NIS2 glossary of legal terms

For each concept you see the term used in the national act, a verbatim quote from the law and the exact provision. Every quote comes from our legal knowledge base and links to the official source.

Risk management

Term in the law: cybersecurity risk-management measures

Provision: S.L. 460.41, article 19

n systems acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption

View official source

Incident notification

Term in the law: notification

Provision: S.L. 460.41, article 7

where applicable, a list of the Member States where they provide services falling within the scope of this order. (5) The essential or important entities shall notify the CIP Department about any changes to the details submitted in accordance with sub-article (4) without delay and, in any event, within two (2) weeks of the d

View official source

Essential and important entities

Term in the law: essential entities / important entities

Provision: S.L. 460.41, article 4

4. (1) For the purposes of this order, the following entities shall be considered to be essential entities: (a) entities of a type indicated in the First Schedule which exceed the ceilings for medium-sized enterprises provided for in accordance with Article 2(1) of

View official source

Supply chain security

Term in the law: supply chain security

Provision: S.L. 460.41, article 19

is and information system security; (b) incident handling; (c) business continuity, such as backup management and disaster recovery, and crisis management; (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers; (e) security in network and

View official source

Management body

Term in the law: management bodies

Provision: S.L. 460.41, article 18

18. (1) The CIP Department, or where designated the competent authority, shall ensure that management bodies of such essential and important entities approve the cybersecurity risk- management measures in accordance with article 19 and oversee their implementation. Th

View official source

Supervision

Term in the law: competent authority (CIP Department, national supervisory authority)

Provision: S.L. 460.41, article 7

7. (1) The CIP Department shall be the national supervisory authority responsible for monitoring the implementation of this order at national level and ensuring compliance therewith, implementing relevant provisions of this order

View official source

Conformity assessment

Term in the law: assess the effectiveness of cybersecurity risk-management measures; risk assessments

Provision: S.L. 460.41, article 19

ty in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption

View official source

Training

Term in the law: cybersecurity training

Provision: S.L. 460.41, article 19

ndling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption; (i) human resources security, insider risk management policy

View official source

Frequently asked questions

Which NIS2 terms are defined in the law of Malta?

S.L. 460.41 defines, among others: cybersecurity risk-management measures; notification; essential entities / important entities; supply chain security; management bodies; competent authority (CIP Department, national supervisory authority); assess the effectiveness of cybersecurity risk-management measures; risk assessments; cybersecurity training. Each term is shown with a verbatim quote from the law and the exact provision.

Back to home