Article 79
(security of networks and services)
(1) Undertakings must adopt appropriate technical and organisational measures to
appropriately manage the risk to the security of networks and services, and particularly to
prevent and minimise the impact of security incidents on users and interconnected networks.
The measures adopted must, having regard to the state of the art, ensure a level of security
appropriate to the risk presented.
(2) The measures referred to in the first paragraph of this Article shall include the adoption
and implementation of an appropriate security plan, which shall be a business secret of the
undertaking.
(3) The security plan shall include at least the following:
- a definition of all the security risks at the undertaking, as well as those outside the
undertaking, that could threaten the operation of the public communications network or that
could disrupt the provision of publicly available electronic communications services by the
undertaking;
- a definition of the likelihood of an event for all the security risks referred to in the previous
indent;
- a definition of the level of the negative effects and consequences for operation of the public
communications network and for publicly available communications services for all the
security risks referred to in the first indent;
- a definition of measures to reduce the likelihood of the occurrence of a security incident;
- a definition of measures to reduce negative effects and mitigate the consequences of a
security incident;
- the definition of an appropriate method of organising security at the undertaking, an integral
part of which shall be security of the network and the information system and the physical
protection of facilities and equipment;
- the definition of an appropriate method of ensuring sufficient numbers of staff at key posts
at the undertaking engaged in a professional capacity in security matters;
- the definition of a method for the regular verification of compliance of the measures and
procedures conducted with those described in the security plan.
Article 80
(network integrity)
Network operators must adopt all measures necessary to secure the integrity of their networks
so as to ensure continuity of provision of services over those networks.
Article 81
(obligation to notify and report on breaches of security or integrity)
(1) Undertakings must notify the Agency, as soon as it learns of them, of all breaches of
security or integrity if these breaches have had a significant impact on the operation of public
communications networks or the provision of public communications services.
(2) Where appropriate and with regard to the seriousness of the breach, the Agency shall
notify the national contact point for security incidents (SI-CERT) of breaches of security of
networks and services and of breaches of network integrity.
(3) Where appropriate and with regard to the seriousness of the breach, the Agency shall
notify the regulatory authorities of other Member States and the European Information and