This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
The First Supervision of the Implementation of Information Security Measures Has Begun
Authorities and other entities designated as key and important subjects under the Law on Information Security have been sent an initial questionnaire by the Agency to gain insight into the current application of information security measures and to assess the state of cybersecurity in sectors defined by law. The purpose of the first supervision is, among other things, to understand how the entity manages information security, the level of management involvement in managing cyber risks, understanding legal obligations, and establishing cooperation between the Agency and the supervisory entity. The analysis of received responses indicates that key entities show a higher percentage of compliance with information security measures than important entities, and some sectors demonstrate a high level of compliance. Responses also reveal that the most pronounced weaknesses include the organization of the information security system, responsibilities, employee management, and awareness raising, indicating a need for more active management participation in implementing information security measures within the entities they oversee. It is important to note that the Agency's activities relate to critical infrastructure, primarily key and important entities that apply information and communication technologies and provide services of special importance for life, health, citizen safety, and the functioning of the state. The Agency plans to organize working meetings and training sessions with domestic and international partners to support and further strengthen the capacities of key and important entities in implementing information security measures.