Network and Information Systems Directive

8.18 The EU Network and Information Systems Directive aims to improve the resilience of key network and information systems by addressing the following (referred to as ‘pillars’)

improving cyber security capabilities of EU member states

facilitating cooperation on cyber security among EU member states

introducing security measures and incident reporting obligations for key sectors.1

8.19 The structure envisaged in the Directive for achieving these objectives is outlined in Figure 8.5.

Figure 8.5 Directive — Implementation approach

Objectives

Pillar 3 Security measures and incident notification requirements Identify critical network and information systems IdIednetniftyif yo poepreartaotrosr s ofo ef ses esnetniatila l sesrevrivciecse s Manage digital service providers
CSIRT NetworkManage digital service providers

Pillar 1 Improve national cyber capabilities

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Figure from page 6

Source: Directive (EU) 2016/1148 of the European Parliament — Network and Information Systems Directive. Analysis by the Office of the Comptroller and Auditor General.

Notes: Complete.

Partially implemented.

Not implemented.

Measures relating to national cyber security

Pillar 1 — Improve national cyber capabilities

Pages 6–7 · View in original PDF