SlideShare a Scribd company logo
1 of 13
Cybersecurity Regulatory
Outlook in EU and Slovakia
BEST PRACTICES FROM SLOVAKIA
Rastislav Janota
Chairman
Cyber Security Committee
Security Council of the Slovak Republic
National Security Authority
CYBERSECURITY IS TOPIC FOR?
Who should take care on
Cybersecurity?
WE ALL!
Everyone is responsible for own data
and own services...
CHALLENGES DURING PROCESS
• Alignment with other regulations and their regulators
• Defining balance between minimum regulation and comprehensive regulation approach
• Creating national CSIRT network structure, accreditation of CSIRTs incl. private one’s
• Alignment with Critical Infrastructure Protection legislation
• Definitions of sectors and subsectors for OES incl. managing authorities and their duties
• Mandatory government CSIRTs for sectorial managing authorities, government outsourcing
and last-resort option
• Defining areas for future voluntary ‘win-win’ cooperation with the market instead of
mandatory duties
DIFFERENT EU REGULATIONS
• General Data Protection Regulation (GDPR) – 2016/679
– To strengthen and unify data protection for all individuals within the European Union (EU)
– Regulator – Office for Personal Data Protection of the Slovak Republic
• Payment Services Directive (PSD2) – 2015/2366
– To regulate payment services and payment service providers throughout the European
Union (EU)
– Regulator – National Bank of Slovakia
• Regulatory framework for electronic communications – Telecoms Package (2009)
– To create a common set of regulations for the telecoms industry across all 27 EU states
– Regulator –Regulatory Authority for Electronic Communication and Postal Services
• Network and Information Security Directive 2016/1148
– To force companies and organizations to protect their systems/data from cyber-attacks
– Regulator – National Security Authority
BASIC CYBERSPACE ACTIVITIES
• Cyber Crime
– Responsible Ministry of Interior (police, crime investigators), prosecutors, courts
• Cyber Defense
– Ministry of Defense
• Cyber Intelligence
– Intelligence services
• Cyber Security
– NIS transposition,
– Cybersecurity regulation
– Regulation of sectors/subsectors
– Security standards, risk management, auditing, regulation, enforcement work
– Incident reporting and handling
– National Cybersecurity Centre and National CSIRT (SK-CERT)
– Security Operation Centre
Cyber Security Committee
CYBERSECURITY GOVERNANCE IN SLOVAKIA
Parliament
National Cybersecurity Centre / SK-CERT
Security Council
Government
Managing authority
Sector/Subsector n
National Security Authority
Managing authority
Sector/Subsector 2
Managing authority
Sector/Subsector 1
CSIRT
Sector 1 and 2
CSIRT
Sector n
CSIRT
Commercial
CYBERSECURITY LAW IN SLOVAKIA
Content of law
• Definitions
• Cybersecurity governance in Slovak republic,
• National Cybersecurity Centre (and SK-CERT),
• Integrated Cybersecurity Information System,
• Duties and capacities of Operator of essential services and Digital service provider
• CSIRT units and their accreditation,
• Security requirements and incident notification and handling
• Implementation and enforcement
• Other procedures and bylaws
• Update (alignment) of Critical Infrastructure Law with Cybersecurity Law
• Definition of sectors and subsectors for OES
CYBERSECURITY LAW IN SLOVAKIA
Key duties from NIS and law
• establishes security requirements for operators of essential services and for digital service
providers
• establishes notification requirements for operators of essential services and for digital
service providers
Tools
• identification and impact criteria of the operated service
• contents of security measures, contents and structure of the security documentation and
scope of the general security measures
• identification criteria for respective categories of cybersecurity incidents and details of
cybersecurity incidents reporting
DEFINITION OF SECTORS AND SUBSECTORS FOR OES
Sector Subsector Managing authority CIP NIS CiiP
Banking Ministry of Finance ☑️ ☑️
Transport
Air transport
Ministry of transport and
construction
☑️ ☑️ ☑️
Rail transport ☑️ ☑️ ☑️
Water transport ☑️ ☑️ ☑️
Road transport ☑️ ☑️ ☑️
Digital Infrastructure
National Security
Authority
☑️ ☑️
Electronic
Communication
Satellite communication
Ministry of transport and
construction
☑️ ☑️
Electronic communications networks and
electronic communications services
☑️ ☑️
Financial market
infrastructures
Ministry of Finance ☑️ ☑️
DEFINITION OF SECTORS AND SUBSECTORS FOR OES
Sector Subsector Managing authority CIP NIS CIIP
Postal services
Ministry of transport and
construction
☑️ ☑️
Energy
Mining
Ministry of Economy
☑️ ☑️
Electricity ☑️ ☑️ ☑️
Oil ☑️ ☑️ ☑️
Gas ☑️ ☑️ ☑️
Heat-power ☑️
Other Industries
Pharmaceutical
Ministry of Economy
☑️ ☑️
Metallurgical ☑️ ☑️
Chemical ☑️ ☑️
Health
All medical facilities (incl. Hospitals and
private clinics)
Ministry of Health ☑️ ☑️ ☑️
DEFINITION OF SECTORS AND SUBSECTORS FOR OES
Sector Subsector Managing authority CIP NIS CIIP
Water and
Atmosphere
Weather service
Ministry of the
environment
☑️ ☑️
Water works ☑️ ☑️
Drinking water supply and distribution ☑️ ☑️ ☑️
Public Administration
Public order and security Ministry of interior ☑️
Information systems of public
administration
Deputy Prime Minister’s
Office for Investments
and Informatization
☑️ ☑️
Defense Ministry of defense ☑️
Intelligence services Intelligence services ☑️
Classified Information Protection National Security
Authority
☑️
NIS TRANSPOSITION TIMELINE
• July 2016 - NIS approval July
• September 2016 - first internal draft
• October 2016 - NIS Implementation international workshop, Bratislava
• December 2016 – first round of public consultation
• End of January, February 2017 – second round of public consultation
• February 2017 – public workshop after second public consultation
• March – May 2017 – third round of public consutations
• Jun 2017 – official intra-ministerial commenting procedure
• July – September 2017 – preparation of final version
• October 2017 – approval by Slovak government
• November 2017 – parliament procedure
• January 2018 - approval of the law by parliament
• March 1st, 2018 – entry into force
THANK YOU
rastislav.janota@nbu.gov.sk

More Related Content

Similar to Cybersecurity Regulatory Outlook in EU and Slovakia

How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
Regulatory perspective in dealing with Cyber crime
Regulatory perspective in dealing with Cyber crimeRegulatory perspective in dealing with Cyber crime
Regulatory perspective in dealing with Cyber crimeCA
 
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationSolent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationNine23Ltd
 
Galaxy Backbone
Galaxy BackboneGalaxy Backbone
Galaxy Backbonebudzeg
 
Smart Grid - Selta's Point Of View
Smart Grid - Selta's Point Of ViewSmart Grid - Selta's Point Of View
Smart Grid - Selta's Point Of ViewStefano Zanin
 
ITV presentation eng.ppt
ITV presentation eng.pptITV presentation eng.ppt
ITV presentation eng.pptBhekumuzi Xaba
 
European Cybersecurity Context
European Cybersecurity ContextEuropean Cybersecurity Context
European Cybersecurity ContextMiguel A. Amutio
 
From Connected To Self-Driving - Securing the Automotive Revolution
From Connected To Self-Driving - Securing the Automotive RevolutionFrom Connected To Self-Driving - Securing the Automotive Revolution
From Connected To Self-Driving - Securing the Automotive RevolutionAlexander Schellong
 
06_-_luca_castellani_-_uncitral_castellani_en.pptx
06_-_luca_castellani_-_uncitral_castellani_en.pptx06_-_luca_castellani_-_uncitral_castellani_en.pptx
06_-_luca_castellani_-_uncitral_castellani_en.pptxRahul890054
 
Illicit trade and e commerce
Illicit trade and e commerceIllicit trade and e commerce
Illicit trade and e commerceOECD Governance
 
Maxtrack - GPS/GLONASS Tracking Platform
Maxtrack - GPS/GLONASS Tracking PlatformMaxtrack - GPS/GLONASS Tracking Platform
Maxtrack - GPS/GLONASS Tracking PlatformAkmal Paiziev
 
ICT enabled administrative burden reduction and cost savings in Uganda (WSIS ...
ICT enabled administrative burden reduction and cost savings in Uganda (WSIS ...ICT enabled administrative burden reduction and cost savings in Uganda (WSIS ...
ICT enabled administrative burden reduction and cost savings in Uganda (WSIS ...Morten Meyerhoff Nielsen
 
Nota Pelaksanaan Kerajaan Elektronik.pdf
Nota Pelaksanaan Kerajaan Elektronik.pdfNota Pelaksanaan Kerajaan Elektronik.pdf
Nota Pelaksanaan Kerajaan Elektronik.pdfnazmijuhari
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRIT Governance Ltd
 
Europe’s benefit from e-Government – ms perspective Giulio Borsari
Europe’s benefit from e-Government – ms perspective Giulio BorsariEurope’s benefit from e-Government – ms perspective Giulio Borsari
Europe’s benefit from e-Government – ms perspective Giulio Borsarie-SENS project
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRIT Governance Ltd
 

Similar to Cybersecurity Regulatory Outlook in EU and Slovakia (20)

Day 02 - EDPS Technology & Privacy unit.pdf
Day 02 - EDPS Technology & Privacy unit.pdfDay 02 - EDPS Technology & Privacy unit.pdf
Day 02 - EDPS Technology & Privacy unit.pdf
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
Regulatory perspective in dealing with Cyber crime
Regulatory perspective in dealing with Cyber crimeRegulatory perspective in dealing with Cyber crime
Regulatory perspective in dealing with Cyber crime
 
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationSolent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
 
Galaxy Backbone
Galaxy BackboneGalaxy Backbone
Galaxy Backbone
 
Smart Grid - Selta's Point Of View
Smart Grid - Selta's Point Of ViewSmart Grid - Selta's Point Of View
Smart Grid - Selta's Point Of View
 
ITV presentation eng.ppt
ITV presentation eng.pptITV presentation eng.ppt
ITV presentation eng.ppt
 
European Cybersecurity Context
European Cybersecurity ContextEuropean Cybersecurity Context
European Cybersecurity Context
 
From Connected To Self-Driving - Securing the Automotive Revolution
From Connected To Self-Driving - Securing the Automotive RevolutionFrom Connected To Self-Driving - Securing the Automotive Revolution
From Connected To Self-Driving - Securing the Automotive Revolution
 
06_-_luca_castellani_-_uncitral_castellani_en.pptx
06_-_luca_castellani_-_uncitral_castellani_en.pptx06_-_luca_castellani_-_uncitral_castellani_en.pptx
06_-_luca_castellani_-_uncitral_castellani_en.pptx
 
NPS-About Us
NPS-About UsNPS-About Us
NPS-About Us
 
Illicit trade and e commerce
Illicit trade and e commerceIllicit trade and e commerce
Illicit trade and e commerce
 
Polish_eCustoms
Polish_eCustomsPolish_eCustoms
Polish_eCustoms
 
Maxtrack - GPS/GLONASS Tracking Platform
Maxtrack - GPS/GLONASS Tracking PlatformMaxtrack - GPS/GLONASS Tracking Platform
Maxtrack - GPS/GLONASS Tracking Platform
 
ICT enabled administrative burden reduction and cost savings in Uganda (WSIS ...
ICT enabled administrative burden reduction and cost savings in Uganda (WSIS ...ICT enabled administrative burden reduction and cost savings in Uganda (WSIS ...
ICT enabled administrative burden reduction and cost savings in Uganda (WSIS ...
 
Nota Pelaksanaan Kerajaan Elektronik.pdf
Nota Pelaksanaan Kerajaan Elektronik.pdfNota Pelaksanaan Kerajaan Elektronik.pdf
Nota Pelaksanaan Kerajaan Elektronik.pdf
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPR
 
Europe’s benefit from e-Government – ms perspective Giulio Borsari
Europe’s benefit from e-Government – ms perspective Giulio BorsariEurope’s benefit from e-Government – ms perspective Giulio Borsari
Europe’s benefit from e-Government – ms perspective Giulio Borsari
 
Enisa and cyber security standards
Enisa and cyber security standardsEnisa and cyber security standards
Enisa and cyber security standards
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPR
 

Recently uploaded

call girls in DLF Phase 1 gurgaon 🔝 >༒9540349809 🔝 genuine Escort Service 🔝...
call girls in DLF Phase 1  gurgaon  🔝 >༒9540349809 🔝 genuine Escort Service 🔝...call girls in DLF Phase 1  gurgaon  🔝 >༒9540349809 🔝 genuine Escort Service 🔝...
call girls in DLF Phase 1 gurgaon 🔝 >༒9540349809 🔝 genuine Escort Service 🔝...saminamagar
 
YHR Fall 2023 Issue (Joseph Manning Interview) (2).pdf
YHR Fall 2023 Issue (Joseph Manning Interview) (2).pdfYHR Fall 2023 Issue (Joseph Manning Interview) (2).pdf
YHR Fall 2023 Issue (Joseph Manning Interview) (2).pdfyalehistoricalreview
 
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...narwatsonia7
 
Angels_EDProgrammes & Services 2024.pptx
Angels_EDProgrammes & Services 2024.pptxAngels_EDProgrammes & Services 2024.pptx
Angels_EDProgrammes & Services 2024.pptxLizelle Coombs
 
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best ServicesMadurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best Servicesnajka9823
 
call girls in Punjabi Bagh DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Punjabi Bagh DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Punjabi Bagh DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Punjabi Bagh DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
2024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 272024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 27JSchaus & Associates
 
2024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 252024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 25JSchaus & Associates
 
Jewish Efforts to Influence American Immigration Policy in the Years Before t...
Jewish Efforts to Influence American Immigration Policy in the Years Before t...Jewish Efforts to Influence American Immigration Policy in the Years Before t...
Jewish Efforts to Influence American Immigration Policy in the Years Before t...yalehistoricalreview
 
(多少钱)Dal毕业证国外本科学位证
(多少钱)Dal毕业证国外本科学位证(多少钱)Dal毕业证国外本科学位证
(多少钱)Dal毕业证国外本科学位证mbetknu
 
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...narwatsonia7
 
Powering Britain: Can we decarbonise electricity without disadvantaging poore...
Powering Britain: Can we decarbonise electricity without disadvantaging poore...Powering Britain: Can we decarbonise electricity without disadvantaging poore...
Powering Britain: Can we decarbonise electricity without disadvantaging poore...ResolutionFoundation
 
Start Donating your Old Clothes to Poor People
Start Donating your Old Clothes to Poor PeopleStart Donating your Old Clothes to Poor People
Start Donating your Old Clothes to Poor PeopleSERUDS INDIA
 
Monastic-Supremacy-in-the-Philippines-_20240328_092725_0000.pdf
Monastic-Supremacy-in-the-Philippines-_20240328_092725_0000.pdfMonastic-Supremacy-in-the-Philippines-_20240328_092725_0000.pdf
Monastic-Supremacy-in-the-Philippines-_20240328_092725_0000.pdfCharlynTorres1
 
Action Toolkit - Earth Day 2024 - April 22nd.
Action Toolkit - Earth Day 2024 - April 22nd.Action Toolkit - Earth Day 2024 - April 22nd.
Action Toolkit - Earth Day 2024 - April 22nd.Christina Parmionova
 
history of 1935 philippine constitution.pptx
history of 1935 philippine constitution.pptxhistory of 1935 philippine constitution.pptx
history of 1935 philippine constitution.pptxhellokittymaearciaga
 

Recently uploaded (20)

call girls in DLF Phase 1 gurgaon 🔝 >༒9540349809 🔝 genuine Escort Service 🔝...
call girls in DLF Phase 1  gurgaon  🔝 >༒9540349809 🔝 genuine Escort Service 🔝...call girls in DLF Phase 1  gurgaon  🔝 >༒9540349809 🔝 genuine Escort Service 🔝...
call girls in DLF Phase 1 gurgaon 🔝 >༒9540349809 🔝 genuine Escort Service 🔝...
 
YHR Fall 2023 Issue (Joseph Manning Interview) (2).pdf
YHR Fall 2023 Issue (Joseph Manning Interview) (2).pdfYHR Fall 2023 Issue (Joseph Manning Interview) (2).pdf
YHR Fall 2023 Issue (Joseph Manning Interview) (2).pdf
 
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
High Class Call Girls Bangalore Komal 7001305949 Independent Escort Service B...
 
Angels_EDProgrammes & Services 2024.pptx
Angels_EDProgrammes & Services 2024.pptxAngels_EDProgrammes & Services 2024.pptx
Angels_EDProgrammes & Services 2024.pptx
 
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best ServicesMadurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
Madurai Call Girls 7001305949 WhatsApp Number 24x7 Best Services
 
call girls in Punjabi Bagh DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Punjabi Bagh DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Punjabi Bagh DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Punjabi Bagh DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
2024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 272024: The FAR, Federal Acquisition Regulations - Part 27
2024: The FAR, Federal Acquisition Regulations - Part 27
 
2024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 252024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 25
 
Jewish Efforts to Influence American Immigration Policy in the Years Before t...
Jewish Efforts to Influence American Immigration Policy in the Years Before t...Jewish Efforts to Influence American Immigration Policy in the Years Before t...
Jewish Efforts to Influence American Immigration Policy in the Years Before t...
 
(多少钱)Dal毕业证国外本科学位证
(多少钱)Dal毕业证国外本科学位证(多少钱)Dal毕业证国外本科学位证
(多少钱)Dal毕业证国外本科学位证
 
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
 
Powering Britain: Can we decarbonise electricity without disadvantaging poore...
Powering Britain: Can we decarbonise electricity without disadvantaging poore...Powering Britain: Can we decarbonise electricity without disadvantaging poore...
Powering Britain: Can we decarbonise electricity without disadvantaging poore...
 
Start Donating your Old Clothes to Poor People
Start Donating your Old Clothes to Poor PeopleStart Donating your Old Clothes to Poor People
Start Donating your Old Clothes to Poor People
 
Monastic-Supremacy-in-the-Philippines-_20240328_092725_0000.pdf
Monastic-Supremacy-in-the-Philippines-_20240328_092725_0000.pdfMonastic-Supremacy-in-the-Philippines-_20240328_092725_0000.pdf
Monastic-Supremacy-in-the-Philippines-_20240328_092725_0000.pdf
 
Action Toolkit - Earth Day 2024 - April 22nd.
Action Toolkit - Earth Day 2024 - April 22nd.Action Toolkit - Earth Day 2024 - April 22nd.
Action Toolkit - Earth Day 2024 - April 22nd.
 
history of 1935 philippine constitution.pptx
history of 1935 philippine constitution.pptxhistory of 1935 philippine constitution.pptx
history of 1935 philippine constitution.pptx
 

Cybersecurity Regulatory Outlook in EU and Slovakia

  • 1. Cybersecurity Regulatory Outlook in EU and Slovakia BEST PRACTICES FROM SLOVAKIA Rastislav Janota Chairman Cyber Security Committee Security Council of the Slovak Republic National Security Authority
  • 2. CYBERSECURITY IS TOPIC FOR? Who should take care on Cybersecurity? WE ALL! Everyone is responsible for own data and own services...
  • 3. CHALLENGES DURING PROCESS • Alignment with other regulations and their regulators • Defining balance between minimum regulation and comprehensive regulation approach • Creating national CSIRT network structure, accreditation of CSIRTs incl. private one’s • Alignment with Critical Infrastructure Protection legislation • Definitions of sectors and subsectors for OES incl. managing authorities and their duties • Mandatory government CSIRTs for sectorial managing authorities, government outsourcing and last-resort option • Defining areas for future voluntary ‘win-win’ cooperation with the market instead of mandatory duties
  • 4. DIFFERENT EU REGULATIONS • General Data Protection Regulation (GDPR) – 2016/679 – To strengthen and unify data protection for all individuals within the European Union (EU) – Regulator – Office for Personal Data Protection of the Slovak Republic • Payment Services Directive (PSD2) – 2015/2366 – To regulate payment services and payment service providers throughout the European Union (EU) – Regulator – National Bank of Slovakia • Regulatory framework for electronic communications – Telecoms Package (2009) – To create a common set of regulations for the telecoms industry across all 27 EU states – Regulator –Regulatory Authority for Electronic Communication and Postal Services • Network and Information Security Directive 2016/1148 – To force companies and organizations to protect their systems/data from cyber-attacks – Regulator – National Security Authority
  • 5. BASIC CYBERSPACE ACTIVITIES • Cyber Crime – Responsible Ministry of Interior (police, crime investigators), prosecutors, courts • Cyber Defense – Ministry of Defense • Cyber Intelligence – Intelligence services • Cyber Security – NIS transposition, – Cybersecurity regulation – Regulation of sectors/subsectors – Security standards, risk management, auditing, regulation, enforcement work – Incident reporting and handling – National Cybersecurity Centre and National CSIRT (SK-CERT) – Security Operation Centre
  • 6. Cyber Security Committee CYBERSECURITY GOVERNANCE IN SLOVAKIA Parliament National Cybersecurity Centre / SK-CERT Security Council Government Managing authority Sector/Subsector n National Security Authority Managing authority Sector/Subsector 2 Managing authority Sector/Subsector 1 CSIRT Sector 1 and 2 CSIRT Sector n CSIRT Commercial
  • 7. CYBERSECURITY LAW IN SLOVAKIA Content of law • Definitions • Cybersecurity governance in Slovak republic, • National Cybersecurity Centre (and SK-CERT), • Integrated Cybersecurity Information System, • Duties and capacities of Operator of essential services and Digital service provider • CSIRT units and their accreditation, • Security requirements and incident notification and handling • Implementation and enforcement • Other procedures and bylaws • Update (alignment) of Critical Infrastructure Law with Cybersecurity Law • Definition of sectors and subsectors for OES
  • 8. CYBERSECURITY LAW IN SLOVAKIA Key duties from NIS and law • establishes security requirements for operators of essential services and for digital service providers • establishes notification requirements for operators of essential services and for digital service providers Tools • identification and impact criteria of the operated service • contents of security measures, contents and structure of the security documentation and scope of the general security measures • identification criteria for respective categories of cybersecurity incidents and details of cybersecurity incidents reporting
  • 9. DEFINITION OF SECTORS AND SUBSECTORS FOR OES Sector Subsector Managing authority CIP NIS CiiP Banking Ministry of Finance ☑️ ☑️ Transport Air transport Ministry of transport and construction ☑️ ☑️ ☑️ Rail transport ☑️ ☑️ ☑️ Water transport ☑️ ☑️ ☑️ Road transport ☑️ ☑️ ☑️ Digital Infrastructure National Security Authority ☑️ ☑️ Electronic Communication Satellite communication Ministry of transport and construction ☑️ ☑️ Electronic communications networks and electronic communications services ☑️ ☑️ Financial market infrastructures Ministry of Finance ☑️ ☑️
  • 10. DEFINITION OF SECTORS AND SUBSECTORS FOR OES Sector Subsector Managing authority CIP NIS CIIP Postal services Ministry of transport and construction ☑️ ☑️ Energy Mining Ministry of Economy ☑️ ☑️ Electricity ☑️ ☑️ ☑️ Oil ☑️ ☑️ ☑️ Gas ☑️ ☑️ ☑️ Heat-power ☑️ Other Industries Pharmaceutical Ministry of Economy ☑️ ☑️ Metallurgical ☑️ ☑️ Chemical ☑️ ☑️ Health All medical facilities (incl. Hospitals and private clinics) Ministry of Health ☑️ ☑️ ☑️
  • 11. DEFINITION OF SECTORS AND SUBSECTORS FOR OES Sector Subsector Managing authority CIP NIS CIIP Water and Atmosphere Weather service Ministry of the environment ☑️ ☑️ Water works ☑️ ☑️ Drinking water supply and distribution ☑️ ☑️ ☑️ Public Administration Public order and security Ministry of interior ☑️ Information systems of public administration Deputy Prime Minister’s Office for Investments and Informatization ☑️ ☑️ Defense Ministry of defense ☑️ Intelligence services Intelligence services ☑️ Classified Information Protection National Security Authority ☑️
  • 12. NIS TRANSPOSITION TIMELINE • July 2016 - NIS approval July • September 2016 - first internal draft • October 2016 - NIS Implementation international workshop, Bratislava • December 2016 – first round of public consultation • End of January, February 2017 – second round of public consultation • February 2017 – public workshop after second public consultation • March – May 2017 – third round of public consutations • Jun 2017 – official intra-ministerial commenting procedure • July – September 2017 – preparation of final version • October 2017 – approval by Slovak government • November 2017 – parliament procedure • January 2018 - approval of the law by parliament • March 1st, 2018 – entry into force