Defining the reporting threshold for a cybersecurity incident under the NIS Directive and the NIS 2 Directive

被引:9
|
作者
Schmitz-Berndt, Sandra [1 ,2 ]
机构
[1] Univ Luxembourg, Fac Law Econ & Finance, L-2721 Luxembourg, Luxembourg
[2] 4 Rue Alphonse Weicker, L-2721 Luxembourg, Luxembourg
来源
JOURNAL OF CYBERSECURITY | 2023年 / 9卷 / 01期
关键词
NIS Directive; incident reporting; cybersecurity; NIS; 2; Directive;
D O I
10.1093/cybsec/tyad009
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
The NIS Directive and sector-specific cybersecurity regulations require the reporting of (security) incidents to supervisory authorities. Following the risk-based approach adopted in the NIS Directive, the NIS 2 Directive enlists as a basic security element the reporting of significant incidents that (i) have caused or (ii) are capable to cause harm, as well as (iii) notifying the service recipients of cyber threats. Although during the interinstitutional negotiations between the European Commission, the European Parliament, and the Council of the European there was consensus that the NIS Directive's reporting framework needs to be reformed, views on the determination of what needs to be reported varied. This paper outlines and analyses the different concepts of a report-worthy significant incident that have been proposed during the legislative procedure for the NIS 2 Directive from a legal and policy perspective. Irrespective of further motives that may inhibit reporting, legal compliance is difficult to achieve where legal requirements are vague. In that regard, the difficulties to determine the reporting thresholds in the past and in the future are addressed. In consideration of the increased attack surface and threat scenario, it is argued that incidents where no harm has materialized should not be treated any different than incidents that have actually resulted in harm in order to acquire the envisaged full picture of the threat landscape and create value for business and society.
引用
收藏
页数:11
相关论文
共 50 条
  • [31] CyberSecurity Resilience Act (CRA) in practice for IoT devices: Getting ready for the NIS2
    Jara, Antonio J.
    Cuevas Martinez, Iris
    Sanchez Sanchez, Jaime
    2024 IEEE SMART CITIES FUTURES SUMMIT, SCFC 2024, 2024, : 56 - 60
  • [32] Turning Up the Heat? EU Sustainability Goals and the Role of Reporting under the Non-Financial Reporting Directive
    Ahern, Deirdre
    EUROPEAN COMPANY AND FINANCIAL LAW REVIEW, 2016, 13 (04) : 599 - 630
  • [33] Defining benchmark values for nutrients under the Water Framework Directive: Application in twelve Portuguese estuaries
    Caetano, Miguel
    Raimundo, Joana
    Nogueira, Marta
    Santos, Maria
    Mil-Homens, Mario
    Prego, Ricardo
    Vale, Carlos
    MARINE CHEMISTRY, 2016, 185 : 27 - 37
  • [34] Internal Control over Financial Reporting for Romanian Investment Firms under MiFID Directive Requirements
    Danescu, Tatiana
    Spatacean, Ovidiu
    Bolos, Bradut
    APPLIED ECONOMICS, BUSINESS AND DEVELOPMENT, 2010, : 86 - 91
  • [35] THE EVER-INCREASING CYBERSECURITY COMPLIANCE IN EUROPE: THE NIS 2 AND WHAT ALL BUSINESSES IN THE EU SHOULD BE AWARE OF
    Lucini, Valentino
    RUSSIAN LAW JOURNAL, 2023, 11 (06) : 145 - 154
  • [36] Nickel sulfides for electrocatalytic hydrogen evolution under alkaline conditions: a case study of crystalline NiS, NiS2, and Ni3S2 nanoparticles
    Jiang, Nan
    Tang, Qing
    Sheng, Meili
    You, Bo
    Jiang, De-en
    Sun, Yujie
    CATALYSIS SCIENCE & TECHNOLOGY, 2016, 6 (04) : 1077 - 1084
  • [37] Evaluation of the Community Reporting System for Food-borne Outbreaks under Directive 2003/99/EC
    Recio, Jose Ignacio Arraz
    Ammon, Andrea
    Bailie, Harry
    Bedriova, Marta
    Picherot, Melanie
    Borck, Birgitte
    Camilleri, Karen
    Chobanov, Georgi
    Costache, Adriana
    De Smet, Kris
    Hartung, Matthias
    Helwigh, Birgitte
    Hofshagen, Merete
    Kiudulas, Vaidotas
    Lahti, Elina
    Much, Peter
    O'Connor, Lisa
    Van Oosterom, Rob A. A.
    Osek, Jacek
    Paramio Lucas, Jose Luis
    Pavsic, Manca
    Pipis, Christodoulos
    Raulo, Saara
    Ricci, Antonia
    Ribakova, Tatjana
    Rizzi, Valentina
    Satran, Petr
    Schon, Joseph
    Sogel, Jelena
    Szabados, Petra
    Santos, Patricia Tavares
    Unger, Kilian
    Vanholme, Luc
    Vourvidis, Dimitris
    EFSA JOURNAL, 2008, 6 (03):
  • [38] The EU’s cybersecurity framework: the interplay between the Cyber Resilience Act and the NIS 2 DirectiveDer Cybersicherheitsrahmen der Europäischen Union: das Zusammenspiel zwischen Cyber Resilience Act und NIS-2-Richtlinie
    Philipp Eckhardt
    Anastasia Kotovskaia
    International Cybersecurity Law Review, 2023, 4 (2): : 147 - 164
  • [39] Institutional isomorphism under the test of Non-financial Reporting Directive. Evidence from Italy and Spain
    Posadas, Stefania Carolina
    Ruiz-Blanco, Silvia
    Fernandez-Feijoo, Belen
    Tarquinio, Lara
    MEDITARI ACCOUNTANCY RESEARCH, 2023, 31 (07) : 26 - 48
  • [40] Photocatalytic degradation of 2,4,6-trinitrotoluene (TNT) in the presence of ZnS, NiS and ZnS/NiS supported Clinoptilolite under UV irradiation: experimental and neural network modelling
    Norouzi, Mahdi
    Karimian, Azam
    Dehghani, Hosseine
    Rezvan Leylan, Seyyed Alireza
    INTERNATIONAL JOURNAL OF ENVIRONMENTAL ANALYTICAL CHEMISTRY, 2023, 103 (09) : 2082 - 2106