CHAPTER II
System for ensuring cyber security
Security measures
Section 4
(1) Security measures are a set of activities with the purpose of ensuring the security of information
in information systems and the availability and reliability of services and electronic
communication networks1) in cyberspace.
(2) Public authorities and legal or natural persons specified in Section 3, letters c) to f) are obliged to
introduce and implement security measures to the extent necessary for ensuring cyber security
of the information or communication system of critical information infrastructure, information
system of essential service or important information system, and to keep record in security
documentation.
(3) A digital service provider is obliged to introduce and implement suitable and adequate security
measures for electronic communication networks and information systems used in relation to the
provision of the service, while these security measures take into account the ensuring of
information security, handling of cyber security incidents, the management of the continuity of
activities, monitoring, auditing, testing and compliance with international regulations.
(4) Public authorities and legal or natural persons specified in Section 3, letters c) to f) are obliged to
take into consideration the requirements stemming from security measures during the selection
of suppliers for their information or communication system and to include these requirements in
the contract they conclude with the supplier. Taking into account the requirements stemming
from security measures according to the first sentence to the extent necessary to fulfil the
requirements according to this Act shall not be considered an unlawful restriction of competition
or an unjustified barrier to competition.
(5) Public authorities and legal or natural persons specified in Section 3, letters c) to g) that execute
public powers are obliged particularly to ensure in the contract concluded with a provider of cloud
computing services that security rules for the provision of cloud computing services set out by
the Agency are observed, and that, based on their request, they shall without undue delay have
access to the information and data the provider of cloud computing services stores for them,
including the possibility to check the stored information and data in real time. Other necessary
elements of a contract are:
a) The obligation of the service provider to respect the security policy of the service user
b) Determining the level of services provided
c) A system for approving subcontractors to the cloud computing service
d) Conditions for termination of the contractual relationship from the perspective of security
e) Management of the continuity of activities in relation to the provided cloud computing
service
f)
Determining the owner of the stored data
g) A non-disclosure agreement related to the contractual relationship