Pillar 3 — Security and incident notification requirements

8.23 The Directive requires the identification of entities/enterprises that qualify as OES or DSP based on specified criteria (see Figure 8.7). Certain obligations arise under the Directive depending on the criteria that organisations meet.1 Reportable incidents arise when disruption significantly impacts service provision above a certain threshold.2

Figure 8.7 Categorisation criteria for service providers

Figure 8.7 Categorisation criteria for service providers

Figure 8.7 Categorisation criteria for service providers

Figure 8.7 Categorisation criteria for service providers

An operator

A digital

of an essential

service provider

service

Provides an online

Established in an EU

marketplace, online search engine or cloud computing services within an EU member state.

member state and is a specific type of entity set out in the Directive.

8 29

Provides services at a

Provides a service

that is essential to society and the economy.

distance, for renumeration, by electronic means.

Provides a service

Provides services at

the specific request of the recipient of the service.

that depends on network and information systems.

An incident affecting

Is monitored by the

the network and information security of that service would have significant effects on its service provision.

National Competent Authority through ex post supervision for compliance with the Directive.

Source: Directive (EU) 2016/1148 of the European Parliament — Network and Information Systems Directive

Measures relating to national cyber security

8.24 To date, the National Cyber Security Centre has identified approximately 60 entities as potential OESs in seven sectors specified in the Network and Information Systems Directive. The Minister has not yet completed formal designation of these entities as OESs.

8.25 There are obligations on the Minister as national competent authority to establish and maintain a register of OESs. The register must be reviewed on a regular basis, at least every two years.

8.26 A DSP providing a service in another EU state but headquartered in Ireland is considered the responsibility of the Irish authorities for cyber security purposes.

8.27 The Department notes that the State is responsible for dealing with the security of services provided across the EU by multinational companies (deemed DSPs under the Directive), that have their European headquarters located in Ireland. As a result, Ireland will have additional financial and administrative responsibility associated with acting as the de facto European security regulator, which will impact on resourcing requirements in the future.

8.28 The Minister has authority to require both OESs and DSPs to provide all information needed in order to assess the security of their network and information systems.

8.29 Furthermore, the Department published draft security measures and incident reporting guidelines for OESs and DSPs on 16 November 2017 for consultation. It is intended that these will be finalised following transposition of the Directive.

Governance and oversight

Pages 8–10 · View in original PDF