The Network and Information System Security Act — NISG (see publications) only concerns defined sectors defined in §2 of the Act:
Energy, transport, banking, financial market infrastructures, healthcare, drinking water supply, digital infrastructures as operators of essential services. In addition, providers of digital services, such as online marketplaces, online search engines and cloud computing services, as well as public administration bodies.
Whether a company must meet the requirements of the Network and Information Systems Security Act as an operator of essential services will be determined by the Federal Chancellor and sent to the affected companies by notice, probably starting in Q2 2019. However, due to the new composition of the Austrian Federal Government, we assume a later delivery.
As a provider of digital services, you have to take action yourself and check whether the requirements of the NISG have to be met.
There is no ISO 27001 certification obligation for operators of essential services in Austria, but there is an obligation in the specified areas of
- Governance and risk managemen
- Dealing with suppliers and third parties
- Security architecture
- System administration
- Identity and access management
- System maintenance and operations
- Physical security
- Incident detection
- Incident management
- Business continuity
- Crisis management
Implement appropriate measures and provide evidence of operational effectiveness through regular audits within a 3‑year period.
Although there is no ISO 27001 certification requirement, we believe it is essential to establish a structured approach. Mapping of the divisions with the requirements of ISO 27001 is recommended here. Finally, the use of ISO 27001 is useful and recommended, as the CIP process can be used for the NISG verification. Of course there are a lot of further advantages of an ISO 27001 certification, please read our further article on this topic. “Should i certify my company to ISO 27001?”.
In our next article of the ISO 27001 series, we will highlight the importance of implementing an ISMS system according to ISO 27001 for suppliers of large customers and what advantages this has in supplier management.