19.7.2016
Official Journal of the European Union
EN
L 194/21
7.
Competent authorities acting together within the Cooperation Group may develop and adopt guidelines
concerning the circumstances in which operators of essential services are required to notify incidents, including on the
parameters to determine the significance of the impact of an incident as referred to in paragraph 4.
Article 15
Implementation and enforcement
1.
Member States shall ensure that the competent authorities have the necessary powers and means to assess the
compliance of operators of essential services with their obligations under Article 14 and the effects thereof on the
security of network and information systems.
2.
Member States shall ensure that the competent authorities have the powers and means to require operators of
essential services to provide:
(a) the information necessary to assess the security of their network and information systems, including documented
security policies;
(b) evidence of the effective implementation of security policies, such as the results of a security audit carried out by the
competent authority or a qualified auditor and, in the latter case, to make the results thereof, including the
underlying evidence, available to the competent authority.
When requesting such information or evidence, the competent authority shall state the purpose of the request and
specify what information is required.
3.
Following the assessment of information or results of security audits referred to in paragraph 2, the competent
authority may issue binding instructions to the operators of essential services to remedy the deficiencies identified.
4.
The competent authority shall work in close cooperation with data protection authorities when addressing
incidents resulting in personal data breaches.
CHAPTER V
SECURITY OF THE NETWORK AND INFORMATION SYSTEMS OF DIGITAL SERVICE PROVIDERS
Article 16
Security requirements and incident notification
1.
Member States shall ensure that digital service providers identify and take appropriate and proportionate technical
and organisational measures to manage the risks posed to the security of network and information systems which they
use in the context of offering services referred to in Annex III within the Union. Having regard to the state of the art,
those measures shall ensure a level of security of network and information systems appropriate to the risk posed, and
shall take into account the following elements:
(a) the security of systems and facilities;
(b) incident handling;
(c) business continuity management;
(d) monitoring, auditing and testing;
(e) compliance with international standards.