← Malta

L.S. 460.35(R) Ordni dwar Miżuri għal Livell Għoli Komuni ta’ Sigurtà tan-Netwerks u tas-Sistemi tal-Informazzjoni

Obsah (5)Article 4Article 2Article 13aArticle 19Article 3

MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 1 SUBSIDIARY LEGISLATION 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS ORDER* 6th July, 2018 LEGAL NOTICE 216

2018, as amended by Legal Notice 335

2018 and 307

2024. PART I - PRELIMINARY 1.

(1)The title

this order is Measures for High Common Level

Security

Network and Information Systems Order. Citation and scope.

(2)This order transposes Directive (EU) 2016/1148

the European Parliament and

the Council

6 July 2016 concerning measures for a high common level

security

network and information systems across the Union. 2. In this order unless the context otherwise requires: "autonomous CSIRT" means a self-organised CSIRT which provides a monitoring function

CSIRT services and alerts to its own business or other agencies, operators

essential services or digital service providers; Interpretation. Amended by: L.N. 307

2024. "CIIP Unit" means the Critical Information Infrastructure Protection Unit as established under article 5

(1); "cloud computing service" means a digital service that enables access to a scalable and elastic pool

shareable computing resources; "consumer" means any natural person who is acting for purposes which are outside his trade, business, craft or profession; "critical information infrastructure" or "CII" means an information and communication technology asset, system, network or part thereof which is essential for the maintenance

vital societal functions, health, safety, security, economic or social well-being

people, and the disruption or destruction

which would have a significant impact in Malta as a result

the failure to maintain those functions; "critical infrastructure" or "CI" has the same meaning assigned to it by article 2

the Critical Infrastructures and European Critical Infrastructures (Identification, Designation and Protection) Order; *These regulations have been repealed by Legal Notice 71

  1.   S.L.
  2. 2 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS "CSIRT" means computer security incident response team;   Cap. 586. "Data Protection Commissioner" means the Information and Data Protection Commissioner as appointed under article 11

the Data Protection Act.    S.L. 460.24. "Department" means the Critical Infrastructure Protection Department established by article 3

the Critical Infrastructures and European Critical Infrastructures (Identification, Designation and Protection) Order;  S.L. 419.06. "digital service" means a service within the meaning

regulation 2

the Notification Procedure Regulations which is

a type listed in the Third Schedule; "DNS service provider" means an entity which provides DNS services on the internet; "digital service provider" means any legal person that provides a digital service; "domain name system" or "DNS" means a hierarchical distributed naming system in a network which refers queries for domain names; "incident" means any event having an effect on the security

network and information systems; "incident handling" means all procedures supporting the detection, analysis and containment

an incident and the response thereto; "internet exchange point" or "IXP" means a network facility which enables the interconnection

more than two independent autonomous systems, primarily for the purpose

facilitating the exchange

internet traffic; an IXP provides interconnection only for autonomous systems; an IXP does not require the internet traffic passing between any pair

participating autonomous systems to pass through any third autonomous system, nor does it alter or otherwise interfere with such traffic;  Cap. 418. "Malta Communications Authority" means the authority established under article 3

the Malta Communications Authority Act; "Member States" means the Member States

the European Union; "Minister" means the Minister responsible for the protection

critical infrastructure and critical information infrastructure protection; MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 "national strategy on the security

network and information systems" means a framework providing strategic objectives and priorities on the security

network and information systems at national level; "network and information system" means: (a) an electronic communications network within the meaning

article 2

the Electronic Communications (Regulation) Act; (b) any device or group

interconnected or related devices, one or more

which, pursuant to a program, perform automatic processing

digital data; or (

  1. c)digital data stored, processed, retrieved or transmitted by elements covered under paragraphs (
  2. a)and (
  3. b)for the purposes

their operation, use, protection and maintenance. "online marketplace" means a digital service that allows consumers, traders or both as respectively defined in paragraph (a) and in paragraph (b)

Article 4

(1)

Directive 2013/11/EU

the European Parliament and

the Council to conclude online sales or services contracts with traders either on the online marketplace’s website or on a trader's website that uses computing services provided by the online marketplace; "online search engine" means a digital service that allows users to perform searches

, in principle, all websites or websites in a particular language on the basis

a query on any subject in the form

a keyword, phrase or other input, and returns links in which information related to the requested content can be found; "operator

essential services" means a public or private entity

a type referred to in the Second Schedule, which meets the criteria laid down in article 9

(2); "operator security plan" or "business continuity management" is the overall procedure identifying the assets, systems, networks or part thereof within critical information infrastructures, operator

essential services and, or digital service providers, identifying the security solutions and technical measures that exist or are being implemented for their protection and the identification, selection and prioritization

counter measures and procedures; "representative" means any natural or legal person established in the Union explicitly designated to act on behalf

a digital service provider not established in the Union, which may be addressed by a national competent authority or a CSIRT instead

the digital service provider with regard to the obligations

that digital service provider  Cap. 399. 3 4 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS under this order; "risk" means any reasonably identifiable circumstance or event having a potential effect on the security

network and information systems and leading to uncertainty on the objectives

an asset, system, network or part thereof. An effect is a deviation from the expected objectives, objectives may have different aspects and may apply at different levels, positive or negative. Objectives can have different aspects (such as financial, health and safety, and environmental goals) and can apply at different levels (such as strategic, organization-wide, project, product and process). Risk is

ten characterized by reference to potential events and consequences, or a combination

these. Risk is

ten expressed in terms

a combination

the consequences

an event, including changes in circumstances, and the associated likelihood

occurrence; "risk assessment" is the overall process

risk identification, risk analysis and risk evaluation, incorporating the identification

risk sources, events, their causes and their potential consequences, comprehending the nature

risk and determining the level

risk, with the ultimate objective

comparing the results

the risk analysis with the risk criteria in order to determine whether the risk and, or its magnitude is acceptable or tolerable; "security

network and information systems" means the ability

network and information systems to resist, at a given level

confidence, any action that compromises the availability, authenticity, integrity or confidentiality

stored or transmitted or processed data or the related services

fered by, or accessible via those network and information systems; "standard" means a standard within the meaning

paragraph

(1)

Article 2

Regulation (EU) No 1025/2012

the European Parliament and

the Council; "specification" means a technical specification within the meaning

paragraph

(4)

Article 2

Regulation (EU) No 1025/ 2012

the European Parliament and

the Council; "top-level domain name registry" means an entity which administers and operates the registration

internet domain names under a specific top-level domain; "trader" means any natural persons, or any legal person irrespective

whether privately or publicly owned, who is acting, including through any person acting in his name or on his behalf, for purposes relating to his trade, business, craft or profession;  Cap. 460. "Treaty" shall have the same meaning as in article 2

the European Union Act. MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 3.

(1)The security and notification requirements

this order shall not apply to undertakings which are subject to the requirements

Article 13a

and 13b

Directive 2002/21/EC

the European Parliament and

the Council, or to trust service providers which are subject to requirements

Article 19

Regulation (EU) No 910/2014

the European Parliament and

the Council. Applicability.

(2)This order applies without prejudice to the Critical Infrastructures and European Critical Infrastructures (Identification, Designation and Protection) Order and Directives 2011/93/EU and 2013/40/EU

the Europe Parliament and

the Council.  S.L. 460.24. 5

(3)Without prejudice to Article 346 TFEU, information that is confidential pursuant to law, such as rules on business confidentiality, shall be exchanged with the European Commission and relevant authorities only where such exchange is necessary for the application

this order. The information exchanged shall be limited to that which is relevant and proportionate to the purpose

such exchange. Such exchange

information shall preserve the confidentiality

that information and protect the security and commercial interests

operators

essential services and digital service providers.

(4)This order is without prejudice to the actions taken to safeguard essential State functions, in particular to safeguard national security, including actions protecting information the disclosure

which is contrary to the essential interests

the security

Malta, and to maintain law and order, in particular to allow for the investigation, detection and prosecution

criminal

fences.

(5)Where a sector-specific law requires operators

essential services or digital service providers either to ensure the security

their network and information systems or to notify incidents, provided that such requirements are at least equivalent in effect to the obligations laid down in this order, those provisions

that sector-specific law shall apply. 4. Processing

personal data pursuant to this order shall be carried out in accordance with the Data Protection Act and Regulation 2016/679/EU

the European Parliament and

the Council. Processing

personal data.  Cap. 586. PART II – CRITICAL INFORMATION INFRASTRUCTURE PROTECTION UNIT, CSIRTMalta and CSIRTs 5.

(1)There shall be a Critical Information Infrastructure Protection Unit within the Department, herein referred to as the ‘CIIP Unit’.
(2)The CIIP Unit shall be responsible for monitoring the application

this order and shall be the national competent authority The CIIP Unit. Amended by: L.N. 307

2024. 6 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS covering the sectors referred to in the Second Schedule and the services referred to in the Third Schedule.

(3)The CIIP Unit shall be responsible for: (a) establishing the criteria for the identification and designation

operators

essential services and digital service providers; (b) identifying and designating operators

essential services within Malta pursuant to article 9; (c) identifying the services provided by operators

essential services and digital service providers; (d) ensuring that a risk assessment is carried out by operators

essential services and digital service providers; (e) ensuring that operators

essential services and digital service providers draw up and maintain an operator security plan; (f) instigating simulated runs

operator security plans by operators

essential services and digital service providers. (g) without prejudice to article 3

(3), building partnerships with operators

Critical Information Infrastructures (CIIs) for information sharing; (h) maintaining a register

CSIRTs, operators

essential services and digital service providers providing services in Malta; (

  1. i)exercising a liaison function to ensure cross-border cooperation with the relevant authorities in other Member States and with the Cooperation Group and the CSIRTs network; (
  2. j)adopting a national strategy on the security

network and information systems pursuant to article 8; (k) monitoring security measures taken by operators

essential services pursuant to article 11.

(4)The CIIP Unit shall also perform such related and consequential duties as the Minister may delegate from time to time.
(5)The CIIP Unit shall, whenever appropriate and in accordance with law, consult and cooperate with the relevant national law enforcement authorities and the Data Protection Commissioner. MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 6.

(1)There shall be a National CSIRT within the CIIP Unit, to be known as CSIRTMalta which shall comply with the requirements and tasks set out in paragraphs 1 and 2

the First Schedule respectively, covering at least the sectors referred to in the Second Schedule and the services referred to in the Third Schedule. CSIRTMalta shall be responsible for risk and incident handling in accordance with a well-defined process. 7 CSIRTs. Amended by: L.N. 307

2024.

(2)CSIRT Malta shall inform the CIIP Unit about incident notifications submitted pursuant to this order.
(3)Operators

an essential service shall receive CSIRT monitoring services from any

the following CSIRTs which shall comply with the requirements and tasks set out in paragraphs 1 and 3 respectively

the First Schedule: (a) an internal CSIRT providing CSIRT monitoring services and alerts within operators

essential services; (b) an autonomous CSIRT may be contracted to perform CSIRT monitoring services.

(4)Any operator

essential services which fails to establish a CSIRT as provided for in sub-article

(3)shall be liable to an administrative fine in accordance with the procedure under article 19.
(5)The Department and CIIP Unit shall cooperate for the better fulfilment

the obligations laid down in this order. 7. The Minister shall ensure that: Resources. (a) the CIIP Unit and CSIRTMalta have adequate resources to carry out in an effective and efficient manner, the tasks assigned to them and thereby to fulfil the objectives

this order; (b) CSIRTMalta shall have access to an appropriate, secure and resilient communication and information infrastructure at national level. PART III– NATIONAL FRAMEWORK ON THE SECURITY

NETWORK AND INFORMATION SYSTEMS 8. The CIIP Unit in collaboration with other entities and stakeholders, shall adopt a national strategy on the security

network and information systems defining the strategic objectives and appropriate policy and regulatory measures with a view to achieving and maintaining a high level

security

network and information systems and covering at least the sectors referred to in the Second Schedule and the services referred to in the Third Schedule. The national strategy on the security

network and information systems National Strategy on the security

network and information systems. 8 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS shall address, in particular, the following issues: (a) the objectives and priorities

the national strategy on the security

network and information systems; (b) a governance framework to achieve the objectives and priorities

the national strategy on the security

network and information systems, including roles and responsibilities

the government bodies and the other relevant actors; (c) the identification

measures relating to preparedness, response and recovery, including cooperation between the public and private sectors; (d) an indication

the education, awareness-raising and training programmes relating to the national strategy on the security

network and information systems; (e) an indication

the research and development plans relating to the national strategy on the security

network and information systems; (

  1. f)a risk assessment plan to identify risks; (
  2. g)a list

the various actors involved in the implementation

the national strategy on the security

network and information systems. PART IV – SECURITY

NETWORK AND INFORMATION SYSTEMS

OPERATORS

ESSENTIAL SERVICE Identification

operators

essential services. 9.

(1)The CIIP Unit shall for each sector and subsector referred to in the Second Schedule identify operators

essential services within Malta.

(2)In identifying operators

essential services pursuant to sub-article

(1)the CIIP unit shall take into account that: (a) the entity provides a service which is essential for the maintenance

critical societal, economic activities or both; (b) the provision

that service depends on network and information systems; and (c) an incident would have significant disruptive effects on the provision

that service.

(3)For the purposes

sub-article

(1), the CIIP Unit shall establish a list

the services referred to in paragraph (a)

sub-article MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35

(2).
(4)Upon a request in writing by the CIIP Unit, a potential operator

essential services in Malta shall within twenty

(20)days provide a list

essential services it provides.

(5)The CIIP Unit shall review the list provided pursuant to sub-article
(4), and inform the potential operator

essential services whether it has been designated as an operator

essential services pursuant to this article within reasonable time.

(6)A designated operator

essential services shall comply with the designation notification referred to in sub-article

(5)within a stipulated time as may be directed by the CIIP Unit.
(7)Any undertaking which fails to comply with the CIIP Unit’s request pursuant to sub-article
(4)shall be liable to an administrative fine in accordance with the procedure under article 19.
(8)The CIIP Unit shall on a regular basis, and at least every two years after 9 May 2018, review and, where appropriate, update the list

identified operators

essential services. 10.

(1)When determining the significance

a disruptive effect as referred to in article 9

(2)(c), the CIIP Unit shall take into account at least the following cross-sectoral factors: (a) the number

users relying on the service provided by the entity concerned; (b) the dependency

other sectors referred to in the Second Schedule on the service provided by that entity; (c) the impact that incidents could have, in terms

degree and duration, on economic and societal activities or public safety; (d) the market share

that entity; (

  1. e)the geographic spread with regard to the area that could be affected by an incident; (
  2. f)the importance

the entity for maintaining a sufficient level

the service, taking into account the availability

alternative means for the provision

that service; (g) the dependency

a critical infrastructure, critical information infrastructure, or both, on the service provided by that entity.

(2)In order to determine whether an incident would have a Significant disruptive effect. 9 10 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS significant disruptive effect, the CIIP Unit shall also, where appropriate, take into account sector-specific factors. Security requirements and incident notification. 11.

(1)The CIIP Unit shall ensure that operators

essential services: (a) take appropriate and proportionate technical and organisational measures to manage the risks posed to the security

network and information systems which they use in their operations. Having regard to the state

the art, those measures shall ensure a level

security

network and information systems appropriate to the risk posed; (b) take appropriate measures to prevent and minimise the impact

incidents affecting the security

the network and information systems used for the provision

such essential services, with a view to ensuring the continuity

those services; and (c) appoint a security liaison

ficer who shall have the necessary expertise and who shall: (i) facilitate the development, implementation, maintenance and review

an operator

essential services preparedness, processes and solutions; (ii) ensure that an operator

essentials services conducts and maintains appropriate risk assessments; (iii) ensure that the operator

essential services maintains and exercises an operator security plan; and (iv) act as the point

contact for security related issues for ensuring the fulfilment

the obligations laid down in this order between the operator

essential services and the Critical Information Infrastructure Protection (CIIP) Unit.

(2)Operators

essential services shall notify the CIIP Unit, without undue delay,

incidents having a significant impact on the continuity

the essential services they provide. Notifications shall include information enabling the CIIP Unit to determine, any local or cross-border impact

the incident. Notification shall not make the notifying party subject to increased liability.

(3)In order to determine the significance

the impact

an incident, the following parameters in particular shall be taken into account: (a) the number

users affected by the disruption

MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 essential service; (b) the duration

the incident; (

  1. c)the geographical spread with regard to the area affected by the incident; (
  2. d)service; the sectors affected by the disruption

essential (e) the dependency

a critical infrastructure, critical information infrastructure, or both, on the disruption

essential services.

(4)On the basis

the information provided in the notification by the operator

essential services, the CIIP Unit shall, inform the other affected Member States if the incident has a significant impact on the continuity

essential services in that Member State. In so doing, the CIIP Unit, in accordance with law, shall preserve the security and commercial interests

the operator

essential services, as well as the confidentiality

the information provided in its notification. Where the circumstances allow, the CIIP Unit shall provide the notifying operator

essential services with relevant information regarding the follow-up

its notification, such as information that could support the effective incident handling. The CIIP Unit shall forward notifications as referred to in the first paragraph to single points

contact

other affected Member States.

(5)Where a designated operator

essential services provides a service to an undertaking providing electronic communications networks and, or services in terms

the Electronic Communications (Regulation) Act, any security breach affecting such operator

essential services shall also be notified by the relevant CSIRT to the Malta Communications Authority: Provided that in this context, in exercising their regulatory oversight, the CIIP Unit and the Malta Communications Authority shall consult each other and each shall give due consideration to any advice that the other may give.

(6)After consulting the notifying operator

essential services, the CIIP Unit may inform the public about individual incidents, where public awareness is necessary in order to prevent an incident or to deal with an ongoing incident.

(7)Any operator

essential services which fails to comply with the obligations

this article shall be liable to an administrative    Cap. 399. 11 12 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS fine in accordance with the procedure under article 19. Implementation and enforcement. 12.

(1)The Minister shall ensure that the CIIP Unit has the necessary powers and means to assess the compliance

operators

essential services with their obligations under article 11 and the effects thereof on the security

network and information systems.

(2)Upon the request

the CIIP Unit, operators

essential services shall without undue delay provide: (a) the information necessary to assess the security

their network and information systems, including documented security policies; (b) evidence

the effective implementation

security policies, such as the results

a security audit carried out by the CIIP Unit or a qualified auditor and, in the latter case to make the results thereof, including the underlying evidence, available to the CIIP Unit. When requesting such information, the CIIP Unit shall state the purpose

the request and specify what information is needed.

(3)Following the assessment

information, evidence or results

security audits referred to in sub-article

(2), the CIIP Unit may issue binding instructions to the operators

essential service to remedy the deficiencies identified.

(4)The CIIP Unit shall work in close cooperation with the Data Protection Commissioner when addressing incidents resulting in personal data breaches. PART V – SECURITY

NETWORK AND INFORMATION SYSTEMS

DIGITAL SERVICE PROVIDERS Security requirements and incident notification. 13.

(1)Digital service providers shall identify and take appropriate and proportionate technical and organisational measures to manage the risks posed to the security

network and information systems which they use in the context

fering services within Malta referred to in the Third Schedule. Having regard to the state

the art, those measures shall ensure a level

security

network and information systems appropriate to the risk posed, and shall take into account the following elements: (a) the security

systems and facilities; (

  1. b)incident handling; (
  2. c)business continuity management; (
  3. d)monitoring, auditing and testing; MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS (e) [ S.L. 460.35 compliance with international standards.

(2)Digital service providers shall take measures to prevent and minimise the impact

incidents affecting the security

their network and information systems on the services referred to in the Third Schedule that are

fered within Malta, with a view to ensuring the continuity

those services.

(3)Digital service providers shall without undue delay, notify the CIIP Unit

any incident having a substantial impact on the provision

a service as referenced in the Third Schedule that they

fer within Malta. Notifications shall include information to enable the CIIP Unit to determine the significance

any local and crossborder impact. Notification shall not make the notifying party subject to increased liability.

(4)In order to determine whether the impact

an incident is substantial, the following parameters in particular shall be taken into account: (a) the number

users affected by the incident, in particular users relying on the service for the provision

their own services; (b) the duration

the incident; (

  1. c)the geographical spread with regard to the area affected by the incident; (
  2. d)the extent

the disruption

the functioning

the service; (e) activities; the extent

the impact on economic and societal (f) the importance

the entity for maintaining a sufficient level

the service, taking into account the availability

alternative means for the provision

that service; (g) the dependency

a critical infrastructure, critical information infrastructure, or both, on the service provided by that entity. The obligation to notify an incident shall only apply where the digital service provider has access to the information needed to assess the impact

an incident against the parameters referred to in the first paragraph.

(5)Where an operator

essential services relies on a thirdparty digital service provider for the provision

a service which is 13 14 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS essential for the maintenance

critical societal and economic activities, any significant impact on the continuity

the essential services due to an incident affecting the digital service provider shall be notified in writing and without undue delay by that operator.

(6)Where appropriate, and in particular if the incident referred to in sub-article
(3)concerns two or more Member States, the CIIP Unit shall inform the competent authority or CSIRT

the other affected Member States. In so doing, the CIIP Unit shall, in accordance with the law, preserve the digital service provider’s security and commercial interests as well as the confidentiality

the information provided.

(7)After consulting the digital service provider concerned, the CIIP Unit, where appropriate, may inform the public about individual incidents or require the digital service provider to do so, where public awareness is necessary in order to prevent an incident or to deal with an ongoing incident, or where disclosure

the incident is otherwise in the public interest.

(8)Without prejudice to article 3
(4), the CIIP Unit shall not impose any further security or notification requirements on digital service providers.
(9)Part V shall not apply to micro and small enterprises as defined in Commission Recommendation 2003/361/EC.
(10)Any digital service provider which fails to comply with the obligations set out in this article shall be liable to the imposition

an administrative fine in accordance with the procedure under article 19. Implementation and enforcement. 14.

(1)The CIIP Unit shall take action, if necessary, through ex post supervisory measures, when provided with evidence that a digital service provider does not meet the requirements laid down in article 13. Such evidence may be submitted by a competent authority

another Member State where the service is provided by the digital service provider itself.

(2)For the purposes

sub-article

(1), the CIIP Unit shall have the necessary powers and means to require digital service providers to: (a) provide the information necessary to assess the security

their network and information systems, including documented security policies; (b) remedy any failure to meet the requirements laid down in article 13.

(3)Where: MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 15 (

  1. a)a digital service provider has its main establishment or a representative in Malta, but its network and information systems is located in one or more Member States; or (
  2. b)a digital service provider has its main establishment or a representative in a Member State, but its network and information systems is located in Malta, the CIIP Unit shall cooperate and assist competent authorities

other Member States as necessary. Such assistance and cooperation may cover information exchanges between the CIIP Unit and other Member State competent authorities concerned and requests to take supervisory measures referred to in sub-article

(2). 15. Where a designated digital service provider provides a service to an undertaking providing electronic communications networks and services in terms

the Electronic Communications (Regulation) Act, any security breach affecting such digital service provider shall also be notified by the relevant CSIRT to the Malta Communications Authority: Malta Communications Authority.    Cap. 399. Provided that in this context, in exercising their regulatory oversight, the CIIP Unit and the Malta Communications Authority shall consult each other and each shall give due consideration to any advice that the other may give. 16.

(1)For the purposes

this order, a digital service provider shall be deemed to be under the jurisdiction

Malta if it has its main establishment in Malta. A digital service provider shall be deemed to have its main establishment in Malta when it has its head

fice in Malta. Jurisdiction and territoriality.

(2)A digital service provider that is not established in the Union, but

fers services referred to in the Third Schedule within the Union, shall be deemed to be under the jurisdiction

Malta where its representative is established in Malta.

(3)The designation

a representative by the digital service provider shall be without prejudice to legal actions which could be initiated against the digital service provider itself. PART VI - STANDARDISATION AND VOLUNTARY NOTIFICATION 17. In the implementation

article 11

(1)and article 13
(1)and
(2), the CIIP Unit shall, without imposing or discriminating in favour

the use

a particular type

technology, encourage the use

European or internationally accepted standards and specifications relevant to the security

network and information systems. Standardisation. 16 [ S.L. 460.35 Voluntary notification. MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS 18.

(1)Entities which have not been identified as operators

essential services and are not digital service providers may notify, on a voluntary basis, incidents having a significant impact on the continuity

the services which they provide.

(2)When processing notifications, the CIIP Unit shall act in accordance with the procedure set out in article 11 and may prioritise the processing

mandatory notifications over voluntary notifications. Voluntary notifications shall only be processed where such processing does not constitute a disproportionate or undue burden on the CIIP Unit. Voluntary notification shall not result in the imposition upon the notifying entity

any obligations to which it would not have been subject had it not given that notification. PART VII – ENFORCEMENT AND SANCTIONS Enforcement. 19.

(1)The CIIP Unit may take the following measures in respect

any undertaking which infringes any provision

this order or

any other law which the CIIP Unit is entitled to enforce, or who fails to comply with any decision given by the CIIP Unit: (a) the imposition

an administrative fine in accordance with the provisions

this article; and (b) order the cessation

any act or omission which is in breach

this order.

(2)The CIIP Unit shall, before proceeding to take any

the measures under sub-article

(1), write to the undertaking concerned, warning it

the measure that may be taken and the specific reason why it may be taken, requiring it to cease or rectify its acts or omissions and, or to make its submissions thereto within such period not being less than fifteen

(15)days which period, without prejudice to the provisions

sub-article

(4), may be abridged if the CIIP Unit considers that the continuance

the infringement impacts negatively the effective exercise by the CIIP Unit

its regulatory functions and, or warrants the immediate intervention

the CIIP Unit: Provided that where the measure is an administrative fine the undertaking concerned shall also be informed

the amount

the fine: Provided further that when issuing a warning under this sub-article, the CIIP Unit may impose such conditions as it may consider reasonable in the circumstances.

(3)If the undertaking concerned remedies the infringement within the period established by the CIIP Unit in accordance with subarticle
(2), and agrees in writing to abide with any condition that the MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 CIIP Unit may impose, the CIIP Unit may at its discretion desist from proceeding any further, this without prejudice to any regulatory measures that may have already been imposed.

(4)If after the lapse

the period mentioned in sub-article

(3), the CIIP Unit considers that the undertaking concerned has not given any valid reasons to demonstrate why no measure should be taken against it, the CIIP Unit shall notify the undertaking concerned in writing, specifying the nature

the infringement, stating the measure being taken, and if the measure is an administrative fine, stating the amount

the fine being imposed.

(5)Notwithstanding the provisions

sub-article

(2), where the CIIP Unit has prima facie evidence that the infringement represents an immediate and significant disruptive effect in Malta, the CIIP Unit may take urgent interim measures to remedy the situation in advance

reaching a final decision, including ordering the immediate cessation

the act or omission giving cause to the infringement: Provided that the undertaking which is subject to such contemplated measures, shall, thereafter, be given a reasonable opportunity to state its view and propose any remedies: Provided further that the interim measures shall be valid for a maximum

three months, subject to extension for a further period

three months, in circumstances where enforcement procedures have not been completed.

(6)The notification as referred to in sub-article
(4)shall, upon the expiry

the time limit for appeal therefrom, upon the service

a copy thereof by means

a judicial act on the undertaking indicated in the notice, constitute an executive title for all effects and purposes

Title VII

Part I

Book Second

the Code

Organization and Civil Procedure: Provided that if the undertaking against which the notice has been issued, files an appeal before the Tribunal within the twenty

(20)day period referred to under article 22, and concurrently with or before the filing

its appeal requests the Tribunal to suspend the effects

the notice, then the CIIP Unit shall desist from issuing a judicial act as referred to in this sub-article until such time as the request for suspension has been determined, withdrawn or otherwise dealt with: Provided further that the Tribunal shall determine any requests for suspension referred to in this sub-article expeditiously. Before determining any such request the Tribunal shall give the CIIP Unit a reasonable opportunity to reply and make its submissions.

(7)The effect

a decision

the CIIP Unit to which an appeal relates shall not, except where the Tribunal so orders, be       Cap. 12. 17 18 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS suspended in consequence

the bringing

the appeal. Quantum

an administrative fine. 20.

(1)An undertaking which, fails to: (
  1. a)implement appropriate and proportionate security measures pursuant to article 11 and 13; or (
  2. b)fails to cooperate with the CIIP Unit when exercising its monitoring obligations under this order, shall be liable to an administrative fine

not less than one thousand euro (€1000) and not more than one hundred thousand euro (€100,000) for each violation and one hundred euro (€100) for each day during which such violation persists, which fine shall be determined and imposed by the CIIP Unit, in accordance with the procedure under article 19: Provided that any daily fine imposed may be backdated to the date

the commission or commencement

the infringement.

(2)An undertaking which: (
  1. a)incident; fails to notify where it ought to have notified an (
  2. b)fails to comply with a lawful instruction from the CIIP Unit; or (
  3. c)fails to comply with the provisions

this order other than those listed under sub-article

(1); shall be liable to an administrative fine

not less than five hundred euro (€500) and not more than fifty thousand euro ((€50,000) for each violation and fifty euro (€50) for each day during which such violation persists, which fine shall be determined and imposed by the CIIP Unit, in accordance with the procedure under article 19: Provided that any daily fine imposed may be backdated to the date

the commission or commencement

the infringement.

(3)In determining the amount

an administrative fine, regard shall be had in particular to the nature and extent

the infringement, its duration and the impact on critical societal and economic activities. PART VIII ADMINISTRATIVE REVIEW TRIBUNAL Administrative Review Tribunal. 21.

(1)The Administrative Review Tribunal shall be competent to hear and determine appeals from decisions

the CIIP Unit as provided in this order or in any law. MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35

(2)The provisions

the Administrative Justice Act, in so far as they apply to the Administrative Review Tribunal, shall apply to any proceedings before the said Tribunal and the words ‘public administration’ in the said enactment shall be construed as a reference to the CIIP Unit. Cap. 490. 22.

(1)The right to appeal to the Tribunal shall be competent to any undertaking to which the decision is addressed. Appeals from decisions. 19
(2)An appeal from a decision

the CIIP Unit shall be made by application and shall be filed with the Secretary

the Tribunal within twenty

(20)days from the date on which the said decision has been notified. 23. In determining an appeal the Tribunal shall take into account the merits

the appeal, and may in whole or in part, confirm or annul the decision appealed from, giving in writing the reasons for its decision and shall cause such decision to be made public and communicated to the parties to the appeal. Decisions

the Tribunal. 20 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS FIRST SCHEDULE REQUIREMENTS AND TASKS

COMPUTER SECURITY INCIDENT RESPONSE TEAMS (CSIRTs) The requirements and tasks

CSIRTs shall be adequately and clearly defined and supported by national policy and, or regulation. Such requirements and tasks shall include the following:

(1)Requirements for all CSIRTs: (a) CSIRTs shall ensure a high level

availability

their communications services by avoiding single points

failure and shall have several means for being contacted and for contacting others at all times. Furthermore, the communication channels shall be clearly specified and well known to the constituency and cooperative partners. (

  1. b)CSIRTs' premises and the supporting information systems shall be located in secure sites. (
  2. c)Operator Security and Business continuity: (
  3. i)CSIRTs shall be equipped with an appropriate system for managing and routing requests, in order to facilitate handovers. (
  4. ii)CSIRTs shall be adequately staffed with computer security incident response

ficers (CSIROs) to ensure availability at all times. (iii) CSIRTs shall rely on an infrastructure the continuity

which is ensured. To that end, redundant systems and backup working space shall be available. (d) CSIRTs shall have the possibility to participate, where they wish to do so, in local, international cooperation networks or both.

(2)CSIRTMalta’s tasks: (
  1. a)following: CSIRTMalta tasks shall include at least the (
  2. i)monitoring incidents at a national level; MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 (ii) providing early warning, alerts, announcements and dissemination

information to relevant stakeholders about risks and incidents; (iii) Coordinating and responding to incidents providing the necessary support and advice to constituents; (

  1. iv)providing dynamic risk analysis and situational awareness; and incident (
  2. v)participating in the CSIRTs network and in the European Cooperation Group to ensure the effective, efficient and secure cooperation at the European level; (
  3. b)CSIRTMalta shall establish relationships with the public and private sector; cooperation (
  4. c)To facilitate cooperation, CSIRTMalta shall promote the adoption and use

common or standardised practices for: (

  1. i)incident and risk-handling procedures; (
  2. ii)incident, classification schemes.

(3)risk and information CSIRTs' tasks: (
  1. a)CSIRTs' tasks shall include at least the following: (
  2. i)networks; monitoring incidents

assets, systems, or (ii) providing early warning, alerts, announcements and dissemination

information to relevant stakeholders about risks and incidents; (iii) responding to incidents; (iv) providing dynamic risk analysis and situational awareness. and incident 21 22 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35 SECOND SCHEDULE TYPES

ENTITIES FOR THE PURPOSES

THE INTERPRETATION

"OPERATOR

ESSENTIAL SERVICES" UNDER ARTICLE 2 Sector Subsector Type

entity MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS 1. Energy (a) Electricity [ S.L. 460.35 Electricity undertakings as defined in point

(35)

Article 2

Directive 2009/72/EC

the European Parliament and

the Council

(1), which carry out the function

‘supply’ as defined in point

(19)

Article 2

that Directive Distribution system operators as defined in point

(6)

Article 2

Directive 2009/72/EC Transmission system operators as defined in point

(4)

Article 2

Directive 2009/72/EC (b) Oil Operators

oil transmission pipelines Operators

oil production, refining and treatment facilities, storage and transmission (c) Gas Supply undertakings as defined in point

(8)

Article 2

Directive 2009/73/EC

the European Parliament and

the Council

(2)Distribution system operators as defined in point
(6)

Article 2

Directive 2009/73/EC Transmission system operators as defined in point

(4)

Article 2

Directive 2009/73/EC Storage system operators as defined in point

(10)

Article 2

Directive 2009/73/EC LNG system operators as defined in point

(12)

Article 2

Directive 2009/73/EC Natural gas undertakings as defined in point

(1)

Article 2

Directive 2009/ 73/EC Operators

natural gas refining and treatment facilities 23 24 [ S.L. 460.35 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS 2. Transport (a) Air transport Air carriers as defined in point

(4)

Article 3

Regulation (EC) No 300/ 2008

the European Parliament and

the Council

(3)Airport managing bodies as defined in point
(2)

Article 2

Directive 2009/ 12/EC

the European Parliament and

the Council

(4), airports as defined in point
(1)

Article 2

that Directive, including the core airports listed in point 2

Annex II to Regulation (EU) No 1315/2013

the European Parliament and

the Council

(5), and entities operating ancillary installations contained within airports Traffic management control operators providing air traffic control (ATC) services as defined in point
(1)

Article 2

Regulation (EC) No 549/ 2004

the European Parliament and

the Council

(6)(b) Rail Transport Infrastructure managers as defined in point
(2)

Article 3

Directive 2012/ 34/EU

the European Parliament and

the Council

(7)Railway undertakings as defined in point
(1)

Article 3

Directive 2012/ 34/EU, including operators

service facilities as defined in point

(12)

Article 3

Directive 2012/34/EU (c) Water transport Inland, sea and coastal passenger and freight water transport companies, as defined for maritime transport in Annex I to Regulation (EC) No 725/2004

the European Parliament and

the Council

(8), not including the individual vessels operated by those companies Managing bodies

ports as defined in point

(1)

Article 3

Directive 2005/ 65/EC

the European Parliament and

the Council

(9), including their port facilities as defined in point
(11)

Article 2

Regulation (EC) No 725/ 2004, and entities operating works and equipment contained within ports Operators

vessel traffic services as defined in point (o)

Article 3

Directive 2002/59/EC

the European Parliament and

the Council

(10)MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS (d) Road transport [ S.L. 460.35 Road authorities as defined in point

(12)

Article 2

Commission Delegated Regulation (EU) 2015/962

(11)responsible for traffic management control Operators

Intelligent Transport Systems as defined in point

(1)

Article 4

Directive 2010/40/EU

the European Parliament and

the Council

(12)3. Banking Credit institutions as defined in point
(1)

Article 4

Regulation (EU) No 575/ 2013

the European Parliament and

the Council

(13)4. Financial market infrastructures Operators

trading venues as defined in point

(24)

Article 4

Directive 2014/65/EU

the European Parliament and

the Council

(14)Central counterparties (CCPs) as defined in point
(1)

Article 2

Regulation (EU) No 648/2012

the European Parliament and

the Council

(15)
  1. Health sector
  2. Drinking water supply and distribution Health care settings (including hospitals and private clinics) Healthcare providers as defined in point (g)

Article 3

Directive 2011/24/EU

the European Parliament and

the Council

(16)Suppliers and distributors

water intended for human consumption as defined in point

(1)(a)

Article 2

Council Directive 98/83/EC

(17)but excluding distributors for whom distribution

water for human consumption is only part

their general activity

distributing other commodities and goods which are not considered essential services 7.Digital Infrastructure IXPs DNS service providers TLD name registries 8. Public Administration

(1)
(2)Government Departments, entities, assets, systems and networks within the public service and public sector. Directive 2009/72/EC

the European Parliament and

the Council

13 July 2009 concerning common rules for the internal market in electricity and repealing Directive 2003/54/EC (OJ L 211, 14.8.2009, p. 55). Directive 2009/73/EC

the European Parliament and

the Council

13 July 2009 concerning common rules for the internal market in natural gas and repealing Directive 2003/55/EC (OJ L 211, 14.8.2009, p. 94). 25 26 MEASURES FOR HIGH COMMON LEVEL

SECURITY

NETWORK AND INFORMATION SYSTEMS [ S.L. 460.35

(3)Regulation (EC) No 300/2008

the European Parliament and

the Council

11 March 2008 on common rules in the field

civil aviation security and repealing Regulation (EC) No 2320/2002 (OJ L 97, 9.4.2008, p. 72). Directive 2009/12/EC

the European Parliament and

the Council

11 March 2009 on airport charges (OJ L 70, 14.3.2009, p. 11). Regulation (EU) No 1315/2013

the European Parliament and

the Council

11 December 2013 on Union guidelines for the development

the trans–European transport network and repealing Decision No 661/2010/EU (OJ L 348, 20.12.2013, p. 1). Regulation (EC) No 549/2004

the European Parliament and

the Council

10 March 2004 laying down the framework for the creation

the single European sky (the framework Regulation) (OJ L 96, 31.3.2004, p. 1). Directive 2012/34/EU

the European Parliament and

the Council

21 November 2012 establishing a single European railway area (OJ L 343, 14.12.2012, p. 32). Regulation (EC) No 725/2004

the European Parliament and

the Council

31 March 2004 on enhancing ship and port facility security (OJ L 129, 29.4.2004, p. 6). Directive 2005/65/EC

the European Parliament and

the Council

26 October 2005 on enhancing port security (OJ L 310, 25.11.2005, p. 28). Directive 2002/59/EC

the European Parliament and

the Council

27 June 2002 establishing a Community vessel traffic monitoring and information system and repealing Council Directive 93/75/EEC (OJ L 208, 5.8.2002, p. 10). Commission Delegated Regulation (EU) 2015/962

18 December 2014 supplementing Directive 2010/40/EU

the European Parliament and

the Council with regard to the provision

EU–wide real–time traffic information services (OJ L 157, 23.6.2015, p. 21). Directive 2010/40/EU

the European Parliament and

the Council

7 July 2010 on the framework for the deployment

Intelligent Transport Systems in the field

road transport and for interfaces with other modes

transport (OJ L 207, 6.8.2010, p. 1). Regulation (EU) No 575/2013

the European Parliament and

the Council

26 June 2013 on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1). Directive 2014/65/EU

the European Parliament and

the Council

15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU (OJ L 173, 12.6.2014, p. 349). Regulation (EU) No 648/2012

the European Parliament and

the Council

4 July 2012 on OTC derivatives, central counterparties and trade repositories (OJ L 201, 27.7.2012, p. 1). Directive 2011/24/EU

the European Parliament and

the Council

9 March 2011 on the application

patients’ rights in cross–border healthcare (OJ L 88, 4.4.2011, p. 45). Council Directive 98/83/EC

3 November 1998 on the quality

water intended for human consumption (OJ L 330, 5.12.1998, p. 32).

(4)
(5)
(6)
(7)
(8)
(9)
(10)
(11)
(12)
(13)
(14)
(15)
(16)
(17)THIRD SCHEDULE TYPES

DIGITAL SERVICES FOR THE PURPOSES

THE INTERPRETATION

"DIGITAL SERVICE" UNDER ARTICLE 2

  1. Online marketplace.
  2. Online search engine.
  3. Cloud computing service.

🔗 Għas-sors uffiċjali

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.