f)
Withdrawal notice period and reasons for the withdrawal
g) Ban on the misuse of data acquired while performing activities specified in Section 17,
paragraph 2
h) Definition of the conditions for the performance of the national CERT activities according to
Section 17, paragraph 3 and
i)
Method for the data transfer and the extent of the data transferred to the Agency in the case
of contract termination
(3) The contract concluded according to paragraph 1 shall be published in the Official Journal of the
Agency, except for the parts of the contract the publishing of which is not allowed by another legal
regulation.
(4) If the contract according to paragraph 1 is not concluded, or if the contract is terminated, the
activity of the national CERT shall be performed by the Agency.
Section 20
Governmental CERT
Governmental CERT as a part of the Agency:
a) Receives notices of contact details from public authorities and legal or natural persons specified
in Section 3, letters c) to g)
b) Receives reports on cyber security incidents from public authorities and legal or natural persons
specified in Section 3, letters c) to g)
c)
Evaluates data on cyber security events and cyber security incidents from a critical information
infrastructure, information system of essential service, important information systems and other
information systems of public administration
d) Provides public authorities and legal or natural persons specified in Section 3, letters c) to g) with
methodical support and help
e) Cooperates with public authorities and legal or natural persons specified in Section 3, letters c) to
g) when a cyber security incident or a cyber security event occurs
f)
Receives suggestions and data from public authorities and legal or natural persons specified in
Section 3, and from other authorities and legal or natural persons, and evaluates these
suggestions and data
g) Receives data from the operator of the national CERT and evaluates this data
h) Receives data from public authorities that operate in the field of cyber security abroad and
evaluates this data
i)
Provides data from the incident record according to Section 9, paragraph 4 to the operator of the
national CERT, to public authorities operating in the field of cyber security abroad and to other
legal or natural persons operating in the field of cyber security
j)
Carries out vulnerability analyses in the field of cyber security
k) Informs the relevant public authority of another Member State of a cyber security incident with a
significant impact on the continuity of the provision of essential services in this Member State, or