NIS Directive: a higher common level of network and IT system security within the EU
Home Our blog Firma elettronica NIS Directive: a higher common level of network and IT system security within the EU
Discover best-in-class collaboration tools that drive your agile workplace.
Learn more about what you can accomplish with our solutions.
Broaden your offering through electronic signature integration.
Explore helpful resources around secure collaboration and more.
Discover who we are and why our solutions are used by more than one million users.
Home Our blog Firma elettronica NIS Directive: a higher common level of network and IT system security within the EU
Abonnez-vous pour connaรฎtre les derniรจres nouveautรฉs dโOodrive
The different strategies in place at a European level are a good place to start when it comes to raising awareness of cybersecurity within the European Union. The Network and Information Security (NIS) Directive, adopted in July 2016, is a perfect example of this.ย Member States have until May 9, 2018, to transpose the legislation into their national law.
โCybersecurity incidents often cross borders and affect more than one EU Member State. A fragmented approach to cybersecurity leaves us all vulnerable and poses a high security risk to Europe as a wholeโ Guillaume Poupard, Director General of the French National Cybersecurity Agency (ANSSI)
The NIS Directive aims to introduce measures designed to provide a higher common level of network and IT system security for every country in the EU. โNetwork and information systems and services play a vital role in society,โ according to the legislation. โTheir reliability and security are essential to economic and societal activities, and in particular to the functioning of the internal market.โ Under the legislation, there are new security requirements which a large number of private sector businesses as well as โoperators of essential servicesโ must comply with.
The new EU law is based on four major points:
The directive first seeks to help Member States build their own national capacities in cybersecurity. Each country must implement a national strategy setting out its strategic objectives, political measures, and appropriate regulations, with a view to โachieving a higher level of security of network and information systemsโ. EU Member States are also obligated to designate a national competent authority for cybersecurity (such as ANSSI in France) and national computer security incident response teams or CSIRTs (such as CERT-FR in France).
Cooperation is also a pivotal theme in the NIS Directive. Member States must be willing to cooperate on cybersecurity, something which will be ensured through the creation of a cooperation group and a European network of CSIRTs. The cooperation group is primarily responsible for promoting good practice on sharing information on incidents, as well as awareness and training. The network of national CSIRTs, on the other hand, will be charged with sharing technical information on risks and vulnerabilities.
Operators of essential services (entities which provide a service essential to maintaining vital societal and/or economic activities such as energy, transport, banking, and healthcare) and digital service providers (such as online marketplaces, search engines, and cloud service providers) are subject to specific rules on managing security risks and reporting serious incidents.
For operators of essential services, the legislation states that an incident could significantly disrupt the ability to provide those services. In order to comply with the requirements of the new EU directive, Member States must therefore ensure that these operators โtake appropriate and proportionate technical and organizational measures to manage the risksโ posed to the security of networks and information systems. These entities must also notify national authorities about any incident that has a significant impact on the continuity of essential services that they provide.
In France, issues related to the security of critical operators have already been addressed. The NIS Directive lays down provisions similar to Franceโs Military Programming Act (Loi de Programmation Militaire or LPM), but at a European level. The act establishes the security rules necessary for protecting essential operators. โThe list of essential operators covered by the NIS Directive is more comprehensive than the list of those in France set out by the LPM, which is something we welcome,โ declared Guillaume Poupard at the International Cybersecurity Forum in 2016. โThere are many essential operators which donโt appear on the list in the French act, and itโs good that the European directive casts a wider net.โ
Products
Oodrive sign free trial
Solutions by industry
Solutions by department
Abonnez-vous pour recevoir toutes les actualitรฉs autour du numรฉrique de confiance