dokumendiregister.ee
OtsingAsutusedMCP
dokumendiregister.eeAsutusedEesti avalike dokumendiregistrite otsing · nimistu.ee andmetel
Otsing›Tarbijakaitse ja Tehnilise Järelevalve Amet
Sissetulev kiriAvalik

Kiri

Tarbijakaitse ja Tehnilise Järelevalve Amet · 12. märts 2020
Viit
17-13/2020/0626
Registreeritud
12. märts 2020
Dokumendi liik
Sissetulev kiri
Adressaat
Majandus- ja Kommunikatsiooniministeerium
Saabumis/saatmisviis
e-post
Funktsioon
17 Elektrooniline side 2020 - ...
Sari
17-13 Raadioseadmete tehniliste nõuetega seotud kirjavahetus
Toimik
17-13/2020
Vastutaja
Maret Ots (Kasutajad, Sideosakond, Sagedushalduse talitus)

Failid

  • 📎hispaania eelõu.pdf803 KB
  • 📎hispaania_teatis.pdf388 KB

Sisu (failidest)

1. ------IND- 2019 0637 E-- EN- ------ 20200113 --- --- PROJET ROYAL DECREE XX/20XX IMPLEMENTING ROYAL DECREE-LAW 12/2018 OF 7 SEPTEMBER 2018 ON THE SECURITY OF INFORMATION NETWORKS AND SYSTEMS Royal Decree-Law 12/2018 of 7 September 2018 on the security of information networks and systems transposes Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union, and in its third final provision, grants the government the power to implement the provisions of said Royal Decree-Law into law. To fulfil this mandate, with the aim of developing and fleshing out aspects considered in the aforementioned Royal Decree-Law, this Royal Decree is now adopted, featuring five chapters and five additional provisions, four final provisions and one annex. To meet this objective, this Royal Decree completes the designation of competent authorities for the security of information networks and systems, as per Royal Decree- Law 12/2018 of 7 September 2018, by specifying those corresponding to essential service operators that are not considered critical operators and that do not fall under Law 40/2015 of 1 October 2015 on the Public Sector Legal Framework, with attention to the strategic sectors indicated in Law 8/2011 of 28 April 2011 laying down measures for the protection of critical infrastructure. Moreover, this Royal Decree implements the cases for cooperation and coordination between the reference CSIRTs, which occur over the National Cyber- incident Reporting and Monitoring Platform. In particular, it implements the provisions of the Royal Decree-Law in situations affecting operators with an impact on national defence, and the actions indicated for particularly serious cases that require a higher level of coordination than that required in ordinary situations, as well as the action required when the activities of the reference CSIRTs may affect a critical operator in some way. The liaison duties of the role of single point of contact, specified in Directive (EU) 2016/1148, are performed to ensure cross-border cooperation with the competent authorities of other European Union Member States, as well as with the cooperation group and the CSIRT network. These duties of the National Security Council, as the single point of contact, are in addition to the duties to coordinate the activities of the competent authorities, assigned under Royal Decree-Law 12/2018. This Royal Decree also implements the provisions of Royal Decree-Law 12/2018 on the measures needed to meet the security obligations on the part of operators of essential services, which must be detailed in a statement of applicability of security measures signed by the information security officer of the operator, whose duties are also set out in this Royal Decree. With regard to incident reporting, the Royal Decree implements the reporting obligations on operators of essential services for incidents that may have a significant disruptive impact on said services, and incidents that may affect the information networks and systems used to provide the essential services, even if they have not had a real adverse impact on them, by way of reference to the impact and threat levels, depending on the case at hand, provided for in the National Incident Reporting and Management Instruction in the annex. 1 The incident reporting procedure is carried out by means of the National Cyber- incident Reporting and Monitoring Platform, to enable the exchange of information between operators of essential services and digital service providers, the competent authorities and the reference CSIRTs, with guaranteed confidentiality, integrity and availability for the information. Finally, with regard to security compliance supervision, the Royal Decree imposes the obligation on operators of essential services and digital service providers to cooperate with the competent authorities, which may also require collaboration with the reference CSIRTs in the performance of their supervisory role. The additional provisions of this Royal Decree include the legal framework applicable to the Bank of Spain in light of its special legal status as a public-law entity with its own legal personality and full public and private capacity, which acts independently of the Public Administration in performing its activities and meeting its goals, and as an integral part of the European System of Central Banks (ESCB) and the Single Supervisory Mechanism (SSM). This special legal status means that the security framework for information networks and systems applies to the extent that it does not interfere with the nature, duties and independence of the Bank of Spain. This Royal Decree has undergone the procedure for the provision of information in relation to technical regulations and of rules related to Information Society services provided for in Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015 laying down a procedure for the provision of information in the field of technical regulations and of rules on Information Society services, and in Royal Decree 1337/1999 of 31 July 1999 regulating the provision of information in the field of technical standards and regulations and of rules on Information Society services. Moreover, this regulation is in accordance with the principles for sound regulation set out in Article 129 of Law 39/2015 of 1 October 2015 on Common Administrative Procedures in Public Administration, under which the Public Authorities must act in the exercise of legislative initiative, particularly the principles of necessity, effectiveness, proportionality, legal certainty, transparency and efficiency. This Royal Decree is adopted by virtue of the exclusive powers granted to the State over matters of the general telecommunications system and public safety by Article 149(1)(21 and 29) of the Constitution. This Royal Decree, resulting from intense dialogue and collaboration between the various Ministerial Departments and stakeholder agencies, was drafted after consultation with organisations representing the affected sectors. Therefore, at the joint proposal of the Minister for Economy and Business, the Minister for the Interior and the Minister for Defence, with prior approval from the Minister for Territorial Policy and Public Administration, in accordance with the Council of State and following deliberation by the Council of Ministers at its meeting of …. 2 THE FOLLOWING IS DECREED: CHAPTER I General provisions Article 1. Aim and scope. 1. This Royal Decree is intended to implement Royal Decree-Law 12/2018 of 7 September 2018 on the security of information networks and systems. In particular, it is intended to: a) designate the competent authorities in matters of information network and system security for operators of essential services that are not considered critical operators and that do not fall under the scope of Law 40/2015 of 1 October 2015 on the Public Sector Legal Framework; b) implement cooperation and coordination between the competent authorities and the reference CSIRTs over the National Cyber-incident Reporting and Monitoring Platform, provided for in Article 11 of this Royal Decree; c) set out the duties of the single point of contact; d) specify the measures needed to meet the security obligations on operators of essential services and digital service providers; e) set out the duties of information security officers for operators of essential services; f) adopt the National Incident Reporting and Management Instruction. 2. The scope of this Royal Decree is detailed in Article 2 of Royal Decree- Law 12/2018 of 7 September 2018, without prejudice to the provisions of Article 18 of said Royal Decree-Law. Article 2. Definitions 1. For the purposes of this Royal Decree, ‘competent authorities’ shall mean the authorities indicated in Article 9 of Royal Decree-Law 12/2018 of 7 September 2018, and Article 3 of this Royal Decree. 2. The other terms used in this Royal Decree shall have the meanings given in Royal Decree-Law 12/2018 of 7 September 2018. CHAPTER II Strategic and institutional framework Article 3. Competent authorities. 1. The following parties shall be the competent authorities for the operators of essential services that are not critical operators as per Article 9(1)(a)(2º) of Royal Decree-Law 12/2018 of 7 September 2018: a) for the transport sector: the Ministry of Public Works, via the Secretariat of State for Infrastructure, Transport and Housing; 3 b) for the energy sector: the Ministry for the Ecological Transition, via the Secretariat of State for Energy; c) for the information technology and telecommunications sector: the Ministry of the Economy and Business, via the Secretariat of State for Digital Advancement; d) for the finance and taxation sector: i. the Ministry of the Economy and Business, via the Secretariat of State for the Economy and Business Support, for insurance providers; ii. the Bank of Spain, for credit institutions; iii. the National Securities Market Commission, for investment service providers and for management firms for collective investment institutions; e) for the space sector: the Ministry of Defence, via the General Secretariat for Defence Policy; f) for the chemical industry sector: the Ministry of the Interior, via the Secretariat of State for Security; g) for the research facilities sector: the Ministry of Science, Innovation and Universities, via the Secretariat of State for Universities, Research, Development and Innovation; h) for the health sector: the Ministry of Health, Consumer Affairs and Social Welfare, via the General Secretariat for Health and Consumer Affairs; i) for the water sector: the Ministry for the Ecological Transition, via the Secretariat of State for the Environment; j) for the food sector: i. the Ministry of Agriculture, Fisheries and Food, via the General Secretariat for Agriculture and Food; ii. the Ministry of Health, Consumer Affairs and Social Welfare, via the General Secretariat for Health and Consumer Affairs; iii. the Ministry of Industry, Trade and Tourism, via the Secretariat of State for Trade; k) for the nuclear sector: i. the Ministry for the Ecological Transition, via the Secretariat of State for Energy; ii. the Nuclear Security Council. 2. Without prejudice to the provisions of Chapter IV on cybersecurity incident management, the competent authorities may issue a ministerial order or circular, depending on the case, to establish appropriate communication channels with operators of essential services and digital service providers to supervise the security and incident reporting requirements applicable to these parties. These ministerial orders or circulars may also include action protocols for coordination with reference CSIRTs. Article 4. Cooperation and coordination with reference CSIRTs 1. Cooperation amongst the reference CSIRTs and between them and the competent authorities shall be handled over the National Cyber-incident Reporting and Monitoring Platform. 4 2. For the purposes of the cooperation referred to in Article 11(1)(a)(3º) of Royal Decree-Law 12/2018 of 7 September 2018, ‘operators with an impact on national defence’ shall be providers of basic services essential to the functioning of the Ministry of Defence or to the effectiveness of the Armed Forces established by the National Commission for the Protection of Critical Infrastructure at the proposal of the Ministry of Defence. The National Commission for the Protection of Critical Infrastructure shall report designation of an operator with an impact on National Defence to the operator pursuant to the provisions of Royal Decree 704/2011 of 20 May 2011 adopting the Regulation on protection of critical infrastructure. Wherever possible, the designation shall be reported immediately. In addition, the reference CSIRTs shall be informed of the operators of essential services in their community that are designated as operators with an impact on National Defence. The Ministry of Defence shall provide the National Commission for the Protection of Critical Infrastructure with updates on changes of operators providing these services, which shall prompt the corresponding notifications of registration or deregistration as operators with an impact on National Defence to both the operators themselves and their reference CSIRTs. 3. ‘Particularly serious cases’ as referred to in the first paragraph of Article 11(2) of Royal Decree-Law 12/2018 of 7 September 2018, in which the CERT of the National Cryptography Centre [CCN-CERT] shall provide national coordination for the technical response of the CSIRTs, shall be all cases with a very high or critical impact or threat level as per the provisions of the annex, in view of the nature of the initial or subsequent incident reports received by the reference CSIRT, and that require a level of technical coordination with other CSIRTs that is higher than that required in ordinary situations. The National Cybersecurity Council, which may act through its Standing Committee, shall be informed immediately and may cancel the coordination provided for in this article, which shall not affect the incident reporting process in Articles 11 and 19(1 and 2) of Royal Decree-Law 12/2018 of 7 September 2018. 4. The CCN-CERT (in the case as per the preceding paragraph) or the Cybersecurity Coordination Office (in the cases as per the second paragraph of Article 11(2) of Royal Decree-Law 12/2018 of 7 September 2018) shall request at least the following information from the reference CSIRT after the initial incident report: a) confirmation that the incident details are correct, with specific verification of any of the following details that are available: i. incident classification; ii. incident threat level; iii. incident impact; b) any action plan of the CSIRT to arrive at a technical solution for the incident; c) any information for determining the potential cross-border impact of the incident. Wherever possible, the National Cyber-incident Reporting and Monitoring Platform shall be used for the communications referred to in this paragraph. 5. If an operator with an impact on National Defence is affected by an incident, it shall analyse its scope to determine if it could affect the functioning of the Ministry of Defence or the effectiveness of the Armed Forces. If so, it shall report this immediately to its reference CSIRT, which shall inform the Spanish Defence CERT [ESP DEF CERT] through the established channels. In such cases, the ESP DEF CERT shall be properly kept up-to-date on incident management progress. 5 Article 5. Single point of contact. 1. Pursuant to Article 13 of Royal Decree-Law 12/2018 of 7 September 2018, the National Security Council shall perform the following duties via the National Security Department: a) provide the European Commission with the list of national operators of essential services identified for each sector and subsector referred to in Article 6 of Royal Decree-Law 12/2018 of 7 September 2018, and inform the single points of contact of other States of its intent to identify an operator of essential services of another Member State that offers services in Spain; b) forward information on incidents with cross-border impact from the competent authorities or reference CSIRTs to the contacts in other European Union Member States, pursuant to Article 25 of Royal Decree-Law 12/2018 of 7 September 2018; c) relay the corresponding information on incidents that may have a disruptive impact on essential services from the contacts in the corresponding Member States to the reference CSIRTs and competent national authorities, so they can take appropriate measures according to their respective duties; d) issue relevant instructions to the competent authorities to draft the annual report referred to in Article 27(1) of Royal Decree-Law 12/2018 of 7 September 2018, on the type and number of incidents reported, their impact on the services provided or on other services and their national or cross-border nature within the European Union, in accordance with the indications of the cooperation group on the form and content of the information provided; e) request that the competent authorities submit the annual report referred to in the preceding subparagraph and draft an annual report summarising the incident reports received, which it shall forward to the cooperation group before 15 February of each year and, subsequently, to the competent authorities and the reference CSIRTs, for their information. 2. In addition to the liaison duties provided for in the preceding subparagraph, and pursuant to Article 9(2) of Royal Decree-Law 12/2018 of 7 September 2018, the National Security Council, via its special cybersecurity committee, shall ensure coordination of the activities of the competent authorities by: a) promoting consistency between any special security requirements adopted by the competent authorities, pursuant to Article 6(4) of this Royal Decree; b) promoting consistency between any special obligations adopted by the competent authorities, pursuant to Article 8(3) of this Royal Decree; c) supporting coordination of the regulations and activities of the competent authorities and the activities of the reference CSIRTs with the information security regulations and activities of the data protection and public safety authorities. 3. Similarly, the National Security Council shall perform the coordination duties as per paragraph 2 above in the cases as per Article 18 of Royal Decree-Law 12/2018 of 7 September 2018. 6 CHAPTER III Security requirements Article 6. Measures for compliance with security obligations 1. Operators of essential services and digital service providers shall take suitable and proportionate technical and organisational measures to manage risks to the security of the information networks and systems used when providing the services, for both their own networks and systems and those of third-party providers. 2. Operators of essential services shall adopt security policies for information networks and systems, taking into account the principles of comprehensive security, risk management, prevention, response and recovery, lines of defence, periodic reassessment and segregation of duties. These policies shall consider at least the following aspects: a) risk analysis and management; b) third-party or provider risk management; c) catalogue of physical, technological, organisational and security measures; d) HR and professionalism; e) acquisition of security products or services; f) incident detection and management; g) operational continuity assurance and recovery plans; h) continuous improvement; i) system interconnectivity; j) user activity logging. 3. The security measures adopted by operators of essential services shall take into account, in particular, dependencies of information networks and systems and the continuity of services or supplies contracted by the operator, and interactions with third- party information networks and systems. The measures adopted shall be detailed in a document entitled ‘Statement of Applicability of security measures’, which shall be signed by the information security officer designated as per the following article. This document, which shall be submitted to the relevant competent authority within six months after designation of the operator as an operator of essential services, shall be updated at least once every three years. The relevant competent authority shall supervise both the initial Statement of Applicability of the security measures and its subsequent updates, pursuant to Article 14 of this Royal Decree. 4. The measures referred to in the preceding paragraphs shall take those in Annex II to Royal Decree 3/2010 of 8 January 2010 governing the National Security Framework as a reference where applicable, and shall be based on other pre-existing national security frameworks wherever possible. Without prejudice to the above, other recognised international standards may also be taken into account. 5. The measures adopted may be supplemented with other measures, based on specific needs. In particular, they shall be supplemented with any special measures adopted by the competent authority, pursuant to Articles 16(4) and 32(2) of Royal Decree-Law 12/2018 of 7 September 2018. 7 Article 7. Information security officer 1. Pursuant to Article 16(3) of Royal Decree-Law 12/2018 of 7 September 2018, operators of essential services shall designate an information security officer to perform the duties of the contact and technical coordination with the competent authority pursuant to this Royal Decree. 2. Operators of essential services shall designate and notify the relevant competent authority of the information security officer within three months after their designation as operators of essential services, as well as any appointments and dismissals affecting the information security officer designation within 30 days after their occurrence. 3. The information security officer shall act as a point of contact with the competent authority for supervision of the security requirements for information networks and systems, and as a special point of contact for coordination of incident management with the reference CSIRT. Pursuant to Article 16(3) of Royal Decree-Law 12/2018 of 7 September 2018, this officer shall be responsible for performance of at least the following duties: a) develop security policies and submit them to the organisation for adoption, pursuant to Article 6(2) of this Royal Decree, which shall include suitable and proportionate technical and organisational measures to manage risks to the security of information networks and systems used and to minimise the impact of cyber-incidents affecting the organisation and the services, pursuant to the provisions of Article 6 of this Royal Decree; b) supervise and develop implementation of security policies, standards and procedures derived from the organisation, supervise their effectiveness and conduct periodic security audits; c) draft the ‘Statement of Applicability of security measures’ document referred to in the second paragraph of Article 6(3) of this Royal Decree; d) serve as a trainer for good practices in information network and system security, for both hardware and software aspects; e) provide the competent authority, via the reference CSIRT and without undue delay, with reports on incidents with a disruptive impact on the provision of services, as referred to in Article 19(1) of Royal Decree-Law 12/2018 of 7 September 2018; f) receive, interpret and supervise the implementation of instructions and guides issued by the competent authority, both for normal operation and for correction of identified shortcomings; g) compile, prepare and submit information or documentation to the competent authority or the reference CSIRT, at its request or at the officer’s own initiative. The information security officer may use third-party services in the performance of his or her duties. 8 4. Operators of essential services shall ensure that the information security officer meets the following requirements: a) support from personnel with suitable expertise and experience in cybersecurity, from organisational, technical and legal perspectives, to perform the duties specified in the preceding paragraph; b) access to the resources needed to perform these duties; c) hold a position in the organisation that facilitates performance of his or her duties, and participate in a proper and timely manner in all matters related to security, and maintain real and effective communication with upper management; d) maintain proper independence from information network and system managers. 5. If the requirements for knowledge, experience, independence and any applicable level of education are met, the duties and responsibilities entrusted to the information security officer may be combined with those indicated for the Security and Liaison Officer, the Data Protection Officer or the Security Officer under the National Security Framework, pursuant to the regulations applicable to these roles. CHAPTER IV Security incident management Article 8. Security incident management 1. Operators of essential services and digital service providers shall manage and resolve security incidents that affect the information networks and systems used when providing their services, for both their own systems and networks and those of third-party providers. This obligation covers both incidents detected by the operator or provider itself and those reported by the reference CSIRT or the competent authority, if they are aware of any circumstances that raise suspicions of an incident. 2. Without prejudice to Article 28(1) of Royal Decree-Law 12/2018 of 7 September 2018, operators of essential services and digital service providers may request specialised support from the reference CSIRT for incident management, in which case they shall heed the instructions it provides to resolve the incident, mitigate its impact and restore the affected systems. 3. In incident resolution, operators of essential services shall apply the relevant aspects of the security management policy for information networks and systems as per Article 6 of this Royal Decree, and the special obligations imposed by the competent authorities. 4. In addition, operators shall take into account incidents that may affect their own information networks and systems as well as those of third-party providers that may interact with their own, even if the latter are digital services providers falling under this Royal Decree. Article 9. Incident reporting obligations on operators of essential services 1. Operators of essential services shall notify the relevant competent authority, via the reference CSIRT, of incidents that may have a significant disruptive impact on 9 these services, which for these purposes shall be incidents with a critical, very high or high impact, as specified in Section 4 of the National Incident Reporting and Management Instruction, given in the annex to this Royal Decree. In addition, they shall report any events or incidents which, due to their threat level, may affect information networks and systems used to provide essential services, even if they have not yet had an actual adverse impact on these. For these purposes, these incidents shall be those with a critical, very high or high threat level, as specified in Section 3 of said Instruction. 2. Without prejudice to the above, the competent authorities may impose special obligations, pursuant to Article 19(5) of Royal Decree-Law 12/2018 of 7 September 2018, that set levels different from those in the National Incident Reporting and Management Instruction, as well as sector-specific factors and thresholds, applicable to operators subject to supervision. Article 10. Incident reporting procedures 1. The reference CSIRTs shall ensure a smooth exchange of information with the relevant competent authorities, ensuring proper monitoring during incident management, and access to the information used in the various stages of incident management. 2. Operators of essential services shall submit reports via the designated information security officer. If an operator of essential services meets the criteria set out in Article 6(2) of Royal Decree-Law 12/2018 of 7 September 2018 on the security of information networks and systems, the information security officer shall coordinate this with the Security and Liaison Officer as per Article 16 of Law 8/2011 of 28 April 2011, setting out measures to protect critical infrastructure. 3. Operators of essential services shall submit an initial report as soon as they have the information to establish that circumstances warrant reporting, in view of the relevant factors and thresholds, and in any case within no more than 48 hours after they become aware that the incident occurred. Interim reports shall be provided as needed to update or supplement the information in the initial report, and to report on incident progress, until it is resolved, followed by a final incident report after resolution, with detailed information on the development of the event, assessment of the likelihood of recurrence and any corrective measures the operator plans to take. 4. Where available, reports shall include information for determining any cross- border effects from the incident. 5. The provisions in the paragraphs above shall apply to digital service providers not otherwise regulated under the implementing act provided for in Article 16(9) of Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union. 6. The reference CSIRT, in collaboration with the competent authority, shall assess this information promptly to determine if the incident could have a significant disruptive impact on the essential services provided in other European Union Member States, in which case the single point of contact shall report this to the affected Member States. In addition, along with the relevant reference CSIRT, the competent authority shall assess information from other Member States on incidents with potential cross- 10 border impacts, and shall report this and forward the relevant information to any operators of essential services that may be affected. Article 11. National Cyber-incident Reporting and Monitoring Platform 1. In partnership with the INCIBE-CERT and the ESP DEF CERT, the CCN-CERT shall make the National Cyber-incident Reporting and Monitoring Platform available to all stakeholders. 2. The platform shall enable secure and reliable information exchange and incident monitoring between operators of essential services or digital services provides, the competent authorities and reference CSIRTs, without prejudice to the special requirements applicable for personal data protection. 3. Moreover, this platform shall ensure information availability, authenticity, integrity and confidentiality, and shall be usable to meet the reporting requirement under sector regulations, pursuant to Article 19(5) of Royal Decree-Law 12/2018 of 7 September 2018. 4. The platform shall also feature various communication channels for use by the competent authorities and the reference CSIRTs. The platform shall ensure access for the competent authorities to all information related to the report and the current status of incidents in their areas of competency, so they can conduct the necessary monitoring and supervision of incident progress at all times. Similarly, the platform shall provide the competent authorities with access to statistical data, in particular those necessary to generate the reports indicated in Article 5 of this Royal Decree. 5. In addition, the platform shall implement the incident reporting and management procedure with 24/7 availability, with at least the following capabilities: a) cyber-incident management with incorporation of type, criticality and third- party reports, as per the annex; b) exchange of information on cyber-threats; c) sample analysis; d) vulnerability logging and reporting; e) secure communication between parties involved in different forms and on different platforms; f) bulk data exchange; g) generation of aggregate reports and statistics. Article 12. Incident information 1. Where circumstances permit, the reference CSIRTs shall provide operators of essential services and digital service providers that submit reports with the relevant information for incident report monitoring, in particular information that may facilitate effective incident management. 2. In addition, the competent authorities and the reference CSIRTs shall provide operators of essential services and digital service providers that may be affected by these incidents with any information that may be relevant to incident prevention and/or resolution. 3. When providing the information as per the above paragraphs, the competent authorities and the reference CSIRTs shall protect the commercial interests of operators 11 of essential services and digital service providers by maintaining the confidentiality of the information they receive from these providers wherever possible, pursuant to Article 15 of Royal Decree-Law 12/2018 of 7 September 2018. Article 13. Action in response to allegedly criminal incidents 1. As soon as possible and in accordance with Article 262 of the Code of Criminal Procedure, the Cybersecurity Coordination Office of the CNPIC shall notify the State prosecution service, by way of the Judicial Police, of any security incidents reported to it that are criminal in nature, with concurrent submission of the information available on the incident. To this end, it may request any information related to the incident that it deems necessary from the affected operators or the reference CSIRTs. 2. The consultations provided for in Article 14(1) of Royal Decree-Law 12/2018 of 7 September 2018, on public safety and security, shall be conducted through the Cybersecurity Coordination Office. CHAPTER V Supervision Article 14. Supervision of security requirements 1. Within their areas of activity, the competent authorities shall supervise compliance with any security and incident reporting obligations applicable to operators of essential services and digital service providers pursuant to Royal Decree- Law 12/2018 of 7 September 2018 and this Royal Decree. Operators of essential services and digital service providers shall collaborate with the competent authority in this supervision, by facilitating inspection activities, providing any and all information requested to this effect, and heeding any instructions issued to correct identified shortcomings. Compliance with security obligations for information networks and systems may be attested by certification under a security scheme recognised by the competent authority. The competent authorities may conduct the inspection activities required in the performance of their supervisory duties. In particular, the inspection activities of the competent authorities shall be intended to: a) verify compliance with any technical standards and instructions applicable to operators subject to supervision; b) verify performance of the duties of the information security officer designated by operators of essential services, pursuant to Article 7(3) of this Royal Decree; c) conduct the checks, inspections, tests and reviews necessary to verify compliance with the security measures provided for in Article 6, in particular the security policy of operators of essential services and the Statement of Applicability of security measures. Pursuant to Article 32(1) of Royal Decree-Law 12/2018 of 7 September 2018, where advisable given the required volume or complexity of inspection activities, the competent authorities may require an operator of essential services to submit an audit report, prepared by an independent and financially solvent third-party entity, on the security of its information networks and systems. 12 2. The reference CSIRTs shall collaborate with the competent authorities, where the latter requests such, in the performance of the duties referred to in the preceding paragraph. In particular, they shall provide technical advice on the suitability of security measures taken by the operators of essential services and digital service provides by virtue of Article 6 of this Royal Decree. In addition, in cases of operators with an impact on National Defence as per Article 4(2) of this Royal Decree, the ESP DEF CERT may collaborate with the competent authority in this supervision. 3. In cases of digital service providers, this shall be coordinated with the corresponding competent authorities of the European Union Member States where these providers provide services or have their main establishment in the EU. First additional provision. References to competent authorities The references to Ministries, bodies and entities given in Article 3 of this Royal Decree shall apply to those that replace these or take on their powers in the future. Second additional provision. Designation of information security officer by designated operators of essential services Operators of essential services designated as per the first additional provision of Royal Decree-Law 12/2018 of 7 September 2018 shall notify the relevant competent authority of the identity of the information security officer within three months after entry into force of this Royal Decree. Third additional provision. Guidelines for incident management and compliance with reporting obligations The National Security Council, at the proposal of its special cybersecurity committee, and with its duties as single point of contact set out by the National Security Department, shall adopt guidelines on the National Incident Reporting and Management Instruction included in the annex, and to update the National Cyber-incident Reporting and Management Guide, which provide guidelines and recommendations for meeting the reporting obligations under this Royal Decree, and Royal Decree-Law 12/2018 of 7 September 2018, to improve coordination and optimise the resources dedicated to managing incidents that affect information network and system security. These guidelines may be complied into a National Cybersecurity Incident Reporting and Management Guide. Fourth additional provision. Special regime for the Bank of Spain The provisions of this Royal Decree shall apply without prejudice to the powers and duties granted to the Bank of Spain, the European Central Bank and the European System of Central Banks, in accordance with the Treaty on the Functioning of the European Union, the Statutes of the European System of Central Banks and of the European Central Bank, Council Regulation (EU) No 1024/2013 of 15 October 2013 and Law 13/1994 of 1 June 1994 on the Autonomy of the Bank of Spain. Where not covered in its special regulations and where compatible with its nature, duties and independence, the provisions of this Royal Decree shall apply to the Bank of Spain. 13 Fifth additional provision. Cases of dependence on third-party providers With regard to Article 19(3) of Royal Decree-Law 12/2018 of 7 September 2018, if operators of essential services or digital service providers depend on third-party providers subject to the ninth addition provision of Law 34/2002 of 11 July 2002 on information society and e-commerce services, the competent CERT for the third-party provider shall be: - the CCN-CERT of the National Cryptography Centre [CCN], if the provider falls under the scope of Law 40/2015 of 1 October 2015; - the INCIBE-CERT of the Spanish National Cybersecurity Institute [INCIBE], in all other cases. First final provision. Powers of regulatory implementation The Minister for the Economy and Business, the Minister for the Interior and the Minister for Defence, as well as the Ministers and bodies indicated in Article 3, shall be authorised, either jointly or separately depending on the subject matter, to issue the provisions required to implement and apply this Royal Decree within their respective areas of competency. Second final provision. Powers to amend the annex The National Security Council shall be authorised to amend the annex, at the proposal of its special cybersecurity committee, by way of an agreement published by an order of the Ministry of the Presidency. Third final provision. Attribution of powers. This Royal Decree is issued under the provisions of subparagraphs 21 and 29 of Article 149(1) of the Constitution, which grant the State exclusive powers over matters of the general telecommunications system and public safety, respectively. Fourth final provision. Entry into force This royal decree shall enter into force on the day after its publication in the Official State Gazette. Madrid, [day] [month] 2020. 14 ANNEX National Cyber-incident Reporting and Management Instruction 1. Reporting obligation Incidents shall be assigned to one of the threat and impact levels given in this Instruction, taking into account the reporting obligation for all incidents categorised as CRITICAL, VERY HIGH or HIGH for all obligated parties subject to this National Cyber-incident Reporting and Management Instruction. In such cases, they shall report incidents logged in their information networks and systems in a proper and timely manner and shall report any impact or threat levels that exceed the thresholds given in this Instruction. The reference criterion for cybersecurity incident reporting shall be the threat level assigned to an incident, without prejudice to the fact that during its development, mitigation and resolution, the incident will be categorised with a certain impact level which may make it advisable to report the incident to the competent authority or the reference CSIRT. In any case, if a particular event may be assigned more than one incident type due to its potential characteristics, it shall be assigned the type with the highest threat level according to the criteria given in this Instruction. 2. Classification/types of cyber-incidents The following Classification/Types of cyber-incidents shall be used to assign a specific type to an incident logged in an information network or system during reporting to the competent authority or the reference CSIRT. CLASSIFICATION/TYPES OF CYBER-INCIDENTS Classification INCIDENT TYPE Description and practical examples Unsolicited mass emails. The recipient of the Spam content did not grant valid authorisation to receive a collective message. Defamatory or discriminatory content. Abusive Hate crime E.g.: cyberbullying, racism, threats to a person or content directed at groups. Child pornography, Material that visually depicts content related to child inappropriate sexual pornography, incitement of violence, etc. or violent content System infected with malware. E.g.: System, Infected system computer or mobile phone infected with a rootkit C&C server Connection to Command and Control (C&C) server (Command and via malware or infected systems. Harmful Control) content Resource used to spread malware. E.g.: resource Malware distribution of an organisation used to spread malware. Resource that hosts malware on configuration files. Malware configuration E.g.: webinject attack for Trojan. 15 Sending requests to a system to uncover possible vulnerabilities. This also includes verification and Network scanning testing processes to collect data on hosting, services and accounts. E.g.: DNS, ICMP and SMTP requests, port scanning. Data gathering Packet analysis Network traffic monitoring and recording. (sniffing) Collection of personal information without using Social engineering technology. E.g.: lies, trickery, bribes, threats. Attempt to compromise a system or interrupt a Exploitation of known service by exploiting vulnerabilities with a vulnerabilities standardised identifier (see CVE). E.g.: buffer overflows, back-doors, cross-site scripting (XSS). Intrusion attempt Attempted access Multiple attempts to breach credentials. E.g.: with breach of attempts to crack passwords, brute force attacks. credentials Unknown attack Attack using an unknown exploit. Compromise of Compromise of a system in which the attacker has account with acquired privileges. privileges Compromise of Compromise of a system using accounts without account without privileges. Intrusion privileges Compromise of Compromise of an application by exploiting applications software vulnerabilities. E.g.: SQL injection. Physical intrusion. E.g.: unauthorised access to a Theft Data Processing Centre. Denial of service attack. E.g.: sending requests to a DoS (Denial of web application to cause a service interruption or Service) delay. Distributed denial of service attack. E.g.: SYN DDoS (Distributed packet flood, reflection and amplification attacks Denial of Service) using UDP-based services. Availability Improper software configuration causing service Misconfiguration availability problems. E.g.: DNS server with obsolete KSK for the DNSSEC root zone Physical sabotage. E.g.: cutting of hardware cables Sabotage or arson. Interruptions with external causes. E.g.: natural Interruptions disaster. Unauthorised access to data. E.g.: theft of access Data Unauthorised data credentials by intercepting traffic or accessing compromise access physical documents. 16 Unauthorised data modification. E.g.: an attacker Unauthorised data uses stolen credentials to modify a system or modification application or uses ransomware to encrypt data. Loss of information. E.g.: loss due to hard drive Data loss failure or physical theft. Use of resources for inappropriate purposes, Unauthorised use of including profit-seeking activities. E.g.: use of email resources to participate in pyramid schemes. Offering or installing unlicensed software or other Copyright copyrighted material. E.g.: Warez. Fraud Type of attack where an entity impersonates Impersonation another for unlawful gain. Impersonating another entity to trick the user into Phishing disclosing private credentials. Publicly accessible services that may feature weak Weak encryption encryption. E.g.: web servers susceptible to POODLE/FREAK attacks. Publicly accessible services that can be used to DDoS amplification reflect or amplify DDoS attacks. E.g.: open DNS resolvers or NTP servers with monlist monitoring. Services with Vulnerable potential undesired E.g.: Telnet, RDP or VNC. access Public access to services that could potentially Data disclosure disclose sensitive data. E.g.: SNMP or Redis. Vulnerable system. E.g.: client proxy Vulnerable system misconfiguration (WPAD), outdated system versions. Any incidents not falling under the above Other categories. Attacks targeting specific organisations based on Other highly sophisticated means of concealment, anonymity and persistence. This threat typically APT uses social engineering techniques to achieve objectives, along with the use of known or authentic attack procedures. Table 1. Classification/types of cyber-incidents 3. Cyber-incident threat level The threat indicator determines the potential danger that the occurrence of an incident poses in the information or communication systems of the affected entity, and for the services provided or, where applicable, business continuity. This indicator is based on characteristics intrinsic to the type of threat and its behaviour. Incidents shall be assigned one of the following threat levels: CRITICAL, VERY HIGH, HIGH, MEDIUM, LOW. 17 Critical level:  APT Very high level:  Malware distribution  Malware configuration  Theft  Sabotage  Interruptions High level:  Child pornography, inappropriate sexual or violent content  Infected system  C&C server (Command and Control)  Compromise of applications  Compromise of accounts with privileges  Unknown attack  DoS (Denial of Service)  DDoS (Distributed Denial of Service)  Unauthorised data access  Unauthorised data modification  Data loss  Phishing Medium level:  Hate speech  Social engineering  Exploitation of known vulnerabilities  Attempted access with breach of credentials  Compromise of accounts without privileges  Misconfiguration  Unauthorised use of resources  Copyright  Impersonation  Weak encryption  DDoS amplification  Services with potential undesired access  Data disclosure  Vulnerable system Low level:  Spam  Network scanning  Packet analysis (sniffing)  Other 18 4. Cyber-incident impact level The cyber-incident impact indicator shall be determined by assessing the consequences that the cyber-incident has had on the duties and activities of the affected organisation, on its assets or on the affected individuals. This process takes into account aspects such as potential or actual consequences of a specific threat on an information and/or communication system, as well as on the affected entity itself (public or private entities, and individuals). The criteria used to determine the impact level assigned to a cyber-incident are based on the following parameters:  impact on Public Safety and Security;  impact on the provision of an essential service or on critical infrastructure;  types of information or systems affected;  level of impact on the facilities of the organisation;  potential interruption to the normal provision of services for the organisation;  internal and external time and costs to restore the facilities to normal operation;  financial losses;  geographic area affected;  associated damage to reputation. Incidents shall be assigned one of the following impact levels: CRITICAL, VERY HIGH, HIGH, MEDIUM, LOW, NO IMPACT. Critical level:  significant impact on National Security;  impact on civilian security, with a potential threat to human life;  impact on Critical Infrastructure;  impact on systems classified as SECRET;  impact on over 90% of the systems of the organisation;  interruption in provision of services longer than 24 hours or for over 50% of users;  resolution of the cyber-incident requires over 100 person-days;  economic impact of over 0.1% of current GDP;  cross-border impact;  very serious damage to reputation and continuous international media coverage. Very high level:  impact on civilian security, with a potential threat to property;  significant impact on official activities or missions abroad;  impact on essential services;  impact on systems classified as PRIVILEGED;  impact on over 75% of the systems of the organisation;  interruption in provision of services for over 8 hours or over 35% of users;  resolution of the cyber-incident requires between 30 and 100 person-days;  economic impact of between 0.07% and 0.1% of current GDP;  geographic extent exceeds four autonomous communities or one special interest territory;  damage to national reputation and image (Spanish brand);  serious damage to reputation and continuous national media coverage. 19 High level:  impact on over 50% of the systems of the organisation;  interruption in provision of services for over 1 hour or over 10% of users;  resolution of the cyber-incident requires between 5 and 30 person-days;  economic impact of between 0.03% and 0.07% of current GDP;  geographic extent exceeds three autonomous communities;  damage to reputation that is difficult to repair, with media attention (extensive media coverage) and impact on reputation of third parties. Medium level:  impact on over 20% of the systems of the organisation;  interruption in provision of services for over 5% of users;  resolution of the cyber-incident requires between 1 and 5 person-days;  economic impact of between 0.001% and 0.03% of current GDP;  geographic extent exceeds two autonomous communities;  significant damage to reputation, with media attention (extensive media coverage). Low level:  impact on the systems of the organisation;  interruption to provision of a service;  resolution of the cyber-incident requires less than 1 person-day;  economic impact of between 0.0001% and 0.001% of current GDP;  geographic extent exceeds one autonomous community;  isolated damage to reputation, without media attention. No impact:  no significant impact. 5. Information to report to the competent authority in cases of incidents In the initial report, the obligated party shall include information for all fields in the table below of which the party is aware at the time, and shall later complete all of the table fields in the final incident report. What to report Description A sentence providing a general description of the incident. Matter This will be a legacy field in all reports related to the incident. Name of operator of essential services or digital service OES/DSP provider. Strategic sector Energy, transport, finance, etc. Indicate, as precisely as possible, when the cyber-incident Incident time and date occurred. 20 Time and date Indicate, as precisely as possible, when the cyber-incident incident detected was detected. Description Describe what happened in detail. Provide the technical information on the number and type of Technological assets affected by the cyber-incident, including IP resources affected addresses, operating systems, applications, versions, etc. Indicate the cause of the incident, if known. Opening a Origin of incident suspicious file, connection of a USB device, access to a malicious website, etc. Possible type and classification of the cyber-incident Type (classification) according to the indicated types. Threat level Indicate the threat level assigned to the incident. Impact level Indicate the impact level assigned to the incident. Indicate whether the incident has a cross-border impact on Cross-border impact any European Union Member State. Actions taken so far in response to the cyber-incident. Action plan and Indicate the Action Plan applied and countermeasures countermeasures taken. Indicate whether the party affected is a company or Parties affected individual, and the impacts according to the assigned impact level. Means needed for resolution (person- Capacity used to resolve the incident in person-hours. hours) Estimated financial Costs associated with the incident, both direct and indirect. impact (if known) Geographic extent (if Municipality, autonomous community, national, international, known) etc. Damage to reputation Impact on corporate image of operator. (if known) Provide a list of documents attached to help determine the Attachments cause of the problem or resolve it (screenshots, data logs, emails, etc.). Regulations affected National Security Framework [ENS]/GDPR/NIS/CIP/other Does it require law Yes/no enforcement action? Table 2. Information to report to the competent authority in cases of incidents 6. Reporting timeframe All obligated parties affected by an incident that must be reported to the competent authority, via the reference CSIRT, shall submit the required initial, interim and final 21 reports, in a proper and timely manner, according to the reporting timeframes given below.  The initial report consists in alerting the authorities to the existence of an incident.  The interim report updates the authorities with the latest available information related to the incident.  The final report supplements and confirms the final information related to the incident. Nevertheless, the obligated party shall submit any and all additional interim or subsequent reports that it deems necessary. Threat and impact Initial report Interim report Final report level CRITICAL Immediately 24/48 hours 20 days VERY HIGH Immediately 72 hours 40 days HIGH Immediately - - MEDIUM - - - LOW - - - Table 3. Reporting timeframe The times given in Table 3 for ‘interim’ and ‘final’ reports apply starting from the time of submission of the ‘initial’ report. The ‘initial’ report timeframe applies starting from the time when the party became aware of the incident. 7. Terms and definitions ABUSIVE CONTENT  Unsolicited mass emails (SPAM): Unsolicited emails sent to a large number of users, or a high number of emails sent to the same user over a short period of time.  Bullying: With regard to virtual bullying or cyberbullying, the use of digital means of communication to bully a person or group of people, by way of personal attacks or divulging private, personal or false information.  Extortion: Use of violence or intimidation to force a person or business to commit or refrain from acts with the intention to damage this party, or to profit from the results.  Offensive messages: Unexpected or unwanted communication, and actions or behaviours that harm the dignity, reputation or self-esteem of another person.  Offence: Any act classified as an offence according to Organic Law 10/1995 of 23 November 1995 of the Criminal Code.  Paedophilia: Any behaviour related to those described in Title VIII of the Criminal Code, concerning the grooming or use of minors or persons with disabilities in need of special protection for acts that threaten their sexual integrity or freedom.  Racism: Any criminal offence including offences against persons or property, where the victim, location or target of the offence was chosen due to its real or perceived connection to, sympathy or affiliation with, support of or membership in a social group, race, religion or sexuality.  Inciting violence: Presentation, before a gathering of people or any other method of dissemination, of ideas or beliefs that praise the crime or extol its perpetrator. 22 HARMFUL CONTENT  Malware (harmful code): This term is derived from the words ‘malicious’ and ‘software’. Any software that performs actions such as data extraction or another type of modification of a system can be categorised as malware. Thus, the term ‘malware’ encompasses various types of harmful programmes.  Viruses: Type of malware whose main objective is to change the behaviour of a computer system without user permission. Viruses are spread by the execution of software, files or documents with a harmful payload on a system, with the ability to replicate itself from one system to another. The most common methods of infection are removable devices, online downloads and email attachments. Nevertheless, viruses may also be spread by online scripts, documents and XSS vulnerabilities. It should be noted that a virus requires human action to spread, unlike other malware, such as worms.  Worm: Malicious software whose main feature is its ability to spread rapidly. It is intended to replicate itself to new systems to infect them and keep replicating itself to other IT hardware, by any means, such as email, IRC, FTP, P2P and other special or widely used protocols.  Trojan: Type of malware disguised as legitimate software to trick the victim into installing it on their system. Once installed, the harmful software can perform the malicious activity in the background. A Trojan does not depend on a human action and cannot replicate itself, but it can cause serious harm to a system as a Trojan or by exploiting software vulnerabilities.  Spyware: Type of malware that spies on user activities without their awareness or consent. This may include keylogging, monitoring, data gathering and data theft. Spyware can spread via Trojans or software exploits.  Rootkit: A collection of harmful software that enables privileged access to areas of a machine, while at the same time concealing its presence by corrupting the Operating System or other applications. Here, the term ‘machine’ covers the full spectrum of IT systems, from smartphones to ICS. Thus, rootkits are intended to effectively conceal payloads and enable their existence in the system.  Dialler: Type of malware installed on a machine that automatically dials premium- rate telephone numbers without user consent. These actions incur financial costs for the victim by charging for the calls made.  Ransomware: This term encompasses malware that infects a machine and prevents the user from accessing the data stored on the system. Normally, the victim then receives some form of communication demanding payment of a ransom in order to access the system and the locked files.  Malicious bot: ‘Botnet’ is a term used to refer to a collection of machines controlled remotely with generally malicious intent. A bot is malicious software that receives orders from a main attacker who controls the machine remotely. C&C servers allow the attacker to control bots and execute orders given remotely.  RAT: An acronym for ‘Remote Access Tool’, this refers to special remote control functionality of an information system that is integrated into certain malware families or samples.  C&C: Short for ‘Command and Control’, these are command and control panels (also known as C2s) that cyber-criminals use to control specific zombie machines infected with samples of the same malware family. Command and control panels serve as a point of reference, control and management for infected machines.  Suspicious connection: Any exchange of information over a local or public network whose origin or destination – and legitimacy – are not fully determined. 23 DATA GATHERING  Port scanning: Use of software for local or remote analysis of the status of the ports of a machine connected to a network. This action is intended to gather information for identification of active services and potential vulnerabilities on the network.  Network scanning: Use of software for local or remote analysis of the status of a network. This action is intended to gather information for identification of active services and potential vulnerabilities on the network.  Technology scanning: Use of software for local or remote analysis of the technologies present or available on a specific network or information system, to obtain the references of the hardware/software present, as well as their versions, and potential vulnerabilities.  DNS zone transfer (AXFR IXFR): DNS server transaction used to replicate databases between a primary server and secondary servers. These transactions may be authoritative (AXFR) or incremental (IXFR).  Packet analysis (sniffing): Use of software to analyse traffic on a network to gather information. An attacker can collect and read unencrypted traffic.  Social engineering: Techniques intended to obtain sensitive information from a target, generally using persuasive methods, against the will and without the knowledge of the victim.  Phishing: Fraud committed using telematic means where the scammer attempts to obtain confidential information (passwords, banking details, etc.) from legitimate users by fraudulent means using social engineering.  Spear Phishing: A form of phishing where the attacker focuses on a specific target. INTRUSIONS  Exploit: Any practice where a cyber-criminal harms an information and/or communication system for unlawful purposes or without proper authorisation.  SQL injection: Type of exploit involving the introduction of malformed SQL strings or strings that the recipient is not expecting or cannot properly control; these cause unexpected results in the target application or program and allow the attacker to produce unexpected effects without authorisation on the target system.  Cross-Site Scripting XSS (Direct or Indirect): Attack intended to exploit a vulnerability in web applications, where the attacker injects malformed statements or injects strings that the recipient is not expecting or cannot properly control.  Cross-Site Request Forgery (CSRF): This is a type of harmful website exploit where unauthorised commands are sent by a user that the website trusts. This vulnerability is also known as XSRF, hostile linking, one-click attacks, session riding and automatic attacks. Unlike XSS attacks, which exploit a user’s trust in a particular site, Cross-Site Request Forgery exploits a website’s trust in a particular user.  Defacement: Type of website attack that changes the visual appearance of a webpage. These attacks typically use techniques such as SQL injections or some kind of vulnerability in the page or server.  File inclusion (RFI and LFI): Vulnerability that allows an attacker to display or execute remote files stored on other servers due to a programming error on the page that contains file inclusion functions. Local File Inclusion (LFI) is similar to the remote file inclusion vulnerability, but instead of including remote files, it can only include local files, i.e. files on the current server for execution. 24  Control system evasion: Process used by a malware sample or a collection of actions orchestrated by a cyber-criminal to harm or evade security systems or policies implemented by specific information and communication systems.  Pharming: IT attack that exploits DNS server vulnerabilities. When a user attempts to access the website, the browser automatically redirects the user to an IP address hosting a malicious website that replaces the real one, where the attacker can obtain sensitive information from the user.  Brute force attack: Process that an attacker uses to harm a validation system based on access credentials, a password, etc., by trying all possible combinations, to access information and/or communication systems for which the attacker does not have privileges or authorisations.  Dictionary attack: Process that an attacker uses to harm a validation system based on access credentials, a password, etc., by using a previously generated dictionary with specific character combinations, to access information and/or communication systems for which the attacker does not have privileges or authorisations.  Access credential theft: Unauthorised access to or theft of access credentials for information and/or communication systems. AVAILABILITY  DoS (Denial of Service): Group of techniques intended to render a server inoperative. This type of attack attempts to overload a server to prevent legitimate users using the services it provides. This attack consists in flooding the server with service requests until it cannot respond to them, resulting in its collapse.  DDoS (Distributed Denial of Service): DoS variant where requests are submitted to the same destination in a coordinated manner from multiple points. This uses networks of bots, generally without the knowledge of users.  Misconfiguration: Software configuration errors directly associated with loss of service availability.  Sabotage/terrorism/vandalism: Attacks intended to interrupt or degrade provision of a service, causing significant harm to service continuity for an institution or significant damage to reputation, committed for ideological, political or religious reasons.  Disruption without malicious intent: Actions that may interrupt or degrade provision of a service, causing significant harm to service continuity for an institution or significant damage to reputation.  SYN or UDP flood: Methods used to perform DoS or DDoS attacks consisting in initiating a high volume of sessions to prevent the server responding to legitimate requests.  Open DNS Resolver: DNS server that can resolve recursive DNS lookups from any point of origin on the internet. Malicious users often use this server type to conduct DDoS attacks. DATA COMPROMISE  Unauthorised access to data or cyber-spying: Process that an unauthorised user employs to access and view unauthorised content.  Unauthorised data modification: Process that an unauthorised user employs to access and modify unauthorised content.  Unauthorised data deletion: Process that an unauthorised user employs to access and delete unauthorised content. 25  Data exfiltration: Process that an unauthorised user employs to disseminate information in channels or sources where sharing this information is not planned or authorised.  Unauthorised access to systems: Process that the user employs to access an information and/or communication system without proper authorisation or without tacit or express approval, but without harming any services, systems or networks.  POODLE/FREAK attack: Process that makes a server use an unintended and insecure communication protocol to exfiltrate information. FRAUD  Unauthorised use of resources: Use of technologies and/or services by users that are not properly authorised by the competent Management or company.  Identity theft: Malicious activity where an attacker pretends to be a different person to commit some form of fraud or harassment.  Intellectual property rights: Intellectual property is the collection of rights falling to authors and other owners (artists, producers, broadcasters, etc.) for the works and performances they create.  Other fraud: Financial trickery intended to gain a benefit, and that results in harm to someone. VULNERABILITIES  Vulnerable technology: Vulnerabilities in technologies, services or networks that are known to their administrators.  Precarious security policy: Deficient security policy for an organisation, allowing cyber-criminals to gain unauthorised access, that cannot be reliably determined, to information systems during a specific period of time. OTHER  Cyber-terrorism: Computer crimes as per Articles 197 bis and ter and 264 to 264 quater of Organic Law 10/1995 on the Criminal Code where these crimes are committed for the purposes specified in Article 573(1) of said law. These purposes are to: - subvert constitutional order or eliminate or seriously destabilise the functioning of the political institutions or the social or economic structures of the State, or force public authorities to perform or refrain from a particular action; - seriously disturb public peace; - seriously destabilise the functioning of an international organisation; - provoke a state of terror in the general public or a part thereof.  CIP computer damage: Computer crimes as per Article 264(2)(3 and 4) of Organic Law 10/1995 on the Criminal Code related to the deletion, damaging, modification, suppression or inaccessibility of data, computer programs or electronic documents for Critical Infrastructure, and serious misconduct related to the above that affects the provision of an Essential Service.  APT (Advanced Persistent Threat)/AVT (Advanced Volatile Threat): Attacks targeting specific organisations based on highly sophisticated means of concealment, anonymity and persistence. This threat typically uses social 26 engineering techniques to achieve objectives, along with the use of known or authentic attack procedures.  DGA domains: Procedure for dynamic generation of domains to host Command and Control servers, a technique used in botnets to evade enforcement.  Cryptography: Technique consisting in encrypting a message, known as ‘plaintext’, by converting it into an encrypted message or ‘ciphertext’, which cannot be read without the key used to encrypt it.  Proxy: Intermediate computer, usually a server, used to communicate between two other machines, normally in a manner this is transparent to the user. GENERAL  Cybersecurity: Field of security dealing with crimes committed in cyberspace and their prevention.  Cyberspace: Virtual space encompassing all IT and communication systems, including both information systems and industrial control systems. Cyberspace is based on the availability of the internet as the network of networks, supplemented with other data transport networks.  Information networks and systems: This term refers to any of the following three objects: - an electronic communications network in the sense of Article 2(a) of Directive 2002/21/EC; - any device that automatically processes digital data by means of a program, or any group of interconnected or interrelated devices in which one or more devices do so; - digital data that are stored, processed, retrieved or transmitted using the aforementioned elements for their functioning, use, protection or maintenance.  Information network and system security: the ability of information networks and systems to withstand, to a particular degree of reliability, any action that compromises the availability, authenticity, integrity or confidentiality of the data stored, transmitted or processed, or the corresponding services provided by or accessible via such information networks and systems.  Operator of essential services: a public or private entity of one of the types indicated in Annex II that meets the criteria set out in Article 5(2) of Directive (EU) 2016/1148 of the European Parliament and of the Council.  Digital service: a service in the sense of Article 1(1)(b) of Directive (EU) 2015/1535 of the European Parliament and of the Council that is of one of the types indicated in Annex III.  Digital service provider: any legal person that provides a digital service.  Cyber-incident: any act with a real adverse impact on the security of information networks and systems.  Cyber-incident management: all procedures applied to detect, analyse, limit and respond to an incident.  Cyber-threat: Threat to the systems and services present in cyberspace or accessible from it.  Types: Classes or groups of subjects or objects with shared characteristics.  GDPR: General Data Protection Regulation, Regulation EU 2016/679. 27  OpenPGP: Standard based on the PGP program (Pretty Good Privacy), intended to protect information using public-key cryptography, and facilitate document authentication using digital signatures.  Web inject: Free open-source tool mainly designed to automate testing of web applications and web services.  Telnet: Network protocol that enables access to another machine for remote management as if the user were seated at it.  RDP: Remote Desktop Protocol. Proprietary protocol developed by Microsoft that enables communication to execute an application between a Windows server and a terminal.  VNC (Virtual Network Computing): Free software program based on a client- server structure that enables remote observation of server actions via a client computer.  SNMP (Simple Network Management Protocol): Network protocol used to exchange messages for network device management.  Redis: In-memory database engine, based on storage in hash tables.  ICMP: Internet Control Message Protocol.  Clean backup: Secure and uncompromised restoration point for a system. 28 Maret Ots Saatja: Karl Stern <[email protected]> Saatmisaeg: esmaspäev, 9. märts 2020 13:25 Adressaat: Mart Laas; Maret Ots Teema: teatis Manused: 2019637E.DOCX Tere Saadan Hispaania teatise 637 „KUNINGLIK DEKREET XX/20XX, MILLEGA RAKENDATAKSE 7. SEPTEMBRI 2018. AASTA KUNINGLIKKU DEKREET-SEADUST 12/2018, VÕRGU- JA INFOSÜSTEEMIDE TURVALISUSE KOHTA“. Ooteaeg lõpeb juba 16.03. KUNINGLIK DEKREET XX/20XX, MILLEGA RAKENDATAKSE 7. SEPTEMBRI 2018. AASTA KUNINGLIKKU DEKREET- SEADUST 12/2018, VÕRGU- JA INFOSÜSTEEMIDE TURVALISUSE KOHTA Eelnõu puudutab oluliste ja teatavate digiteenuste osutamist eri valdkondades, sealhulgas kosmosetööstuses, valitsuses, keemia- ja tuumatööstustes, uurimisasutustes ja toiduainetööstuses. Dekreedi eesmärk on tõsta peamistes majandus- ja sotsiaalvaldkondades oluliste teenuste osutamiseks kasutatavate võrgu- ja infosüsteemide turvalisust, mille puhul on üha enam vahejuhtumeid, mis on mõnikord nii tõsised, et mõjutavad oluliselt nende teenuste osutamist ja toovad märkimisväärset kahju ohustatud kasutajatele. Dekreetseaduses 12/2018 võrgu- ja infosüsteemide turvalisuse kohta võetakse üle Euroopa Parlamendi ja nõukogu 6. juuli 2016. aasta direktiiv (EL) 2016/1148 meetmete kohta, millega tagada võrgu- ja infosüsteemide turvalisuse ühtlaselt kõrge tase kogu liidus, ning selle kolmandas lõppsättes antakse valitsusele volitused rakendada seaduses eespool nimetatud kuningliku dekreetseaduse sätteid. Kooskõlas ülaltooduga täiendatakse selle dekreediga 7. septembri 2018. aasta kuningliku dekreedi 12/2018 alusel võrgu- ja infosüsteemide turvalisuse osas pädevate asutuste määramist, tehes kindlaks need asutused, mis vastavad oluliste teenuste osutajatele ja keda ei peeta esmatähtsaks ning kes ei kuulu 1. oktoobril 2015. aasta avaliku sektori õiguslikku raamistikku käsitleva seaduse 40/2015 kohaldamisalasse, pöörates tähelepanu 28. aprilli 2011. aasta seaduses 8/2011 osutatud strateegilistele sektoritele, millega kehtestatakse meetmed esmatähtsa infrastruktuuri kaitseks. Peale selle rakendatakse dekreediga standardsete CSIRTide (küberturbe intsidentide lahendamise üksuste) vahelist koostööd ja koordineerimist juhtumite puhul, mis kuuluvad küberjuhtumite teavitamise ja järelevalve riikliku platvormi pädevusalasse. Eelkõige rakendatakse sellega kuningliku dekreedi sätteid olukordades, mis mõjutavad riikliku julgeolekuga seotud ettevõtjaid, samuti meetmeid, mis on ette nähtud eriti tõsiste juhtumite korral, mis nõuavad suuremat kooskõlastamist kui tavaolukorrad, samuti tegevuses, kus see on hädavajalik standardsete CSIRTide tegevuste jaoks, mis võivad esmatähtsat ettevõtjat kuidagi ohustada. 1
Allikas: Tarbijakaitse ja Tehnilise Järelevalve Amet dokumendiregister →