h) Setting the level of data protection from the perspective of confidentiality, accessibility and integrity i) Rules for customer audit j) Stating the obligations of the service provider to inform the user of cyber security incidents related to the performance of the contract (6) A cloud computing service provider, and public authorities and legal or natural persons specified in Section 3, letters c) to g) that execute public powers shall also state in their contract the amount of money paid for costs efficiently incurred for the implementation of security rules and the method of payment. (7) Taking into account the requirements for security measures deriving from security rules, security measures and other requirements stated in the contract according to paragraph 5 that are necessary to fulfil the requirements according to this Act shall not be considered an unlawful restriction of competition or an unjustified barrier to competition. Section 4a (1) Public authorities and legal or natural persons who became operators of information or communication systems of a critical information infrastructure, or operators of important information systems, and who are not administrators of such a system, are obliged to immediately and provably inform the administrator of the system of this fact and the fact that this administrator became a public authority or legal or natural person according to Section 3, letters c), d) or e). (2) Public authorities and legal or natural persons who became operators or administrators of information or communication systems of a critical information infrastructure are obliged to immediately and provably inform the entity operating the electronic communications network to which their concerned information or communication system of critical information infrastructure is connected to, of this fact and the fact that this entity fulfilled the requirements for becoming a public authority or legal or natural person according to Section 3, letter b). (3) Public authorities and legal or natural persons that are identified as operators of an essential service according to Section 22a and are not at the same time the operators or administrators of their information systems of essential service are obliged to immediately and provably inform the operator or the administrator of this essential service information system of their identification and of the fact that the operator or the administrator fulfilled the requirements to becoming a public authority or legal or natural person according to Section 3, letter f). Section 5 (1) Security measures are as follows: a) Organisational measures b) Technical measures (2) Organisational measures are as follows: a) Information security management system

Select target paragraph3