Official
Journal
important information infrastructure has been
identified in the public and private sectors. ,
besides, minimum security measures to be
implemented for better cybersecurity in this
infrastructure have been developed along with
the development of a methodological
mechanism for sector CSIRT establishment and
operation at the national level.
The legal framework on electronic
communication security is completed with
legal provisions on the security and integrity of
electronic communication networks and
telecommunication networks covered by Law
No. 9918, dated 19.5.2008 “On electronic
communication in the Republic of Albania” as
amended, which has transposed EU directives
on electronic communication.
The cybersecurity legal framework has also
designated the National Electronic Certification
and Cybersecurity Authority (NECCA), as the
authority responsible for overseeing the
implementation of the law.
As a result, after the implementation of the
law on security, the current critical information
infrastructure situation in the banking sector
has improved compared to two years ago.
Considerable security measures, approved by
NECCA have been applied in this
infrastructure, and sector CSIRT shas been
established, creating a safe cyberspace.
In the financial sector, cybersecurity is
divided into two pillars, the public and the
private, and the current situation is as follows:
Security measures according to the
applicable legislation and in compliance with
the ISO 27001 standard are applied in critical
government information infrastructure used by
public institutions, allocated in the government
data center, and managed by the National
Agency on Information Society. NAIS is a
government sector CSRIT and was certified in
2018 for this standard, and ISO 27001 standard
policies are applied to any government
infrastructure managed by NAIS.
Critical infrastructure managed by private
operators is currently being identified and in
some cases, the investment to develop them is
also being identified.
Year 2021 - Issue 7
In the health sector, which is also divided
into the public and private pillars, the
cybersecurity situation is as follows:
Measures approved according to the law on
security have been applied in critical
infrastructure
managed
by
public
operators/institutions, which has led to
improved cybersecurity levels. Besides, groups
responsible for managing and addressing
incidents, which did not exist when the legal
framework was absent, have also been
established.
The private operator managed information
infrastructure, considered to be critical
infrastructure as defined by the European
Commission legal framework on information
networks and infrastructure, have not been
identified and the situation study conducted by
the relevant authority found that they do not
meet
security
elements
that
critical
infrastructure should guarantee.
Energy Sector Currently, all generation,
transmission, and distribution energy system
operators are implementing innovative
technologies based on computer systems and
data transmission networks, to manage and
optimize their technological processes.
SCADA systems are implemented or are
planned for implementation in all three sectors
of the energy system, and they have their
operation, computer system, and data
transmission centers. Along with reading and
analyzing energy system data remotely,
operation modules automating processes that
are currently completed manually by operators
are planned for implementation in the near
future. Transitioning to independent systems
that operate automatically will certainly require
the implementation of security measures and
policies, since the impact of cyber-incidents
would be great. This will certainly require
energy operators to pay special attention to
system security and to develop internal
procedures and human capacities for
cybersecurity when planning ICT projects and
automation.
Page|1487