b) The identification data of the system where the cyber security incident occurred c) Information about the source of the cyber security incident d) A procedure for handling the cyber security incident and its outcome (2) The data specified in Section 20, letters f) to h) and l) are part of the incident record. (3) The Agency provides data from the incident record to authorities that execute public powers for the purpose of fulfilling tasks within their competence. (4) The Agency may provide data from the incident record to the operator of the national CERT, to public authorities in the field of cyber security abroad and to other legal or natural persons operating in the field of cyber security in the extent necessary to ensure the protection of cyberspace. Section 10 (1) Employees of the Czech Republic employed at the Agency who take a part in solving a cyber security incident are subject to the obligation of confidentiality with regard to the data from the incident record. The obligation of confidentiality shall last even after the termination of employment at the Agency. (2) The director of the Agency may exempt persons defined in paragraph 1 from the obligation of confidentiality with regard to the data from the incident record, providing a statement on the extent of the data access and the exemption. Section 10a Information which if accessed may jeopardise the ensuring of cyber security or the efficiency of measures issued on the basis of this Act, or information recorded in the incident record from which it might be possible to identify the public authority or legal or natural person which reported the security incident, shall not be provided according to legal regulations governing free access to information. Section 11 Measures (1) Measures are actions that are needed to protect information systems or services and electronic communication networks1) from a threat in the field of cyber security or from a cyber security incident, or to resolve an already occurred cyber security incident. (2) Measures are as follows: a) Warning b) Reactive measure c) Protective measure (3) Reactive measures are obligatorily applied by: a) Public authorities and legal or natural persons specified in Section 3, letters a) and b) under the state of cyber emergency or under the state of emergency4) declared on the basis of a request specified in Section 21, paragraph 6

Select target paragraph3