RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Digital infrastructure

You are both an obliged entity and part of somebody else’s supply chain, so alongside your own obligations you receive your customers’ questionnaires.

What the Act requires of this sector

Digital infrastructure is the Annex I sector where competences differ by sub-sector more than anywhere else.

For trust service providers the competent body is the state administration body responsible for digital society development. For public electronic communications networks and services it is the Croatian Regulatory Authority for Network Industries (HAKOM). For DNS services, cloud computing, data centres, content delivery networks and internet exchange points it is the central state authority for cyber security. For the top-level domain name registry it is the state administration body responsible for science and education.

The competent CSIRT for most sub-sectors is the national cyber security centre (NCSC-HR), and for the top-level domain name registry the national CERT. In addition, for entities in this sector Annex III of the Regulation sets out an extended set of physical security measures, under Article 46 of the Regulation.

Where this sector usually gets stuck

Customer questionnairesWithout an ordered evidence file every questionnaire becomes a new project.
Shared responsibility in the cloudThe boundary is often assumed and rarely written down.
Availability as the only metricUptime is measured, recovery capability is not.

What we do for you

01A readiness review across the thirteen measures02An ordered evidence file for customer answers03Clarifying responsibility with the cloud provider04Testing recovery, not just backups05Security clauses in customer contracts

Who from the sector falls in scope

WHOCATEGORYNOTE
Qualified trust service providers, the TLD registry, DNS providersEssentialRegardless of size, Article 9, indent 2 of the Act
Providers of public electronic communications networks and servicesEssential or importantMedium and large are essential, micro and small important; the network industries regulator is competent
Data centres, cloud computing, content delivery networksEssential or importantBy size; the central state authority for cyber security is competent
Internet exchange pointsEssential or importantBy size

The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.

CASE FROM PRACTICE · NETHERLANDS, 2011

DigiNotar: the certificate authority that lost trust and disappeared

An attacker got into the systems of a Dutch certificate authority and issued several hundred fraudulent certificates, including ones for Google domains. They were used to intercept user traffic. Once it became public, browsers dropped DigiNotar from their trust stores, the Dutch government took over part of its operations, and the company soon ceased trading. For a trust service provider, losing trust is not a cost line; it is the end of the business.

SOURCE: Fox-IT report for the Dutch government and statements by Dutch authorities, 2011 and 2012.

Frequently asked questions

The questions digital infrastructure providers ask first, mostly about customer questionnaires and responsibility in the cloud.

Which services are in scope?

Data centres, electronic communications networks, cloud services, DNS, the top level domain registry and trust services. The competent authority and the competent CSIRT differ by sub-sector.

How do we answer customer security questionnaires?

With an organised evidence file. Once the documentation is arranged by measure, a questionnaire becomes an extract rather than a new project.

Who is responsible for what in the cloud?

The boundary is set in the contract and written down. An assumed split of responsibility is the most common source of dispute after an incident.

Is availability a sufficient metric?

It is not. Alongside uptime you measure recoverability, meaning time to restore the service and the maximum acceptable data loss, with evidence that restoration was actually tested.

Do we carry obligations towards our own customers?

You do. Your customers are regulated entities, so security clauses, incident notification and rights of inspection migrate into your contracts.

Do we have stricter physical security obligations?

You do. For entities in the digital infrastructure sector, Annex III of the Regulation sets out an extended set of physical security measures, under Article 46. Measure 13 of Annex II is therefore broader for you than for other sectors.

Do the obligations apply when we provide the service from abroad?

The answer depends on the place of establishment and on where the service is provided, so that is settled at the outset, before any documentation is written. Special jurisdiction rules apply to some entities in this sector.

Related pages

The pages that set out in full what digital infrastructure has to show in measures and evidence.

Let us put the evidence file in order before the next questionnaire.

Half an hour, no obligation. We look at the last questionnaire you received and how long it took you to fill in.

Book a callINFO@RISKORIA.EU · +385 97 737 1345