Book
Directiva (UE) 2022/2555 privind măsuri pentru un nivel comun ridicat de securitate cibernetică în Uniune
by Parlamentul European și Consiliul Uniunii Europene · 2022 · 1 reading card · public domain
1 card
Directiva (UE) 2022/2555 privind măsuri pentru un nivel comun ridicat de securitate cibernetică în Uniune · 2022
Management approves the measures and answers for them: NIS2 no longer leaves security at the level of the technical department.
Directive (EU) 2022/2555, NIS2 for short, is transposed in Romania by Emergency Ordinance 155/2024, published in the Official Gazette no. 1332 of 31 December 2024; the competent authority is the National Cyber Security Directorate. Covered entities split into essential and important, and the difference lies in the supervisory regime and the ceiling on fines, not in the set of measures. Article 21 requires appropriate and proportionate measures, on an all-hazards approach, and lists ten minimum categories: risk analysis, incident handling, continuity, supply chain security, secure acquisition and development, assessment of effectiveness, cyber hygiene and training, cryptography, human resources security and access control, multi-factor authentication. Article 23 sets the tempo: early warning within 24 hours, notification within 72, final report within one month. Article 20 says the management body approves the measures and can be held liable.
“Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services.”