(EU) No. 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ 2012 L 316, p. 12). Article 3. Cyber Security Principles 1. Cyber security is based on the following key cyber security principles: 1) non-discrimination of cyber space, which means that the provisions of legislation are applied and benefits are stored both in physical and cyber space equally; 2) management of cyber security risk, which means that the applicable cybersecurity measures must ensure that regularly assessed risks of cyber security entities are captured; 3) proportionality of cyber security, which means that legal, organisational and technical cyber security measures, which are applied, shall not restrict the activities of cyber security entities in cyber space more than required; 4) supremacy of public interest, which means that the applicable cyber security measures shall first guarantee the protection of public interest, however, shall not, in principle, infringe on consumer rights or limit their freedom in cyber space proportionally; 5) standardisation and technological neutrality, which means that when implementing cyber security measures, cyber security entities shall be encouraged to follow the national, the EU and other international communications and information systems’ cyber security standards and specification, without demanding to apply any specific type of technology and without giving it the priority; 6) subsidiarity, which means that cyber security entities, which operate information systems and use them for the provision of services, are responsible for cyber security of information systems as well as for services which are provided using such systems. In the areas which fall within the exclusive competence of cyber security entities, the authorities which develop and implement cyber security policy shall take measures solely when cyber security of the communications and information systems and services provided using such systems cannot be ensured by cyber security entities which manage such systems and use them for the provision of services. 2. When applying legal provisions which regulate cyber security, consideration shall be taken of the principles set forth in Article 3(1). These principles shall be inter-aligned and coordinated; neither of them shall be given priority or prevalence.

Select target paragraph3