Official Journal important information infrastructure has been identified in the public and private sectors. , besides, minimum security measures to be implemented for better cybersecurity in this infrastructure have been developed along with the development of a methodological mechanism for sector CSIRT establishment and operation at the national level. The legal framework on electronic communication security is completed with legal provisions on the security and integrity of electronic communication networks and telecommunication networks covered by Law No. 9918, dated 19.5.2008 “On electronic communication in the Republic of Albania” as amended, which has transposed EU directives on electronic communication. The cybersecurity legal framework has also designated the National Electronic Certification and Cybersecurity Authority (NECCA), as the authority responsible for overseeing the implementation of the law. As a result, after the implementation of the law on security, the current critical information infrastructure situation in the banking sector has improved compared to two years ago. Considerable security measures, approved by NECCA have been applied in this infrastructure, and sector CSIRT shas been established, creating a safe cyberspace. In the financial sector, cybersecurity is divided into two pillars, the public and the private, and the current situation is as follows: Security measures according to the applicable legislation and in compliance with the ISO 27001 standard are applied in critical government information infrastructure used by public institutions, allocated in the government data center, and managed by the National Agency on Information Society. NAIS is a government sector CSRIT and was certified in 2018 for this standard, and ISO 27001 standard policies are applied to any government infrastructure managed by NAIS. Critical infrastructure managed by private operators is currently being identified and in some cases, the investment to develop them is also being identified. Year 2021 - Issue 7 In the health sector, which is also divided into the public and private pillars, the cybersecurity situation is as follows: Measures approved according to the law on security have been applied in critical infrastructure managed by public operators/institutions, which has led to improved cybersecurity levels. Besides, groups responsible for managing and addressing incidents, which did not exist when the legal framework was absent, have also been established. The private operator managed information infrastructure, considered to be critical infrastructure as defined by the European Commission legal framework on information networks and infrastructure, have not been identified and the situation study conducted by the relevant authority found that they do not meet security elements that critical infrastructure should guarantee. Energy Sector Currently, all generation, transmission, and distribution energy system operators are implementing innovative technologies based on computer systems and data transmission networks, to manage and optimize their technological processes. SCADA systems are implemented or are planned for implementation in all three sectors of the energy system, and they have their operation, computer system, and data transmission centers. Along with reading and analyzing energy system data remotely, operation modules automating processes that are currently completed manually by operators are planned for implementation in the near future. Transitioning to independent systems that operate automatically will certainly require the implementation of security measures and policies, since the impact of cyber-incidents would be great. This will certainly require energy operators to pay special attention to system security and to develop internal procedures and human capacities for cybersecurity when planning ICT projects and automation. Page|1487

Select target paragraph3