{"id":708,"date":"2024-01-29T16:47:57","date_gmt":"2024-01-29T16:47:57","guid":{"rendered":"https:\/\/nis2resources.eu\/?page_id=708"},"modified":"2024-08-09T07:41:24","modified_gmt":"2024-08-09T07:41:24","slug":"article-7","status":"publish","type":"page","link":"https:\/\/nis2resources.eu\/directive-2022-2555-nis2\/article-7\/","title":{"rendered":"Article 7, National cybersecurity strategy"},"content":{"rendered":"\n
1. Each Member State shall adopt a national cybersecurity strategyNational Cybersecurity Strategy<\/span> Means a coherent framework of a Member State providing strategic objectives and priorities in the area of cybersecurity and the governance to achieve them in that Member State.\r\r- Definition according Article 6 Directive (EU) 2022\/2555 (NIS2 Directive)<\/a><\/span><\/span><\/span> that provides for the strategic objectives, the resources required to achieve those objectives, and appropriate policy and regulatory measures, with a view to achieving and maintaining a high level of cybersecurityCybersecurity<\/span> \u2018cybersecurity\u2019 means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019\/881;\r\r- Definition according Article 6 Directive (EU) 2022\/2555 (NIS2 Directive)<\/a>\r\r'cybersecurity\u2019 means the activities necessary to protect network and information systems, the users of such systems,\rand other persons affected by cyber threats;\r\r- Definition according Article 2, point (1), of Regulation (EU) 2019\/881;<\/span><\/span><\/span>. The national cybersecurity strategy shall include:<\/p>\n\n\n\n (a) objectives and priorities of the Member State\u2019s cybersecurity strategy covering in particular the sectors referred to in Annexes I and II;<\/p>\n\n\n\n (b) a governance framework to achieve the objectives and priorities referred to in point (a) of this paragraph, including the policies referred to in paragraph 2;<\/p>\n\n\n\n (c) a governance framework clarifying the roles and responsibilities of relevant stakeholders at national level, underpinning the cooperation and coordination at the national level between the competent authorities, the single points of contact, and the CSIRTs under this Directive, as well as coordination and cooperation between those bodies and competent authorities under sector-specific Union legal acts;<\/p>\n\n\n\n (d) a mechanism to identify relevant assets and an assessment of the risks in that Member State;<\/p>\n\n\n\n (e) an identification of the measures ensuring preparedness for, responsiveness to and recovery from incidents, including cooperation between the public and private sectors;<\/p>\n\n\n\n (f) a list of the various authorities and stakeholders involved in the implementation of the national cybersecurity strategy;<\/p>\n\n\n\n (g) a policy framework for enhanced coordination between the competent authorities under this Directive and the competent authorities under Directive (EU) 2022\/2557 for the purpose of information sharing on risks, cyber threats, and incidents as well as on non-cyber risks, threats and incidents and the exercise of supervisory tasks, as appropriate;<\/p>\n\n\n\n (h) a plan, including necessary measures, to enhance the general level of cybersecurity awareness among citizens.<\/p>\n\n\n\n 2. As part of the national cybersecurity strategy, Member States shall in particular adopt policies:<\/p>\n\n\n\n (a) addressing cybersecurity in the supply chain for ICT products and ICT services used by entities for the provision of their services;<\/p>\n\n\n\n (b) on the inclusion and specification of cybersecurity-related requirements for ICT products and ICT services in public procurement, including in relation to cybersecurity certification, encryption and the use of open-source cybersecurity products;<\/p>\n\n\n\n (c) managing vulnerabilities, encompassing the promotion and facilitation of coordinated vulnerabilityVulnerability<\/span> Means a weakness, susceptibility or flaw of ICT products or ICT services that can be exploited by a cyber threat.\r\r- Definition according Article 6 Directive (EU) 2022\/2555 (NIS2 Directive)<\/a><\/span><\/span><\/span> disclosure under Article 12(1);<\/p>\n\n\n\n (d) related to sustaining the general availability, integrity and confidentiality of the public core of the open internet, including, where relevant, the cybersecurity of undersea communications cables;<\/p>\n\n\n\n