a)
which types of information may or must be registered, stored and analysed in
connection with the monitoring
b)
who shall have access to information which is registered and stored in connection
with the monitoring
c)
how access is to be granted to registered or stored information
d)
that information pursuant to the first and second paragraphs shall be subject to
different storage period than five years.
Section 6-5.Penetration testing of critical national information systems
An undertaking may ask the National Security Authority to attempt to penetrate its
critical national information systems. The purpose must be to check whether security
measures are adequate. The undertakings' employees must be informed that such a check
may be performed.
If the check entails the processing of personal data, this shall not be more extensive than
necessary for the purpose.
Information to which the check provides access may only be used for the purpose of the
check. When the information is no longer required, it shall be erased. Knowledge and
experience acquired by the National Security Authority through the penetration testing
may be used in the further development of the National Security Authority's general
security work.
The National Security Authority shall issue a report to the undertaking on the results of
the check. The report shall only contain information which may help to improve the
undertaking's security.
The King may issue regulations on the penetration of critical national information
systems, and regulations authorising the performance of such checks by parties other
than the National Security Authority.
Section 6-6.Communication and content monitoring of information
systems
An undertaking may ask the National Security Authority to check whether its information
systems process classified information beyond the scope permitted by the system's
security approval. The undertakings' employees must be informed that such a check may
be performed.
The National Security Authority may perform the check by intercepting and reading
information which is processed by or sent between information systems.
13/30