lagen.nu
CON/2024/14

Opinion of the European Central Bank of 13 May 2024 on cybersecurity (CON/2024/14)

Utgivare
Europeiska centralbanken
Antagen
2024-05-13
Språk
engelska
Ämnesord
http://eurovoc.europa.eu/5456, http://eurovoc.europa.eu/c_3e6af2e7
Källa
eur-lex.europa.eu
Endast på engelskaEuropeiska centralbanken har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska centralbanken.

OPINION OF THE EUROPEAN CENTRAL BANK of 13 May 2024 on cybersecurity (CON/2024/14) Introduction and legal basis

On 12 April 2024 the European Central Bank (ECB) received a request from the Ministry of Finance of the Republic of Latvia for an opinion on a draft law on national cybersecurity (hereinafter the ‘draft law’). The ECB’s competence to deliver an opinion is based on Articles 127(4) and 282(5) of the Treaty on the Functioning of the European Union and the third and fifth indents of Article 2(1) of Council Decision 98/415/EC , as the draft law relates to Latvijas Banka and to payment and settlement systems. In accordance with the first sentence of Article 17.5 of the Rules of Procedure of the European Central Bank, the Governing Council has adopted this opinion.

1. Purpose of the draft law

1.1 The main purpose of the draft law is to improve cybersecurity in Latvia and to implement Directive (EU) 2022/2555 of the European Parliament and of the Council . The draft law replaces the Law on IT security currently in force, which implemented Directive (EU) 2016/1148 of the European Parliament and of the Council . The draft law strengthens and enhances the existing measures and procedures to bolster the security of network and information systems of essential and important entities, as set out in Directive (EU) 2022/2555, and national critical information and communication technology (ICT) infrastructures defined in accordance with the Law on national security . 1.2 More specifically, the draft law has three aims . First, it aims to improve ICT security, including by laying down the requirements for the provision and receipt of essential and important services, and also for the operation of information and communication technologies. Second, the draft law aims to determine the procedures for ensuring cybersecurity, providing for the division of responsibility among the relevant national authorities, the competence of Nacionālais kiberdrošības centrs (NKC, the National Cybersecurity Centre), the framework of cooperation, and the tasks for the promotion of

cybersecurity. Third, the draft law aims to promote the implementation of cybersecurity measures in such a way as to be able to foresee, prevent and overcome cyber threats in a timely manner and to eliminate their consequences, ensuring the continuity of the confidentiality, integrity and availability of services to the extent possible. 1.3 The draft law applies to Latvijas Banka in its entirety. The consultation letter sent to the ECB by the Latvian Minister of Finance explains that for the past two years, Latvian public institutions have experienced a dramatic increase in malicious cyber activities. In 2022, Latvia was the target of 16 % of all cyberattacks against Member States, while the Baltic states collectively were targeted by 32 % of all cyberattacks. Therefore, the consulting authority believes that the cybersecurity of all Latvian public institutions, including Latvijas Banka, should be strengthened, and that excluding Latvijas Banka from the scope of the draft law would pose a major risk to Latvian national security and to the security of the Eurosystem as a whole. 1.4 The draft law provides that the Cabinet of Ministers determines (1) minimum cybersecurity requirements ; (2) the minimum contents of a plan for the management of cyber risks and the continuity of operations, as well as procedures for supervision and control of the execution of the 8 9 10 plan ; (3) the requirements for the cybersecurity of data centres ; (4) cyber hygiene requirements ; and (5) restrictions on activities in the event of a cyber incident . 1.5 Although under the draft law a new institution (the NKC) is established, Latvijas Banka’s cybersecurity compliance will continue to be supervised by Satversmes Aizsardzības birojs (SAB, the Constitution Protection Bureau), which is a state security service. The main tasks of SAB include intelligence, counterintelligence and the protection of state (official) secrets. Such supervision of the cybersecurity of Latvijas Banka will entail checking its conformity with the cybersecurity requirements determined by the Cabinet of Ministers, on-site checks and remote monitoring of information and 12 13 technologies, data and document checks , annual self-assessment reports and a cybersecurity conformity audit . 1.6 If a cyber incident significantly threatens the security of information systems or electronic communications networks and cannot be prevented by other means, SAB may resort to restricting activities, such as, for example, restricting access to the internet protocol (IP) address involved in the cyber incident; restricting access to the mobile platform application involved in the cyber incident; or making changes to the domain name system records . In the event of non-compliance by Latvijas Banka, SAB would be entitled to issue a warning to Latvijas Banka or to direct Latvijas Banka to: (1) take certain actions to remedy the non-compliance, setting a reasonable timeframe for remedying the non-compliance and reporting on progress in remedying the non-compliance; (2) immediately

cease and desist from any further conduct in violation of the provisions of the draft law; (3) inform the recipients of services or publish information on the cyber threat, its nature and extent, as well as the actions necessary to prevent or mitigate it; (4) inform the recipients of services or publish information on the detected infringements of Latvijas Banka . In the event that Latvijas Banka fails to comply with the abovementioned obligations, SAB is entitled to instruct Latvijas Banka to suspend the operation of its information system, resource or e-service until the detected non-compliance is eliminated.

2. General observations

2.1 Directive (EU) 2022/2555 is a minimum-harmonisation directive. Article 5 of that Directive provides that it does not preclude Member States from adopting or maintaining provisions ensuring a higher level of cybersecurity, provided that such provisions are consistent with Member States’ obligations laid down in Union law. The draft law goes beyond Directive (EU) 2022/2555, which excludes central banks (along with parliaments and the judiciary) from the definition of a ‘public administration entity’ .This would have the consequence that the Latvian component of Eurosystem-owned and operated financial market infrastructures, such as TARGET, would not benefit from the exclusion of central banks from the application of Directive (EU) 2022/2555. 2.2 The ECB refers to its previous stance taken in the context of national measures implementing Directive (EU) 2016/1148, whereby the ECB supported the aim of Directive (EU) 2016/1148 of ensuring a high common level of network and information security across the Union and of achieving a consistency of approach in this field across business sectors and Member States . The ECB strongly supports the objectives of Directive (EU) 2022/2555 to increase the level of cyber resilience across all relevant sectors, reduce inconsistencies across the internal market and improve the level of situational awareness and the collective capability to prepare and respond by ensuring efficient cooperation in the Union . As already noted by the ECB, it is important to ensure that the internal market is a safe place to do business and that all Member States have a certain minimum level of preparedness for cybersecurity incidents . Directive (EU) 2022/2555 produces benefits from synergies and economies of scale. In particular, dedicated national cyber security authorities have the potential to become repositories of considerable resources and expertise which the Eurosystem may draw upon. Concurrently, it should be ensured that the provisions of the national legislation transposing Directive (EU) 2022/2555 are interpreted and applied consistently with the Eurosystem’s competences, and respect the principle of central bank independence enshrined in Article 130 of the Treaty. Indeed, Latvijas Banka’s independent exercise of its tasks and responsibilities within the

Eurosystem, for instance to implement monetary policy and for the smooth operation of payment and settlement systems, should not be affected. Central bank independence does not have the consequence of separating the Union’s central banks entirely from the Union and exempting them from every rule of Union law . This also applies to national legislative measures capable of applying to national central banks (NCBs). Furthermore, the exercise of SAB powers is subject to various specific rules and guarantees, whilst the purpose for which they may be used is clearly delineated. In that respect, certain provisions of the draft law provide for specifically listed powers of SAB to be exercised with a view to achieving the objectives set out in the draft law . Therefore, national measures implementing Directive (EU) 2022/2555 that extend to NCBs, such as the draft law, are not per se precluded from applying to Eurosystem central banks.

3. Impact of the draft law on TARGET and on payment systems overseen by the ECB and the Eurosystem

3.1 In accordance with the fourth indent of Article 127(2) of the Treaty, promotion of the smooth operation of payment systems is one of the core tasks of the European System of Central Banks. Furthermore, pursuant to Article 22 of the Statute of the European System of Central Banks and of the European Central Bank (hereinafter the ‘Statute of the ESCB’),,the ECB and the NCBs may provide facilities, and the ECB may make regulations, to ensure efficient and sound clearing and payment systems within the Union and with other countries. Thus, the ECB and the Eurosystem as a whole have a particular interest in an enhanced level of network information security in respect of payment systems, as it fosters confidence in the euro and the smooth functioning of the economy in the euro area and beyond. 3.2 Systemically important payment systems (SIPS) such as, for example, EURO1, STEP2-T and TARGET are identified pursuant to ECB Decisions and are thus overseen by the ECB as the competent authority under Regulation (EU) No 795/2014 of the European Central Bank 25 26 (ECB/2014/28) . SIPS are subject to regular assessment related to operational risk , which allows the competent Eurosystem central bank, as the competent authority, to verify that the systems are in compliance. In cases of non-compliance, the competent Eurosystem central bank has the power to impose sanctions or corrective measures to ensure compliance . 3.3 Regulation (EU) No 795/2014 (ECB/2014/28) inter alia contains provisions aimed at ensuring cyber resilience for financial market infrastructures. It provides that a SIPS operator is required to establish

an effective cyber resilience framework with appropriate governance measures in place to manage cyber risk. The SIPS operator must identify its critical operations and supporting assets, and have appropriate measures in place to protect them from, detect, respond to and recover from cyberattacks. These measures are to be regularly tested. The SIPS operator is required to ensure that it has a sound level of situational awareness of cyber threats. The SIPS operator is required to ensure that there is a process of continuous learning and evolution to enable it to adapt its cyber resilience framework to the dynamic nature of cyber risks, in a timely manner, whenever needed. 3.4 The ECB understands that the draft law should be without prejudice to the oversight of SIPS given that such oversight is performed on the basis of ECB regulations issued on the basis of Article 3.1, Article 22 and the first indent of Article 34.1 of the Statute of the ESCB. 3.5 Among the listed SIPS, TARGET plays a distinct role, as it is the large value payment system for the euro, which is owned and operated by the Eurosystem and which serves as the channel for the implementation of the euro area’s monetary policy. TARGET has its own legal personality and is subject to harmonised legal conditions defined in Guideline (EU) 2022/912 of the European Central Bank (ECB/2022/8) . The Latvian component of TARGET, TARGET-Latvija, for which Latvijas Banka acts as the operator, would appear to fall within the scope of the draft law, as the draft law applies to Latvijas Banka and no exemption with regard to infrastructures or payment systems operated by Latvijas Banka is provided. 3.6 Against this background, the ECB would welcome the establishment of cooperation arrangements between SAB and Latvijas Banka going beyond what is currently envisaged in the draft law , which pertains only to matters related to the cybersecurity of the financial entities referred to in Article 2 of Regulation (EU) 2022/2554 of the European Parliament and of the Council . The ECB suggests that, in the context of such cooperation, effective information-sharing and consultation mechanisms are put in place in order to prevent situations which could undermine the ability of Latvijas Banka to perform its ESCB tasks independently. In particular, Latvijas Banka would need to be informed about actual and potential cyber incidents, as well as planned or adopted measures which may affect the TARGET-Latvija component in a timely and efficient manner in order to enable Latvijas Banka to fulfil its obligations under the Treaty and the Statute of the ESCB. Such arrangements would also ensure that SAB and Latvijas Banka exchange information and consult on actual and potential cyber incidents or threats in the financial sector’s systems, and in particular infrastructures operated by the Eurosystem, and on planned and adopted measures, in an effective and timely manner without the need to resort to the unilateral enforcement measures envisaged under the draft law. 3.7 In addition, the ECB stands ready to cooperate with SAB, with a view to ensuring that best practices with regard to Directive (EU) 2022/2555 are established and followed . The ECB also suggests that the respective cooperation and information-sharing arrangements are established between SAB and

the ECB, through Latvijas Banka, to ensure that the overall functioning of TARGET is not undermined. This opinion will be published on EUR-Lex.

Done at Frankfurt am Main, 13 May 2024. [signed]

The President of the ECB

Christine LAGARDE

Fotnoter

  1. 1 Council Decision 98/415/EC of 29 June 1998 on the consultation of the European Central Bank by national authorities regarding draft legislative provisions (OJ L 189, 3.7.1998, p. 42).
  2. 2 Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80).
  3. 3 Informācijas tehnoloģiju drošības likums, Latvijas Vēstnesis, 2010, 178. Nr.
  4. 4 Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union (OJ L 194, 19.7.2016, p. 1). 5 Nacionālās drošības likums, Latvijas Vēstnesis, 473/476, 29.12.2000.
  5. 7 See Section 24 of the draft law. 8 See Section 26 of the draft law. 9 See Section 28 of the draft law.
  6. 16 See Section 43 of the draft law. 17 See Article 6(35) of Directive (EU) 2022/2555. 18 See paragraph 2.1 of Opinion CON/2014/58 of the European Central Bank of 25 July 2014 on a proposal for a directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security across the Union (OJ C 352, 7.10.2014, p. 4), paragraph 2.1 of Opinion CON/2017/10, paragraph 2.2 of Opinion CON/2018/22, paragraph 2.2 of Opinion CON/2018/27 and paragraph 2.2 of Opinion CON/2019/17. All ECB opinions are published on EUR-Lex. 19 See Opinion CON/2022/14 of the European Central Bank of 11 April 2022 on the Proposal for a Directive of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148 (OJ C 233, 16.6.2022, p. 22), General observations. 20 See paragraph 2.2 of Opinion CON/2019/17.
  7. 21 See judgment of the Court of Justice of 10 July 2003, Commission v ECB, C-11/00, EU:C:2003:395, paragraphs 134 to 136. 22 See Sections 7, 8 and 12 of the draft law. 23 See Section 2 of the draft law. 24 Decision ECB/2014/35 of the European Central Bank of 13 August 2014 on the identification of TARGET2 as a systemically important payment system pursuant to Regulation (EU) No 795/2014 on oversight requirements for systemically important payment systems (OJ L 245, 20.8.2014, p. 5); Decision ECB/2014/36 of the European Central Bank of 13 August 2014 on the identification of EURO1 AND STEP2-T as systemically important payment systems pursuant to Regulation (EU) No 795/2014 on oversight requirements for systemically important payment systems, available on EUR-Lex. 25 Regulation of the European Central Bank (EU) No 795/2014 of 3 July 2014 on oversight requirements for systemically important payment systems (ECB/2014/28) (OJ L 217, 23.7.2014, p. 16). 26 See Article 15 of Regulation (EU) No 795/2014 (ECB/2014/28). 27 See paragraph 3.4 of Opinion CON/2017/10 and paragraph 3.1.2 of Opinion CON/2019/17.
  8. 28 Guideline (EU) 2022/912 of the European Central Bank of 24 February 2022 on a new-generation Trans-European Automated Real-time Gross Settlement Express Transfer system (TARGET) and repealing Guideline ECB/2012/27(ECB/2022/8) (OJ L 163, 17.6.2022, p. 84). 29 See Section 13(3)1) of the draft law. 30 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1). 31 See paragraph 6.3 of Opinion CON/2018/22 and paragraph 2.4 of Opinion CON/2019/17.