h) Setting the level of data protection from the perspective of confidentiality, accessibility and
integrity
i)
Rules for customer audit
j)
Stating the obligations of the service provider to inform the user of cyber security incidents
related to the performance of the contract
(6) A cloud computing service provider, and public authorities and legal or natural persons specified
in Section 3, letters c) to g) that execute public powers shall also state in their contract the amount
of money paid for costs efficiently incurred for the implementation of security rules and the
method of payment.
(7) Taking into account the requirements for security measures deriving from security rules, security
measures and other requirements stated in the contract according to paragraph 5 that are
necessary to fulfil the requirements according to this Act shall not be considered an unlawful
restriction of competition or an unjustified barrier to competition.
Section 4a
(1) Public authorities and legal or natural persons who became operators of information or
communication systems of a critical information infrastructure, or operators of important
information systems, and who are not administrators of such a system, are obliged to immediately
and provably inform the administrator of the system of this fact and the fact that this
administrator became a public authority or legal or natural person according to Section 3, letters
c), d) or e).
(2) Public authorities and legal or natural persons who became operators or administrators of
information or communication systems of a critical information infrastructure are obliged to
immediately and provably inform the entity operating the electronic communications network to
which their concerned information or communication system of critical information infrastructure
is connected to, of this fact and the fact that this entity fulfilled the requirements for becoming a
public authority or legal or natural person according to Section 3, letter b).
(3) Public authorities and legal or natural persons that are identified as operators of an essential
service according to Section 22a and are not at the same time the operators or administrators of
their information systems of essential service are obliged to immediately and provably inform the
operator or the administrator of this essential service information system of their identification
and of the fact that the operator or the administrator fulfilled the requirements to becoming a
public authority or legal or natural person according to Section 3, letter f).
Section 5
(1) Security measures are as follows:
a) Organisational measures
b) Technical measures
(2) Organisational measures are as follows:
a) Information security management system