Security
On 1 August 2017 the NÚKIB (National Cyber and Information Security Agency) began operating in Brno, split off from the NBÚ (National Security Authority) by an amendment to the law. The institution is meant to provide expert help in the event of serious cyber threats to the state — protecting systems critical to the state (police, ministries, energy and so on), fighting cybercrime (in cooperation with the police), cryptographic protection and managing the non-public part of the Galileo satellite system. NÚKIB therefore does not exist to help individuals; that role belongs to CSIRT.
It currently has 119 employees — not only IT specialists, but lawyers, political scientists and theorists too — and could grow to as many as 400.
Legislation
This year and next will bring a whole series of significant changes that extend the existing IT legislation and will newly affect almost every organisation. Which are the main ones?
-
Minor amendment on cyber security — in force from 1 July 2017
- this is Act No. 104/2017 Coll., which amends Act No. 181/2014 Coll.
- it newly sets out the definition of an operator of information and communication systems and its obligations
- it governs the relationship between the operator and the administrator
- it increases the penalties for breaching those obligations
-
Major amendment on cyber security — in force from 1 August 2017
- Act No. 205/2017 Coll., which amends Act No. 181/2014 Coll.
- a response to EU Directive 2016/1148 — NIS (Network and Information Security), on measures for a high common level of security of network and information systems across the Union
- it newly defines two groups of obliged entities:
- operators of essential services
- healthcare, transport, and the energy and chemical industries, for example
- digital service providers
- search engines, online stores, cloud computing services
- exactly which entities are covered will follow from impact criteria to be defined in a further decree, along with additional requirements on providers setting out which security measures they must implement
- it establishes NÚKIB (the National Cyber and Information Security Agency)
-
GDPR — in force from 25 May 2018
- the EU regulation on the protection of natural persons with regard to the processing of personal data and on the free movement of such data
- this is a legal standard that absolutely every company will have to meet (protecting both employee and client data)
- requirements placed on institutions and organisations
- implementing data protection by design and by default
- introducing pseudonymisation of personal data
- keeping records of processing activities
- consulting the supervisory authority before processing personal data
- appointing a data protection officer, or DPO
- thanks to it, EU citizens gain considerably more rights and more ability to influence how their personal data is processed
- where these conditions are not met, the GDPR introduces heavy penalties
-
the European ePrivacy Regulation
- will clarify the GDPR’s requirements in the context of electronic communications