Gaps in NIS standardisation - Recommendations for improving NIS in EU standardisation policy
Recommendations for improving NIS in EU standardisation policy
V. 1.0 NOVEMBER 2016 About ENISA
The European Union Agency for Network and Information Security (ENISA) is a centre of network and information security expertise for the EU, its member states, the private sector and Europe’s citizens. ENISA works with these groups to develop advice and recommendations on good practice in information security. It assists EU member states in implementing relevant EU legislation and works to improve the resilience of Europe’s critical information infrastructure and networks. ENISA seeks to enhance existing expertise in EU member states by supporting the development of cross-border communities committed to improving network and information security throughout the EU. More information about ENISA and its work can be found at www.enisa.europa.eu.
Contact
For contacting the authors please use isdp@enisa.europa.eu For media enquiries about this paper, please use press@enisa.europa.eu.
Acknowledgements
We would like to thank all those who contributed to this study and reviewed it, specifically the members of various Standard Developing Organisations.
Legal notice
Notice must be taken that this publication represents the views and interpretations of the authors and editors, unless stated otherwise. This publication should not be construed to be a legal action of ENISA or the ENISA bodies unless adopted pursuant to the Regulation (EU) No 526/2013. This publication does not necessarily represent state-of the-art and ENISA may update it from time to time.
Third-party sources are quoted as appropriate. ENISA is not responsible for the content of the external sources including external websites referenced in this publication.
This publication is intended for information purposes only. It must be accessible free of charge. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication.
Copyright Notice
© European Union Agency for Network and Information Security (ENISA), 2016 Reproduction is authorised provided the source is acknowledged.
ISBN: 978-92-9204-186-1 doi: 10.2824/975760 Catalogue number: TP-06-16-337-EN-N
Table of Contents
Executive Summary 4
1. Landscape of the European NIS-related standardisation 5
The context for NIS 5
European and global efforts in NIS standardisation 6
1.2.1 Critical Infrastructure Protection initiative support to NIS 7
Work of Cybersecurity Focus Group (CSCG) 7
New context – NIS Directive 7
2. Analysis of the NIS Directive against standards requirements 9
3. NIS Directive requirements 10
Overview 10
Risk management for networks and information systems 10
Impact prevention and minimisation 10
Computer Security Incident Response Teams (CSIRTs), Competent Authorities, and Single Points of Contact 11
Identification of Operators 11
4. Recommendations 12
Annex A: Definitions and abbreviations 13
Definitions 13
Abbreviations 13
Annex B: Summary of NIS Directive technical requirements 14
Overview 14
Executive Summary
This report recommends that the European Commission, with the support of the Member States, pursuant to the NIS Directive, adopt a standards based framework for the exchange of threat and defensive measure information that impacts the functioning of Network Information Infrastructure (NII). The capabilities from this framework underscore NII as Critical Infrastructure of the EU and its Member States.
This report recognizes the work already addressed by a number of European bodies including the designated European Standardization Organisations (CEN, CENELEC and ETSI) and the Cyber Security Focus Group (CSCG), the European Reference Network for Critical Infrastructure Protection (ERNCIP), and individual Member States who have already taken steps to facilitate information sharing between Computer Security Incident Response Teams (CSIRTs). The recommendations of this report include extending the technical basis for information sharing in the following ways:
Adopting open standards in threat exchange based on the globally accepted STIX/TAXII/CyBOX platform to be prepared as an European Norm (EN) defining the syntax and semantics of the data and the necessary transfer protocol, and an accompanying guide to the implementation of the standard Extending the risk analysis and defensive measures capabilities defined in current standards to allow Member States to address the NII and NIS provisions necessary to mitigate risk both at national and regional level. This should be prepared as an EN extending the capabilities already described in ETSI TS 102 165-1, ETSI TR 103 305, ISO/IEC 15408 and in relevant ISO/IEC JTC1 2700x series standards.
In making the recommendations above, it is noted that it is not possible to separate provisions for NIS from general provisions for cyber security which have been developed by a broad array of ICT standards bodies and implemented to varying extents by the entities subject to the NIS Directive. A significant concern consists in the fact that EU Regulation No 1025/2012 referenced by the NIS Directive only defines a small handful of organisations as constituting standardization bodies. This is not an accurate reflection of the current state of the market, nor those used within the highly specialized sectors to which the Directive applies.
Furthermore, NII, NIS and Cyber security cannot be geographically isolated and applied only to the European Union. This distributed complexity should be considered in implementing of the necessary information sharing required for effective NIS. Thus many of the capabilities of the NII, of commercial necessity, will be implemented using software and hardware from a global market and not a market restricted to the EU.
1. Landscape of the European NIS-related standardisation The context for NIS
The Network Information Security (NIS) domain is one of the many dimensions of the multi-dimensional cyber-security landscape that can be visualised as a set of linked questions:
1. What is cyber security? 2. Who or what is affected? i.e. What is the cyber environment? 3. What measures enable protection? 4. What measures enable threat detection?
5. What measures enable thwarting and other remedies?
6. What legal remedies exist?
The NIS scope and the scope of what is cyber-security have considerable overlap and whilst the focus of the NIS Directive may be considered as relating to questions 3, 4 and 5 the reality is that the entire set of 6 questions needs to be considered in giving an assurance of NIS as required through the detail to be found in the articles of the NIS Directive. The visual model of the scope of the NIS Directive within Cyber-Security
Focus of the Directive
is shown in Figure 1.
Defense against attack of Network Information Systems shares the same set of fundamental building blocks as any other system. The well-known CIA paradigm (Confidentiality, Integrity, Availability) leads to well-known and understood triples of {threat, security-dimension, countermeasure} such as {interception, confidentiality, encryption}. The role of the CIA paradigm is most often seen in 2 areas: Risk analysis; and, Countermeasure deployment. The CIA paradigm applies equally to NIS as to any other domain in cybersecurity.
European and global efforts in NIS standardisation
Standards are developed for global markets, and whilst there are some regional localisations that are addressed by the European Standardisation Organisations (ESOs) designated in Regulation (EU) No 1025/2012, the state of the global standards market in the NIS and Cyber-security domain is complex and highly specialized within ICT sectors. Practically the formal recognition processes for technical standardisation has been progressively side-lined by the rapid growth over the past twenty years of what may be termed alternative standards development bodies.
The following list enumerates the bodies involved in global cyber security standards whilst a more complete list of bodies is maintained by ETSI in ETSI TR 103 306 and a similar list has been captured in report number 3 of the Cyber Security Focus Group (CSCG).
The actual global cyber security standards ecosystem today used by the ICT industry is depicted in Table 1. This ecosystem is, however, so complex and rapidly evolving that it is probably incomplete. The Table
reflects the recognition in Recital (32) of the NIS Directive that “standardisation of security requirements is a market-driven process.”
Unfortunately, the definition of what constitutes a standard or a specification in the Directive is fundamentally at odds with this recognition by referencing Regulation (EU) No 1025/2012 which excludes almost all the bodies cited in Table 1. (Only CEN, CENELEC, ETSI, ISO/IEC and ITU are recognized as standards bodies).
An immediate consequence of the diversity of the current standardisation ecosystem, and because of the extremely rapid pace of change, is that it is increasingly difficult to authoritatively determine if gaps in standardization or in capability exist. Any failure to recognize the reality of the ecosystem and the constituent members will gravely harm the aims of the NIS Directive and the harmonization of NII/NIS.
1.2.1 Critical Infrastructure Protection initiative support to NIS
The ERNCIP (European Reference Network for Critical Infrastructure Protection) initiative has identified a set of Cyber Security and Network protection standards. However, the ERNCIP work has not addressed NII as a domain in its own right and this needs to be revised. The NII is increasingly a component of all other Critical Infrastructures and this trend is expected to continue to the point that all CI shall have an NII component.
Work of Cybersecurity Focus Group (CSCG)
Within the EU the core standards bodies (CEN, CENELEC and ETSI) have set up the Cybersecurity Coordination Group (CSCG), transformed into Cybersecurity Focus Group (keeping the same acronym) after withdrawal of ETSI, which main goals include giving strategic advice to the technical committees of European standards developing organisations and EU Institution. In this frame, the CSCG has undertaken extended work emanating from the White Paper "Recommendations for a Strategy on European Cyber Security Standardisation" resulting in a further set of documents aimed at defining the term Cyber Security and the stakeholders involved. As noted above, it is not possible to distinguish capabilities for NII/NIS from the provisions for the general ICT/Cybersecurity domains and thus many of the recommendations of the CSCG apply equally to NIS.
New context – NIS Directive
Whilst it may be suggested that the NIS Directive imposes new requirements, it is probably more correct to state that the NIS Directive imposes essential requirements for harmonization and interoperability of the attack and defense context. The illustration in Figure 2 identifies the interfaces and operations to be made common for NIS Directive conformance.
NOTE 1: Each Member State will designate one or more CSIRTs. If multiple, the Competent Authority will coordinate NOTE 2: Processing of personal data pursuant to this Directive shall be carried out in accordance with Directive 95/46/EC; processing of personal data by Union institutions and bodies pursuant to this Directive shall be carried out in accordance with Regulation (EC) No 45/2001 [Article 1a]
As indicated in Table 1, above, there are many bodies proposing standardisation in these areas. The key aspects identified in the NIS Directive are those dealing, as shown in Figure 2, with reporting between a service provider and the CSIRT (variously named as ESP-CSIRT, DSP-CSIRT, PECN-CSIRT, and other-CSIRT) and between the CSIRTs and the Competent Authorities. Internally to the service provider domain are two key sets of actions to be undertaken: Monitor and defence of the information system Privacy compliance processing
2. Analysis of the NIS Directive against standards requirements
This document provides an analysis of gaps in the standards landscape for Network and Information Security and provides recommendations for further standards development to allow the NIS Directive to be fulfilled and for the wider domain of NII to give assurances of security. An article by article summary of the analysis is given in "Annex B: Summary of NIS Directive technical requirements".
The analysis of gaps and subsequent recommendations are derived from an analysis of the NIS Directive to identify where standards are explicitly called for or are mentioned as requirements.
The research, however extends beyond the core standardisation requirements of the NIS Directive, but takes into account other areas mentioned in the directive, where standards might be considered helpful, but also reviews where requirements from other areas may potentially overlap or even contradict requirements exposed by the NIS Directive.
The analysis of requirements has been mapped against existing standards to identify if such existing standards may form the basis of a NIS framework.
Where possible, draft standards and projects at earlier stages have been considered. This is particularly important as the NII and general networking world are continuously evolving and the role of network virtualization, of the greater use of cryptography, and of the evolution in the role of virtual operators of networks and services, has been taken into account in identifying the broad set of requirements for NIS.
In line with the objectives of the NIS Directive, a strong focus was given to generic process-oriented standards for cyber security in organizations (risk management, information sharing, etc.). Conversely, cybersecurity standards in NIS Directive Art. 14 essential services sectors (energy, transport, banking, financial markets, etc) were not significantly examined. In other cases, such as NIS Directive Art. 15 Digital Services (cloud computing, IoT, embedded systems, big data, etc.), dedicated cyber security standards (e.g. public key infrastructure) were taken into account. The highly disparate sectors made it infeasible to take into account all the standards in a comprehensive fashion within a single focused analysis.
Within the recommendations, attention was given to the existing initiatives that could benefit from synergies with work in standards, especially involving contractual Public-Private Partnerships (cPPPs) and Horizon 2020 (H2020).
3. NIS Directive requirements Overview
As a result of performed deconstruction of NIS Directive, several distinct areas have been identified, where specific requirements can be reflected in standards. A more in depth review is given below that expands upon the article-by-article review of Annex B.
Risk management for networks and information systems
Articles 14 and 15 of the NISD require “appropriate and proportionate technical and organizational measures to manage the risks posed to the security of networks and information systems” for operators of essential services and digital service providers respectively. With regards to the latter, the NISD specifically requires to take into account:
security of systems and facilities, incident management, business continuity management, monitoring, auditing and testing, compliance with international standards.
Recent activity in ETSI has led to the publication of ETSI TR 103 305 addressing the role of ICT in Critical Infrastructure. It contains detailed consideration of the role of business continuity management, risk analysis and incident management. Whilst ETSI, in its Technical Committee CYBER, has committed to the extension of this work, there is still no formal plan in place to accomplish this task. Some work has also been done in ISO/IEC JTC1 SC27, which addresses risk and security management in the ISO 27000 series of management documents.
Furthermore, ETSI has published a modified set of controls for cyber security. In a similar fashion to the ICT for CI work, they will be further refined in normative specifications in due course. Additional work that addresses event detection within the context of risk analysis and incident management can be found in the following specifications: ETSI GS ISI 004 V1.1.1 (2013-12): Information Security Indicators (ISI); Guidelines for event detection implementation ETSI GS ISI 002 V1.2.1 (2015-11): Information Security Indicators (ISI); Event Model A security event classification model and taxonomy
As part of the rapid evolution and extension of the existing specifications for Structured Threat Information Expression (STIX), Trusted Automated eXchange of Indicator Information (TAXII) and Cyber Observable eXpression (CybOX) within the OASIS (standardisation body with which ETSI cooperates closely), additional risk and event categorizations are being added.
Impact prevention and minimisation
As noted, Articles 14 and 15 of the NISD require appropriate technical and operational measures "to prevent and minimise the impact of incidents affecting the security of the networks and information systems" for operators of essential services and digital service providers respectively. The Critical Security Controls specified in TR 103 305 are especially relevant, and efforts are underway to adjust the controls very quickly in response to threat conditions. The topic of risk management is also addressed by ETSI in TS
102 165-1 and ISO/IEC 15408 in the context of security assurance, as well as by some of the ISO/IEC JTC1 27000 series of specifications.
There is a significant issue arising from impact prevention, surrounding recovery to an equivalent stable state. This has been addressed in ETSI TR 103 303 with a summary of the concern stated as follows: "If an attacker has exploited systems using "strategy A" which have been successfully immunised against, it is essential that all connected and stakeholder systems that are vulnerable to the same "strategy A" have to be similarly immunised in order to defend against future attacks where "strategy A" is used as a sidechannel attack at a related stakeholder". The reporting of an attack and the means used to immunize the system thus have to be shared, in order to prevent the form of side channel attack indicated.
Computer Security Incident Response Teams (CSIRTs), Competent Authorities, and Single Points of Contact
In Article 7, the NISD requires Member States to designate one or more Computer Security Incident Response Teams (CSIRTs) "for handling incidents and risks according to a well-defined process, which shall comply with the requirements set out in point (1) of Annex I." Where there are multiple CSIRTs, a Competent Authority within the Member State and a designated Single Point of Contact are also key entities that are part of the structured exchange of information. Annex I further provides an extensive list of required capabilities, such as:
high availability of communications services by avoiding single points of failure and providing several means for being contacted and for contacting others at all times communication channels clearly specified and well known to the constituency and cooperative partners. appropriate system for managing and routing requests, in order to facilitate handovers infrastructure whose continuity of operation is ensured
The complete set of entities and associated information exchange architecture resulting from Art. 7 is very complex – as depicted in Figure 2, above. Not only can there be multiple entities within each Member State, among whom information must be exchanged, but there are also equivalent entities in every other Member and Non-Member State that have to be accommodated. It is also foreseeable that some Member States for highly specialized Essential Services will designate third party entities collectively representing the operators (e.g., Information Sharing and Analysis Centres). In addition, foreign providers of digital services must designate domestic representatives for purpose of the NISD requirements.
Identification of Operators
Article 3a (5) of the NISD requires the Cooperation Group to support a consistent approach among Member States to identify (cf. lit. a-d ) operators of essential services.
In identifying NII as a component of CI, the guidance of ETSI TR 103 303 and succeeding work should be considered as the base for future standardization. In particular, ETSI TR 103 303 recommends that organisations should be familiar with the definition(s) of CI in their sector(s) and the government body acting as a point of contact in this area. Any organisation believing that they either meet the relevant definition of CI or will do so in the near future should notify the relevant government body. In the context of NISD, the Competent Authority for NIS may also be considered as the Competent Authority for CI.
4. Recommendations
The NISD analysis given in Annex B has identified a small number of gaps in standardisation and some areas of overlap where there is no clear best practice to be adopted. The standardisation analysis has considered a very much wider spectrum of Standards Development Organisations (SDOs) than is implied by the text of Article 16 of the NSID which refers to "internationally accepted standards". The interpretation of this Article for the purpose of presented analysis has been to include standards that have acceptance in the industry from a wide set of bodies. This includes those established under Regulation (EU) No 1025/2012, but should be also extended to the recognised de-facto and industrial groups, thus including groups such as IETF, W3C, OASIS, and established national bodies with international recognition, like FIPS, NIST, BSI and others. A list of such standards bodies with particular roles in Cyber Security, and by inference in Network Information Security, has been published recently as ETSI TR 103 306. It is strongly recommended that this source is adopted as a list of bodies preparing "internationally accepted standards". It is further noted that this list has been summarised in the Cybersecurity Focus Group (CSCG) report number 3 and is presented in Table 1 of this document.
The immediate priority is to simplify the standards for NIS that enable interoperability of event reporting and information sharing. The controls for cyber security have been transposed for the EU context in ETSI TR 103 305. Specific recommendations include:
Reach consensus among Member States and major partners on o Architectures, interfaces, and information exchange expressions o Standards and specifications Given the strong similarities of the NIS Directive and USA Cybersecurity Act, the two implementations should be harmonized to the extent possible, including common architectures, interfaces, structured information expressions and privacy filters Develop a means for Information Sharing and Analysis Centers (ISACs) and Information Sharing and Analysis Organizations (ISAOs) to fit into the NIS Directive model and architecture Develop means for Public Electronic Communication Networks or Publicly Available Electronic Communication Service Providers under EU Directive 2002/21/EC and Trust Providers to fit into the NIS Directive model and architecture Develop additional border gateway defence and threat exchange standards for one Essential Service (Digital Infrastructure Internet Exchange Points) Develop a means for NFV, SDN, MEC and other virtualised infrastructures and services to fit into the NIS Directive model and architecture
Annex A: Definitions and abbreviations Definitions
The following definitions from the NIS Directive apply in the present document:
Network and information system: (a) an electronic communications network within the meaning of Directive 2002/21/EC, and (b) any device or group of inter-connected or related devices, one or more of which, pursuant to a program, perform automatic processing of computer data, as well as (c) computer data stored, processed, retrieved or transmitted by elements covered under point (a) and (b) for the purposes of their operation, use, protection and maintenance. Security: The ability of a network and information system to resist, at a given level of confidence, accident or malicious action that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted data or the related services offered by or accessible via that network and information system; Risk: any circumstance or event having a potential adverse effect on security; Incident: any circumstance or event having an actual adverse effect on security; information society service: service within the meaning of point (2) of Article 1 of Directive 98/34/EC; NIS cooperation plan: a plan establishing the framework for organisational roles, responsibilities and procedures to maintain or restore the operation of networks and information systems, in the event of a risk or an incident affecting them; incident handling: all procedures supporting the analysis, containment and response to an incident; market operator: (a) provider of information society services which enable the provision of other information society services, a non-exhaustive list of which is set out in Annex II of the NIS Directive; (b) operator of critical infrastructure that are essential for the maintenance of vital economic and societal activities in the fields of energy, transport, banking, stock exchanges and health, a non-exhaustive list of which is set out in Annex II of the NIS directive. Standard: a standard referred to in Regulation (EU) No 1025/2012; Specification: a specification referred to in Regulation (EU) No 1025/2012; Trust service provider: a natural or legal person who provides any electronic service consisting in the creation, verification, validation, handling and preservation of electronic signatures, electronic seals, electronic time stamps, electronic documents, electronic delivery services, website authentication, and electronic certificates, including certificates for electronic signature and for electronic seals.
Abbreviations
ENISA: European Union Agency for Network and Information Security ETSI: European Telecommunications Standards Institute NISD: Network and Information Security Directive
Annex B: Summary of NIS Directive technical requirements Overview
Below is the set of stakeholders identified in the NIS Directive:
Basing on the Figure 3, we can identify sets of responsibilities of each stakeholder in the NIS Directive (by article):
e ed ssue ssue m Th at s i s i
h f le. t o assu vices. ard ard ab e d d
vel ser an an s ar tified le efin st st h d m en
s ig id ical ical n h ste sential " is un se " sy o es chn chn atio d rt te te th o term rity a a u p t t be o o
Observ The sec affecte to sup N N
ry C o
ard ex lat n u
n
stand al reg ce e in A n o es
ren e tabl e
n nati n o n easur o
Refe N See o m N
f ] e h n o . a t t gh a e e to ty n and h el n atio t o rk p oi a hi g t cret res lev p rm r th this o d in n u h ecuri rity o re wo ei wi ig s o et l a co eas h n ll ap inf n ce d o d e m a defin sha l ensu h s in th an shal an ati an gy ry f t rd te o tain rk te es rm tes ent auth o em o o a iv lat s shal y st Sta ra ain et wo it gu st p y acc st inf sy er ject m m ate n in b b ilit cur IS re o f net St o d sib e em o er f se atio ries al N e and rk and ember al c s n gic an n b tiv n o m o to rity rm iev w u el licy em fo rri irec atio ste atio o et Respo M lev in te D Each M n strate p ach n [The m N sec sy
er
ld
s s s eho
ate ate ate
stak St St St
ed er er er b b b
fect em em em
Af M M M
er b
m u n
ticle
Ar 4 5 6
. f n s f o no s r h tio c best reed S ic d ard at n er o ei p f d h io ag te o wit to is b gle M o t cifi o U ared an . It m ed in es ed ctice sin be no ecifica ely tial act s t ed th ers and spe fin y E as b ail e to eral t m lik leads e nu h an prep t m ed st et ini pra es h it le ly t u d re verlap t o CERT entifi as b h an tifi ent M bu n practic ised sp est t r f c re ig o t all m are de s. id e n d s fo A h ge o h a b r specific o pro cut cu n the gen rg m pictu ver IS er o is an o ate erm n s and b is s fo o res la lf a n d er eady o rall ed tha s is S. atio m g a se at p xchan sio n that iden n M alr s. EN ard u tse in ard h rts cite n e cedu ro e f i fu gest t gle harm alysis it n id d ro te av ata e end ractice y all
Observ P in general t h CERT repo d they stand sin The is o p an the ove co sug respo gu stand an citatio p b
ad r to as n cept ro o fo h ls n b is ard s and n X rt ati o co o o o ard n t e rm d o h . The ati yBO o le C . stand t n an ati ent A rep to ab end wards ain ce inf t n XII/ IS 3 rm em atio o m g st m o an t TA ren EN 5 ag tio m d rin rm ve inf s do 6 an f ac fo o
Refe The cite sha 1 m relev o in reco m STIX/ thi
g l t e r u b am in o Te rd shal ay a le fo o set m ent se up n sib ts et o n s acc RT p et which en sp m l s s, m o
risk Re respo d ire ces I. A CE e c shal cy ") o h an ex t te requ n
Sta CERT ed pr e ergen ents h y d f An er m : " o within ilit b efin ) r E -d with t (1 y sib em te after g inci t n u ell ly rit lin in lished p p d w m m ab tho a po an Respo Each M Co (herein h to co in est au
er
ld
s eho
ate
stak St
ed er b
fect em
Af M
er b
m u n
ticle
Ar 7
e h red
by t ay
ts, rities ed to se h er
to rr ef m ac be The lish, tho r o be
. Tho ll be
: " tion efe re t ay tab lities a au r 3 ce wit d ting n d m es d sha which
er a
ts edu ts lat ll es sion rd )" ite op oc s nee c
a 2 an (2 h moda ac co 9
mis s pr g ac s s ry h ard n stipu ac
mplemen a ompetent p ting e 1
e the co ra n tion ed and sion ess entin atio of i g p e Com rticl stand s een c h ted in o m ra eme ired articl litate t a sulta ly el le
is ci d op n p p etw n p d ev
Observ Th Commis mean the nec fa b a in impl a co to in A im d Im requ
X X rk s in rk s in be g a o be g a o ard ed yBO ed yBO ld sfer ld sfer u C (w thi u C (w thi the a n ). the a n ). 7 o usin efin n O 7 o usin efin n O ran o ran o w t d XII/ D w t d XII/ D stand ata ata d ithi ay d ithi ay ticle ce d TA YBER ticle ce d TA YBER ce as as n e an n n e an n ar X/ ean S erw C C X/ ean S erw C C ren r at ed w p d r ar at ed w p d T T ctio o ctio o shar rm n r STI SI shar rm n r STI SI refere refere Refe As fo p to fo fu fo ratifi Eur is un ET As fo p to fo fu fo ratifi Eur is un ET
e
erat p e o m b
rk o o
o c affecting yste t
w to s n rk" et ") o o n ents rk d tw o ati
ent w ne inci rm et o n d o man n y n an inf er secure
ilit p tio erati ly p sib a risks o n era rk and o rm p st o sical o o "c o w f ain et trin
Respo To ("c ag n The in
er
ld
eho
t , n t , n
stak en sio en sio
ed ean is ean is et rities et rities p p m p p m o o fect m tho m m tho m
Af Co au Eur Co Co au Eur Co
er b
m u n
ticle
Ar 8 9
d ired
ate el in d requ e at ent. rd o
o m be ad m p o n . m c o ay o e el ical m ev ts and erati s d chn n will b p ac vel o te
d o licy t
atio ses o te al le n n s po y n the c d t lic elega atio u ee o
Observ D Respo n b n P
X X s o rk rk s in rk s in e o be g a o be g a o e t t ical ed ed h ard ld sfer yBO ld sfer yBO (w thi (w thi tend ew the u C a ). the u C a ). T no n n 7 o usin efin n O 7 o usin efin n O d s. echn 7 ran o ran o ex w t d XII/ D w t d XII/ D n ram . stand ata ata an f es d ithi ay d ithi ay g practic o 2 ticle ce d TA YBER ticle ce d TA YBER ere the t ce as as 1 n e an n n e an n h licy s licy X/ ean S erw C C X/ ean S erw C C rkin cati r ar r ar ical gh ren at ed w p d at ed w p d articl u T T act po po ctio o ctio o end m shar rm n r STI SI shar rm n r STI SI p wo d chn d refere refere Refe As fo p to fo fu fo ratifi Eur is un ET As fo p to fo fu fo ratifi Eur is un ET im to an te specifi Ext an fro thro
g to gs se n n n
rk" rm o entin fo pla n n tw e warni o respo lem o h n y o p ne f t ed n m o earl erati at erati o ed p f i p n in o as e o o b h o o t rd erati atio "c o p ce m o eans S c o rm o e g" an m NI y a c co fo in fr y n n f ilit " in b o via th o arn assur t, sib the ge p n atio rk" e n ed o y w ve o a Uni rm iv w us cha arl gi ad fo et
Respo To ex "e To in rece n To acts,
er
ld
eho
t , n t , n n
stak en sio en sio sio
ed ean is ean is ean is et rities et rities p p m p p m p m o o o fect m tho m m tho m m
Af Co au Eur Co Co au Eur Co Eur Co
er b
m u n
ticle
Ar 10 11 12
w r n ay t Es o BOX io m ly, al n ey o M is y fo ain r h th at st o the ilit /Cy be o r S t ch er easi litic o o in es ly XII p tners fo o re p t ar is n a c ed f p ar d and o o e be c h ent in entiti m ee ay sponsib sup X/TA al p n ticul has m se g t d xclud e n al ar le m cha h re STI o o in e ay an p t e s e d ly n atio gh SD p at h is g m in p e ak in cl im u p h s in the rn h 1 t g t ed. atio 0 e NI to te e t that tho h su ach titie tin ithstan tiat 70 en to t ires t ly p ro es 2 al n iev y precis p o p tw rd m e o ego O u verall
Observ Ad ap with in ach n issu n IS ver b who fro o requ sup all
g e n h U e in o ard t rtin m re o n so the ISO o o track f f p al y enti s the E er o m e gram d stand e o all ily ered if erati are n ard ecific ent be m s sup us ro m s. ce st p p al att o n ed by with n sp ay fo rk" o ls un fa em ard atio o ard co o o 0 ren m stand CIP t ag gram w rn lies itio tr 0 m p d n an ro et te entifi aid 70
Refe This m easily p stand the " n co in The id ERN ap ad p co 2 m stand
e
cur e
n se ised ctur n tio ed
o era ag m p rastru o an
o m r har inf y c d
fo al ilit n an w y risk
sib o n atio rks allo o rn w all depl te et
Respo Sh in To n
n er o
ld rs, n s, o trati
eho io is
, ate in t erat stak St p m en o ed ean Un er t Ad et rities b p p o lic fect m tho em arke b u Af Eur Co au M M P
er b
m u n
ticle
Ar 13 14
. d ly f e p al p o n ate ssue n o ssue ssue ssue S tsid ked st 4 a s i u s i s i s i se ati NI o 1 o vo be d ard rn in ard ard ard isatio that m be o te r cl cle d n d o te d d d
o o o be t sta an te an an an e m o r in Arti st e to st st st a fil eeds t m d s ro is n arise fr th n o ical ical ical ical n be t o o P what is ld n ay d nee f s fr ires har s. I u chn chn chn chn atio o te n m an ay o te te te te lied t ctio o U m et p ivalent. n a requ a a a te t ctio acks t t t m t ro o u o o o
Observ Targ co This sh P equ The N b san att the E laws N N N
ly to p e e. f d m e o their f im o em o IEC 00 ld e ts o r s h 8 a that nee u s d P h y o ertak sul ard rs it o sc d t is are o ce ard g ISO/ n eria ST S e cur ed) xisting un e re io in and stand d o h erat This c ran NI se Crit f e f t ysis. p end o s t ce gest n stand clu lysis o o m t the rks. assu in and er g o et o m 8 ted ther ard ren sug m o b anal e e e e ve w o ly 0 rin m rren p m n n n n ark ro et ther 54 u o o o o
Refe The m p n Co (rec o Cu ap 1 As n n stand risk ana sha such N N N N
g
re ce f u
ce n o entin ail acts ee ss lian n lia p o r f itt ce
p lem o m ted m p m s f m pro o -co m n c n entati f i o
o m o S Co n view rce le t delega e p se p NI re y fo u n at im ilit e ed sancti ent o e by ado stig 4 is m lish a lish a sib t 1 n to n rag le ab ab rs o p r u inve we d im we est est o arm o
Respo P an Enco article acts H to P To To
er
ld
s s s eho es,
ate ate ate n n t stak stat St St St en sio sio ed er er er er is is b et rities b b b ean ean p p m p m o o fect em m tho em em em m m
Af M Co au M M M Eur Co Eur Co
er b
m u n
ticle
Ar 15 16 17 18 19 20
a t e u b ssue ssue. ssue s i s i ay s i tho wi m ard ard ard d d d ce an an an st st lian s basis rce st p fo s ical ical m ard n ical n o d e c an o chn chn chn atio te te ver st lt t te a a d a n icu t t we u t o o o iff o Observ N N H so d N
ard
stand
ce
ren e e e n n n o o o Refe N N N
s n o f visi o o al law n n o D pr o IS to ati licati D n b al f N o IS rn as pu u ce f N D o IS s of y w al jo ien n ci ilit io al la day ffi lish N 0 sib n n ab 2 ed aud in o d sposit n D natio est te IS Respo Tran in To within N In
er ld
s s s eho
ate ate ate stak St St St
ed er er er b b b
fect em em em
Af M M M
er b
m u n
ticle
Ar 21 22 23
ENISA
European Union Agency for Network and Information Security Science and Technology Park of Crete (ITE) Vassilika Vouton, 700 13, Heraklion, Greece
Athens Office
1 Vass. Sofias & Meg. Alexandrou Marousi 151 24, Athens, Greece Catalogue Number TP-06-16-337-EN-N
PO Box 1309, 710 01 Heraklion, Greece ISBN: 978-92-9204-186-1 DOI: 10.2824/975760 Tel: +30 28 14 40 9710 info@enisa.europa.eu www.enisa.europa.eu
Fotnoter
- www.enisa.europa.eu European Union Agency For Network And Information Security
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Figure 1: Visualisation of the relationship of NIS Directive to Cyber-security
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- 3GPP CCRA ETSI ISI IIC OAA Platform Industrie 4.0 3GPP SA2 CEN ETSI LI InfluxDB OASIS RIOT 3GPP SA3 CENELEC ETSI MTS-SIG IO-Link OASIS CTI ROS 3GPP SA5 CEPOL ETSI NFV IoT Security ODVA SAE International Foundation 3GPP CT CERT-EU ETSI NTECH IoTivity OGC SensiNact ACDC CIA ETSI SAGE IPEN OIC-CERT SGIP ACEA: CIIAII FIDO Alliance IPSO OM2M Sofia2 AEF CIS FIRST ISA OMA TCG AIOTI CLEPA Fi-ware ISF OMG The KNX Association AllJoyn Contiki GlobalPlatform ISO OneM2M The Open Group Allseen Continua: Health GSMA ISO JTC1/SC27 ONOS The ULE Alliance Alliance Alliance Apache CSA GSMA FASG ISO JTC1/SC6 OPC Foundation The ZigBee Spark Alliance APCERT CSC H2020 ISO JTC1/SC7 Open Connectivity ThingSpeak Forum Arduino: CSCG HGI ITU ITU-D OpenDaylight Thread group ASHRAE DICOM HL7 International ITU ITU-R openHAB TMForum Automation easyway HYPER/CAT ITU ITU-T OpenIoT UDG Alliance ML AVNU eCl@ss ICANN ITU OpenRemote UniverSaal BEREC EclipseIoT IEC LinuxIoTDM OpenStack UPnP Bluetooth ECRG IEEE LoRa Alliance OpenWSN W3C Broadband ENISA IEEE 802 LAN/MAN MITRE OPFNV Weightless Forum Standards Committee C2C-CC Enocean Alliance IEEE P2413 Mosquitto OSCE Wi-Fi Alliance CA/B Forum ERTICO - ITS Europe IETF NATO OSGi Alliance WWRF Cable Labs ETSI IETF IRTF NATO CCDCOE OWASP Calypso ETSI CYBER IETF MILE NATO LIBGUIDE Paho CCC ETSI E2NA IETF SACM NIST Particle CC-Link ETSI ESI IHE Node-RED PI International
- Table 1: Significant Cyber Security Standards fora
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Figure 2: Interfaces of NIS Directive
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Figure 3: Stakeholders of NIS Directive
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016
- Gaps in NIS standardisation
- v. 1.0 | November 2016