SlideShare a Scribd company logo
1 of 12
TRANSPOSING THE NIS
DIRECTIVE
PROGRESS AND BEST PRACTICES
FROM SLOVAKIA
Rastislav Janota
Chairman
Cyber Security Committee
Security Council of the Slovak Republic
National Security Authority
Cybersecurity is topic for?
Who should take care on
Cybersecurity?
WE ALL!
Everyone is responsible for own data
and own services...
Challenges during process
• Alignment with other regulations and their regulators
• Defining balance between minimum regulation and comprehensive regulation approach
• Creating national CSIRT network structure, accreditation of CSIRTs incl. private one’s
• Alignment with Critical Infrastructure Protection legislation
• Definitions of sectors and subsectors for OES incl. managing authorities and their duties
• Mandatory government CSIRTs for sectorial managing authorities, government outsourcing
and last-resort option
• Defining areas for future voluntary ‘win-win’ cooperation with the market instead of
mandatory duties
Different EU REGULATIONS
• General Data Protection Regulation (GDPR) – 2016/679
– To strengthen and unify data protection for all individuals within the European Union (EU)
– Regulator – Office for Personal Data Protection of the Slovak Republic
• Payment Services Directive (PSD2) – 2015/2366
– To regulate payment services and payment service providers throughout the European
Union (EU)
– Regulator – National Bank of Slovakia
• Regulatory framework for electronic communications – Telecoms Package (2009)
– To create a common set of regulations for the telecoms industry across all 27 EU states
– Regulator –Regulatory Authority for Electronic Communication and Postal Services
• Network and Information Security Directive 2016/1148
– To force companies and organizations to protect their systems/data from cyber-attacks
– Regulator – National Securty Authority
Basic cyberspace activities
• Cyber Crime
– Responsible Ministry of Interior (police, crime investigators), prosecutors, courts
• Cyber Defense
– Ministry of Defense
• Cyber Intelligence
– Intelligence services
• Cyber Security
– National Security Authority
– NIS transposition,
– Cybersecurity regulation
– Regulation of sectors/subsectors
– Security standards, risk management, auditing, regulation, enforcement work
– Incident reporting and handling
– National Cybersecurity Centre and National CSIRT (SK-CERT)
– Security Operation Centre
Cybersecurity law in Slovakia
Content of law
•Definitions
•Cybersecurity governance in Slovak republic,
•National Cybersecurity Centre (and SK-CERT),
•Integrated Cybersecurity Information System,
•Duties and capacities of Operator of essential services and Digital service provider
•CSIRT units and their accreditation,
•Security requirements and incident notification and handling
•Implementation and enforcement
•Other procedures and bylaws
•Update (alignment) of Critical Infrastructure Law with Cybersecurity Law
•Definition of sectors and subsectors for OES
Cyber Security Committee
Cybersecurity governance in Slovakia
Parliament
National Cybersecurity Centre / SK-CERT
Security Council
Government
Managing authority
Sector/Subsector n
National Security Authority
Managing authority
Sector/Subsector 2
Managing authority
Sector/Subsector 1
CSIRT
Sector 1 and 2
CSIRT
Sector n
CSIRT
Commercial
Definition of sectors and subsectors for OES
Sector Subsector Managing authority CIP NIS CiiP
Banking Ministry of Finance ☑️ ☑️
Transport
Air transport
Ministry of transport and
construction
☑️ ☑️ ☑️
Rail transport ☑️ ☑️ ☑️
Water transport ☑️ ☑️ ☑️
Road transport ☑️ ☑️ ☑️
Digital Infrastructure
National Security
Authority
☑️ ☑️
Electronic
Communication
Satellite communication
Ministry of transport and
construction
☑️ ☑️
Electronic communications networks and
electronic communications services
☑️ ☑️
Financial market
infrastructures
Ministry of Finance ☑️ ☑️
Definition of sectors and subsectors for OES
Sector Subsector Managing authority CIP NIS CIIP
Postal services
Ministry of transport and
construction
☑️ ☑️
Energy
Mining
Ministry of Economy
☑️ ☑️
Electricity ☑️ ☑️ ☑️
Oil ☑️ ☑️ ☑️
Gas ☑️ ☑️ ☑️
Heat-power ☑️
Other Industries
Pharmaceutical
Ministry of Economy
☑️ ☑️
Metallurgical ☑️ ☑️
Chemical ☑️ ☑️
Health
All medical facilities (incl. Hospitals and
private clinics)
Ministry of Health ☑️ ☑️ ☑️
Definition of sectors and subsectors for OES
Sector Subsector Managing authority CIP NIS CIIP
Water and
Atmosphere
Weather service
Ministry of the
environment
☑️ ☑️
Water works ☑️ ☑️
Drinking water supply and distribution ☑️ ☑️ ☑️
Public Administration
Public order and security Ministry of interior ☑️
Information systems of public
administration
Deputy Prime Minister’s
Office for Investments
and Informatization
☑️ ☑️
Defense Ministry of defense ☑️
Intelligence services Intelligence services ☑️
Classified Information Protection National Security
Authority
☑️
NIS transposition Timeline
• July 2016 - NIS approval July
• September 2016 - first internal draft
• October 2016 - NIS Implementation international workshop, Bratislava
• December 2016 – first round of public consultation
• End of January, February 2017 – second round of public consultation
• February 2017 – public workshop after second public consultation
• March – May 2017 – third round of public consutations
• Jun 2017 – official intra-ministerial commenting procedure
• July – September 2017 – preparation of final version
• October 2017 – approval by Slovak government
• November 2017 – parliament procedure
• January 2018 - approval of the law by parliament
• March 1st
, 2018 – entry into force
THANK YOU
rastislav.janota@nbu.gov.sk

More Related Content

Similar to Transposing the NIS directive (Cybersecurity law) - NSA Slovkia - Rastislav Janota

How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...PECB
 
WSO2Con EU 2015: Implementing National Interoperability Platform
WSO2Con EU 2015: Implementing National Interoperability PlatformWSO2Con EU 2015: Implementing National Interoperability Platform
WSO2Con EU 2015: Implementing National Interoperability PlatformWSO2
 
ITV presentation eng.ppt
ITV presentation eng.pptITV presentation eng.ppt
ITV presentation eng.pptBhekumuzi Xaba
 
European Cybersecurity Context
European Cybersecurity ContextEuropean Cybersecurity Context
European Cybersecurity ContextMiguel A. Amutio
 
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationSolent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationNine23Ltd
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRIT Governance Ltd
 
Nota Pelaksanaan Kerajaan Elektronik.pdf
Nota Pelaksanaan Kerajaan Elektronik.pdfNota Pelaksanaan Kerajaan Elektronik.pdf
Nota Pelaksanaan Kerajaan Elektronik.pdfnazmijuhari
 
Aare reintam estonia_ciip_activites
Aare reintam estonia_ciip_activitesAare reintam estonia_ciip_activites
Aare reintam estonia_ciip_activitesS.E. CTS CERT-GOV-MD
 
Europe’s benefit from e-Government – ms perspective Giulio Borsari
Europe’s benefit from e-Government – ms perspective Giulio BorsariEurope’s benefit from e-Government – ms perspective Giulio Borsari
Europe’s benefit from e-Government – ms perspective Giulio Borsarie-SENS project
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRIT Governance Ltd
 
Rutkowski OASIS CTI F2F Cybersecurity Act Preso 20160115
Rutkowski OASIS CTI F2F Cybersecurity Act Preso 20160115Rutkowski OASIS CTI F2F Cybersecurity Act Preso 20160115
Rutkowski OASIS CTI F2F Cybersecurity Act Preso 20160115James Bryce Clark
 
SK INSPIRE monitoring & reporting (2013)
SK INSPIRE monitoring & reporting (2013)SK INSPIRE monitoring & reporting (2013)
SK INSPIRE monitoring & reporting (2013)Martin Tuchyna
 
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...IT Governance Ltd
 
The Impact of Cloud: Cloud Computing Security and Privacy
The Impact of Cloud: Cloud Computing Security and PrivacyThe Impact of Cloud: Cloud Computing Security and Privacy
The Impact of Cloud: Cloud Computing Security and PrivacyCharles Mok
 
DSS ITSEC 2013 Conference 07.11.2013 - CERT.LV
DSS ITSEC 2013 Conference 07.11.2013 - CERT.LVDSS ITSEC 2013 Conference 07.11.2013 - CERT.LV
DSS ITSEC 2013 Conference 07.11.2013 - CERT.LVAndris Soroka
 

Similar to Transposing the NIS directive (Cybersecurity law) - NSA Slovkia - Rastislav Janota (20)

Enisa and cyber security standards
Enisa and cyber security standardsEnisa and cyber security standards
Enisa and cyber security standards
 
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
How Can ISO/IEC 27001 Help Organizations Align With the EU Cybersecurity Regu...
 
WSO2Con EU 2015: Implementing National Interoperability Platform
WSO2Con EU 2015: Implementing National Interoperability PlatformWSO2Con EU 2015: Implementing National Interoperability Platform
WSO2Con EU 2015: Implementing National Interoperability Platform
 
ITV presentation eng.ppt
ITV presentation eng.pptITV presentation eng.ppt
ITV presentation eng.ppt
 
European Cybersecurity Context
European Cybersecurity ContextEuropean Cybersecurity Context
European Cybersecurity Context
 
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationSolent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPR
 
20120822 schubert alpbach_final
20120822 schubert alpbach_final20120822 schubert alpbach_final
20120822 schubert alpbach_final
 
Nota Pelaksanaan Kerajaan Elektronik.pdf
Nota Pelaksanaan Kerajaan Elektronik.pdfNota Pelaksanaan Kerajaan Elektronik.pdf
Nota Pelaksanaan Kerajaan Elektronik.pdf
 
Aare reintam estonia_ciip_activites
Aare reintam estonia_ciip_activitesAare reintam estonia_ciip_activites
Aare reintam estonia_ciip_activites
 
Europe’s benefit from e-Government – ms perspective Giulio Borsari
Europe’s benefit from e-Government – ms perspective Giulio BorsariEurope’s benefit from e-Government – ms perspective Giulio Borsari
Europe’s benefit from e-Government – ms perspective Giulio Borsari
 
Polish_eCustoms
Polish_eCustomsPolish_eCustoms
Polish_eCustoms
 
Data Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPRData Flow Mapping and the EU GDPR
Data Flow Mapping and the EU GDPR
 
Rutkowski OASIS CTI F2F Cybersecurity Act Preso 20160115
Rutkowski OASIS CTI F2F Cybersecurity Act Preso 20160115Rutkowski OASIS CTI F2F Cybersecurity Act Preso 20160115
Rutkowski OASIS CTI F2F Cybersecurity Act Preso 20160115
 
SK INSPIRE monitoring & reporting (2013)
SK INSPIRE monitoring & reporting (2013)SK INSPIRE monitoring & reporting (2013)
SK INSPIRE monitoring & reporting (2013)
 
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
The GDPR and NIS Directive Risk-Based Security Measures and Incident Notifica...
 
ODSC Boston 2019 - Arturo O. Amador
ODSC Boston 2019 - Arturo O. AmadorODSC Boston 2019 - Arturo O. Amador
ODSC Boston 2019 - Arturo O. Amador
 
The Impact of Cloud: Cloud Computing Security and Privacy
The Impact of Cloud: Cloud Computing Security and PrivacyThe Impact of Cloud: Cloud Computing Security and Privacy
The Impact of Cloud: Cloud Computing Security and Privacy
 
NPS-About Us
NPS-About UsNPS-About Us
NPS-About Us
 
DSS ITSEC 2013 Conference 07.11.2013 - CERT.LV
DSS ITSEC 2013 Conference 07.11.2013 - CERT.LVDSS ITSEC 2013 Conference 07.11.2013 - CERT.LV
DSS ITSEC 2013 Conference 07.11.2013 - CERT.LV
 

Recently uploaded

Russian Call Girl Hebbagodi ! 7001305949 ₹2999 Only and Free Hotel Delivery 2...
Russian Call Girl Hebbagodi ! 7001305949 ₹2999 Only and Free Hotel Delivery 2...Russian Call Girl Hebbagodi ! 7001305949 ₹2999 Only and Free Hotel Delivery 2...
Russian Call Girl Hebbagodi ! 7001305949 ₹2999 Only and Free Hotel Delivery 2...narwatsonia7
 
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
2023 Ecological Profile of Ilocos Norte.pdf
2023 Ecological Profile of Ilocos Norte.pdf2023 Ecological Profile of Ilocos Norte.pdf
2023 Ecological Profile of Ilocos Norte.pdfilocosnortegovph
 
Yellow is My Favorite Color By Annabelle.pdf
Yellow is My Favorite Color By Annabelle.pdfYellow is My Favorite Color By Annabelle.pdf
Yellow is My Favorite Color By Annabelle.pdfAmir Saranga
 
(多少钱)Dal毕业证国外本科学位证
(多少钱)Dal毕业证国外本科学位证(多少钱)Dal毕业证国外本科学位证
(多少钱)Dal毕业证国外本科学位证mbetknu
 
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
call girls in West Patel Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service ...
call girls in West Patel Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service ...call girls in West Patel Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service ...
call girls in West Patel Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service ...saminamagar
 
2024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 252024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 25JSchaus & Associates
 
productionpost-productiondiary-240320114322-5004daf6.pptx
productionpost-productiondiary-240320114322-5004daf6.pptxproductionpost-productiondiary-240320114322-5004daf6.pptx
productionpost-productiondiary-240320114322-5004daf6.pptxHenryBriggs2
 
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
Club of Rome: Eco-nomics for an Ecological Civilization
Club of Rome: Eco-nomics for an Ecological CivilizationClub of Rome: Eco-nomics for an Ecological Civilization
Club of Rome: Eco-nomics for an Ecological CivilizationEnergy for One World
 
call girls in Mayapuri DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Mayapuri DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Mayapuri DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Mayapuri DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
call girls in sector 22 Gurgaon 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in sector 22 Gurgaon  🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in sector 22 Gurgaon  🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in sector 22 Gurgaon 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
call girls in Mehrauli DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Mehrauli  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Mehrauli  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Mehrauli DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls ServiceCall Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Servicenarwatsonia7
 
Earth Day 2024 - AMC "COMMON GROUND'' movie night.
Earth Day 2024 - AMC "COMMON GROUND'' movie night.Earth Day 2024 - AMC "COMMON GROUND'' movie night.
Earth Day 2024 - AMC "COMMON GROUND'' movie night.Christina Parmionova
 
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...narwatsonia7
 
Angels_EDProgrammes & Services 2024.pptx
Angels_EDProgrammes & Services 2024.pptxAngels_EDProgrammes & Services 2024.pptx
Angels_EDProgrammes & Services 2024.pptxLizelle Coombs
 

Recently uploaded (20)

Russian Call Girl Hebbagodi ! 7001305949 ₹2999 Only and Free Hotel Delivery 2...
Russian Call Girl Hebbagodi ! 7001305949 ₹2999 Only and Free Hotel Delivery 2...Russian Call Girl Hebbagodi ! 7001305949 ₹2999 Only and Free Hotel Delivery 2...
Russian Call Girl Hebbagodi ! 7001305949 ₹2999 Only and Free Hotel Delivery 2...
 
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Narela DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Kirti Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
2023 Ecological Profile of Ilocos Norte.pdf
2023 Ecological Profile of Ilocos Norte.pdf2023 Ecological Profile of Ilocos Norte.pdf
2023 Ecological Profile of Ilocos Norte.pdf
 
Yellow is My Favorite Color By Annabelle.pdf
Yellow is My Favorite Color By Annabelle.pdfYellow is My Favorite Color By Annabelle.pdf
Yellow is My Favorite Color By Annabelle.pdf
 
(多少钱)Dal毕业证国外本科学位证
(多少钱)Dal毕业证国外本科学位证(多少钱)Dal毕业证国外本科学位证
(多少钱)Dal毕业证国外本科学位证
 
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Vasant Kunj DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
9953330565 Low Rate Call Girls In Adarsh Nagar Delhi NCR
9953330565 Low Rate Call Girls In Adarsh Nagar Delhi NCR9953330565 Low Rate Call Girls In Adarsh Nagar Delhi NCR
9953330565 Low Rate Call Girls In Adarsh Nagar Delhi NCR
 
call girls in West Patel Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service ...
call girls in West Patel Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service ...call girls in West Patel Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service ...
call girls in West Patel Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service ...
 
2024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 252024: The FAR, Federal Acquisition Regulations - Part 25
2024: The FAR, Federal Acquisition Regulations - Part 25
 
productionpost-productiondiary-240320114322-5004daf6.pptx
productionpost-productiondiary-240320114322-5004daf6.pptxproductionpost-productiondiary-240320114322-5004daf6.pptx
productionpost-productiondiary-240320114322-5004daf6.pptx
 
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Laxmi Nagar DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
Club of Rome: Eco-nomics for an Ecological Civilization
Club of Rome: Eco-nomics for an Ecological CivilizationClub of Rome: Eco-nomics for an Ecological Civilization
Club of Rome: Eco-nomics for an Ecological Civilization
 
call girls in Mayapuri DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Mayapuri DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Mayapuri DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Mayapuri DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
call girls in sector 22 Gurgaon 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in sector 22 Gurgaon  🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in sector 22 Gurgaon  🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in sector 22 Gurgaon 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
call girls in Mehrauli DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Mehrauli  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in Mehrauli  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in Mehrauli DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls ServiceCall Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
Call Girls Service AECS Layout Just Call 7001305949 Enjoy College Girls Service
 
Earth Day 2024 - AMC "COMMON GROUND'' movie night.
Earth Day 2024 - AMC "COMMON GROUND'' movie night.Earth Day 2024 - AMC "COMMON GROUND'' movie night.
Earth Day 2024 - AMC "COMMON GROUND'' movie night.
 
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
Premium Call Girls Btm Layout - 7001305949 Escorts Service with Real Photos a...
 
Angels_EDProgrammes & Services 2024.pptx
Angels_EDProgrammes & Services 2024.pptxAngels_EDProgrammes & Services 2024.pptx
Angels_EDProgrammes & Services 2024.pptx
 

Transposing the NIS directive (Cybersecurity law) - NSA Slovkia - Rastislav Janota

  • 1. TRANSPOSING THE NIS DIRECTIVE PROGRESS AND BEST PRACTICES FROM SLOVAKIA Rastislav Janota Chairman Cyber Security Committee Security Council of the Slovak Republic National Security Authority
  • 2. Cybersecurity is topic for? Who should take care on Cybersecurity? WE ALL! Everyone is responsible for own data and own services...
  • 3. Challenges during process • Alignment with other regulations and their regulators • Defining balance between minimum regulation and comprehensive regulation approach • Creating national CSIRT network structure, accreditation of CSIRTs incl. private one’s • Alignment with Critical Infrastructure Protection legislation • Definitions of sectors and subsectors for OES incl. managing authorities and their duties • Mandatory government CSIRTs for sectorial managing authorities, government outsourcing and last-resort option • Defining areas for future voluntary ‘win-win’ cooperation with the market instead of mandatory duties
  • 4. Different EU REGULATIONS • General Data Protection Regulation (GDPR) – 2016/679 – To strengthen and unify data protection for all individuals within the European Union (EU) – Regulator – Office for Personal Data Protection of the Slovak Republic • Payment Services Directive (PSD2) – 2015/2366 – To regulate payment services and payment service providers throughout the European Union (EU) – Regulator – National Bank of Slovakia • Regulatory framework for electronic communications – Telecoms Package (2009) – To create a common set of regulations for the telecoms industry across all 27 EU states – Regulator –Regulatory Authority for Electronic Communication and Postal Services • Network and Information Security Directive 2016/1148 – To force companies and organizations to protect their systems/data from cyber-attacks – Regulator – National Securty Authority
  • 5. Basic cyberspace activities • Cyber Crime – Responsible Ministry of Interior (police, crime investigators), prosecutors, courts • Cyber Defense – Ministry of Defense • Cyber Intelligence – Intelligence services • Cyber Security – National Security Authority – NIS transposition, – Cybersecurity regulation – Regulation of sectors/subsectors – Security standards, risk management, auditing, regulation, enforcement work – Incident reporting and handling – National Cybersecurity Centre and National CSIRT (SK-CERT) – Security Operation Centre
  • 6. Cybersecurity law in Slovakia Content of law •Definitions •Cybersecurity governance in Slovak republic, •National Cybersecurity Centre (and SK-CERT), •Integrated Cybersecurity Information System, •Duties and capacities of Operator of essential services and Digital service provider •CSIRT units and their accreditation, •Security requirements and incident notification and handling •Implementation and enforcement •Other procedures and bylaws •Update (alignment) of Critical Infrastructure Law with Cybersecurity Law •Definition of sectors and subsectors for OES
  • 7. Cyber Security Committee Cybersecurity governance in Slovakia Parliament National Cybersecurity Centre / SK-CERT Security Council Government Managing authority Sector/Subsector n National Security Authority Managing authority Sector/Subsector 2 Managing authority Sector/Subsector 1 CSIRT Sector 1 and 2 CSIRT Sector n CSIRT Commercial
  • 8. Definition of sectors and subsectors for OES Sector Subsector Managing authority CIP NIS CiiP Banking Ministry of Finance ☑️ ☑️ Transport Air transport Ministry of transport and construction ☑️ ☑️ ☑️ Rail transport ☑️ ☑️ ☑️ Water transport ☑️ ☑️ ☑️ Road transport ☑️ ☑️ ☑️ Digital Infrastructure National Security Authority ☑️ ☑️ Electronic Communication Satellite communication Ministry of transport and construction ☑️ ☑️ Electronic communications networks and electronic communications services ☑️ ☑️ Financial market infrastructures Ministry of Finance ☑️ ☑️
  • 9. Definition of sectors and subsectors for OES Sector Subsector Managing authority CIP NIS CIIP Postal services Ministry of transport and construction ☑️ ☑️ Energy Mining Ministry of Economy ☑️ ☑️ Electricity ☑️ ☑️ ☑️ Oil ☑️ ☑️ ☑️ Gas ☑️ ☑️ ☑️ Heat-power ☑️ Other Industries Pharmaceutical Ministry of Economy ☑️ ☑️ Metallurgical ☑️ ☑️ Chemical ☑️ ☑️ Health All medical facilities (incl. Hospitals and private clinics) Ministry of Health ☑️ ☑️ ☑️
  • 10. Definition of sectors and subsectors for OES Sector Subsector Managing authority CIP NIS CIIP Water and Atmosphere Weather service Ministry of the environment ☑️ ☑️ Water works ☑️ ☑️ Drinking water supply and distribution ☑️ ☑️ ☑️ Public Administration Public order and security Ministry of interior ☑️ Information systems of public administration Deputy Prime Minister’s Office for Investments and Informatization ☑️ ☑️ Defense Ministry of defense ☑️ Intelligence services Intelligence services ☑️ Classified Information Protection National Security Authority ☑️
  • 11. NIS transposition Timeline • July 2016 - NIS approval July • September 2016 - first internal draft • October 2016 - NIS Implementation international workshop, Bratislava • December 2016 – first round of public consultation • End of January, February 2017 – second round of public consultation • February 2017 – public workshop after second public consultation • March – May 2017 – third round of public consutations • Jun 2017 – official intra-ministerial commenting procedure • July – September 2017 – preparation of final version • October 2017 – approval by Slovak government • November 2017 – parliament procedure • January 2018 - approval of the law by parliament • March 1st , 2018 – entry into force