
The European Union has adopted a new regulation (2019/881), which addresses key aspects related to cybersecurity.
The regulation, which came into force on June 27, aims to improve protection and security in cyberspace. Let's take a look at its key points.
The Digital Transformation that companies' processes and services means that relevant laws and regulations must be drafted or amended with such frequency as to adapt to the current situation.
Cybersecurity has become a major concern. There are more and more cyber attacks that can cause major problems for companies, public organizations, and individuals.
It is worth noting that the majority of attacks that take place in the EU originate from countries within its borders, with the Netherlands being the main source of origin.
Furthermore, the increasing need to interconnect and integrate various technologies and devices opens the door to new vulnerabilities.
Until recently, legislation on cybersecurity was the responsibility of each country. However, the fact that these threats know no borders made it necessary to develop a legal framework that would regulate the management of cyberspace at a European level.
With this in mind, European Regulation 2019/881 was created, which deals with cybersecurity at all levels within the countries of the European Union.
This new cybersecurity law, which repeals Regulation 526/2013, consists of two main axes on which it is developed. On the one hand, it lays the foundations for the structure and operation of the European Agency for Internet Security (ENISA) and on the other hand, it defines the standards that will allow the certification of cybersecurity of information technologies in the Europe of 28 countries.
With the new European Regulation 2019/881, ENISA intends to bring together all member countries, becoming the reference body for cybersecurity issues, reducing the existing fragmentation.
In order for technological products and services to receive all security guarantees, systems that certify cybersecurity must be defined. These systems must be properly defined (objectives, elements, implementation levels, approval procedures, evaluation, review, etc.).
In addition, lists of products, services and processes that have been assessed against the cybersecurity requirements required in these systems. All this information, including the plans, will be published on the ENISA website.
Organizations wishing to benefit from these measures must meet certain conditions, including the following:
- Provide users with recommendations on the installation, configuration, operation, and maintenance of their product or service.
- Have updates.
- Inform users about potential security issues.
- Provide access to files that reflect the vulnerabilities of the product or service.
The General Data Protection Regulation (GDPR) came into effect on May 25, 2018. This new law applies to all companies that collect and process data belonging to European Union (EU) citizens.
