d) Important information systems and their determination criteria
e) Content and extent of the security rules for public authorities and legal or natural persons that
execute public powers that use the services of cloud computing providers
Section 6a
(1) The operator of an information or communication system of a critical information infrastructure
or the operator of an important information system may assign the task of administrating the
information or communication system of the critical information infrastructure or the task of
administrating the important information system to another public authority or legal or natural
person, unless this contradicts another act.
(2) The administrator of the information or communication system of a critical information
infrastructure or the administrator of an important information system shall transfer the data,
operational data and information they have in relation to the administration of this system at the
request of the operator of this system, without undue delay and in the agreed format. The
provisions of legislation governing intellectual property rights are not affected by the transfer of
the data, operational data and information.
(3) If the administrator of an information or communication system of a critical information
infrastructure or the administrator of an important information system ceases administrating this
system, they shall transfer the data, operational data and information they have in relation to the
administration of this system that are needed for potential further administration of this
information system or another use, and shall dispose of their copies in his digital environment in
a secure way at the request of the operator of this system. The means of the disposal of the data,
operational data and information, as well as their copies, shall be set out by an implementing legal
regulation.
(4) The administrator of an information or communication system of a critical information
infrastructure, or the administrator of an important information system, is entitled to
reimbursement of efficiently incurred costs for the transfer of the data, operational data and
information according to paragraphs 2 and 3; the costs shall be paid to the administrator by the
operator of such a system.
Cyber security event and cyber security incident
Section 7
(1) A cyber security event is an event that may cause a breach in the security of information in
information systems, a breach in the security of service provision or a breach of security and
integrity of electronic communication networks1).
(2) A cyber security incident is a breach in the security of information in information systems, a breach
in the security of service provision or a breach of security and integrity of electronic
communication networks1) due to the cyber security event.
(3) Public authorities and legal or natural persons specified in Section 3, letters b) to f) are obliged to
detect cyber security events in their important network, in their information or communication