// regulations wiki

NIS2 / Law on Cyber Security

← All documents

Intro — LAW ON CYBER SECURITY OF THE REPUBLIC OF LITHUANIA

In simple words: XII-1428 Vilnius CHAPTER I GENERAL PROVISIONS It is descriptive — it defines context or terms rather than imposing direct obligations.

Original text

11 December 2014 No. XII-1428

Vilnius

CHAPTER I

GENERAL PROVISIONS

Article 1 — Purpose and Application of the Law

In simple words: This Law establishes the organisation, management and control of the cyber security system, defines the institutions forming and implementing the cyber security policy, their competences, functions, rights and obligations, the managers of state information resources and/or managers, managers of critical information… It contains 2 binding requirements ("shall/must" rules) organisations have to follow.

Original text

1. This Law establishes the organisation, management and control of the cyber security system, defines the institutions forming and implementing the cyber security policy, their competences, functions, rights and obligations, the managers of state information resources and/or managers, managers of critical information infrastructure, providers of public communications networks and/or public electronic communications services, and obligations and responsibilities of providers of electronic information hosting services and measures to ensure cybersecurity.

2. This Law shall be applied under the conditions and in accordance with the procedure laid down therein to state institutions forming and implementing cyber security policy, entities of public administration, managing and/or managing state information resources, managers of critical information infrastructure, providers of public communications networks and/or public electronic communications services, and providers of electronic information hosting services, business entities operating in the field of information technology, scientific and higher education institutions (hereinafter referred to as cybersecurity participants).

3. This Law shall be applied to the extent that the public relations regulated by this Law are not regulated by the Law on Legal Protection of Personal Data of the Republic of Lithuania, the Law on Electronic Communications of the Republic of Lithuania, the Law on the Fundamentals of National Security of the Republic of Lithuania and the Law on the Management of State Information Resources of the Republic of Lithuania.

Article 2 — The main concepts of this law

In simple words: 1.Shipping: 'Electronic information hosting services' means information society services which include the provision of access to the means for the creation and processing of electronic information and electronic data (hereinafter referred to as 'electronic information') and/or the storage of electronic information… It contains 1 binding requirement ("shall/must" rules) organisations have to follow.

Original text

1.Shipping: 'Electronic information hosting services' means information society services which include the provision of access to the means for the creation and processing of electronic information and electronic data (hereinafter referred to as 'electronic information') and/or the storage of electronic information provided by the recipient of services.

2. "critical information infrastructure" means an electronic communications network or part thereof, an information system or part thereof, a group of information systems or an industrial process management system or a part thereof, regardless of whether its operator is a private or public administration entity, in which a cyber incident is likely to cause serious damage to national security, the national economy, the interests of the State and society.

3. 'Cyberspace ' means an environment in which electronic information is generated and/or transmitted via computers or other information and communication technology equipment connected by an electronic communications network or other information and communication technology equipment.

4. 'Cyber incident' means an event or act which causes or may cause an unauthorised connection or enables unauthorised access to, disruption or alteration of, including takeover, the operation of an information system, electronic communications network or industrial process management system, destroying, damaging, deleting or altering electronic information, deleting or restricting access to electronic information, as well as to create conditions for the appropriation or other use of non-public electronic information by persons who do not have such a right.

5. 'Cybersecurity' means a set of legal, information dissemination, organisational and technical measures to prevent, detect, analyse and respond to cyber incidents, as well as to restore the normal functioning of electronic communications networks, information systems or industrial process management systems in the event of such incidents.

6. 'Industrial process management system ' means a system consisting of equipment based on information and communication technologies for the monitoring or control of technological processes in industry, energy, transport, water supply services and other sectors of economic activity.

7. Other notions used in this Law shall be understood as they are defined in the Republic of Lithuania Law on Electronic Communications, the Republic of Lithuania Law on the Management of State Information Resources, the Republic of Lithuania Law on Information Society Services, the Republic of Lithuania Law on Legal Protection of Personal Data, the Republic of Lithuania Law on Intelligence, the Republic of Lithuania Law on Criminal Intelligence and the Republic of Lithuania Law on Public Administration.

Article 3 — Principles of cybersecurity

In simple words: Cybersecurity shall be based on general principles of law, the principles governing the functioning of electronic communications and the following principles of cybersecurity: 1) non-discrimination in cyberspace – the provisions of laws and regulations and the protected goods are equally applied in both physical and… It contains 7 binding requirements ("shall/must" rules) organisations have to follow.

Original text

1. Cybersecurity shall be based on general principles of law, the principles governing the functioning of electronic communications and the following principles of cybersecurity:

1) non-discrimination in cyberspace – the provisions of laws and regulations and the protected goods are equally applied in both physical and cyberspace;

2) cybersecurity proportionality – the applied cybersecurity measures may not be stricter than necessary to ensure cybersecurity, and the applicable legal, organisational and technical cybersecurity requirements must not restrict the activities of cybersecurity participants in cyberspace more than necessary;

3) public interest predominance – the cyber security measures used must first of all ensure the protection of the public interest of the society, however, they must not substantially violate the rights of individual consumers or disproportionately restrict their freedom in cyberspace.

2. All the principles referred to in paragraph 1 of this Article shall be duly taken into account in the application of the legal rules governing cybersecurity. These principles shall be compatible with each other and shall not be prioritised in advance.

CHAPTER II

CYBERSECURITY POLICY FORMULATION AND IMPLEMENTATION

Article 4 — Cybersecurity policy-making and implementation authorities

In simple words: The strategic objectives of the cyber security policy and the measures necessary to achieve them shall be established by the Government of the Republic of Lithuania (hereinafter referred to as the Government). The Cyber Security Policy shall be formed, organised, controlled and coordinated by the Ministry of National… It contains 4 binding requirements ("shall/must" rules) organisations have to follow.

Original text

1. The strategic objectives of the cyber security policy and the measures necessary to achieve them shall be established by the Government of the Republic of Lithuania (hereinafter referred to as the Government).

2. The Cyber Security Policy shall be formed, organised, controlled and coordinated by the Ministry of National Defence of the Republic of Lithuania (hereinafter referred to as the Ministry of National Defence). The Ministry of the Interior of the Republic of Lithuania (hereinafter referred to as the Ministry of the Interior), the National Cyber Security Centre, the Communications Regulatory Authority of the Republic of Lithuania (hereinafter referred to as the Communications Regulatory Authority), the State Data Protection Inspectorate and the Police Department under the Ministry of the Interior of the Republic of Lithuania (hereinafter referred to as the Police Department) shall participate in the formation of cyber security policy to the extent necessary for the performance of the functions established in this Law legal regulation of the activities of public administration entities managing state information resources, managers of critical information infrastructure, providers of public communications networks and/or public electronic communications services, and providersof e-electronic information hosting services.

3. The cyber security policy shall be implemented by the Ministry of the Interior, the National Cyber Security Centre, the Communications Regulatory Authority, the State Data Protection Inspectorate and the Police Department within the scope of their competence.

Article 5 — Government powers in the field of cybersecurity

In simple words: The Government shall: 1) form the Cyber Security Council and approve its regulation, the number of members of the Council and instruct the Minister of National Defence to determine the personal composition of the Council; 2) approve the methodology for the identification of the Critical Information Infrastructure and… It contains 1 binding requirement ("shall/must" rules) organisations have to follow.

Original text

The Government shall:

1) form the Cyber Security Council and approve its regulation, the number of members of the Council and instruct the Minister of National Defence to determine the personal composition of the Council;

2) approve the methodology for the identification of the Critical Information Infrastructure and the Critical Information Infrastructure and/or the list of managers of such infrastructure;

3) approve the organisational and technical cybersecurity requirements applicable to critical information infrastructure, organisational and technical cybersecurity requirements applicable to State information resources;

4) approve the National Cyber Incident Management Plan;

5) approve standard plans for the management of cyber incidents in critical information infrastructures;

6) perform other functions established in the legal acts of the Republic of Lithuania in the field of ensuring cyber security.

Article 6 — Powers of the Ministry of National Defence in the field of cyber security

In simple words: The Ministry of National Defence, when formulating the cyber security policy and organising, controlling and coordinating its implementation: 1) prepare and submit to the Government for approval the organisational and technical cyber security requirements applicable to the critical information infrastructure and the… It is descriptive — it defines context or terms rather than imposing direct obligations.

Original text

The Ministry of National Defence, when formulating the cyber security policy and organising, controlling and coordinating its implementation:

1) prepare and submit to the Government for approval the organisational and technical cyber security requirements applicable to the critical information infrastructure and the organisational and technical cyber security requirements applicable to the State information resources;

2) prepare and submit the National Cyber Incident Management Plan to the Government for approval;

3) submit to the Government for approval standard plans for the management of cyber incidents in critical information infrastructures;

4) approve cyber defence plans for critical information infrastructures;

5) prepare and approve the regulations of the Cyber Security Information Network;

6) perform other functions established in the legal acts of the Republic of Lithuania in the field of ensuring cyber security.

Article 7 — Powers of the Ministry of the Interior in the field of cybersecurity

In simple words: Ministry of the Interior: 1) prepare and submit to the Government for approval the Critical Information Infrastructure Identification Methodology and the Critical Information Infrastructure and/or the List of Managers of such Infrastructure; 2) perform other functions established in the legal acts of the Republic of… It is descriptive — it defines context or terms rather than imposing direct obligations.

Original text

Ministry of the Interior:

1) prepare and submit to the Government for approval the Critical Information Infrastructure Identification Methodology and the Critical Information Infrastructure and/or the List of Managers of such Infrastructure;

2) perform other functions established in the legal acts of the Republic of Lithuania in the field of ensuring cyber security.

Article 8 — Powers of the Communications Regulatory Authority in the field of cybersecurity

In simple words: The Communications Regulatory Authority shall, as part of the implementation of its cybersecurity policy, regulate the activities of providers of public communications networks and/or public electronic communications services and providers of electronic information hosting services in the field of cybersecurity… It contains 3 binding requirements ("shall/must" rules) organisations have to follow.

Original text

1. The Communications Regulatory Authority shall, as part of the implementation of its cybersecurity policy, regulate the activities of providers of public communications networks and/or public electronic communications services and providers of electronic information hosting services in the field of cybersecurity assurance and, within the scope of its competence:

1) prepare and approve a description of the procedure and conditions for the provision of information on cyber incidents and the applied measures for the management of such incidents to the Communications Regulatory Authority;

2) prepare and approve organisational and technical requirements applicable to ensure the security and integrity of electronic information hosting services;

3) prepare and approve a description of the procedure and conditions for the provision of technical information necessary for the assessment of the cybersecurity status of public communications networks, public electronic communications services and/or electronic information hosting services to the Communications Regulatory Authority;

(4) carry out investigations into the integrity of the infrastructure of public communications networks and/or providers of public electronic communications services;

5) carry out investigations of the cybersecurity status of public communication networks, public electronic communications services and/or electronic information hosting services;

6) perform other functions established in the legal acts of the Republic of Lithuania in the field of ensuring cyber security.

2. The Communications Regulatory Authority shall, in order to ensure the security and integrity of public communications networks, public electronic communications services and electronic information hosting services, to prevent the spread of cyber incidents, to mitigate cyber incidents involving providers of public communications networks and/or public electronic communications services, providers of electronic information hosting services and/or recipients of public electronic communications services and electronic information hosting services has the right to issue binding instructions and set a deadline for the execution of instructions to providers of public communications networks and/or public electronic communications services and/or electronic information hosting services. The instructions of the Communications Regulatory Authority must be reasoned and proportionate to the achievement of the objective.

Article 9 — Cybersecurity Council

In simple words: The Cyber Security Council is a permanent collegial institution that analyses the state of cyber security assurance in the Republic of Lithuania and makes proposals to cyber security participants for the improvement of this situation. The Cyber Security Council is composed of representatives of state institutions… It contains 3 binding requirements ("shall/must" rules) organisations have to follow.

Original text

1. The Cyber Security Council is a permanent collegial institution that analyses the state of cyber security assurance in the Republic of Lithuania and makes proposals to cyber security participants for the improvement of this situation. The Cyber Security Council is composed of representatives of state institutions forming and implementing cyber security policy, representatives of business entities operating in the field of information technologies, representatives of scientific and higher education institutions, managers of critical information infrastructure, providers of public communications networks and/or public electronic communications services, representatives of providers of electronic information hosting services, and, if necessary, other persons.

2. The Cyber Security Council shall be headed by a representative of the Ministry of National Defence.

3. The economic and technical support of the work of the Cyber Security Council shall be carried out by the Ministry of National Defence or an institution authorised by it.

4. The Cybersecurity Council shall:

1) submit proposals to cyber security participants regarding cyber security priorities, development directions, results to be achieved and ways of their implementation;

2) submit proposals to cyber security participants regarding wider opportunities for cooperation between the public sector, business and science in the field of ensuring cyber security;

3) analyse the trends of improvement of cyber security assurance, provide conclusions and proposals to cyber security participants on the management of cyber incidents;

4) provide recommendations to cyber security participants on strengthening cyber security.