RISKORIA ADVISING & PROFESSIONAL SERVICES D.O.O. · ZAGREB+385 97 737 1345INFO@RISKORIA.EU

Public administration

Public bodies carry obligations under the law, and for state administration bodies the audit is performed by the Information Systems Security Bureau, not a managed security service provider as in the private sector.

What the Act requires of this sector

The public sector sits in Annex I, and its categorisation is governed by Article 12, separately from the size criteria that apply to business.

State administration bodies and other state bodies, together with legal persons vested with public authority, are classified as essential entities regardless of size, with an assessment of importance applied to the latter. Entities that manage, develop or maintain state information infrastructure are essential regardless of size. Local and regional self-government units are classified as important entities, likewise regardless of size and subject to an assessment of importance.

For the public sector the competent authority for cyber security requirements is the central state authority for information security, that is the National Security Council Office (UVNS), and the competent CSIRT is the national cyber security centre (NCSC-HR). For state administration bodies and other state bodies the audit is carried out by the Information Systems Security Bureau, under Article 32(3) of the Act.

Where this sector usually gets stuck

Procurement that does not ask for securityIf the tender does not ask, the supplier will not offer.
Split accountabilityIT, legal and management each assume another owns the measure.
Citizen requests for access to dataThe clock runs even when nobody is assigned.

What we do for you

01A readiness review across the thirteen measures02Security requirements in tender documentation03Accountability split and measure owners04Incident handling and reporting within the deadlines05Data protection and access logging

Who from the sector falls in scope

WHOCATEGORYNOTE
State administration bodiesEssentialRegardless of size, Article 12(1)
Other state bodies and legal persons with public authorityEssentialRegardless of size, subject to an assessment of importance for essential activities
Managers of state information infrastructureEssentialRegardless of size, Article 12(2)
Local and regional self-government unitsImportantRegardless of size, subject to an assessment of importance, Article 12(3)
Entities in the education systemImportantRegardless of size, subject to an assessment of particular importance, Article 13; the CSIRT is the national CERT

The category is set by the competent authority and the level of measures by the national risk assessment; both are explained in the overview of the Act.

CASE FROM PRACTICE · GERMANY, JULY 2021

Anhalt-Bitterfeld: the district that declared a state of emergency after an attack

A district of 160,000 people declared a state of emergency. Ransomware encrypted the systems, social benefit payments stopped and public registers were blocked, and normal operation returned only over a period of months. A similar scenario later repeated itself in other European cities. Compliance work in public administration takes longer because it runs through budgeting and procurement, so preparation should start at least a year before the deadline.

SOURCE: Public reporting by the competent German and UK authorities; ENISA.

Frequently asked questions

The questions public bodies ask first, mostly about audits, procurement and who owns which measure.

Who performs the audit in state administration bodies?

In state administration bodies and other state bodies the audit is carried out by the Information Systems Security Bureau, under Article 32(3) of the Act. Local and regional self-government units are important entities, so they carry out a self-assessment every two years and an audit only at the request of the competent authority. The competent CSIRT is the national cyber security centre.

Are local self government units also in scope?

State administration bodies are essential entities regardless of size. Local and regional self government units are important entities regardless of size, subject to an assessment of their importance. Other state bodies and legal persons with public authority are essential entities regardless of size, also subject to that assessment.

How do we build security into public procurement?

Through requirements in the tender documents: security clauses in the contract, an obligation to report incidents, a right of inspection and conditions for remote access. If it is not in the documents, no bidder will offer it.

How far in advance should we start?

At least a year before the deadline, because compliance work runs through budgeting and procurement. Those steps cannot be sped up by willpower.

Who owns a measure when accountability is split?

The head of the organisational unit that decides on it, not the IT team that implements it. A measure without a name does not exist in practice.

Related pages

The pages that set out in full what public administration has to show in measures and evidence.

Let us settle who owns which measure.

Half an hour, no obligation. We go through who owns which measure and where the gaps are.

Book a callINFO@RISKORIA.EU · +385 97 737 1345