For each concept you see the term used in the national act, a verbatim quote from the law and the exact provision. Every quote comes from our legal knowledge base and links to the official source.
Risk management
Term in the law: cybersecurity risk-management measures
Provision: S.L. 460.41, article 19
n systems acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption
View official source
Incident notification
Term in the law: notification
Provision: S.L. 460.41, article 7
where applicable, a list of the Member States where they provide services falling within the scope of this order. (5) The essential or important entities shall notify the CIP Department about any changes to the details submitted in accordance with sub-article (4) without delay and, in any event, within two (2) weeks of the d
View official source
Essential and important entities
Term in the law: essential entities / important entities
Provision: S.L. 460.41, article 4
4. (1) For the purposes of this order, the following entities shall be considered to be essential entities: (a) entities of a type indicated in the First Schedule which exceed the ceilings for medium-sized enterprises provided for in accordance with Article 2(1) of
View official source
Supply chain security
Term in the law: supply chain security
Provision: S.L. 460.41, article 19
is and information system security; (b) incident handling; (c) business continuity, such as backup management and disaster recovery, and crisis management; (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers; (e) security in network and
View official source
Management body
Term in the law: management bodies
Provision: S.L. 460.41, article 18
18. (1) The CIP Department, or where designated the competent authority, shall ensure that management bodies of such essential and important entities approve the cybersecurity risk- management measures in accordance with article 19 and oversee their implementation. Th
View official source
Supervision
Term in the law: competent authority (CIP Department, national supervisory authority)
Provision: S.L. 460.41, article 7
7. (1) The CIP Department shall be the national supervisory authority responsible for monitoring the implementation of this order at national level and ensuring compliance therewith, implementing relevant provisions of this order
View official source
Conformity assessment
Term in the law: assess the effectiveness of cybersecurity risk-management measures; risk assessments
Provision: S.L. 460.41, article 19
ty in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption
View official source
Training
Term in the law: cybersecurity training
Provision: S.L. 460.41, article 19
ndling and disclosure; (f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (g) basic cyber hygiene practices and cybersecurity training; (h) policies and procedures regarding the use of cryptography and, where appropriate, encryption; (i) human resources security, insider risk management policy
View official source