a) which types of information may or must be registered, stored and analysed in connection with the monitoring b) who shall have access to information which is registered and stored in connection with the monitoring c) how access is to be granted to registered or stored information d) that information pursuant to the first and second paragraphs shall be subject to different storage period than five years. Section 6-5.Penetration testing of critical national information systems An undertaking may ask the National Security Authority to attempt to penetrate its critical national information systems. The purpose must be to check whether security measures are adequate. The undertakings' employees must be informed that such a check may be performed. If the check entails the processing of personal data, this shall not be more extensive than necessary for the purpose. Information to which the check provides access may only be used for the purpose of the check. When the information is no longer required, it shall be erased. Knowledge and experience acquired by the National Security Authority through the penetration testing may be used in the further development of the National Security Authority's general security work. The National Security Authority shall issue a report to the undertaking on the results of the check. The report shall only contain information which may help to improve the undertaking's security. The King may issue regulations on the penetration of critical national information systems, and regulations authorising the performance of such checks by parties other than the National Security Authority. Section 6-6.Communication and content monitoring of information systems An undertaking may ask the National Security Authority to check whether its information systems process classified information beyond the scope permitted by the system's security approval. The undertakings' employees must be informed that such a check may be performed. The National Security Authority may perform the check by intercepting and reading information which is processed by or sent between information systems. 13/30

Select target paragraph3