b) The identification data of the system where the cyber security incident occurred
c) Information about the source of the cyber security incident
d) A procedure for handling the cyber security incident and its outcome
(2) The data specified in Section 20, letters f) to h) and l) are part of the incident record.
(3) The Agency provides data from the incident record to authorities that execute public powers for
the purpose of fulfilling tasks within their competence.
(4) The Agency may provide data from the incident record to the operator of the national CERT, to
public authorities in the field of cyber security abroad and to other legal or natural persons
operating in the field of cyber security in the extent necessary to ensure the protection of
cyberspace.
Section 10
(1) Employees of the Czech Republic employed at the Agency who take a part in solving a cyber
security incident are subject to the obligation of confidentiality with regard to the data from the
incident record. The obligation of confidentiality shall last even after the termination of
employment at the Agency.
(2) The director of the Agency may exempt persons defined in paragraph 1 from the obligation of
confidentiality with regard to the data from the incident record, providing a statement on the
extent of the data access and the exemption.
Section 10a
Information which if accessed may jeopardise the ensuring of cyber security or the efficiency of
measures issued on the basis of this Act, or information recorded in the incident record from which it
might be possible to identify the public authority or legal or natural person which reported the security
incident, shall not be provided according to legal regulations governing free access to information.
Section 11
Measures
(1) Measures are actions that are needed to protect information systems or services and electronic
communication networks1) from a threat in the field of cyber security or from a cyber security
incident, or to resolve an already occurred cyber security incident.
(2) Measures are as follows:
a) Warning
b) Reactive measure
c) Protective measure
(3) Reactive measures are obligatorily applied by:
a) Public authorities and legal or natural persons specified in Section 3, letters a) and b) under
the state of cyber emergency or under the state of emergency4) declared on the basis of a
request specified in Section 21, paragraph 6