used in the further development of the National Security Authority's general security
work.
The National Security Authority shall issue a report to the undertaking on the results of
the inspection. The report shall only contain information which may help to improve the
undertaking's security.
The King may issue regulations on technical surveillance countermeasures, and
regulations authorising the performance of such inspections by parties other than the
National Security Authority.
Section 5-6.Cryptosecurity
Cryptosystems which are to be used to protect classified information must be approved by
the National Security Authority.
The National Security Authority is the national administrator of cryptomaterials and a
supplier of cryptosecurity services to undertakings. The National Security Authority may
approve other suppliers of cryptosecurity services.
The National Security Authority shall approve encryption algorithms used in equipment
intended for export.
The King may issue regulations on cryptosecurity.
Chapter 6. Information system security
Section 6-1.Critical national information systems
An information system is nationally critical if it handles critical national information or if
it is itself of vital importance to fundamental national functions.
The King may issue regulations on the identification of critical national information
systems.
Section 6-2.Protection of critical national information systems
Undertakings shall ensure an appropriate level of security for critical national information
systems, so that
a)
the information systems function as intended
b)
unauthorised persons do not gain access to information processed by the systems
c)
information processed by the systems is not altered or lost
11/30