airport charges (OJ L 70, 14.3.2009, p. 11). Regulation (EU) No 1315/2013
the European Parliament and
the Council
11 December 2013 on Union guidelines for the development
the trans–European transport network and repealing Decision No 661/2010/EU (OJ L 348, 20.12.2013, p. 1). Regulation (EC) No 549/2004
the European Parliament and
the Council
10 March 2004 laying down the framework for the creation
the single European sky (the framework Regulation) (OJ L 96, 31.3.2004, p. 1). Directive 2012/34/EU
the European Parliament and
the Council
21 November 2012 establishing a single European railway area (OJ L 343, 14.12.2012, p. 32). Regulation (EC) No 725/2004
the European Parliament and
the Council
31 March 2004 on enhancing ship and port facility security (OJ L 129, 29.4.2004, p. 6). Directive 2005/65/EC
the European Parliament and
the Council
26 October 2005 on enhancing port security (OJ L 310, 25.11.2005, p. 28). Directive 2002/59/EC
the European Parliament and
the Council
27 June 2002 establishing a Community vessel traffic monitoring and information system and repealing Council Directive 93/75/EEC (OJ L 208, 5.8.2002, p. 10). Commission Delegated Regulation (EU) 2015/962
18 December 2014 supplementing Directive 2010/40/EU
the European Parliament and
the Council with regard to the provision
EU–wide real–time traffic information services (OJ L 157, 23.6.2015, p. 21). Directive 2010/40/EU
the European Parliament and
the Council
7 July 2010 on the framework for the deployment
Intelligent Transport Systems in the field
road transport and for interfaces with other modes
transport (OJ L 207, 6.8.2010, p. 1). Regulation (EU) No 575/2013
the European Parliament and
the Council
26 June 2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1). Directive 2014/65/EU
the European Parliament and
the Council
15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU (OJ L 173, 12.6.2014, p. 349). Regulation (EU) No 648/2012
the European Parliament and
the Council
4 July 2012 on OTC derivatives, central counterparties and trade repositories (OJ L 201, 27.7.2012, p. 1). Directive 2011/24/EU
the European Parliament and
the Council
9 March 2011 on the application
patients’ rights in cross–border healthcare (OJ L 88, 4.4.2011, p. 45). Council Directive 98/83/EC
3 November 1998 on the quality
water intended for human consumption (OJ L 330, 5.12.1998, p. 32).
DIGITAL SERVICES FOR THE PURPOSES
THE INTERPRETATION
"DIGITAL SERVICE" UNDER ARTICLE 2
AI explanation based on the official legal text. Indicative, not a substitute for legal advice.