o
o
o
o
6
products and services. In the short term, the
government will advocate the adoption of
mandatory certification for specific product groups.
That is, for products where the risk is greatest or
products that have many problems in practice. In the
long term, there must be a gradual expansion of
mandatory certification or compliance with a CE
mark for all internet-connected products should be
implemented.
In addition, the Netherlands will encourage the
adoption of international standards, partnerships
and frameworks. The Netherlands wants to
proactively join relevant European and global
standardisation and certification initiatives through
the NEN standardisation platform. The Netherlands
is also going pursue multilateral cooperation on
standardisation for the Internet of Things, amongst
others through the Global Forum on Cyber Expertise
(GFCE).
Together with public and private parties, the
government will develop a monitoring system with
information about the digital security of digital
products, with specific attention to Internet of Things
devices. The government will include international
experiences in this.
The government will enter into discussions with
internet access providers about how they will
contribute to combating insecure Internet of Things
devices – analogues to the successful approach to
botnets. Product testing is crucial to gain assurances
on the digital security of devices. Based on use cases
from various sectors, a pilot will be launched to gain
knowledge and understanding on what a shared
testing platform can offer.
The development and commercialisation of
innovative solutions can make an important
contribution to making hardware and software
digitally secure. Through the National Cyber Security
Research Agenda III (NCSRA III), which is due to be
published in 2018, the Netherlands will pursue the
development of cybersecurity research aimed at the
development and commercialisation of innovative
solutions. In addition, various research tenders that
o
o
o
SBIR benut de creativiteit van ondernemers om maatschappelijke problemen op te lossen en daagt ondernemers uit om nieuwe producten te ontwikkelen en op de
markt te brengen, zie https://www.rvo.nl/subsidies-regelingen/sbir.
7
o
contribute to new, innovative, digitally secure
hardware and software are ongoing as a result of
application of the Small Business Innovation
Research (SBIR)6. Furthermore, the government
encourages open-source encryption by making
additional resources available for this within the
framework of NCSRA III. Finally, the government will
organise dialogue sessions on innovative solutions to
keep hardware and software secure or whether some
solutions should be discontinued. This also refers to
objectives under Ambition 5.
Liability is an important financial incentive for
suppliers to make and keep their hardware and
software secure. The government is discussing focus
areas, areas of improvement and potential solutions
for liability with regard to digitally insecure hardware
and software with stakeholders and academics. In
addition, the Netherlands is actively participating in
the liability and new technologies experts group and
involves the contribution of Dutch stakeholders in
this process. Furthermore, in the negotiations on the
Proposal for a Directive on Digital Content and
Digital Services, the Netherlands proposes to include
an obligation to make security updates mandatory in
all cases involving software supplied to a consumer.
Setting minimum security requirements can keep
insecure products off the market. The government
will investigate which minimum requirements could
be set for devices through the European Radio
Equipment Directive.7
The government will investigate what additional
measures are needed and desirable for the digital
security of hardware and software when procured by
central government.
Supervision and enforcement encourages suppliers
to comply with laws and regulations. The
government will organise a national dialogue session
for supervisory bodies to see what role they can play
in the near future to promote the digital security of
hardware and software, to create synergy between
the various activities of the supervisory bodies and to
examine how cooperation between supervisory
bodies can be improved.
Kamerstuk 26643, nr. 467 en Kamerstuk 24095, nr. 415.
28 | National Cyber Security Agenda A cyber secure Netherlands