e) Acts as a point of contact for public authorities and legal or natural persons specified in
Section 3, letters a), b) and h)
f)
Carries out vulnerability analyses in the cyber security field
g) Transfers to the Agency data on cyber security incidents reported according to Section 8,
paragraph 3 without disclosing the reportee to the Agency
h) Transfers to the Agency upon request data according to Section 16, paragraphs 5 and 6
i)
Fulfils the role of a CSIRT team according to relevant European Union legislation12)
j)
Informs the relevant public authority of another Member State about a cyber security
incident with a significant impact on the continuity of the provision of essential or digital
service in this Member State without stating the identification details of the announcer, and
also informs the Agency, while maintaining the security and commercial interests of the
announcer
k) Cooperates with CSIRT teams of other Member States
l)
Receives reports about cyber security incidents from public authorities and legal or natural
persons specified in Section 3, and if its capacities allow it, processes and provides the public
authorities or legal or natural persons affected by the cyber security incident with methodical
support, help and cooperation
(3) The operator of the national CERT may, on their own behalf and responsibility, also perform other
business activities in the field of cyber security unspecified by this Act, if such an activity does not
harm the fulfilment of obligations specified in paragraph 2.
(4) The operator of the national CERT shall coordinate their activities with the Agency while fulfilling
their obligations specified in paragraph 2.
(5) The operator of the national CERT shall act impartially when fulfilling the obligations according to
paragraph 2.
Section 18
The operator of the national CERT
(1) The operator of the national CERT can only be a legal person which:
a) Fulfils the conditions specified in paragraph 2 and
b) Concluded a public-law contract with the Agency according to Section 19
(2) The operator of the national CERT can only be a legal person which:
a) Does not carry out any activities against the interests of the Czech Republic according to the
Act on the Protection of Classified Information, and has never done so
b) Has been administrating or operating information systems or services and electronic
communication networks1), or has been participating in their administration and operation,
for at least a period of 5 years
c) Has technological prerequisites for the field of cyber security
d) Is a member of a multinational organisation operating in the field of cyber security