19.7.2016
Official Journal of the European Union
EN
L 194/15
(b) the list of services referred to in paragraph 3;
(c) the number of operators of essential services identified for each sector referred to in Annex II and an indication of
their importance in relation to that sector;
(d) thresholds, where they exist, to determine the relevant supply level by reference to the number of users relying on
that service as referred to in point (a) of Article 6(1) or to the importance of that particular operator of essential
services as referred to in point (f) of Article 6(1).
In order to contribute to the provision of comparable information, the Commission, taking the utmost account of the
opinion of ENISA, may adopt appropriate technical guidelines on parameters for the information referred to in this
paragraph.
Article 6
Significant disruptive effect
1.
When determining the significance of a disruptive effect as referred to in point (c) of Article 5(2), Member States
shall take into account at least the following cross-sectoral factors:
(a) the number of users relying on the service provided by the entity concerned;
(b) the dependency of other sectors referred to in Annex II on the service provided by that entity;
(c) the impact that incidents could have, in terms of degree and duration, on economic and societal activities or public
safety;
(d) the market share of that entity;
(e) the geographic spread with regard to the area that could be affected by an incident;
(f) the importance of the entity for maintaining a sufficient level of the service, taking into account the availability of
alternative means for the provision of that service.
2.
In order to determine whether an incident would have a significant disruptive effect, Member States shall also,
where appropriate, take into account sector-specific factors.
CHAPTER II
NATIONAL FRAMEWORKS ON THE SECURITY OF NETWORK AND INFORMATION SYSTEMS
Article 7
National strategy on the security of network and information systems
1.
Each Member State shall adopt a national strategy on the security of network and information systems defining the
strategic objectives and appropriate policy and regulatory measures with a view to achieving and maintaining a high
level of security of network and information systems and covering at least the sectors referred to in Annex II and the
services referred to in Annex III. The national strategy on the security of network and information systems shall address,
in particular, the following issues:
(a) the objectives and priorities of the national strategy on the security of network and information systems;