1. ------IND- 2019 0637 E-- EN- ------ 20200113 --- --- PROJET
ROYAL DECREE XX/20XX IMPLEMENTING ROYAL DECREE-LAW 12/2018 OF
7 SEPTEMBER 2018 ON THE SECURITY OF INFORMATION NETWORKS AND
SYSTEMS
Royal Decree-Law 12/2018 of 7 September 2018 on the security of information
networks and systems transposes Directive (EU) 2016/1148 of the European Parliament
and of the Council of 6 July 2016 concerning measures for a high common level of
security of network and information systems across the Union, and in its third final
provision, grants the government the power to implement the provisions of said Royal
Decree-Law into law.
To fulfil this mandate, with the aim of developing and fleshing out aspects
considered in the aforementioned Royal Decree-Law, this Royal Decree is now adopted,
featuring five chapters and five additional provisions, four final provisions and one annex.
To meet this objective, this Royal Decree completes the designation of competent
authorities for the security of information networks and systems, as per Royal Decree-
Law 12/2018 of 7 September 2018, by specifying those corresponding to essential
service operators that are not considered critical operators and that do not fall under
Law 40/2015 of 1 October 2015 on the Public Sector Legal Framework, with attention to
the strategic sectors indicated in Law 8/2011 of 28 April 2011 laying down measures for
the protection of critical infrastructure.
Moreover, this Royal Decree implements the cases for cooperation and
coordination between the reference CSIRTs, which occur over the National Cyber-
incident Reporting and Monitoring Platform. In particular, it implements the provisions of
the Royal Decree-Law in situations affecting operators with an impact on national
defence, and the actions indicated for particularly serious cases that require a higher
level of coordination than that required in ordinary situations, as well as the action
required when the activities of the reference CSIRTs may affect a critical operator in
some way.
The liaison duties of the role of single point of contact, specified in
Directive (EU) 2016/1148, are performed to ensure cross-border cooperation with the
competent authorities of other European Union Member States, as well as with the
cooperation group and the CSIRT network. These duties of the National Security
Council, as the single point of contact, are in addition to the duties to coordinate the
activities of the competent authorities, assigned under Royal Decree-Law 12/2018.
This Royal Decree also implements the provisions of Royal Decree-Law 12/2018
on the measures needed to meet the security obligations on the part of operators of
essential services, which must be detailed in a statement of applicability of security
measures signed by the information security officer of the operator, whose duties are
also set out in this Royal Decree.
With regard to incident reporting, the Royal Decree implements the reporting
obligations on operators of essential services for incidents that may have a significant
disruptive impact on said services, and incidents that may affect the information networks
and systems used to provide the essential services, even if they have not had a real
adverse impact on them, by way of reference to the impact and threat levels, depending
on the case at hand, provided for in the National Incident Reporting and Management
Instruction in the annex.
1
The incident reporting procedure is carried out by means of the National Cyber-
incident Reporting and Monitoring Platform, to enable the exchange of information
between operators of essential services and digital service providers, the competent
authorities and the reference CSIRTs, with guaranteed confidentiality, integrity and
availability for the information.
Finally, with regard to security compliance supervision, the Royal Decree
imposes the obligation on operators of essential services and digital service providers to
cooperate with the competent authorities, which may also require collaboration with the
reference CSIRTs in the performance of their supervisory role.
The additional provisions of this Royal Decree include the legal framework
applicable to the Bank of Spain in light of its special legal status as a public-law entity
with its own legal personality and full public and private capacity, which acts
independently of the Public Administration in performing its activities and meeting its
goals, and as an integral part of the European System of Central Banks (ESCB) and the
Single Supervisory Mechanism (SSM). This special legal status means that the security
framework for information networks and systems applies to the extent that it does not
interfere with the nature, duties and independence of the Bank of Spain.
This Royal Decree has undergone the procedure for the provision of information
in relation to technical regulations and of rules related to Information Society services
provided for in Directive (EU) 2015/1535 of the European Parliament and of the Council
of 9 September 2015 laying down a procedure for the provision of information in the field
of technical regulations and of rules on Information Society services, and in Royal
Decree 1337/1999 of 31 July 1999 regulating the provision of information in the field of
technical standards and regulations and of rules on Information Society services.
Moreover, this regulation is in accordance with the principles for sound regulation set out
in Article 129 of Law 39/2015 of 1 October 2015 on Common Administrative Procedures
in Public Administration, under which the Public Authorities must act in the exercise of
legislative initiative, particularly the principles of necessity, effectiveness, proportionality,
legal certainty, transparency and efficiency.
This Royal Decree is adopted by virtue of the exclusive powers granted to the
State over matters of the general telecommunications system and public safety by
Article 149(1)(21 and 29) of the Constitution.
This Royal Decree, resulting from intense dialogue and collaboration between the
various Ministerial Departments and stakeholder agencies, was drafted after
consultation with organisations representing the affected sectors.
Therefore, at the joint proposal of the Minister for Economy and Business, the
Minister for the Interior and the Minister for Defence, with prior approval from the Minister
for Territorial Policy and Public Administration, in accordance with the Council of State
and following deliberation by the Council of Ministers at its meeting of ….
2
THE FOLLOWING IS DECREED:
CHAPTER I
General provisions
Article 1. Aim and scope.
1. This Royal Decree is intended to implement Royal Decree-Law 12/2018 of
7 September 2018 on the security of information networks and systems. In particular, it
is intended to:
a) designate the competent authorities in matters of information network and
system security for operators of essential services that are not considered
critical operators and that do not fall under the scope of Law 40/2015 of
1 October 2015 on the Public Sector Legal Framework;
b) implement cooperation and coordination between the competent authorities
and the reference CSIRTs over the National Cyber-incident Reporting and
Monitoring Platform, provided for in Article 11 of this Royal Decree;
c) set out the duties of the single point of contact;
d) specify the measures needed to meet the security obligations on operators
of essential services and digital service providers;
e) set out the duties of information security officers for operators of essential
services;
f) adopt the National Incident Reporting and Management Instruction.
2. The scope of this Royal Decree is detailed in Article 2 of Royal Decree-
Law 12/2018 of 7 September 2018, without prejudice to the provisions of Article 18 of
said Royal Decree-Law.
Article 2. Definitions
1. For the purposes of this Royal Decree, ‘competent authorities’ shall mean the
authorities indicated in Article 9 of Royal Decree-Law 12/2018 of 7 September 2018, and
Article 3 of this Royal Decree.
2. The other terms used in this Royal Decree shall have the meanings given in
Royal Decree-Law 12/2018 of 7 September 2018.
CHAPTER II
Strategic and institutional framework
Article 3. Competent authorities.
1. The following parties shall be the competent authorities for the operators of
essential services that are not critical operators as per Article 9(1)(a)(2º) of Royal
Decree-Law 12/2018 of 7 September 2018:
a) for the transport sector: the Ministry of Public Works, via the Secretariat of
State for Infrastructure, Transport and Housing;
3
b) for the energy sector: the Ministry for the Ecological Transition, via the
Secretariat of State for Energy;
c) for the information technology and telecommunications sector: the Ministry
of the Economy and Business, via the Secretariat of State for Digital
Advancement;
d) for the finance and taxation sector:
i. the Ministry of the Economy and Business, via the Secretariat of State for
the Economy and Business Support, for insurance providers;
ii. the Bank of Spain, for credit institutions;
iii. the National Securities Market Commission, for investment service
providers and for management firms for collective investment institutions;
e) for the space sector: the Ministry of Defence, via the General Secretariat for
Defence Policy;
f) for the chemical industry sector: the Ministry of the Interior, via the Secretariat
of State for Security;
g) for the research facilities sector: the Ministry of Science, Innovation and
Universities, via the Secretariat of State for Universities, Research,
Development and Innovation;
h) for the health sector: the Ministry of Health, Consumer Affairs and Social
Welfare, via the General Secretariat for Health and Consumer Affairs;
i) for the water sector: the Ministry for the Ecological Transition, via the
Secretariat of State for the Environment;
j) for the food sector:
i. the Ministry of Agriculture, Fisheries and Food, via the General
Secretariat for Agriculture and Food;
ii. the Ministry of Health, Consumer Affairs and Social Welfare, via the
General Secretariat for Health and Consumer Affairs;
iii. the Ministry of Industry, Trade and Tourism, via the Secretariat of State
for Trade;
k) for the nuclear sector:
i. the Ministry for the Ecological Transition, via the Secretariat of State for
Energy;
ii. the Nuclear Security Council.
2. Without prejudice to the provisions of Chapter IV on cybersecurity incident
management, the competent authorities may issue a ministerial order or circular,
depending on the case, to establish appropriate communication channels with operators
of essential services and digital service providers to supervise the security and incident
reporting requirements applicable to these parties.
These ministerial orders or circulars may also include action protocols for
coordination with reference CSIRTs.
Article 4. Cooperation and coordination with reference CSIRTs
1. Cooperation amongst the reference CSIRTs and between them and the
competent authorities shall be handled over the National Cyber-incident Reporting and
Monitoring Platform.
4
2. For the purposes of the cooperation referred to in Article 11(1)(a)(3º) of Royal
Decree-Law 12/2018 of 7 September 2018, ‘operators with an impact on national
defence’ shall be providers of basic services essential to the functioning of the Ministry
of Defence or to the effectiveness of the Armed Forces established by the National
Commission for the Protection of Critical Infrastructure at the proposal of the Ministry of
Defence.
The National Commission for the Protection of Critical Infrastructure shall report
designation of an operator with an impact on National Defence to the operator pursuant
to the provisions of Royal Decree 704/2011 of 20 May 2011 adopting the Regulation on
protection of critical infrastructure. Wherever possible, the designation shall be reported
immediately. In addition, the reference CSIRTs shall be informed of the operators of
essential services in their community that are designated as operators with an impact on
National Defence.
The Ministry of Defence shall provide the National Commission for the Protection
of Critical Infrastructure with updates on changes of operators providing these services,
which shall prompt the corresponding notifications of registration or deregistration as
operators with an impact on National Defence to both the operators themselves and their
reference CSIRTs.
3. ‘Particularly serious cases’ as referred to in the first paragraph of Article 11(2)
of Royal Decree-Law 12/2018 of 7 September 2018, in which the CERT of the National
Cryptography Centre [CCN-CERT] shall provide national coordination for the technical
response of the CSIRTs, shall be all cases with a very high or critical impact or threat
level as per the provisions of the annex, in view of the nature of the initial or subsequent
incident reports received by the reference CSIRT, and that require a level of technical
coordination with other CSIRTs that is higher than that required in ordinary situations.
The National Cybersecurity Council, which may act through its Standing
Committee, shall be informed immediately and may cancel the coordination provided for
in this article, which shall not affect the incident reporting process in Articles 11 and 19(1
and 2) of Royal Decree-Law 12/2018 of 7 September 2018.
4. The CCN-CERT (in the case as per the preceding paragraph) or the
Cybersecurity Coordination Office (in the cases as per the second paragraph of
Article 11(2) of Royal Decree-Law 12/2018 of 7 September 2018) shall request at least
the following information from the reference CSIRT after the initial incident report:
a) confirmation that the incident details are correct, with specific verification of
any of the following details that are available:
i. incident classification;
ii. incident threat level;
iii. incident impact;
b) any action plan of the CSIRT to arrive at a technical solution for the incident;
c) any information for determining the potential cross-border impact of the
incident.
Wherever possible, the National Cyber-incident Reporting and Monitoring
Platform shall be used for the communications referred to in this paragraph.
5. If an operator with an impact on National Defence is affected by an incident, it
shall analyse its scope to determine if it could affect the functioning of the Ministry of
Defence or the effectiveness of the Armed Forces. If so, it shall report this immediately
to its reference CSIRT, which shall inform the Spanish Defence CERT [ESP DEF CERT]
through the established channels.
In such cases, the ESP DEF CERT shall be properly kept up-to-date on incident
management progress.
5
Article 5. Single point of contact.
1. Pursuant to Article 13 of Royal Decree-Law 12/2018 of 7 September 2018, the
National Security Council shall perform the following duties via the National Security
Department:
a) provide the European Commission with the list of national operators of
essential services identified for each sector and subsector referred to in
Article 6 of Royal Decree-Law 12/2018 of 7 September 2018, and inform the
single points of contact of other States of its intent to identify an operator of
essential services of another Member State that offers services in Spain;
b) forward information on incidents with cross-border impact from the
competent authorities or reference CSIRTs to the contacts in other European
Union Member States, pursuant to Article 25 of Royal Decree-Law 12/2018
of 7 September 2018;
c) relay the corresponding information on incidents that may have a disruptive
impact on essential services from the contacts in the corresponding Member
States to the reference CSIRTs and competent national authorities, so they
can take appropriate measures according to their respective duties;
d) issue relevant instructions to the competent authorities to draft the annual
report referred to in Article 27(1) of Royal Decree-Law 12/2018 of
7 September 2018, on the type and number of incidents reported, their
impact on the services provided or on other services and their national or
cross-border nature within the European Union, in accordance with the
indications of the cooperation group on the form and content of the
information provided;
e) request that the competent authorities submit the annual report referred to
in the preceding subparagraph and draft an annual report summarising the
incident reports received, which it shall forward to the cooperation group
before 15 February of each year and, subsequently, to the competent
authorities and the reference CSIRTs, for their information.
2. In addition to the liaison duties provided for in the preceding subparagraph,
and pursuant to Article 9(2) of Royal Decree-Law 12/2018 of 7 September 2018, the
National Security Council, via its special cybersecurity committee, shall ensure
coordination of the activities of the competent authorities by:
a) promoting consistency between any special security requirements adopted
by the competent authorities, pursuant to Article 6(4) of this Royal Decree;
b) promoting consistency between any special obligations adopted by the
competent authorities, pursuant to Article 8(3) of this Royal Decree;
c) supporting coordination of the regulations and activities of the competent
authorities and the activities of the reference CSIRTs with the information
security regulations and activities of the data protection and public safety
authorities.
3. Similarly, the National Security Council shall perform the coordination duties
as per paragraph 2 above in the cases as per Article 18 of Royal Decree-Law 12/2018
of 7 September 2018.
6
CHAPTER III
Security requirements
Article 6. Measures for compliance with security obligations
1. Operators of essential services and digital service providers shall take suitable
and proportionate technical and organisational measures to manage risks to the security
of the information networks and systems used when providing the services, for both their
own networks and systems and those of third-party providers.
2. Operators of essential services shall adopt security policies for information
networks and systems, taking into account the principles of comprehensive security, risk
management, prevention, response and recovery, lines of defence, periodic
reassessment and segregation of duties.
These policies shall consider at least the following aspects:
a) risk analysis and management;
b) third-party or provider risk management;
c) catalogue of physical, technological, organisational and security measures;
d) HR and professionalism;
e) acquisition of security products or services;
f) incident detection and management;
g) operational continuity assurance and recovery plans;
h) continuous improvement;
i) system interconnectivity;
j) user activity logging.
3. The security measures adopted by operators of essential services shall take into
account, in particular, dependencies of information networks and systems and the
continuity of services or supplies contracted by the operator, and interactions with third-
party information networks and systems.
The measures adopted shall be detailed in a document entitled ‘Statement of
Applicability of security measures’, which shall be signed by the information security
officer designated as per the following article. This document, which shall be submitted
to the relevant competent authority within six months after designation of the operator as
an operator of essential services, shall be updated at least once every three years. The
relevant competent authority shall supervise both the initial Statement of Applicability of
the security measures and its subsequent updates, pursuant to Article 14 of this Royal
Decree.
4. The measures referred to in the preceding paragraphs shall take those in
Annex II to Royal Decree 3/2010 of 8 January 2010 governing the National Security
Framework as a reference where applicable, and shall be based on other pre-existing
national security frameworks wherever possible.
Without prejudice to the above, other recognised international standards may also
be taken into account.
5. The measures adopted may be supplemented with other measures, based on
specific needs. In particular, they shall be supplemented with any special measures
adopted by the competent authority, pursuant to Articles 16(4) and 32(2) of Royal
Decree-Law 12/2018 of 7 September 2018.
7
Article 7. Information security officer
1. Pursuant to Article 16(3) of Royal Decree-Law 12/2018 of 7 September 2018,
operators of essential services shall designate an information security officer to perform
the duties of the contact and technical coordination with the competent authority pursuant
to this Royal Decree.
2. Operators of essential services shall designate and notify the relevant
competent authority of the information security officer within three months after their
designation as operators of essential services, as well as any appointments and
dismissals affecting the information security officer designation within 30 days after their
occurrence.
3. The information security officer shall act as a point of contact with the
competent authority for supervision of the security requirements for information networks
and systems, and as a special point of contact for coordination of incident management
with the reference CSIRT.
Pursuant to Article 16(3) of Royal Decree-Law 12/2018 of 7 September 2018,
this officer shall be responsible for performance of at least the following duties:
a) develop security policies and submit them to the organisation for adoption,
pursuant to Article 6(2) of this Royal Decree, which shall include suitable and
proportionate technical and organisational measures to manage risks to the
security of information networks and systems used and to minimise the
impact of cyber-incidents affecting the organisation and the services,
pursuant to the provisions of Article 6 of this Royal Decree;
b) supervise and develop implementation of security policies, standards and
procedures derived from the organisation, supervise their effectiveness and
conduct periodic security audits;
c) draft the ‘Statement of Applicability of security measures’ document referred
to in the second paragraph of Article 6(3) of this Royal Decree;
d) serve as a trainer for good practices in information network and system
security, for both hardware and software aspects;
e) provide the competent authority, via the reference CSIRT and without undue
delay, with reports on incidents with a disruptive impact on the provision of
services, as referred to in Article 19(1) of Royal Decree-Law 12/2018 of
7 September 2018;
f) receive, interpret and supervise the implementation of instructions and
guides issued by the competent authority, both for normal operation and for
correction of identified shortcomings;
g) compile, prepare and submit information or documentation to the competent
authority or the reference CSIRT, at its request or at the officer’s own
initiative.
The information security officer may use third-party services in the performance
of his or her duties.
8
4. Operators of essential services shall ensure that the information security officer
meets the following requirements:
a) support from personnel with suitable expertise and experience in
cybersecurity, from organisational, technical and legal perspectives, to
perform the duties specified in the preceding paragraph;
b) access to the resources needed to perform these duties;
c) hold a position in the organisation that facilitates performance of his or her
duties, and participate in a proper and timely manner in all matters related
to security, and maintain real and effective communication with upper
management;
d) maintain proper independence from information network and system
managers.
5. If the requirements for knowledge, experience, independence and any
applicable level of education are met, the duties and responsibilities entrusted to the
information security officer may be combined with those indicated for the Security and
Liaison Officer, the Data Protection Officer or the Security Officer under the National
Security Framework, pursuant to the regulations applicable to these roles.
CHAPTER IV
Security incident management
Article 8. Security incident management
1. Operators of essential services and digital service providers shall manage and
resolve security incidents that affect the information networks and systems used when
providing their services, for both their own systems and networks and those of third-party
providers.
This obligation covers both incidents detected by the operator or provider itself
and those reported by the reference CSIRT or the competent authority, if they are aware
of any circumstances that raise suspicions of an incident.
2. Without prejudice to Article 28(1) of Royal Decree-Law 12/2018 of
7 September 2018, operators of essential services and digital service providers may
request specialised support from the reference CSIRT for incident management, in which
case they shall heed the instructions it provides to resolve the incident, mitigate its impact
and restore the affected systems.
3. In incident resolution, operators of essential services shall apply the relevant
aspects of the security management policy for information networks and systems as per
Article 6 of this Royal Decree, and the special obligations imposed by the competent
authorities.
4. In addition, operators shall take into account incidents that may affect their own
information networks and systems as well as those of third-party providers that may
interact with their own, even if the latter are digital services providers falling under this
Royal Decree.
Article 9. Incident reporting obligations on operators of essential services
1. Operators of essential services shall notify the relevant competent authority,
via the reference CSIRT, of incidents that may have a significant disruptive impact on
9
these services, which for these purposes shall be incidents with a critical, very high or
high impact, as specified in Section 4 of the National Incident Reporting and
Management Instruction, given in the annex to this Royal Decree.
In addition, they shall report any events or incidents which, due to their threat
level, may affect information networks and systems used to provide essential services,
even if they have not yet had an actual adverse impact on these. For these purposes,
these incidents shall be those with a critical, very high or high threat level, as specified
in Section 3 of said Instruction.
2. Without prejudice to the above, the competent authorities may impose special
obligations, pursuant to Article 19(5) of Royal Decree-Law 12/2018 of
7 September 2018, that set levels different from those in the National Incident Reporting
and Management Instruction, as well as sector-specific factors and thresholds,
applicable to operators subject to supervision.
Article 10. Incident reporting procedures
1. The reference CSIRTs shall ensure a smooth exchange of information with the
relevant competent authorities, ensuring proper monitoring during incident management,
and access to the information used in the various stages of incident management.
2. Operators of essential services shall submit reports via the designated
information security officer.
If an operator of essential services meets the criteria set out in Article 6(2) of
Royal Decree-Law 12/2018 of 7 September 2018 on the security of information networks
and systems, the information security officer shall coordinate this with the Security and
Liaison Officer as per Article 16 of Law 8/2011 of 28 April 2011, setting out measures to
protect critical infrastructure.
3. Operators of essential services shall submit an initial report as soon as they
have the information to establish that circumstances warrant reporting, in view of the
relevant factors and thresholds, and in any case within no more than 48 hours after they
become aware that the incident occurred.
Interim reports shall be provided as needed to update or supplement the
information in the initial report, and to report on incident progress, until it is resolved,
followed by a final incident report after resolution, with detailed information on the
development of the event, assessment of the likelihood of recurrence and any corrective
measures the operator plans to take.
4. Where available, reports shall include information for determining any cross-
border effects from the incident.
5. The provisions in the paragraphs above shall apply to digital service providers
not otherwise regulated under the implementing act provided for in Article 16(9) of
Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016
concerning measures for a high common level of security of network and information
systems across the Union.
6. The reference CSIRT, in collaboration with the competent authority, shall
assess this information promptly to determine if the incident could have a significant
disruptive impact on the essential services provided in other European Union Member
States, in which case the single point of contact shall report this to the affected Member
States.
In addition, along with the relevant reference CSIRT, the competent authority
shall assess information from other Member States on incidents with potential cross-
10
border impacts, and shall report this and forward the relevant information to any
operators of essential services that may be affected.
Article 11. National Cyber-incident Reporting and Monitoring Platform
1. In partnership with the INCIBE-CERT and the ESP DEF CERT, the CCN-CERT
shall make the National Cyber-incident Reporting and Monitoring Platform available to
all stakeholders.
2. The platform shall enable secure and reliable information exchange and
incident monitoring between operators of essential services or digital services provides,
the competent authorities and reference CSIRTs, without prejudice to the special
requirements applicable for personal data protection.
3. Moreover, this platform shall ensure information availability, authenticity,
integrity and confidentiality, and shall be usable to meet the reporting requirement under
sector regulations, pursuant to Article 19(5) of Royal Decree-Law 12/2018 of
7 September 2018.
4. The platform shall also feature various communication channels for use by the
competent authorities and the reference CSIRTs. The platform shall ensure access for
the competent authorities to all information related to the report and the current status of
incidents in their areas of competency, so they can conduct the necessary monitoring
and supervision of incident progress at all times. Similarly, the platform shall provide the
competent authorities with access to statistical data, in particular those necessary to
generate the reports indicated in Article 5 of this Royal Decree.
5. In addition, the platform shall implement the incident reporting and
management procedure with 24/7 availability, with at least the following capabilities:
a) cyber-incident management with incorporation of type, criticality and third-
party reports, as per the annex;
b) exchange of information on cyber-threats;
c) sample analysis;
d) vulnerability logging and reporting;
e) secure communication between parties involved in different forms and on
different platforms;
f) bulk data exchange;
g) generation of aggregate reports and statistics.
Article 12. Incident information
1. Where circumstances permit, the reference CSIRTs shall provide operators of
essential services and digital service providers that submit reports with the relevant
information for incident report monitoring, in particular information that may facilitate
effective incident management.
2. In addition, the competent authorities and the reference CSIRTs shall provide
operators of essential services and digital service providers that may be affected by
these incidents with any information that may be relevant to incident prevention and/or
resolution.
3. When providing the information as per the above paragraphs, the competent
authorities and the reference CSIRTs shall protect the commercial interests of operators
11
of essential services and digital service providers by maintaining the confidentiality of the
information they receive from these providers wherever possible, pursuant to Article 15
of Royal Decree-Law 12/2018 of 7 September 2018.
Article 13. Action in response to allegedly criminal incidents
1. As soon as possible and in accordance with Article 262 of the Code of Criminal
Procedure, the Cybersecurity Coordination Office of the CNPIC shall notify the State
prosecution service, by way of the Judicial Police, of any security incidents reported to it
that are criminal in nature, with concurrent submission of the information available on the
incident. To this end, it may request any information related to the incident that it deems
necessary from the affected operators or the reference CSIRTs.
2. The consultations provided for in Article 14(1) of Royal Decree-Law 12/2018
of 7 September 2018, on public safety and security, shall be conducted through the
Cybersecurity Coordination Office.
CHAPTER V
Supervision
Article 14. Supervision of security requirements
1. Within their areas of activity, the competent authorities shall supervise
compliance with any security and incident reporting obligations applicable to operators
of essential services and digital service providers pursuant to Royal Decree-
Law 12/2018 of 7 September 2018 and this Royal Decree.
Operators of essential services and digital service providers shall collaborate with
the competent authority in this supervision, by facilitating inspection activities, providing
any and all information requested to this effect, and heeding any instructions issued to
correct identified shortcomings.
Compliance with security obligations for information networks and systems may
be attested by certification under a security scheme recognised by the competent
authority.
The competent authorities may conduct the inspection activities required in the
performance of their supervisory duties. In particular, the inspection activities of the
competent authorities shall be intended to:
a) verify compliance with any technical standards and instructions applicable
to operators subject to supervision;
b) verify performance of the duties of the information security officer designated
by operators of essential services, pursuant to Article 7(3) of this Royal
Decree;
c) conduct the checks, inspections, tests and reviews necessary to verify
compliance with the security measures provided for in Article 6, in particular
the security policy of operators of essential services and the Statement of
Applicability of security measures.
Pursuant to Article 32(1) of Royal Decree-Law 12/2018 of 7 September 2018,
where advisable given the required volume or complexity of inspection activities, the
competent authorities may require an operator of essential services to submit an audit
report, prepared by an independent and financially solvent third-party entity, on the
security of its information networks and systems.
12
2. The reference CSIRTs shall collaborate with the competent authorities, where
the latter requests such, in the performance of the duties referred to in the preceding
paragraph. In particular, they shall provide technical advice on the suitability of security
measures taken by the operators of essential services and digital service provides by
virtue of Article 6 of this Royal Decree.
In addition, in cases of operators with an impact on National Defence as per
Article 4(2) of this Royal Decree, the ESP DEF CERT may collaborate with the
competent authority in this supervision.
3. In cases of digital service providers, this shall be coordinated with the
corresponding competent authorities of the European Union Member States where these
providers provide services or have their main establishment in the EU.
First additional provision. References to competent authorities
The references to Ministries, bodies and entities given in Article 3 of this Royal
Decree shall apply to those that replace these or take on their powers in the future.
Second additional provision. Designation of information security officer by designated
operators of essential services
Operators of essential services designated as per the first additional provision of
Royal Decree-Law 12/2018 of 7 September 2018 shall notify the relevant competent
authority of the identity of the information security officer within three months after entry
into force of this Royal Decree.
Third additional provision. Guidelines for incident management and compliance with
reporting obligations
The National Security Council, at the proposal of its special cybersecurity
committee, and with its duties as single point of contact set out by the National Security
Department, shall adopt guidelines on the National Incident Reporting and Management
Instruction included in the annex, and to update the National Cyber-incident Reporting
and Management Guide, which provide guidelines and recommendations for meeting
the reporting obligations under this Royal Decree, and Royal Decree-Law 12/2018 of
7 September 2018, to improve coordination and optimise the resources dedicated to
managing incidents that affect information network and system security.
These guidelines may be complied into a National Cybersecurity Incident
Reporting and Management Guide.
Fourth additional provision. Special regime for the Bank of Spain
The provisions of this Royal Decree shall apply without prejudice to the powers
and duties granted to the Bank of Spain, the European Central Bank and the European
System of Central Banks, in accordance with the Treaty on the Functioning of the
European Union, the Statutes of the European System of Central Banks and of the
European Central Bank, Council Regulation (EU) No 1024/2013 of 15 October 2013 and
Law 13/1994 of 1 June 1994 on the Autonomy of the Bank of Spain.
Where not covered in its special regulations and where compatible with its nature,
duties and independence, the provisions of this Royal Decree shall apply to the Bank of
Spain.
13
Fifth additional provision. Cases of dependence on third-party providers
With regard to Article 19(3) of Royal Decree-Law 12/2018 of 7 September 2018,
if operators of essential services or digital service providers depend on third-party
providers subject to the ninth addition provision of Law 34/2002 of 11 July 2002 on
information society and e-commerce services, the competent CERT for the third-party
provider shall be:
- the CCN-CERT of the National Cryptography Centre [CCN], if the provider
falls under the scope of Law 40/2015 of 1 October 2015;
- the INCIBE-CERT of the Spanish National Cybersecurity Institute [INCIBE],
in all other cases.
First final provision. Powers of regulatory implementation
The Minister for the Economy and Business, the Minister for the Interior and the
Minister for Defence, as well as the Ministers and bodies indicated in Article 3, shall be
authorised, either jointly or separately depending on the subject matter, to issue the
provisions required to implement and apply this Royal Decree within their respective
areas of competency.
Second final provision. Powers to amend the annex
The National Security Council shall be authorised to amend the annex, at the
proposal of its special cybersecurity committee, by way of an agreement published by
an order of the Ministry of the Presidency.
Third final provision. Attribution of powers.
This Royal Decree is issued under the provisions of subparagraphs 21 and 29 of
Article 149(1) of the Constitution, which grant the State exclusive powers over matters
of the general telecommunications system and public safety, respectively.
Fourth final provision. Entry into force
This royal decree shall enter into force on the day after its publication in the
Official State Gazette.
Madrid, [day] [month] 2020.
14
ANNEX
National Cyber-incident Reporting and Management Instruction
1. Reporting obligation
Incidents shall be assigned to one of the threat and impact levels given in this Instruction,
taking into account the reporting obligation for all incidents categorised as CRITICAL,
VERY HIGH or HIGH for all obligated parties subject to this National Cyber-incident
Reporting and Management Instruction. In such cases, they shall report incidents logged
in their information networks and systems in a proper and timely manner and shall report
any impact or threat levels that exceed the thresholds given in this Instruction.
The reference criterion for cybersecurity incident reporting shall be the threat level
assigned to an incident, without prejudice to the fact that during its development,
mitigation and resolution, the incident will be categorised with a certain impact level
which may make it advisable to report the incident to the competent authority or the
reference CSIRT.
In any case, if a particular event may be assigned more than one incident type due to its
potential characteristics, it shall be assigned the type with the highest threat level
according to the criteria given in this Instruction.
2. Classification/types of cyber-incidents
The following Classification/Types of cyber-incidents shall be used to assign a specific
type to an incident logged in an information network or system during reporting to the
competent authority or the reference CSIRT.
CLASSIFICATION/TYPES OF CYBER-INCIDENTS
Classification INCIDENT TYPE Description and practical examples
Unsolicited mass emails. The recipient of the
Spam content did not grant valid authorisation to receive
a collective message.
Defamatory or discriminatory content.
Abusive
Hate crime E.g.: cyberbullying, racism, threats to a person or
content
directed at groups.
Child pornography,
Material that visually depicts content related to child
inappropriate sexual
pornography, incitement of violence, etc.
or violent content
System infected with malware. E.g.: System,
Infected system
computer or mobile phone infected with a rootkit
C&C server
Connection to Command and Control (C&C) server
(Command and
via malware or infected systems.
Harmful Control)
content
Resource used to spread malware. E.g.: resource
Malware distribution
of an organisation used to spread malware.
Resource that hosts malware on configuration files.
Malware configuration
E.g.: webinject attack for Trojan.
15
Sending requests to a system to uncover possible
vulnerabilities. This also includes verification and
Network scanning testing processes to collect data on hosting,
services and accounts. E.g.: DNS, ICMP and
SMTP requests, port scanning.
Data
gathering
Packet analysis
Network traffic monitoring and recording.
(sniffing)
Collection of personal information without using
Social engineering
technology. E.g.: lies, trickery, bribes, threats.
Attempt to compromise a system or interrupt a
Exploitation of known service by exploiting vulnerabilities with a
vulnerabilities standardised identifier (see CVE). E.g.: buffer
overflows, back-doors, cross-site scripting (XSS).
Intrusion
attempt Attempted access
Multiple attempts to breach credentials. E.g.:
with breach of
attempts to crack passwords, brute force attacks.
credentials
Unknown attack Attack using an unknown exploit.
Compromise of
Compromise of a system in which the attacker has
account with
acquired privileges.
privileges
Compromise of
Compromise of a system using accounts without
account without
privileges.
Intrusion privileges
Compromise of Compromise of an application by exploiting
applications software vulnerabilities. E.g.: SQL injection.
Physical intrusion. E.g.: unauthorised access to a
Theft
Data Processing Centre.
Denial of service attack. E.g.: sending requests to a
DoS (Denial of
web application to cause a service interruption or
Service)
delay.
Distributed denial of service attack. E.g.: SYN
DDoS (Distributed
packet flood, reflection and amplification attacks
Denial of Service)
using UDP-based services.
Availability Improper software configuration causing service
Misconfiguration availability problems. E.g.: DNS server with
obsolete KSK for the DNSSEC root zone
Physical sabotage. E.g.: cutting of hardware cables
Sabotage
or arson.
Interruptions with external causes. E.g.: natural
Interruptions
disaster.
Unauthorised access to data. E.g.: theft of access
Data Unauthorised data
credentials by intercepting traffic or accessing
compromise access
physical documents.
16
Unauthorised data modification. E.g.: an attacker
Unauthorised data
uses stolen credentials to modify a system or
modification
application or uses ransomware to encrypt data.
Loss of information. E.g.: loss due to hard drive
Data loss
failure or physical theft.
Use of resources for inappropriate purposes,
Unauthorised use of
including profit-seeking activities. E.g.: use of email
resources
to participate in pyramid schemes.
Offering or installing unlicensed software or other
Copyright
copyrighted material. E.g.: Warez.
Fraud
Type of attack where an entity impersonates
Impersonation
another for unlawful gain.
Impersonating another entity to trick the user into
Phishing
disclosing private credentials.
Publicly accessible services that may feature weak
Weak encryption encryption. E.g.: web servers susceptible to
POODLE/FREAK attacks.
Publicly accessible services that can be used to
DDoS amplification reflect or amplify DDoS attacks. E.g.: open DNS
resolvers or NTP servers with monlist monitoring.
Services with
Vulnerable
potential undesired E.g.: Telnet, RDP or VNC.
access
Public access to services that could potentially
Data disclosure
disclose sensitive data. E.g.: SNMP or Redis.
Vulnerable system. E.g.: client proxy
Vulnerable system misconfiguration (WPAD), outdated system
versions.
Any incidents not falling under the above
Other
categories.
Attacks targeting specific organisations based on
Other highly sophisticated means of concealment,
anonymity and persistence. This threat typically
APT
uses social engineering techniques to achieve
objectives, along with the use of known or authentic
attack procedures.
Table 1. Classification/types of cyber-incidents
3. Cyber-incident threat level
The threat indicator determines the potential danger that the occurrence of an incident
poses in the information or communication systems of the affected entity, and for the
services provided or, where applicable, business continuity. This indicator is based on
characteristics intrinsic to the type of threat and its behaviour.
Incidents shall be assigned one of the following threat levels: CRITICAL, VERY HIGH,
HIGH, MEDIUM, LOW.
17
Critical level:
APT
Very high level:
Malware distribution
Malware configuration
Theft
Sabotage
Interruptions
High level:
Child pornography, inappropriate sexual or violent content
Infected system
C&C server (Command and Control)
Compromise of applications
Compromise of accounts with privileges
Unknown attack
DoS (Denial of Service)
DDoS (Distributed Denial of Service)
Unauthorised data access
Unauthorised data modification
Data loss
Phishing
Medium level:
Hate speech
Social engineering
Exploitation of known vulnerabilities
Attempted access with breach of credentials
Compromise of accounts without privileges
Misconfiguration
Unauthorised use of resources
Copyright
Impersonation
Weak encryption
DDoS amplification
Services with potential undesired access
Data disclosure
Vulnerable system
Low level:
Spam
Network scanning
Packet analysis (sniffing)
Other
18
4. Cyber-incident impact level
The cyber-incident impact indicator shall be determined by assessing the consequences
that the cyber-incident has had on the duties and activities of the affected organisation,
on its assets or on the affected individuals. This process takes into account aspects such
as potential or actual consequences of a specific threat on an information and/or
communication system, as well as on the affected entity itself (public or private entities,
and individuals).
The criteria used to determine the impact level assigned to a cyber-incident are based
on the following parameters:
impact on Public Safety and Security;
impact on the provision of an essential service or on critical infrastructure;
types of information or systems affected;
level of impact on the facilities of the organisation;
potential interruption to the normal provision of services for the organisation;
internal and external time and costs to restore the facilities to normal operation;
financial losses;
geographic area affected;
associated damage to reputation.
Incidents shall be assigned one of the following impact levels: CRITICAL, VERY HIGH,
HIGH, MEDIUM, LOW, NO IMPACT.
Critical level:
significant impact on National Security;
impact on civilian security, with a potential threat to human life;
impact on Critical Infrastructure;
impact on systems classified as SECRET;
impact on over 90% of the systems of the organisation;
interruption in provision of services longer than 24 hours or for over 50% of
users;
resolution of the cyber-incident requires over 100 person-days;
economic impact of over 0.1% of current GDP;
cross-border impact;
very serious damage to reputation and continuous international media
coverage.
Very high level:
impact on civilian security, with a potential threat to property;
significant impact on official activities or missions abroad;
impact on essential services;
impact on systems classified as PRIVILEGED;
impact on over 75% of the systems of the organisation;
interruption in provision of services for over 8 hours or over 35% of users;
resolution of the cyber-incident requires between 30 and 100 person-days;
economic impact of between 0.07% and 0.1% of current GDP;
geographic extent exceeds four autonomous communities or one special
interest territory;
damage to national reputation and image (Spanish brand);
serious damage to reputation and continuous national media coverage.
19
High level:
impact on over 50% of the systems of the organisation;
interruption in provision of services for over 1 hour or over 10% of users;
resolution of the cyber-incident requires between 5 and 30 person-days;
economic impact of between 0.03% and 0.07% of current GDP;
geographic extent exceeds three autonomous communities;
damage to reputation that is difficult to repair, with media attention (extensive
media coverage) and impact on reputation of third parties.
Medium level:
impact on over 20% of the systems of the organisation;
interruption in provision of services for over 5% of users;
resolution of the cyber-incident requires between 1 and 5 person-days;
economic impact of between 0.001% and 0.03% of current GDP;
geographic extent exceeds two autonomous communities;
significant damage to reputation, with media attention (extensive media
coverage).
Low level:
impact on the systems of the organisation;
interruption to provision of a service;
resolution of the cyber-incident requires less than 1 person-day;
economic impact of between 0.0001% and 0.001% of current GDP;
geographic extent exceeds one autonomous community;
isolated damage to reputation, without media attention.
No impact:
no significant impact.
5. Information to report to the competent authority in cases of incidents
In the initial report, the obligated party shall include information for all fields in the table
below of which the party is aware at the time, and shall later complete all of the table
fields in the final incident report.
What to report Description
A sentence providing a general description of the incident.
Matter This will be a legacy field in all reports related to the
incident.
Name of operator of essential services or digital service
OES/DSP
provider.
Strategic sector Energy, transport, finance, etc.
Indicate, as precisely as possible, when the cyber-incident
Incident time and date
occurred.
20
Time and date Indicate, as precisely as possible, when the cyber-incident
incident detected was detected.
Description Describe what happened in detail.
Provide the technical information on the number and type of
Technological
assets affected by the cyber-incident, including IP
resources affected
addresses, operating systems, applications, versions, etc.
Indicate the cause of the incident, if known. Opening a
Origin of incident suspicious file, connection of a USB device, access to a
malicious website, etc.
Possible type and classification of the cyber-incident
Type (classification)
according to the indicated types.
Threat level Indicate the threat level assigned to the incident.
Impact level Indicate the impact level assigned to the incident.
Indicate whether the incident has a cross-border impact on
Cross-border impact
any European Union Member State.
Actions taken so far in response to the cyber-incident.
Action plan and
Indicate the Action Plan applied and countermeasures
countermeasures
taken.
Indicate whether the party affected is a company or
Parties affected individual, and the impacts according to the assigned impact
level.
Means needed for
resolution (person- Capacity used to resolve the incident in person-hours.
hours)
Estimated financial
Costs associated with the incident, both direct and indirect.
impact (if known)
Geographic extent (if Municipality, autonomous community, national, international,
known) etc.
Damage to reputation
Impact on corporate image of operator.
(if known)
Provide a list of documents attached to help determine the
Attachments cause of the problem or resolve it (screenshots, data logs,
emails, etc.).
Regulations affected National Security Framework [ENS]/GDPR/NIS/CIP/other
Does it require law
Yes/no
enforcement action?
Table 2. Information to report to the competent authority in cases of incidents
6. Reporting timeframe
All obligated parties affected by an incident that must be reported to the competent
authority, via the reference CSIRT, shall submit the required initial, interim and final
21
reports, in a proper and timely manner, according to the reporting timeframes given
below.
The initial report consists in alerting the authorities to the existence of an incident.
The interim report updates the authorities with the latest available information
related to the incident.
The final report supplements and confirms the final information related to the
incident.
Nevertheless, the obligated party shall submit any and all additional interim or
subsequent reports that it deems necessary.
Threat and impact
Initial report Interim report Final report
level
CRITICAL Immediately 24/48 hours 20 days
VERY HIGH Immediately 72 hours 40 days
HIGH Immediately - -
MEDIUM - - -
LOW - - -
Table 3. Reporting timeframe
The times given in Table 3 for ‘interim’ and ‘final’ reports apply starting from the time of
submission of the ‘initial’ report. The ‘initial’ report timeframe applies starting from the
time when the party became aware of the incident.
7. Terms and definitions
ABUSIVE CONTENT
Unsolicited mass emails (SPAM): Unsolicited emails sent to a large number of
users, or a high number of emails sent to the same user over a short period of
time.
Bullying: With regard to virtual bullying or cyberbullying, the use of digital means
of communication to bully a person or group of people, by way of personal attacks
or divulging private, personal or false information.
Extortion: Use of violence or intimidation to force a person or business to commit
or refrain from acts with the intention to damage this party, or to profit from the
results.
Offensive messages: Unexpected or unwanted communication, and actions or
behaviours that harm the dignity, reputation or self-esteem of another person.
Offence: Any act classified as an offence according to Organic Law 10/1995 of
23 November 1995 of the Criminal Code.
Paedophilia: Any behaviour related to those described in Title VIII of the Criminal
Code, concerning the grooming or use of minors or persons with disabilities in
need of special protection for acts that threaten their sexual integrity or freedom.
Racism: Any criminal offence including offences against persons or property,
where the victim, location or target of the offence was chosen due to its real or
perceived connection to, sympathy or affiliation with, support of or membership
in a social group, race, religion or sexuality.
Inciting violence: Presentation, before a gathering of people or any other method
of dissemination, of ideas or beliefs that praise the crime or extol its perpetrator.
22
HARMFUL CONTENT
Malware (harmful code): This term is derived from the words ‘malicious’ and
‘software’. Any software that performs actions such as data extraction or another
type of modification of a system can be categorised as malware. Thus, the term
‘malware’ encompasses various types of harmful programmes.
Viruses: Type of malware whose main objective is to change the behaviour of a
computer system without user permission. Viruses are spread by the execution
of software, files or documents with a harmful payload on a system, with the ability
to replicate itself from one system to another. The most common methods of
infection are removable devices, online downloads and email attachments.
Nevertheless, viruses may also be spread by online scripts, documents and XSS
vulnerabilities. It should be noted that a virus requires human action to spread,
unlike other malware, such as worms.
Worm: Malicious software whose main feature is its ability to spread rapidly. It is
intended to replicate itself to new systems to infect them and keep replicating
itself to other IT hardware, by any means, such as email, IRC, FTP, P2P and
other special or widely used protocols.
Trojan: Type of malware disguised as legitimate software to trick the victim into
installing it on their system. Once installed, the harmful software can perform the
malicious activity in the background. A Trojan does not depend on a human
action and cannot replicate itself, but it can cause serious harm to a system as a
Trojan or by exploiting software vulnerabilities.
Spyware: Type of malware that spies on user activities without their awareness
or consent. This may include keylogging, monitoring, data gathering and data
theft. Spyware can spread via Trojans or software exploits.
Rootkit: A collection of harmful software that enables privileged access to areas
of a machine, while at the same time concealing its presence by corrupting the
Operating System or other applications. Here, the term ‘machine’ covers the full
spectrum of IT systems, from smartphones to ICS. Thus, rootkits are intended to
effectively conceal payloads and enable their existence in the system.
Dialler: Type of malware installed on a machine that automatically dials premium-
rate telephone numbers without user consent. These actions incur financial costs
for the victim by charging for the calls made.
Ransomware: This term encompasses malware that infects a machine and
prevents the user from accessing the data stored on the system. Normally, the
victim then receives some form of communication demanding payment of a
ransom in order to access the system and the locked files.
Malicious bot: ‘Botnet’ is a term used to refer to a collection of machines
controlled remotely with generally malicious intent. A bot is malicious software
that receives orders from a main attacker who controls the machine remotely.
C&C servers allow the attacker to control bots and execute orders given remotely.
RAT: An acronym for ‘Remote Access Tool’, this refers to special remote control
functionality of an information system that is integrated into certain malware
families or samples.
C&C: Short for ‘Command and Control’, these are command and control panels
(also known as C2s) that cyber-criminals use to control specific zombie machines
infected with samples of the same malware family. Command and control panels
serve as a point of reference, control and management for infected machines.
Suspicious connection: Any exchange of information over a local or public
network whose origin or destination – and legitimacy – are not fully determined.
23
DATA GATHERING
Port scanning: Use of software for local or remote analysis of the status of the
ports of a machine connected to a network. This action is intended to gather
information for identification of active services and potential vulnerabilities on the
network.
Network scanning: Use of software for local or remote analysis of the status of a
network. This action is intended to gather information for identification of active
services and potential vulnerabilities on the network.
Technology scanning: Use of software for local or remote analysis of the
technologies present or available on a specific network or information system, to
obtain the references of the hardware/software present, as well as their versions,
and potential vulnerabilities.
DNS zone transfer (AXFR IXFR): DNS server transaction used to replicate
databases between a primary server and secondary servers. These transactions
may be authoritative (AXFR) or incremental (IXFR).
Packet analysis (sniffing): Use of software to analyse traffic on a network to
gather information. An attacker can collect and read unencrypted traffic.
Social engineering: Techniques intended to obtain sensitive information from a
target, generally using persuasive methods, against the will and without the
knowledge of the victim.
Phishing: Fraud committed using telematic means where the scammer attempts
to obtain confidential information (passwords, banking details, etc.) from
legitimate users by fraudulent means using social engineering.
Spear Phishing: A form of phishing where the attacker focuses on a specific
target.
INTRUSIONS
Exploit: Any practice where a cyber-criminal harms an information and/or
communication system for unlawful purposes or without proper authorisation.
SQL injection: Type of exploit involving the introduction of malformed SQL strings
or strings that the recipient is not expecting or cannot properly control; these
cause unexpected results in the target application or program and allow the
attacker to produce unexpected effects without authorisation on the target
system.
Cross-Site Scripting XSS (Direct or Indirect): Attack intended to exploit a
vulnerability in web applications, where the attacker injects malformed
statements or injects strings that the recipient is not expecting or cannot properly
control.
Cross-Site Request Forgery (CSRF): This is a type of harmful website exploit
where unauthorised commands are sent by a user that the website trusts. This
vulnerability is also known as XSRF, hostile linking, one-click attacks, session
riding and automatic attacks. Unlike XSS attacks, which exploit a user’s trust in
a particular site, Cross-Site Request Forgery exploits a website’s trust in a
particular user.
Defacement: Type of website attack that changes the visual appearance of a
webpage. These attacks typically use techniques such as SQL injections or some
kind of vulnerability in the page or server.
File inclusion (RFI and LFI): Vulnerability that allows an attacker to display or
execute remote files stored on other servers due to a programming error on the
page that contains file inclusion functions. Local File Inclusion (LFI) is similar to
the remote file inclusion vulnerability, but instead of including remote files, it can
only include local files, i.e. files on the current server for execution.
24
Control system evasion: Process used by a malware sample or a collection of
actions orchestrated by a cyber-criminal to harm or evade security systems or
policies implemented by specific information and communication systems.
Pharming: IT attack that exploits DNS server vulnerabilities. When a user
attempts to access the website, the browser automatically redirects the user to
an IP address hosting a malicious website that replaces the real one, where the
attacker can obtain sensitive information from the user.
Brute force attack: Process that an attacker uses to harm a validation system
based on access credentials, a password, etc., by trying all possible
combinations, to access information and/or communication systems for which the
attacker does not have privileges or authorisations.
Dictionary attack: Process that an attacker uses to harm a validation system
based on access credentials, a password, etc., by using a previously generated
dictionary with specific character combinations, to access information and/or
communication systems for which the attacker does not have privileges or
authorisations.
Access credential theft: Unauthorised access to or theft of access credentials for
information and/or communication systems.
AVAILABILITY
DoS (Denial of Service): Group of techniques intended to render a server
inoperative. This type of attack attempts to overload a server to prevent legitimate
users using the services it provides. This attack consists in flooding the server
with service requests until it cannot respond to them, resulting in its collapse.
DDoS (Distributed Denial of Service): DoS variant where requests are submitted
to the same destination in a coordinated manner from multiple points. This uses
networks of bots, generally without the knowledge of users.
Misconfiguration: Software configuration errors directly associated with loss of
service availability.
Sabotage/terrorism/vandalism: Attacks intended to interrupt or degrade provision
of a service, causing significant harm to service continuity for an institution or
significant damage to reputation, committed for ideological, political or religious
reasons.
Disruption without malicious intent: Actions that may interrupt or degrade
provision of a service, causing significant harm to service continuity for an
institution or significant damage to reputation.
SYN or UDP flood: Methods used to perform DoS or DDoS attacks consisting in
initiating a high volume of sessions to prevent the server responding to legitimate
requests.
Open DNS Resolver: DNS server that can resolve recursive DNS lookups from
any point of origin on the internet. Malicious users often use this server type to
conduct DDoS attacks.
DATA COMPROMISE
Unauthorised access to data or cyber-spying: Process that an unauthorised user
employs to access and view unauthorised content.
Unauthorised data modification: Process that an unauthorised user employs to
access and modify unauthorised content.
Unauthorised data deletion: Process that an unauthorised user employs to
access and delete unauthorised content.
25
Data exfiltration: Process that an unauthorised user employs to disseminate
information in channels or sources where sharing this information is not planned
or authorised.
Unauthorised access to systems: Process that the user employs to access an
information and/or communication system without proper authorisation or without
tacit or express approval, but without harming any services, systems or networks.
POODLE/FREAK attack: Process that makes a server use an unintended and
insecure communication protocol to exfiltrate information.
FRAUD
Unauthorised use of resources: Use of technologies and/or services by users
that are not properly authorised by the competent Management or company.
Identity theft: Malicious activity where an attacker pretends to be a different
person to commit some form of fraud or harassment.
Intellectual property rights: Intellectual property is the collection of rights falling
to authors and other owners (artists, producers, broadcasters, etc.) for the
works and performances they create.
Other fraud: Financial trickery intended to gain a benefit, and that results in
harm to someone.
VULNERABILITIES
Vulnerable technology: Vulnerabilities in technologies, services or networks that
are known to their administrators.
Precarious security policy: Deficient security policy for an organisation, allowing
cyber-criminals to gain unauthorised access, that cannot be reliably determined,
to information systems during a specific period of time.
OTHER
Cyber-terrorism: Computer crimes as per Articles 197 bis and ter and 264 to
264 quater of Organic Law 10/1995 on the Criminal Code where these crimes
are committed for the purposes specified in Article 573(1) of said law. These
purposes are to:
- subvert constitutional order or eliminate or seriously destabilise the
functioning of the political institutions or the social or economic
structures of the State, or force public authorities to perform or refrain
from a particular action;
- seriously disturb public peace;
- seriously destabilise the functioning of an international organisation;
- provoke a state of terror in the general public or a part thereof.
CIP computer damage: Computer crimes as per Article 264(2)(3 and 4) of
Organic Law 10/1995 on the Criminal Code related to the deletion, damaging,
modification, suppression or inaccessibility of data, computer programs or
electronic documents for Critical Infrastructure, and serious misconduct related
to the above that affects the provision of an Essential Service.
APT (Advanced Persistent Threat)/AVT (Advanced Volatile Threat): Attacks
targeting specific organisations based on highly sophisticated means of
concealment, anonymity and persistence. This threat typically uses social
26
engineering techniques to achieve objectives, along with the use of known or
authentic attack procedures.
DGA domains: Procedure for dynamic generation of domains to host Command
and Control servers, a technique used in botnets to evade enforcement.
Cryptography: Technique consisting in encrypting a message, known as
‘plaintext’, by converting it into an encrypted message or ‘ciphertext’, which
cannot be read without the key used to encrypt it.
Proxy: Intermediate computer, usually a server, used to communicate between
two other machines, normally in a manner this is transparent to the user.
GENERAL
Cybersecurity: Field of security dealing with crimes committed in cyberspace
and their prevention.
Cyberspace: Virtual space encompassing all IT and communication systems,
including both information systems and industrial control systems. Cyberspace
is based on the availability of the internet as the network of networks,
supplemented with other data transport networks.
Information networks and systems: This term refers to any of the following three
objects:
- an electronic communications network in the sense of Article 2(a) of
Directive 2002/21/EC;
- any device that automatically processes digital data by means of a
program, or any group of interconnected or interrelated devices in which
one or more devices do so;
- digital data that are stored, processed, retrieved or transmitted using the
aforementioned elements for their functioning, use, protection or
maintenance.
Information network and system security: the ability of information networks and
systems to withstand, to a particular degree of reliability, any action that
compromises the availability, authenticity, integrity or confidentiality of the data
stored, transmitted or processed, or the corresponding services provided by or
accessible via such information networks and systems.
Operator of essential services: a public or private entity of one of the types
indicated in Annex II that meets the criteria set out in Article 5(2) of
Directive (EU) 2016/1148 of the European Parliament and of the Council.
Digital service: a service in the sense of Article 1(1)(b) of
Directive (EU) 2015/1535 of the European Parliament and of the Council that is
of one of the types indicated in Annex III.
Digital service provider: any legal person that provides a digital service.
Cyber-incident: any act with a real adverse impact on the security of information
networks and systems.
Cyber-incident management: all procedures applied to detect, analyse, limit and
respond to an incident.
Cyber-threat: Threat to the systems and services present in cyberspace or
accessible from it.
Types: Classes or groups of subjects or objects with shared characteristics.
GDPR: General Data Protection Regulation, Regulation EU 2016/679.
27
OpenPGP: Standard based on the PGP program (Pretty Good Privacy),
intended to protect information using public-key cryptography, and facilitate
document authentication using digital signatures.
Web inject: Free open-source tool mainly designed to automate testing of web
applications and web services.
Telnet: Network protocol that enables access to another machine for remote
management as if the user were seated at it.
RDP: Remote Desktop Protocol. Proprietary protocol developed by Microsoft
that enables communication to execute an application between a Windows
server and a terminal.
VNC (Virtual Network Computing): Free software program based on a client-
server structure that enables remote observation of server actions via a client
computer.
SNMP (Simple Network Management Protocol): Network protocol used to
exchange messages for network device management.
Redis: In-memory database engine, based on storage in hash tables.
ICMP: Internet Control Message Protocol.
Clean backup: Secure and uncompromised restoration point for a system.
28
Maret Ots
Saatja: Karl Stern <
[email protected]>
Saatmisaeg: esmaspäev, 9. märts 2020 13:25
Adressaat: Mart Laas; Maret Ots
Teema: teatis
Manused: 2019637E.DOCX
Tere
Saadan Hispaania teatise 637 „KUNINGLIK DEKREET XX/20XX, MILLEGA RAKENDATAKSE 7. SEPTEMBRI 2018. AASTA
KUNINGLIKKU DEKREET-SEADUST 12/2018, VÕRGU- JA INFOSÜSTEEMIDE TURVALISUSE KOHTA“.
Ooteaeg lõpeb juba 16.03.
KUNINGLIK DEKREET XX/20XX, MILLEGA RAKENDATAKSE 7. SEPTEMBRI 2018. AASTA KUNINGLIKKU DEKREET-
SEADUST 12/2018, VÕRGU- JA INFOSÜSTEEMIDE TURVALISUSE KOHTA
Eelnõu puudutab oluliste ja teatavate digiteenuste osutamist eri valdkondades, sealhulgas kosmosetööstuses,
valitsuses, keemia- ja tuumatööstustes, uurimisasutustes ja toiduainetööstuses.
Dekreedi eesmärk on tõsta peamistes majandus- ja sotsiaalvaldkondades oluliste teenuste osutamiseks kasutatavate
võrgu- ja infosüsteemide turvalisust, mille puhul on üha enam vahejuhtumeid, mis on mõnikord nii tõsised, et
mõjutavad oluliselt nende teenuste osutamist ja toovad märkimisväärset kahju ohustatud kasutajatele.
Dekreetseaduses 12/2018 võrgu- ja infosüsteemide turvalisuse kohta võetakse üle Euroopa Parlamendi ja nõukogu
6. juuli 2016. aasta direktiiv (EL) 2016/1148 meetmete kohta, millega tagada võrgu- ja infosüsteemide turvalisuse
ühtlaselt kõrge tase kogu liidus, ning selle kolmandas lõppsättes antakse valitsusele volitused rakendada seaduses
eespool nimetatud kuningliku dekreetseaduse sätteid.
Kooskõlas ülaltooduga täiendatakse selle dekreediga 7. septembri 2018. aasta kuningliku dekreedi 12/2018 alusel
võrgu- ja infosüsteemide turvalisuse osas pädevate asutuste määramist, tehes kindlaks need asutused, mis vastavad
oluliste teenuste osutajatele ja keda ei peeta esmatähtsaks ning kes ei kuulu 1. oktoobril 2015. aasta avaliku sektori
õiguslikku raamistikku käsitleva seaduse 40/2015 kohaldamisalasse, pöörates tähelepanu 28. aprilli 2011. aasta
seaduses 8/2011 osutatud strateegilistele sektoritele, millega kehtestatakse meetmed esmatähtsa infrastruktuuri
kaitseks.
Peale selle rakendatakse dekreediga standardsete CSIRTide (küberturbe intsidentide lahendamise üksuste) vahelist
koostööd ja koordineerimist juhtumite puhul, mis kuuluvad küberjuhtumite teavitamise ja järelevalve riikliku
platvormi pädevusalasse. Eelkõige rakendatakse sellega kuningliku dekreedi sätteid olukordades, mis mõjutavad
riikliku julgeolekuga seotud ettevõtjaid, samuti meetmeid, mis on ette nähtud eriti tõsiste juhtumite korral, mis
nõuavad suuremat kooskõlastamist kui tavaolukorrad, samuti tegevuses, kus see on hädavajalik standardsete
CSIRTide tegevuste jaoks, mis võivad esmatähtsat ettevõtjat kuidagi ohustada.
1