CHAPTER II System for ensuring cyber security Security measures Section 4 (1) Security measures are a set of activities with the purpose of ensuring the security of information in information systems and the availability and reliability of services and electronic communication networks1) in cyberspace. (2) Public authorities and legal or natural persons specified in Section 3, letters c) to f) are obliged to introduce and implement security measures to the extent necessary for ensuring cyber security of the information or communication system of critical information infrastructure, information system of essential service or important information system, and to keep record in security documentation. (3) A digital service provider is obliged to introduce and implement suitable and adequate security measures for electronic communication networks and information systems used in relation to the provision of the service, while these security measures take into account the ensuring of information security, handling of cyber security incidents, the management of the continuity of activities, monitoring, auditing, testing and compliance with international regulations. (4) Public authorities and legal or natural persons specified in Section 3, letters c) to f) are obliged to take into consideration the requirements stemming from security measures during the selection of suppliers for their information or communication system and to include these requirements in the contract they conclude with the supplier. Taking into account the requirements stemming from security measures according to the first sentence to the extent necessary to fulfil the requirements according to this Act shall not be considered an unlawful restriction of competition or an unjustified barrier to competition. (5) Public authorities and legal or natural persons specified in Section 3, letters c) to g) that execute public powers are obliged particularly to ensure in the contract concluded with a provider of cloud computing services that security rules for the provision of cloud computing services set out by the Agency are observed, and that, based on their request, they shall without undue delay have access to the information and data the provider of cloud computing services stores for them, including the possibility to check the stored information and data in real time. Other necessary elements of a contract are: a) The obligation of the service provider to respect the security policy of the service user b) Determining the level of services provided c) A system for approving subcontractors to the cloud computing service d) Conditions for termination of the contractual relationship from the perspective of security e) Management of the continuity of activities in relation to the provided cloud computing service f) Determining the owner of the stored data g) A non-disclosure agreement related to the contractual relationship

Select target paragraph3