Document Generated: 2022-06-22
Status: This is the original version (as it was originally made).
(6) The competent authorities designated under paragraph (1) and the Information Commissioner
must have regard to the national strategy that is published under regulation 2(1) when carrying out
their duties under these Regulations.
Designation of the single point of contact
4.—(1) GCHQ is designated as the SPOC on the security of network and information systems
for the United Kingdom.
(2) The SPOC must—
(a) liaise with the relevant authorities in other Member States, the Cooperation Group and the
CSIRTs network to ensure cross-border co-operation;
(b) consult and co-operate, as it considers appropriate, with relevant law-enforcement
authorities; and
(c) co-operate with the NIS enforcement authorities to enable the enforcement authorities to
fulfil their obligations under these Regulations.
(3) The SPOC must submit reports to—
(a) the Cooperation Group based on the incident reports it received under regulation 11(9)
and 12(15), including the number of notifications and the nature of notified incidents; and
(b) the Commission identifying the number of operators of essential services for each
subsector listed in Schedule 2, indicating their importance in relation to that sector.
(4) The first report mentioned in paragraph (3)(a) must be submitted on or before 9th August
2018 and subsequent reports must be submitted at annual intervals.
(5) The first report mentioned in paragraph (3)(b) must be submitted on or before 9th November
2018 and subsequent reports must be submitted at biennial intervals.
Designation of computer security incident response team
5.—(1) GCHQ is designated as the CSIRT for the United Kingdom in respect of the relevant
sectors and digital services.
(2) The CSIRT must—
(a) monitor incidents in the United Kingdom;
(b) provide early warning, alerts, announcements and dissemination of information to relevant
stakeholders about risks and incidents;
(c) respond to any incident notified to it under regulation 11(5)(b) or regulation 12(8);
(d) provide dynamic risk and incident analysis and situational awareness;
(e) participate and co-operate in the CSIRTs network;
(f) establish relationships with the private sector to facilitate co-operation with that sector;
(g) promote the adoption and use of common or standardised practices for—
(i) incident and risk handling procedures, and
(ii) incident, risk and information classification schemes; and
(h) co-operate with NIS enforcement authorities to enable the enforcement authorities to fulfil
their obligations under these Regulations.
(3) The CSIRT may participate in international co-operation networks if the CSIRT considers
it appropriate to do so.
6