<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>regulation - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/regulation/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/regulation/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Wed, 14 May 2025 12:19:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>regulation - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/regulation/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Evolution of the HDS Framework &#8211; Towards Enhanced Security and Sovereignty </title>
		<link>https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/#respond</comments>
		
		<dc:creator><![CDATA[Perrine Viard]]></dc:creator>
		<pubDate>Wed, 14 May 2025 12:19:40 +0000</pubDate>
				<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital compliance]]></category>
		<category><![CDATA[HDS]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[règlementation]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=25983</guid>

					<description><![CDATA[<p>The Health Data Host (HDS) certification is a French regulatory framework that governs the hosting of personal health data. Established by Decree No. 2018-137 of February 26, 2018, it is mandatory for any entity hosting health data to comply with...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/">Evolution of the HDS Framework &#8211; Towards Enhanced Security and Sovereignty </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;"><span data-contrast="auto">The Health Data Host (HDS) certification is a French regulatory framework that governs the hosting of personal health data. Established by Decree No. 2018-137 of February 26, 2018, it is mandatory for any entity hosting health data </span><span data-contrast="none">to comply with the certification</span><span data-contrast="auto">. It aims to ensure a high level of protection for this particularly sensitive data by imposing strict requirements regarding security, availability, and confidentiality.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In the context where the digital transformation of the healthcare sector is accelerating, the protection of health data is an increasingly critical issue. In 2021, our article &#8220;Health Data Host Certification: Two Years Already!&#8221; by Laurent Guille and Alexandra Cuillerdier, provided a promising initial assessment of the HDS framework. Faced with growing concerns related to data sovereignty and cybersecurity, a redesign was necessary. This evolution towards HDS v2, which came into effect in 2024, marks a turning point in the approach to health data hosting in France, strengthening the protection and sovereignty of health data in an ever-evolving digital context.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">HDS v1: a first structuring but perfectible framework</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">Since its introduction in 2018, the HDS framework has helped structure and professionalize the health data hosting sector. However, this first version of the framework had certain limitations. In particular, the initial framework presented gray areas regarding data sovereignty, especially concerning the location and control of health data. Additionally, the rapid evolution of cyber threats and technologies required a substantial update of security requirements to maintain a level of protection adapted to current risks.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">Overhaul of the Technical and Security Framework</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">On the technical side, the new requirements of the ISO 27001:2023 standard are adopted within the new version of HDS. This update integrates security risk management adapted to new digital contexts, as well as new controls related to cybersecurity. The other normative references are rationalized. References to ISO 20000-1, ISO27017, and ISO27018 standards disappear in the HDS v2 framework, while 31 specific requirements are directly integrated into the framework, which also relies on the ISO/IEC-17021-1:2015 standard to govern conformity assessment. This new version also clarifies the articulation with the requirements of the SecNumCloud framework to facilitate obtaining HDS certification for hosts already qualified with SecNumCloud.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">A Major Strengthening of Digital Sovereignty</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">One of the most significant developments in HDS v2 concerns the strengthening of digital sovereignty. The new framework now requires that the physical hosting of health data be carried out exclusively within the territory of the European Economic Area (EEA). This requirement reinforces guarantees in terms of data protection and contributes to the emergence of an ecosystem of European players in the field of digital health.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">This is complemented by enhanced transparency, which also becomes a central issue of the framework, with two major obligations:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Hosts must now publish on their website a map of any data transfers to countries outside the EEA, thus allowing data subjects and healthcare actors to have clear visibility on the journey of their data;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">In the case of remote access to data from a third country or submission to non-European legislation that does not ensure an adequate level of protection within the meaning of Article 45 of the GDPR, the host must inform its clients in the contract. In particular, it must specify the associated risks and detail the technical and legal measures implemented to limit them.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">Strengthening of Contractual Requirements</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">Subcontracting supervision receives particular attention in HDS v2. The associated measures are reinforced, and hosts must now:</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Precisely detail the certified hosting activities in their contracts;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Maintain complete transparency regarding their subcontracting chain;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Ensure that their subcontractors comply with the same requirements for data security and location;</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<ul style="text-align: justify;">
<li data-leveltext="" data-font="Symbol" data-listid="7" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">Implement mechanisms to control and audit their subcontractors.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></li>
</ul>
<p style="text-align: justify;"><span data-contrast="auto">These new contractual obligations aim to ensure better control of the value chain and greater transparency for data controllers.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">Practical Consequences for the Ecosystem</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">For health data hosts, these evolutions of the framework imply an adaptation of their infrastructures to guarantee the location of data within the EEA. They also require an upgrade of their security measures to meet the requirements of the 2023 version of the ISO 27001 standard and the review of contracts, both with their clients and with their subcontractors.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></p>
<h2 style="text-align: justify;"><span data-contrast="none">Perspectives and Implementation</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6}"> </span></h2>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><span data-contrast="auto">This new modernized version of the HDS framework addresses the growing challenges of security, sovereignty, and transparency. Its implementation is spread over approximately two years, with immediate application for new certifications from November 16, 2024, and a transition period until May 16, 2026, for hosts already certified under HDS v1.</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p style="text-align: justify;"><span data-contrast="auto">In the longer term, several questions arise regarding the evolution of the framework. At a time when the NIS 2 directive already includes healthcare providers and the pharmaceutical industry among its essential sectors of activity, while classifying the manufacturing of medical devices and in vitro diagnostics in its important sectors, the emergence of HDS 2 raises a question: could European cooperation lead to an even more integrated framework for health data protection and harmonize practices across the continent?</span><span data-ccp-props="{&quot;335551550&quot;:6,&quot;335551620&quot;:6,&quot;335559731&quot;:169}"> </span></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/">Evolution of the HDS Framework &#8211; Towards Enhanced Security and Sovereignty </a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2025/05/evolution-of-the-hds-framework-towards-enhanced-security-and-sovereignty/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>US Executive Order &#038; Betchley Declaration</title>
		<link>https://www.riskinsight-wavestone.com/en/2024/05/us-executive-order-betchley-declaration/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2024/05/us-executive-order-betchley-declaration/#respond</comments>
		
		<dc:creator><![CDATA[Amélie Grangien]]></dc:creator>
		<pubDate>Fri, 03 May 2024 08:49:27 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[IA]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[UK]]></category>
		<category><![CDATA[US]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=23097</guid>

					<description><![CDATA[<p>In the evolving landscape of AI governance and regulation, recent efforts have shifted from scattered and reactive measures to cohesive policy frameworks that foster innovation while safeguarding against potential misuse. As AI becomes more integrated into our daily life, both...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/05/us-executive-order-betchley-declaration/">US Executive Order &#038; Betchley Declaration</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">In the evolving landscape of AI governance and regulation, recent efforts have shifted from scattered and reactive measures to cohesive policy frameworks that foster innovation while safeguarding against potential misuse. <br />As AI becomes more integrated into our daily life, both public and private sectors have raised ethical concerns around issues of privacy, bias, accountability, and transparency.</p>
<p style="text-align: justify;"><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-23098" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/article-pierre-photo1-FR-2.png" alt="" width="723" height="471" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/article-pierre-photo1-FR-2.png 723w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/article-pierre-photo1-FR-2-293x191.png 293w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/article-pierre-photo1-FR-2-60x39.png 60w" sizes="(max-width: 723px) 100vw, 723px" /></p>
<figure id="attachment_23071" aria-describedby="caption-attachment-23071" style="width: 594px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-23071 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/article-pierre-photo2-FR.png" alt="" width="594" height="421" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/article-pierre-photo2-FR.png 594w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/article-pierre-photo2-FR-269x191.png 269w, https://www.riskinsight-wavestone.com/wp-content/uploads/2024/05/article-pierre-photo2-FR-55x39.png 55w" sizes="(max-width: 594px) 100vw, 594px" /><figcaption id="caption-attachment-23071" class="wp-caption-text"><a href="https://ourworldindata.org/artificial-intelligence"><em>Source: https://ourworldindata.org/artificial-intelligence</em></a></figcaption></figure>
<p style="text-align: justify;"><br />Today, as governments actively craft AI guidance and legislation, policymakers face the challenge of delicately balancing the need to foster innovation and ensuring accountability. A regulatory framework that prioritizes innovation but relies too heavily on the private sector&#8217;s self-governance could lead to a lack of oversight and accountability. Conversely, while robust safeguards are essential to mitigate potential risks, an overly restrictive approach may stifle technological progress.<br />This whitepaper will explore the approaches proposed by the governments of the United States and the United Kingdom as they pertain to AI governance across both the public and private sectors.</p>
<h2 style="text-align: justify;"><br />American Approach to AI Regulation</h2>
<p style="text-align: justify;">In October of 2023, the White House published the AI Executive Order. The order specifies key near-term priorities of introducing reporting requirements for AI developers exceeding computing thresholds, launching research initiatives, developing frameworks for responsible AI use, and establishing AI governance within the federal government. Longer-term efforts focus on international cooperation, global standards, and AI safety.<br />On the side of ensuring accountability, the order calls for the Secretary of Commerce to enforce reporting provisions for companies developing dual-use AI foundation models, organizations acquiring large-scale computing clusters, and Infrastructure as a Service providers enabling foreign entities to conduct certain AI model training. While these criteria will likely exempt most small to medium sized AI companies from immediate regulations, large industry players like Open AI, Anthropic, and Meta could be affected if they surpass the computing threshold established by the order. <br />On the other side of fostering innovation, further sections of the order reaffirm the US government’s aim to promote AI innovation and competition – supporting R&amp;D initiatives and public-private partnerships, provisioning streamlined visa processes to attract AI talent to the US, prioritizing AI-oriented recruitment within the federal government, clarifying IP issues related to AI, and preventing unlawful collusion. <br />Overall, the nature of the documents published by the US is mostly non-binding, indicating a strategy of encouraging the private sector to self-regulate and align to common AI best practices. In this approach, the White House has been persistent in its messaging that it is committed to nurturing innovation, research, and leadership in the domain, while also balancing with the need for a secure and responsible AI ecosystem.</p>
<h2 style="text-align: justify;"><br />The British Approach to AI Regulation</h2>
<p style="text-align: justify;">The Bletchley Declaration, agreed upon during the AI Safety Summit 2023 held at Bletchley Park, Buckinghamshire, marks a pioneering international effort towards ensuring the safe and responsible development of AI technologies. This declaration represents a commitment from 29 governments to collaborate on developing AI in a manner that is human-centric, trustworthy, and responsible, with the UK, US, China, and major European member states among the notable signatories. The focus is on &#8220;frontier AI,&#8221; which refers to highly capable, general-purpose AI models that could pose significant risks, particularly in areas such as cybersecurity and biotechnology.<br />The declaration emphasizes the need for governments to take proactive measures to ensure the safe development of AI, acknowledging the technology&#8217;s pervasive deployment across various facets of daily life including housing, employment, education, and healthcare. It calls for the development of risk-based policies, appropriate evaluation metrics, tools for safety testing, and building relevant public sector capability and scientific research.<br />In addition to the declaration, a policy paper on AI &#8216;Safety Testing&#8217; was also signed by ten countries, including the UK and the US, as well as major technology companies. This policy paper outlines a broad framework for testing next-generation AI models by government agencies, promoting international cooperation, and enabling government agencies to develop their own approaches to AI safety regulation.<br />The key takeaways from the Bletchley Declaration include a clear signal from governments regarding the urgency to address the development of safe AI. However, how these commitments will translate into specific policy proposals and the role of the newly announced AI Safety Institute (AISI) in the UK&#8217;s regulatory landscape remain to be seen. The AISI&#8217;s mission is to minimize surprise from rapid and unexpected advances in AI, focusing on testing and evaluation of advanced AI systems, foundational AI safety research, and facilitating information exchange.</p>
<p style="text-align: justify;"><br />As they seek to establish themselves as AI leaders in the global community and set the direction for effective policymaking, both the US and the UK are navigating the balance between promoting AI innovation and ensuring ethical governance. While most of the current focus is on proposing guidelines and frameworks for the safe and responsible use of AI, the reference to potential future regulations across both documents should serve as a wake-up call for companies to start aligning their practices with the principles and recommendations outlined. <br />To stay ahead of the curve, organizations should develop robust methodologies to monitor AI risks effectively. This involves adapting their AI strategy to prioritize risk mitigation, identifying potential harms that may arise from the deployment of AI systems, and preparing for forthcoming regulatory measures by implementing a secure and comprehensive risk management program. <br />However, the US and UK opportunist approach to AI legislation is not followed by all. China chose a targeted and evolutive approach by writing a law on Generative AI that came into effect in 2023. Finally, in Europe, the AI Act shows that the EU doesn&#8217;t want to let AI technologies go out of hand.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2024/05/us-executive-order-betchley-declaration/">US Executive Order &#038; Betchley Declaration</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2024/05/us-executive-order-betchley-declaration/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cyber regulatory landscape: challenges and prospects</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/#respond</comments>
		
		<dc:creator><![CDATA[Perrine Viard]]></dc:creator>
		<pubDate>Mon, 18 Sep 2023 11:00:00 +0000</pubDate>
				<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[DORA]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[NIS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=21355</guid>

					<description><![CDATA[<p>A 38% increase of cyber-attacks was estimated in 2022[1]. As this figure illustrates, the cyber threat continues to grow, and has become a major concern for businesses worldwide. To counter this growing threat and maintain digital confidence, governments have long...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/">Cyber regulatory landscape: challenges and prospects</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">A 38% increase of cyber-attacks was estimated in 2022<a href="#_ftn1" name="_ftnref1">[1]</a>. As this figure illustrates, the cyber threat continues to grow, and has become a major concern for businesses worldwide. To counter this growing threat and maintain digital confidence, governments have long been regulating cyberspace, and continue to do so to adapt to changing conditions. As a result, we have seen the gradual emergence of multiple regulations requiring the implementation of cybersecurity and data protection measures, accompanied by different levels of possible sanctions in the event of non-compliance. Companies are now faced with a complex regulatory landscape, requiring the implementation of compliance strategies with adapted organisational models.</p>
<p> </p>
<h2 style="text-align: left;">A denser and more complex cybersecurity regulatory landscape</h2>
<p style="text-align: justify;">The <strong>first attempts to regulate</strong> personal data protection and cybersecurity remained <strong>partial until the early 2000s</strong>, being driven mainly by the United States and the European Union.  Initially, they focused on the protection of personal data, in France with the <em><u>Loi Informatique et Libertés </u></em>(1978) and in the United States with sector-specific regulations: the <em><u>Privacy Act</u></em> (1974) for the public sector, the <em><u>Health Insurance Portability and Accountability Act</u></em> for the healthcare sector (1996) and the <em><u>Gramm-Leach-Bliley Act</u></em> (1999) for the financial sector.</p>
<p style="text-align: justify;">The <strong>first cybersecurity regulations</strong> were introduced in the <strong>financial sector</strong> in the <strong>early 2000s</strong>, with the aim of improving the security of the services provided. Notable regulations include the <em><u>Sarbanes-Oxley Act</u></em> (2002), in the USA, reinforcing corporate transparency in terms of internal control, and the <em><u>Payment Services Directive</u></em> (2007) in the European Union, regulating the security of online payments and transactions.</p>
<p style="text-align: justify;">Since the <strong>early 2010s</strong>, more structuring regulations have emerged to form an <strong>initial cyber regulatory base</strong> in the same regions. These regulations are mainly focused on critical infrastructure protection, with France&#8217;s <em><u>Loi de Programmation Militaire de 2013-2018</u></em> (2013), the USA&#8217;s <em><u>National Cyber Security and Critical Infrastructure Protection Act</u></em> (2014), but also the <em><u>Network and Information Security 1 Directive</u></em> (2016) enacted by the European Union.</p>
<p style="text-align: justify;">It wasn&#8217;t until the <strong>late 2010s that the desire to regulate the cyber space became more global</strong>. As many countries followed in the footsteps of the United States and the European Union, stricter cyber regulations began to emerge, with <strong>far-reaching impacts</strong> on information systems. This can be seen in the arrival of major <strong>personal data protection regulations</strong> around the world: the <em><u>General Data Protection Regulation</u></em> (GDPR, 2018) in Europe, the <em><u>California Consumer Privacy Act</u></em> (CCPA, 2020) in California, the <em><u>Personal Data Protection Law</u></em> (PDPL, 2020) in Brazil, the <em><u>Personal Information Protection Law</u></em> (PIPL, 2021) in China, or the <em><u>Personal Data Law </u></em>(2022) in Russia.</p>
<p style="text-align: justify;">Other regulations aimed at <strong>protecting information systems</strong> are multiplying, with the <em><u>Cybersecurity Law </u></em>in China (2017), the <em><u>NYCRR 500 Cybersecurity Regulations</u></em> for the State of New York (2017), or the new iteration of the <em><u>NIS Directive</u></em> (2023) and DORA in Europe.</p>
<p style="text-align: justify;"><img decoding="async" class="aligncenter size-full wp-image-21357" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture1.png" alt="" width="624" height="332" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture1.png 624w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture1-359x191.png 359w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture1-71x39.png 71w" sizes="(max-width: 624px) 100vw, 624px" /></p>
<p style="text-align: center;"><em>Evolution of cybersecurity regulatory landscape<a href="#_ftn2" name="_ftnref2"><strong>[2]</strong></a> </em></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">Added to this complex cybersecurity regulatory landscape is a <strong>vast ecosystem of cybersecurity requirements and standards</strong>, with <strong>different levels of constraint</strong>: regulatory requirements stemming from cyber or other regulations, mandatory requirements, recommendations or even requirements with contractual value. In this context, it is essential to identify all applicable requirements and the level of constraint they impose.</p>
<p style="text-align: justify;"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-21359" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2.png" alt="" width="938" height="340" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2.png 938w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2-437x158.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2-71x26.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture2-768x278.png 768w" sizes="auto, (max-width: 938px) 100vw, 938px" /></p>
<p style="text-align: center;"><em>Types of cybersecurity requirements and standards, beyond cyber regulations</em></p>
<p> </p>
<h2 style="text-align: left;">A cybersecurity regulatory compliance strategy adapted to the new paradigm</h2>
<p style="text-align: justify;">With the global cybersecurity regulatory landscape becoming increasingly complex, compliance cannot be thought of solely as total compliance with all applicable regulatory requirements. Faced with detailed, costly and sometimes contradictory requirements, it is becoming necessary to implement <strong>risk-based cyber compliance strategies</strong>. The definition of these strategies will be based on a study of the existing level of regulatory compliance, an assessment of the effort and complexity of the measures required to comply with each regulation, and a consideration of the risks associated with potential non-compliance, both in terms of sanctions and IS protection. This analysis, far from seeking to escape the law, aims to identify the benefit/risk of activities, and may lead to redirecting activities, limiting their scope, or acting in concert with the ecosystem to evolve requirements.</p>
<p style="text-align: justify;">To implement such a strategy, it is first essential to <strong>identify all applicable regulations</strong>, and to set up a <strong>regulatory watch</strong> to keep alongside regulatory developments and related news. A two-tiered organisation must then be set up to <strong>manage cyber regulatory compliance</strong>.</p>
<p style="text-align: justify;"><strong>A first level of overall management</strong> aimed at providing a high-level overview: a global analysis of the level of cyber compliance must be carried out. This can be based on a recognised cybersecurity standard such as NIST or ISO 27001 for security requirements. For requirements relating to the protection of personal data, GDPR is a good foundation, since most international regulations on this topic are derived from it. The NIST privacy and ISO privacy standards are also solid references in this field. These benchmarks can be mapped onto the main applicable regulations, and advantage can be taken of existing synergies between regulations, as illustrated by the two examples below.</p>
<p style="text-align: justify;">To complete this analysis, an audit plan should be drawn up to assess compliance with key local regulations in greater detail.</p>
<p style="text-align: justify;"><span style="text-decoration: line-through;"><img loading="lazy" decoding="async" class="wp-image-21361 alignleft" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture3.png" alt="" width="326" height="290" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture3.png 366w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture3-215x191.png 215w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture3-44x39.png 44w" sizes="auto, (max-width: 326px) 100vw, 326px" /> <img loading="lazy" decoding="async" class="wp-image-21363 alignright" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture4.png" alt="" width="329" height="298" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture4.png 369w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture4-210x191.png 210w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture4-43x39.png 43w" sizes="auto, (max-width: 329px) 100vw, 329px" /></span>                                       </p>
<table style="height: 23px; width: 100%; border-collapse: collapse; border-style: solid; border-color: #ffffff;" border="0">
<tbody>
<tr style="height: 23px;">
<td style="width: 42.7381%; height: 23px; border-style: solid; border-color: #ffffff; text-align: center;">Analysis of synergies between the <u>NIS Directive</u> and the <u>LPM</u></td>
<td style="width: 13.9285%; height: 23px; border-style: solid; border-color: #ffffff;"> </td>
<td style="width: 43.3333%; height: 23px; border-style: solid; border-color: #ffffff; text-align: center;">Analysis of synergies between the <u>NIS</u> directive and<u> ISO2702</u></td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">A second level of <strong>&#8220;local&#8221; management</strong>, <strong>on a geographical or business line scale</strong>, aimed at ensuring local regulatory compliance in each of the regions where the Group is present. This requires first of all the implementation of a local watch to identify and know precisely the regulations and associated news. This is followed by a detailed analysis of the level of compliance with local regulations, the identification of specifics needed to ensure the right level of compliance, and the feedback of these elements to the Group to ensure the overall management of compliance actions.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: left;">Protection regulations call into question the need to separate information systems</h2>
<p style="text-align: justify;">Complying with a multitude of cybersecurity regulations is becoming a real challenge for companies with an international presence and centralised information systems. This is due to the stacking up of these regulations, sometimes with incompatible or contradictory provisions, but also to the emergence of requirements with <strong>far-reaching impacts</strong> on information systems.</p>
<p style="text-align: justify;">This is the case, for example, with <strong>China&#8217;s PIPL regulations</strong>, and in particular Article 40, which stipulates that the transfer of data outside China will only be authorized if processing complies with the security assessment established by the Chinese authorities. This regulation will apply above a certain volume of personal data (not yet specified by the Chinese authorities).</p>
<p style="text-align: justify;"><strong>Incompatibilities between regulations</strong> have also arisen between the United States and the European Union. This is illustrated by the invalidation of the U.S. <em><u>Privacy Shield</u></em><a href="#_ftn3" name="_ftnref3"><em><strong>[3]</strong></em></a> by the European Court of Justice, its <em>Schrems</em> rulings calling into question the ability of U.S. Cloud hosts to process the personal data of their European customers in line with European requirements.</p>
<p style="text-align: justify;">Against this backdrop of heightened cybersecurity and personal data protection requirements, emphasised by the protection intentions of certain countries, it may become necessary to study the <strong>need to separate globalised and centralised information systems</strong> by considering separation into several geographical zones, which could be:</p>
<ul style="text-align: justify;">
<li>A zone comprising the USA and the UK</li>
<li>A second zone centered on China</li>
<li>A third zone made up of the European Union and GDPR-relevant<a href="#_ftn4" name="_ftnref4">[4]</a></li>
</ul>
<p style="text-align: justify;">Depending on their regulatory reality and potential developments, other countries or regions could be attached to one or other of these three zones.</p>
<p style="text-align: justify;">In the future, the information systems of these different zones could rely more heavily on the <strong>sovereign clouds</strong> that are currently being developed.</p>
<p> </p>
<h2 style="text-align: left;">Constraints that can even lead to the closure of a region&#8217;s operations</h2>
<p style="text-align: justify;">We&#8217;re even seeing a number of companies halting or postponing the launch of activities in certain countries where the regulatory constraints and associated risks of sanctions are too great in relation to the business challenges and strategy of the company. This is particularly the case in certain US states, and in Europe, where some major players are putting the brakes on their development because of the RGPD (e.g. Google&#8217;s open AI/ Bard, or Meta&#8217;s launch of Thread).</p>
<p style="text-align: justify;"><em> </em></p>
<h2 style="text-align: left;">What&#8217;s next for 2023 and beyond?</h2>
<p style="text-align: justify;"><strong> <img loading="lazy" decoding="async" class="aligncenter size-full wp-image-21365" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5.png" alt="" width="959" height="204" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5.png 959w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5-437x93.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5-71x15.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/09/Picture5-768x163.png 768w" sizes="auto, (max-width: 959px) 100vw, 959px" /></strong></p>
<p style="text-align: justify;">The complex regulatory landscape will continue to expand in the months and years ahead. Both in new areas (AI, product security) and in existing areas, such as critical infrastructure.</p>
<p style="text-align: justify;">On the &#8220;critical infrastructure&#8221; front, after the first phases of regulations focused on personal data protection, the authorities have been looking at critical infrastructure protection, which continues with the NIS2 directive in particular. Adopted on November 10, 2022 and soon to be implemented into French law, it aims to reduce disparities between member states, strengthen cybersecurity in a context of increasing digitalisation, and establish security measures to improve the level of security of critical infrastructures within EU member states.</p>
<p style="text-align: justify;">A new phase is now taking shape, during which regulations will focus on the safety of digital products, with in particular:</p>
<ul style="text-align: justify;">
<li>The <strong><u>AI Act</u></strong>, a European regulation aimed at defining a common frame of reference for the development and use of Artificial Intelligence (AI). Against a backdrop of lightning acceleration in the uses of AI, new regulations are also set to emerge around the world, and particularly in China, where measures have already been taken and led to the closure of 55 applications and 4,200 sites between January and March 2023<a href="#_ftn5" name="_ftnref5">[5]</a>.</li>
<li>The <strong><u>Cyber Resilience Act</u></strong> (C.R.A), another European regulation, which aims to strengthen the security of digital products by imposing measures to be respected by manufacturers right from the product design stage. Not to mention the recent announcement by the White House of the &#8220;Cyber trust mark&#8221; initiative, which targets the same objective but with a different approach<a href="#_ftn6" name="_ftnref6">[6]</a>.</li>
</ul>
<p style="text-align: justify;">The regulatory stakes are not about to diminish, and cyber teams need to be prepared. At the very least, it will be necessary to strengthen links with the business lines concerned, as well as with legal teams. The most mature companies in this field have set up legal departments within their cyber teams, to exchange information with the various legal departments. This may not necessarily be necessary, depending on the organization of each structure, but it can also be a guarantee of strong mobilization.</p>
<p style="text-align: justify;">In all cases, the challenge for companies will be to transform these often mandatory regulatory requirements into a competitive advantage for their business, not by punitive, minimal compliance, but rather by taking ownership of the subject and transforming these practices in a way that can be leveraged externally.</p>
<p> </p>
<p> </p>
<p style="text-align: justify;"><a href="#_ftnref1" name="_ftn1">[1]</a> <a href="https://blog.checkpoint.com/2023/01/05/38-increase-in-2022-global-cyberattacks/">https://blog.checkpoint.com/2023/01/05/38-increase-in-2022-global-cyberattacks/</a></p>
<p style="text-align: justify;"><a href="#_ftnref2" name="_ftn2">[2]</a> Non-exhaustive list of cybersecurity regulations</p>
<p style="text-align: justify;"><a href="#_ftnref3" name="_ftn3">[3]</a> <a href="https://www.cnil.fr/fr/invalidation-du-privacy-shield-les-suites-de-larret-de-la-cjue">https://www.cnil.fr/fr/invalidation-du-privacy-shield-les-suites-de-larret-de-la-cjue</a></p>
<p style="text-align: justify;"><a href="#_ftnref4" name="_ftn4">[4]</a> <em>Countries complying with the level of protection required by the EU </em><a href="https://www.cnil.fr/fr/la-protection-des-donnees-dans-le-monde">https://www.cnil.fr/fr/la-protection-des-donnees-dans-le-monde</a></p>
<p style="text-align: justify;"><a href="#_ftnref5" name="_ftn5">[5]</a> <a href="https://www.01net.com/actualites/comment-les-lois-chinoises-tres-strictes-risquent-de-nuire-a-lia-made-in-china.html">https://www.01net.com/actualites/comment-les-lois-chinoises-tres-strictes-risquent-de-nuire-a-lia-made-in-china.html</a>  </p>
<p style="text-align: justify;"><a href="#_ftnref6" name="_ftn6">[6]</a> <a href="https://arstechnica.com/information-technology/2023/07/the-cyber-trust-mark-is-a-voluntary-iot-label-coming-in-2024-what-does-it-mean/">https://arstechnica.com/information-technology/2023/07/the-cyber-trust-mark-is-a-voluntary-iot-label-coming-in-2024-what-does-it-mean/</a></p>
<p style="text-align: justify;"> </p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/">Cyber regulatory landscape: challenges and prospects</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/09/cyber-regulatory-landscape-challenges-and-prospects/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>While preparing the NIS 2, update of the European overview of NIS transposition by the Member States&#8230;toward convergence ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/09/en-pleine-preparation-de-la-nis-v2-mise-a-jour-du-tour-dhorizon-europeen-de-transposition-de-la-directive-nis-par-les-etats-membres-vers-une-convergence/</link>
		
		<dc:creator><![CDATA[Nicol4sVanThieghem]]></dc:creator>
		<pubDate>Tue, 21 Sep 2021 17:30:00 +0000</pubDate>
				<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[European directive]]></category>
		<category><![CDATA[NIS]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">http://riskinsight-prepro.s189758.zephyr32.atester.fr/?p=16638</guid>

					<description><![CDATA[<p>The Network and Information System Security &#8211; (UE) 2016/1148 directive, commonly referred to as NIS,  was a European directive adopted by the European parliament on July, 6th , 2016. It has been transposed by member states into their national legislations...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/09/en-pleine-preparation-de-la-nis-v2-mise-a-jour-du-tour-dhorizon-europeen-de-transposition-de-la-directive-nis-par-les-etats-membres-vers-une-convergence/">While preparing the NIS 2, update of the European overview of NIS transposition by the Member States&#8230;toward convergence ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">The <a href="https://eur-lex.europa.eu/legal-content/FR/TXT/HTML/?uri=CELEX:32016L1148"><em>Network and Information System Security &#8211; (UE) 2016/1148</em></a> directive, commonly referred to as <strong>NIS</strong>,  was a European directive adopted by the European parliament on July, 6<sup>th</sup> , 2016. It has been transposed by member states into their national legislations until May 9<sup>th</sup>, 2018. In the United Kingdom, the NIS requirements have been included in <a href="https://www.legislation.gov.uk/uksi/2018/506/pdfs/uksi_20180506_en.pdf">The Network and Information Systems Regulation</a>  which came  into force on May 10<sup>th</sup>, 2018 and  the <a href="https://www.legislation.gov.uk/uksi/2020/1245/pdfs/uksi_20201245_en.pdf">The Network and Information Systems (Amendment and Transitional Provision etc.) Regulations</a>  came into force on December 31<sup>st</sup>, 2020.</p>
<p style="text-align: justify;">The NIS directive is the <strong>first initiative of EU-wide legislation on cybersecurity</strong>. Its goal is to <strong>ensure a high and common level of security for European information systems and networks</strong>. To achieve this objective the directive focuses on four key points:</p>
<ul style="text-align: justify;">
<li>Consolidating the member states’ <strong>national cybersecurity capabilities</strong></li>
<li>Creating a <strong>political and organizational cooperation framework</strong> on cybersecurity across the EU,</li>
<li>Ensuring the cybersecurity of <strong>operators of essential services</strong> (OES). OES are private or public entities <strong>providing essential services for the maintenance of economic and societal activities</strong>. The provision of these services <strong>depends on network and information systems</strong>.</li>
<li>Ensuring the cybersecurity of <strong>digital service providers</strong> (DSP). DSPs are defined as “<em>any service normally provided for remuneration, at a distance by electronic means and at the individual request of a recipient of services</em>”<a href="#_ftn1" name="_ftnref1">[1]</a>. Three types of services are mentioned in the NIS Directive: <strong>Cloud computing services</strong>, <strong>online marketplace</strong> and <strong>online search engines</strong>.</li>
</ul>
<p style="text-align: justify;">On the one hand, the security of operators of essential services is a <strong>sovereign prerogative of states while on</strong>n the other hand, the role of the EU is to ensure the <strong>proper functioning of the European market</strong>. In order to reconcile these two objectives, the NIS directive clearly states that: “<em>This Directive should be without prejudice to the possibility for each Member State to take the necessary measures to ensure the protection of the <strong>essential interests of its security</strong>, to <strong>safeguard public policy</strong> and <strong>public security</strong>, and to allow for the investigation, detection and prosecution of criminal offences.”</em><a href="#_ftn2" name="_ftnref2"><em><strong>[2]</strong></em></a><em>.</em> Each country can <strong>therefore adapt the legislative text to fit its priorities and strategic objectives</strong> as well as to guarantee its security and that of its networks and information systems. The NIS directive, however, sets <strong>common requirements</strong> in terms of; <strong>transposition of the directive into national legislation</strong>, of <strong>sectors concerned</strong>, of <strong>risk identification</strong>, of <strong>supervision</strong>, of <strong>implementation of technical and organisational measures</strong>, of <strong>cyber incident notification</strong>, and of <strong>sanctions in case of non-compliance</strong>.</p>
<p style="text-align: justify;">This analysis brings together elements on the transposition of the NIS directive in each of the <strong>27 member states</strong> of the European Union, as well as in the <strong>United-Kingdom</strong> and <strong>Switzerland</strong>. It highlights the various approaches and underlines the similarities and differences between countries, especially in the context of the upcoming evolution of the legislative text. Indeed, a <strong>proposal to revise the NIS directive</strong> has been adopted by the European Commission in December 2020 and <strong>aims at replacing the original text</strong>.</p>
<h1 style="text-align: justify;">An achieved transposition for certain themes…</h1>
<p><strong>Different types and numbers of legislative texts to transpose the NIS</strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16866 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image1-3-437x82.png" alt="" width="437" height="82" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image1-3-437x82.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image1-3-71x13.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image1-3-768x144.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image1-3.png 1526w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p style="text-align: justify;"><strong>The transposition of the NIS occurred in all the national legislations of EU member states. </strong>However, there is <strong>heterogeneity in the type of legislative text adopted</strong>. In most countries, the transposition takes the form of a <strong>law</strong> (<strong>twenty-two countries</strong>), to which <strong>thirteen countries</strong> have added <strong>at least on other legislative text</strong> (ordinance, decree, regulation, amendment or ministerial decision). In <strong>two countries,</strong> the transposition took place in <strong>each sectoral law</strong> which increases the number of legislative texts (<strong>four texts or more</strong>).</p>
<p><img loading="lazy" decoding="async" class=" wp-image-16878 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image7-3-418x191.png" alt="" width="499" height="228" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image7-3-418x191.png 418w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image7-3-71x32.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image7-3-768x351.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image7-3-1536x701.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image7-3.png 1818w" sizes="auto, (max-width: 499px) 100vw, 499px" /></p>
<p><strong>A general implementation of cyber incident notification processes</strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16868 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image2-3-437x105.png" alt="" width="437" height="105" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image2-3-437x105.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image2-3-71x17.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image2-3-768x185.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image2-3.png 1152w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p style="text-align: justify;"><strong>All countries </strong>managed to implement cyber incident notification processes. Once again, there are various approaches depending on the country.</p>
<p><img loading="lazy" decoding="async" class=" wp-image-16880 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image8-3-400x191.png" alt="" width="457" height="218" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image8-3-400x191.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image8-3-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image8-3-768x367.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image8-3-1536x734.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image8-3.png 1934w" sizes="auto, (max-width: 457px) 100vw, 457px" /></p>
<p style="text-align: justify;">There are six different procedures for transmitting alerts during a cyber incident:</p>
<ul style="text-align: justify;">
<li>In the first case (<strong>nine countries</strong>), the operator of essential services must first notify the <strong>competent national authority</strong> of the occurrence of a cyber incident,</li>
<li>A second process (<strong>ten countries</strong>) exists in which the first point of contact is the <strong>CSIRT</strong>, the <strong>Computer Security Incident Response Team</strong>, also called <strong>CERT</strong> (Computer Emergency Response Team),</li>
<li>In a lower number of cases (<strong>three countries</strong>), the OES must notify the <strong>competent sectoral authority</strong>,</li>
<li>The notification of cyber incident is carried out via a <strong>secure platform</strong> in <strong>four countries</strong>.</li>
<li>Even less frequently (<strong>two countries</strong>), the <strong>single point of contact</strong> (SPOC) has to be alerted.</li>
<li>Finally, for one country (Hungary), the OES alerts an <strong>event management centre</strong>.</li>
</ul>
<p style="text-align: justify;">In addition,<strong> all member states</strong> must notify the <strong>point of contact of a member state,</strong> if it is also affected by the cyber incident, and must inform the <strong>public</strong> when necessary.</p>
<p><strong>To comply with the constraints imposed by the NIS, certain states have even gone further</strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16870 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image3-3-437x103.png" alt="" width="437" height="103" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image3-3-437x103.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image3-3-71x17.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image3-3-768x181.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image3-3.png 1340w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p style="text-align: justify;">The NIS directive initially applies to the following sectors: <strong>transport, energy, health, drinking water, banking, finance, </strong>and<strong> digital</strong>. In the transposition, more <strong>than half of the analysed countries</strong> added other essential <strong>sectors and sub-sectors</strong> in addition to the seven previously mentioned. They are listed below, sorted by frequency of occurrence :</p>
<ul style="text-align: justify;">
<li>Austria, Croatia, Cyprus, Lithuania, Malta, Slovakia, Spain and Switzerland also mention<strong> public administration</strong>,</li>
<li>Cyprus, Estonia, Germany, Lithuania, the Netherlands, Slovakia, Spain and Switzerland add <strong>information and communication technologies</strong> and <strong>IT</strong>.</li>
<li>Estonia, France, Germany, Hungary, Lithuania, Slovenia, Spain, Switzerland add</li>
<li>The Czech Republic, Lithuania, the Netherlands, Spain complete the list with <strong>industry</strong>.</li>
<li>Estonia, Germany and Switzerland also mention <strong>heating and housing</strong>.</li>
<li>Lithuania and Slovakia subjoin <strong>defence</strong>, Switzerland <strong>national security</strong>.</li>
<li>Lithuania and Slovenia add the <strong>protection of the environment</strong>.</li>
<li>France is the only one to add <strong>education</strong>.</li>
<li>Spain is the only one to mention <strong>space</strong> and <strong>research centres</strong>.</li>
</ul>
<p><img loading="lazy" decoding="async" class=" wp-image-16882 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image9-3-392x191.png" alt="" width="443" height="216" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image9-3-392x191.png 392w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image9-3-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image9-3-768x374.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image9-3-1536x749.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image9-3.png 1908w" sizes="auto, (max-width: 443px) 100vw, 443px" /></p>
<h1 style="text-align: left;">… However, the variation needs to be finalized on other themes.</h1>
<p><strong>Strong disparities on state supervision</strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16876 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image6-3-437x103.png" alt="" width="437" height="103" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image6-3-437x103.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image6-3-71x17.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image6-3-768x181.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image6-3.png 1238w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p style="text-align: justify;">Several categories and different levels of control are exercised by authorities to certify compliance with the NIS. The strong disparities concern in particular the <strong>authorities ensuring the control</strong> (national or sectoral authority) as well as the <strong>expected level of control</strong> (supervision, inspection, audit, evaluation…): there is <strong>no consensus</strong> around the process to adopt. Moreover, <strong>six countries</strong> <strong>do not provide any information </strong>on the type of supervision implemented.</p>
<p><img loading="lazy" decoding="async" class=" wp-image-16884 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image10-3-433x191.png" alt="" width="526" height="232" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image10-3-433x191.png 433w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image10-3-71x31.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image10-3-768x338.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image10-3-1536x677.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image10-3.png 1906w" sizes="auto, (max-width: 526px) 100vw, 526px" /></p>
<p><strong>Heterogeneous level and diffusion of security measures</strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16872 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image4-3-437x100.png" alt="" width="437" height="100" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image4-3-437x100.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image4-3-71x16.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image4-3-768x176.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image4-3.png 1381w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p style="text-align: justify;">Except for <strong>six countries</strong> for which no information has been given on the type of security measures implemented, there are two main approaches:</p>
<ul style="text-align: justify;">
<li>The security measures are directly mentioned in the <strong>body of the legislative text(s)</strong> transposing the NIS (<strong>eleven countries</strong>),</li>
<li>They are enumerated in; a <strong>guide</strong>, a <strong>list of recommendations</strong>, an <strong>online publication</strong> and established by <strong>different entities</strong> (government, regulation, decree…) in <strong>twelve countries</strong>.</li>
</ul>
<p><img loading="lazy" decoding="async" class=" wp-image-16886 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image11-3-386x191.png" alt="" width="453" height="224" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image11-3-386x191.png 386w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image11-3-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image11-3-768x380.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image11-3-1536x759.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image11-3.png 1726w" sizes="auto, (max-width: 453px) 100vw, 453px" /></p>
<p style="text-align: justify;">For the measures included in the body of the legislative text(s), there are <strong>similarities</strong> on their organisation:</p>
<ul style="text-align: justify;">
<li>The <strong>international norm ISO27001</strong> and the <strong>cybersecurity framework NIST</strong> are used as models to establish the security measures in respectively <strong>four and two countries</strong>.</li>
<li>The same <strong>six categories</strong> (security of systems and installations, handling of incidents, business continuity management…) are used in <strong>four countries</strong>.</li>
</ul>
<p><img loading="lazy" decoding="async" class=" wp-image-16888 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image12-3-395x191.png" alt="" width="437" height="211" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image12-3-395x191.png 395w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image12-3-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image12-3-768x371.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image12-3-1536x743.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image12-3.png 1772w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p><strong>Different amount and format of penalties</strong></p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16874 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image5-3-437x101.png" alt="" width="437" height="101" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image5-3-437x101.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image5-3-71x16.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image5-3-768x178.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image5-3.png 1211w" sizes="auto, (max-width: 437px) 100vw, 437px" /></p>
<p style="text-align: justify;">The financial penalty for not complying with the directive varies in the different countries and can range from <strong>less than a 100k</strong><strong>€ to 20M</strong><strong>€ maximum</strong> (except for Finland which has not implemented any sanctions). Most countries have chosen to apply a fine of <strong>less than 200k</strong><strong>€</strong> (<strong>eighteen countries</strong>) whereas <strong>four countries</strong> have decided that the maximum should be <strong>beyond 1M</strong><strong>€</strong>. It should also be noted that the sanctions are likely to <strong>accumulate in the event of</strong> <strong>multiple non-conformities</strong>, which does not make the <strong>overall maximum amount of a sanction</strong> a certainty.</p>
<p style="text-align: justify;"><strong>Imprisonment sentences</strong> have been implemented in <strong>two countries</strong> (Belgium and Cyprus).</p>
<p style="text-align: justify;">Finally, <strong>four countries</strong> have not yet communicated the penalties in case of non-compliance.</p>
<p><img loading="lazy" decoding="async" class=" wp-image-16890 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image13-3-372x191.png" alt="" width="448" height="230" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image13-3-372x191.png 372w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image13-3-71x36.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image13-3-768x394.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image13-3-1536x788.png 1536w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/Image13-3.png 1770w" sizes="auto, (max-width: 448px) 100vw, 448px" /></p>
<h1 style="text-align: justify;"><strong>Conclusion</strong></h1>
<p style="text-align: justify;">The goal of the NIS directive was to <strong>address the unequal levels of security of networks and information systems</strong> within the European Union. To achieve it, it has now been transposed in <strong>all the member states</strong>. This has led to the <strong>creation of a common security framework</strong> while also leaving the possibility for states to ensure <strong>their security and the protection of their essential and strategic interests</strong>. Indeed, <strong>each country designates its operators of essential services</strong> and <strong>chooses the sectors it deems the most strategic to protect</strong>. In addition, the transposition of the directive as well as the supervision and cyber incident notification processes are carried out by the <strong>authority deemed competent. This is non dependant</strong>whether <strong>national</strong> or <strong>sectoral</strong>, whether it is the <strong>CSIRT</strong> or the <strong>single point of contact</strong>. This flexibility makes it possible for the NIS to adapt to the organisation of all member states. There are <strong>visible similarities</strong> creating groupings between the countries, as well as <strong>major dissimilarities.</strong> These leave room for many variations and make the comparison relevant and rich.</p>
<p style="text-align: justify;">A <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52020PC0823">proposal to revise the NIS directive</a>  was adopted in December 2020, but its provisional calendar has not yet been communicated. However, its main objectives has  been listed and includes <strong>reaching a higher level of cybersecurity and more homogeneous processes</strong> within the EU, while further <strong>increasing the cooperation between member states</strong>. The revision of the NIS directive revolves around;</p>
<ul style="text-align: justify;">
<li>the <strong>abandonment of the distinction between OES and DSPs</strong></li>
<li>the <strong>designation of OES by the Directive and not the states</strong></li>
<li>the <strong>creation of a new European network for major cyber incidents</strong></li>
<li><strong>imposition of CSIRTs supportive of entities</strong>,</li>
<li>the <strong>control by the states of the technical and organisational measures implemented</strong> (for risk analysis and crisis management).</li>
</ul>
<p style="text-align: justify;">These changes will be detailed further in a new article.</p>
<p> </p>
<h3 style="text-align: justify;">Sources :</h3>
<p style="text-align: justify;">Directive Network and Information System &#8211; Article ANSSI Link: <a style="font-size: revert;" href="https://www.ssi.gouv.fr/entreprise/reglementation/directive-nis/">Link to the article on NIS Directive</a></p>
<p style="text-align: justify;">Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union Link : <a style="font-size: revert;" href="https://eur-lex.europa.eu/legal-content/FR/TXT/HTML/?uri=CELEX:32016L1148">Link to the NIS Directive</a></p>
<p style="text-align: justify;">On Digital Service Providers (DSPs) – ANSSI Article – May 23rd 2018 Link : <a style="font-size: revert;" href="https://www.ssi.gouv.fr/entreprise/reglementation/directive-nis/faq-des-fournisseurs-de-service-numerique-fsn/#:~:text=La%20directive%20NIS%20d%C3%A9finit%20le,'un%20destinataire%20de%20services%20%C2%BB">Link to the article on DSPs</a></p>
<p style="text-align: justify;">On Operators of Essential Services (OES) – ANSSI Article Link : <a style="font-size: revert;" href="https://www.ssi.gouv.fr/entreprise/reglementation/directive-nis/faq-operateurs-de-services-essentiels-ose/#:~:text=Qu'est%2Dce%20qu',%C3%A9conomie%20ou%20de%20la%20soci%C3%A9t%C3%A9">Link to the article on OES</a></p>
<p style="text-align: justify;">Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on measures for a high common level of cybersecurity across the Union, repealing Directive (EU) 2016/1148 Link: <a style="font-size: revert;" href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52020PC0823">Link to the proposal of the revised NIS Directive</a></p>
<p style="text-align: justify;"><a href="#_ftnref1" name="_ftn1">[1]</a> Directive (EU) 2015/1535 of the European Parliament and of the Council of 9 September 2015.</p>
<p style="text-align: justify;"><a href="#_ftnref2" name="_ftn2">[2]</a> Directive (UE) 2016/1148 of the European Parliament and of the Council of 6 July 2016.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/09/en-pleine-preparation-de-la-nis-v2-mise-a-jour-du-tour-dhorizon-europeen-de-transposition-de-la-directive-nis-par-les-etats-membres-vers-une-convergence/">While preparing the NIS 2, update of the European overview of NIS transposition by the Member States&#8230;toward convergence ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Saga 1/3: connected car: between cybersecurity and safety</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/10/saga-13-connected-car/</link>
		
		<dc:creator><![CDATA[Qu3tinM4TYas]]></dc:creator>
		<pubDate>Thu, 25 Oct 2018 07:51:05 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Manufacturing & Industry 4.0]]></category>
		<category><![CDATA[connected car]]></category>
		<category><![CDATA[connected mobility]]></category>
		<category><![CDATA[embbeded security]]></category>
		<category><![CDATA[IoT]]></category>
		<category><![CDATA[mobility]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[safety]]></category>
		<category><![CDATA[stakes]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11369/</guid>

					<description><![CDATA[<p>The revolution is underway! The vehicles we drive will become ever-more connected and autonomous in the near future, something that will open the door to new uses. The user experience, in terms of mobility, will undoubtedly be better, but the...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/10/saga-13-connected-car/">Saga 1/3: connected car: between cybersecurity and safety</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>The revolution is underway! The vehicles we drive will become ever-more connected and autonomous in the near future, something that will open the door to new uses. The user experience, in terms of mobility, will undoubtedly be better, but the services on offer will go hand -in-hand with new threats and new cybersecurity issues to be considered.</em></p>
<p><em>In this series, we’ll first present connected vehicles and their associated cybersecurity challenges; the main sources of threat and the risks will be addressed in a second installment. Lastly, a third article will present our views on the issue and the main lines of the response required to address it.</em></p>
<p>&nbsp;</p>
<h2>The connected car: a vehicle supporting a raft of interactions</h2>
<p>Entertainment, an extension of your smartphone, shared mobility, management of the car&#8217;s life cycle&#8230; users are demanding new experiences, and the services and applications they generate are resulting in a range of interactions. We can imagine a smart car being able to find a free parking space, automatically schedule an appointment for maintenance, or turn a traffic light green as it approaches. Since April 1, 2018, all new vehicle models must also have an emergency call system, as well as geolocalization to enable the authorities to be contacted in the case of an accident. In this respect, they are already &#8220;connected&#8221;.</p>
<p>Manufacturers and other players are already capitalizing on the opportunity to maintain a close relationship with customers throughout the vehicle life cycle. By doing this, they become &#8220;<strong>providers of services and mobility solutions</strong>,&#8221; drawing on, among other things, collected data. In particular, because such connectivity represents a step toward autonomy, the vehicle needs to be able to communicate with other vehicles and the surrounding environment. These changes are underway, and their pace will progressively increase.</p>
<p>However, the challenge of cybersecurity is scarcely taken into account, or ignored: yet it has to be a key plank of any connected solution—from the design phase to the end of the life cycle. Such thinking is essential to safeguarding the vehicle’s integrity, protecting passenger lives, and complying with current and future regulation.</p>
<p>The first prerequisite is to properly understand the connected vehicle&#8217;s technologies and ecosystem.</p>
<p>&nbsp;</p>
<h2>How connected vehicles interact with their environment</h2>
<p>A specific feature of a connected vehicle is that it interacts with its ecosystem, via mobile data streams, over both the short and long-ranges.</p>
<ul>
<li><strong>Short-range connections</strong>: Here, the vehicle interacts directly with an object (such as a smartphone, infrastructure, etc.), without any intermediary. It uses technologies with a limited range for local exchanges (WAVE, on-board Wi-Fi, Bluetooth, etc.).</li>
<li><strong>Long-range connections</strong>: Here, the vehicle uses remote access to interact with external components via a cloud platform. 4G, and soon 5G, connections are the technologies of choice for connecting vehicles to the internet.</li>
</ul>
<p>This connected-vehicle concept also covers exchanges with the vehicle’s direct environment under the umbrella term &#8220;Vehicle-to-Everything&#8221; (or V2X). Lastly, the standard, ISO 20077, covers &#8220;<strong>Extended Vehicles</strong>&#8221; (or ExVe) as a whole: which comprise the physical vehicle as well as all the platforms and infrastructures that the car manufacturer is responsible for.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-10710" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/image-1-395x191.png" alt="" width="600" height="290" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/image-1-395x191.png 395w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/image-1-768x372.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/image-1-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/image-1.png 1405w" sizes="auto, (max-width: 600px) 100vw, 600px" /></p>
<p>&nbsp;</p>
<h2>A range of ecosystems and players that need to work together</h2>
<p>The car was once a very closed system; with the exception of diagnostic connections for garages and some connectivity to be able to broadcast multimedia content; any connectivity risks were largely contained. Today, the proliferation of forms of connectivity and access to the internet have opened up new opportunities for manufacturers and service providers, but also for attackers.</p>
<p>The first ecosystem to consider is the . Electronic and communication systems must be able to communicate with each other without the transmitted data or stored secrets being altered or stolen. Among these systems are the ECUs, the mini &#8220;on-board computers&#8221; that control the vehicle’s key functions, such as the braking system, air conditioning, lighting, etc.</p>
<p>Beyond on-board security, there are the <strong>user and owner </strong>(the latter not necessarily an individual) who have the right to give orders to the vehicle according to pre-defined rules. In the future, their authentication will be essential when it comes to questions of responsibility, as well as for verifying the legitimacy of the orders they issue.</p>
<p>Another vitally important aspect concerns connected services that use centralized <strong>platforms</strong>, or even cloud-based ones, which have been developed by the manufacturers or their partners. These platforms represent a significant threat because they can trigger orders for entire fleets of vehicles, and therefore the impact of any problem is multiplied. Manufacturers will need to put in place sufficiently secure solutions to allow such services; they’ll need to combine their own platforms with those of partners and the APIs on the vehicle, as well as ensuring the required level of confidence in the environment.</p>
<p>Lastly, in the medium-term, <strong>external objects and the surrounding environment</strong> (other vehicles, garages, parking lots, road infrastructure, etc.) will need to communicate and share information. The challenges of ensuring security in real time (in terms of availability, integrity, etc.) will be complex ones.</p>
<p>&nbsp;</p>
<h2>Cybersecurity issues: from the virtual to the real world</h2>
<p>People’s safety, inside and outside vehicles, is a top priority for the automotive industry. We might imagine, then, that the cybersecurity issues raised by connected vehicles will be treated with the same degree of rigor—such that they can guarantee the car’s safety and integrity.</p>
<p>The first issue represents an <strong>organizational challenge</strong> for all stakeholders, especially manufacturers, because the emergence of this new model brings together two opposing worlds: <strong>services</strong> and <strong>engineering</strong>. The first is characterized by agility and speed, and large numbers of short-term projects. The second, with a much longer development cycle, must meet the safety and quality requirements associated with vehicle approval. This dichotomy has impacts on cybersecurity and, in particular, its integration into development projects, as well as the coverage of end-to-end risk. For example, as a result of its position, the backend becomes a nerve center that must be fully protected to avoid any risk of a systemic attack that could have repercussions for the entire fleet. Unfortunately, the true value of this need for security is not currently appreciated, mainly as a result of requirements for very short times to market.</p>
<p>Considering the other issues, it’s clear that the cybersecurity challenges for connected vehicles don’t differ greatly from those in the IS world: identity and access management, detection and response, the security of infrastructures, cryptography, third-party management, patch management, etc. A connected vehicle is a mobile IS, and numerous security standards (ISO2700x, NIST 800, etc.) have already been developed. These set out good practice in various guides and reference documents (SAE J3061, AUTOISAC, NHST, etc.) and the topic will shortly be covered to the ISO/SAE 21434 standard.<br />
However, a number of factors inherent to vehicles and their embedded systems mean that the topic needs to be considered from new and specific angles.</p>
<p>The vehicle’s <strong>mobility and connectivity</strong> make security more complex: security must be guaranteed where there is a limited connection, or no connection, and in the context of a changing environment. Regulatory aspects must not be ignored either, given that the vehicle may have to move between countries.</p>
<p>The world of <strong>on-board systems</strong> also places constraints on hardware—in terms of cost, computing power, and size.</p>
<p>Questions about updating components and services arise too, given that a system must be able to <strong>function at all times</strong> but may also be shut down for long periods.</p>
<p>Lastly, vehicles are designed for a <strong>long life cycle</strong>, which implies thinking about security from the start, especially when it comes to managing identities and accesses. This long life cycle also means considering evolving standards over time, as well as developing a model for updates that guarantees vehicle security in a way that is sustainable and manageable for constructors.</p>
<p>&nbsp;</p>
<p><em>The road ahead is long, and cybersecurity is approaching a crossroads that was not in view a decade ago. It’s vital that all players involved grasp the importance of what’s required and start to put in the effort now, before it’s too late.</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/10/saga-13-connected-car/">Saga 1/3: connected car: between cybersecurity and safety</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Cloud Act: does it mean your data is better protected?</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/10/the-cloud-act-does-it-mean-your-data-is-better-protected/</link>
		
		<dc:creator><![CDATA[Etienne Lafore]]></dc:creator>
		<pubDate>Wed, 10 Oct 2018 06:31:27 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[Cloud Act]]></category>
		<category><![CDATA[digital trust]]></category>
		<category><![CDATA[e-privacy]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[protection of personal data]]></category>
		<category><![CDATA[règlementation]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11303/</guid>

					<description><![CDATA[<p>After several attempts to enact laws that facilitate the appropriation of data from customers of US-based services that is being stored outside the United States, the US Congress passed the “Clarifying Lawful Overseas Use of Data (CLOUD) Act” in March...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/10/the-cloud-act-does-it-mean-your-data-is-better-protected/">The Cloud Act: does it mean your data is better protected?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>After several attempts to enact laws that facilitate the appropriation of data from customers of US-based services that is being stored outside the United States, the US Congress passed the <strong>“Clarifying Lawful Overseas Use of Data (CLOUD) Act”</strong> in March 2018, which provides a legal framework for accessing data from US suppliers held outside their home jurisdiction.</em></p>
<p>The bill, originally created to amend a 1986 bill, The Stored Communication Act, allows the United States to force US-based service providers to transfer their customers’ data hosted overseas much more rapidly. It currently takes an average of ten months to obtain the data, rendering investigations conducted from within the US highly unproductive. The bill aims to allow US authorities (from sheriffs to the CIA) to access the <strong>data hosted by US companies, without the authorization of a judge</strong>. <strong>Large technology companies</strong>, who have supported the bill in the Senate, <strong>will be able to oppose a request if</strong>:</p>
<ul>
<li>The customer or subscriber is not a U.S. citizen or resident <em>(</em><a href="https://www.congress.gov/bill/115th-congress/senate-bill/2383/text">section 3.2.b.h.2.i</a><em>), </em><strong><u>and</u></strong></li>
<li>The transfer would require the provider to contravene the regulations of the country hosting the data (<a href="https://www.congress.gov/bill/115th-congress/senate-bill/2383/text">section 3.2.b.h.2.ii</a>)</li>
</ul>
<p>Such a request would then be brought before a US court which would be able to quash (or uphold) the request for the data transfer. Its decision will be based, among other things, on the validity of the information provided, the US’s interest in the request, the scope of the violation, and the chances of it being deemed to contravene the law in the foreign country. The public nature of the appeal is not specified, especially regarding the capacity of companies to communicate about contested requests. Today, it seems likely that the major US players are using such appeals to maintain the trust of their customers.</p>
<p>In order to avoid contravening the regulations of the countries concerned, <strong>the US can enter into bilateral agreements with them</strong>, which, in return for their goodwill, will be able to access data from the United States.</p>
<p>In the US, the CLOUD Act remains contested due to the risks introduced by the potential agreements with foreign countries. The fact that an executive power can put in place mutual agreements worries the American people, who fear that foreign powers are using the CLOUD Act to access their data without any safeguards.</p>
<h2>What are the consequences for customers in Europe?</h2>
<p>While tech giants (like Facebook, Google, Microsoft, and Apple) have supported the bill (with the US authorities refraining from approaching them for back-door access and providing a clear framework for data transfer), <strong>these </strong><strong>regulations raise concerns about customer privacy</strong> for the targeted businesses. The act could leave customers without a right to consult, or any information about access to their data by US authorities.</p>
<p>However, European customers whose data is processed in Europe are now protected by the General Data Protection Regulation (GDPR). Articles 45 and 48 of the regulation, which is now in force, lay down a clear set of rules for allowing data to be transferred to third-party countries. According to Frank Jennings (a renowned lawyer on cloud matters), the European Data Protection Board, which oversees the implementation of the GDPR, <a href="https://www.theregister.co.uk/2018/04/03/us_government_serves_microsoft_with_fresh_warrant_for_irishheld_emails/">will be responsible for deciding</a> whether data appropriation under the CLOUD Act constitutes a necessary measure for the safeguarding of US national security, or whether a request does not comply with the new regulation. <strong>This could force the United States to negotiate with the EU or its Member States on the conditions for such data transmission, thus protecting their citizens against illegitimate transfers</strong>. US customers, however, would remain within the scope of the CLOUD Act.</p>
<p>Negotiations are due to begin between the European Commission and the US. EU leaders have already criticized the US bill as being hastily adopted, something that may complicate negotiations. In the meantime, <a href="https://www.eff.org/deeplinks/2018/03/nearly-100-public-interest-organizations-urge-council-europe-ensure-high">some 100 civil society organizations</a> have urged transparency from the European Council about the negotiations of the CLOUD Act as set out by the &#8220;Convention on Cybercrime&#8221; (or &#8220;Budapest Convention&#8221;).</p>
<h2>Privacy laws: an asset for companies?</h2>
<p>While the GDPR has preoccupied a good number of companies with respect to the changes it involves for their information systems, and that <a href="https://www.riskinsight-wavestone.com/en/2018/03/e-privacy-urgent-attendre/">the ePrivacy Directive is in preparation</a>, it is instructive to consider the connections between regulatory developments and the world of business. Data privacy laws could, whether in the near or distant future, <strong>be considered as an aid to protecting </strong><strong>business’ data and to</strong> <a href="https://www.riskinsight-wavestone.com/en/2017/01/vie-privee-ere-numerique/"><strong>maintaining customers’ trust</strong></a><strong>.</strong></p>
<p>In a world where data-privacy issues are becoming increasingly important (think of <a href="http://www.lemonde.fr/pixels/article/2018/03/22/ce-qu-il-faut-savoir-sur-cambridge-analytica-la-societe-au-c-ur-du-scandale-facebook_5274804_4408996.html">Cambridge Analytica</a> <a href="https://www.cnet.com/news/google-dumps-home-minis-top-touch-function-over-privacy/">and Google Home Mini</a> ), protection of customer data can be a decisive factor when choosing between competing offers. The position US providers will take on privacy and data protection issues is therefore eagerly awaited.</p>
<h2>What can you do today?</h2>
<p>To conclude, the new regulations on privacy remain somewhat ambiguous and may even clash in certain areas. The main conclusion remains that, <strong>as a result of the GDPR, Europeans should be better protected against the CLOUD Act</strong>, provided US suppliers reject inappropriate requests, and the courts with responsibility for arbitrating them play their roles correctly. Meanwhile, non-European customers will not gain greater protection by choosing to host their data in Europe.</p>
<p>While awaiting the implementation of new laws dealing with confidentiality and possible data appropriation, there are steps you can take to protect your personal and business data against it being inappropriately accessed while overseas, and other potential threats:</p>
<ol>
<li>Clarify with your provider <strong>under what conditions it may be required to give access to your data,</strong> without forgetting to consider any mutual legal assistance treaties.</li>
<li><strong>Define or review your hosting strategy</strong> according to the type of data held, your provider’s nationality, and the hosting site’s location.</li>
<li><strong>Favor data hosting in European data centers</strong>, or in countries with well-established data privacy frameworks.</li>
<li><strong>Choosing a French or European supplier enables you to avoid the risks associated with the CLOUD Act</strong>. You must, however, stipulate contractually that it does not use US subcontractors (either directly or indirectly)!</li>
</ol>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/10/the-cloud-act-does-it-mean-your-data-is-better-protected/">The Cloud Act: does it mean your data is better protected?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>“HEALTH DATA HOSTS&#8221;: HEALTH PROVIDES A SHOT IN THE ARM FOR THE FRENCH ISO 27001 CERTIFICATION MARKET</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/08/health-data-hosts-iso-27001/</link>
		
		<dc:creator><![CDATA[Laurent GUILLE]]></dc:creator>
		<pubDate>Tue, 28 Aug 2018 15:24:57 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[data hosting]]></category>
		<category><![CDATA[données de santé]]></category>
		<category><![CDATA[Groupements Hospitaliers de Territoire]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[hébergement des données]]></category>
		<category><![CDATA[ISO27001]]></category>
		<category><![CDATA[legal framework]]></category>
		<category><![CDATA[règlementation]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/2018/04/hebergeur-donnees-sante-iso-27001/</guid>

					<description><![CDATA[<p>On April 1, 2018, the Health Data Host approval procedure, in force since January 2006, was replaced by a Health Data Host certification procedure . This new system includes ISO 27001 certification. While the number of ISO 27001 certifications seems...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/08/health-data-hosts-iso-27001/">“HEALTH DATA HOSTS&#8221;: HEALTH PROVIDES A SHOT IN THE ARM FOR THE FRENCH ISO 27001 CERTIFICATION MARKET</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>On April 1, 2018, the</em> <em><a href="https://www.riskinsight-wavestone.com/en/2016/07/nouvelle-loi-sante-trois-situations-hebergeurs-de-donnees-de-sante/">Health Data Host</a></em><em> approval procedure, in force</em> <em><a href="https://www.legifrance.gouv.fr/eli/decret/2006/1/4/SANX0500308D/jo/texte">since January 2006,</a></em> <em>was replaced by a Health Data Host certification procedure . This new system includes ISO 27001 certification. While the number of ISO 27001 certifications seems to be stagnating in France, this change makes it likely that there will be a shift to strong growth in the coming years.</em></p>
<h2>A NEW LEGAL FRAMEWORK IN 2018 FOR HEALTH DATA HOSTING</h2>
<p>The Health Data Hosting Decree was <a href="https://www.legifrance.gouv.fr/eli/decret/2018/2/26/SSAZ1733293D/jo/texte/fr">published in the French Official Journal on February 28, 2018</a>. This decree confirms the developments announced in <a href="https://www.legifrance.gouv.fr/eli/ordonnance/2017/1/12/AFSZ1626575R/jo">the Order of January 12, 2017, relating to the hosting of personal health data</a>, which is itself an instrument of <a href="https://www.legifrance.gouv.fr/eli/loi/2016/1/26/AFSX1418355L/jo">the act to modernize the health system of January 26, 2016</a>.</p>
<p>This new decree makes Health Data Host certification mandatory for any public or private organization that hosts &#8220;personal health data collected during prevention, diagnosis, care, and social or medical follow-up activities, on behalf of natural or legal persons who are the source of the production or collection of this data, or on behalf of patients themselves&#8221;.</p>
<p>Health Data Host certification must be overseen by an independent body, which has been accredited by the <a href="http://www.cofrac.fr/">French Accreditation Committee (COFRAC)</a> or one of its European equivalents. Achieving certification confirms the conformity of the service with all the relevant requirements. Health Data Host certification remains valid for three years but is subject to annual monitoring.</p>
<h2>APPROVAL OR CERTIFICATION: WHAT’S THE DIFFERENCE?</h2>
<p>As part of the approval process, the candidate organization had to compile a (large!) application file which included a set of completed forms and supporting documents, as well as a compliance audit report prepared by a company of its choosing.</p>
<p>Rather than starting from scratch every time, Health Data Hosting certification now relies almost exclusively on recognized international standards: ISO 27001 in its entirety—and parts of ISO 27017, ISO 27018, and ISO 20000-1. Some specific requirements are added too; these mainly focus on two aspects:</p>
<ul>
<li>The protection of health data: protection of outsourced backups, prohibition of the use of health data for purposes other than the provision of hosting services, the traceability (including names) of the use of generic accounts, and other provisions;</li>
<li>The transparency of the service: the option for the customer to carry out audits, a mandatory revocation policy, including the methods that will be used to return data, provision of the certification audit report at the client’s request, etc.</li>
</ul>
<p>Beyond the &#8220;usual&#8221; gains provided by ISO 27001 certification, which are discussed at length <a href="https://www.riskinsight-wavestone.com/en/tag/iso-27001-en/">in some of our previous articles</a>, these additional requirements aim to professionalize the hosting of services, improve transparency between the hosting provider and its customers, strengthen health-data security, and reaffirm the rights of those whose personal data is being processed in accordance with the General Data Protection Regulation (GDPR).</p>
<h2>HEALTH DATA CERTIFICATION REALLY MEANS TWO CERTIFICATES</h2>
<p>Health Data Host certification now includes two separate certificates, each tailored to a specific type of activity that the host may choose to carry out:</p>
<ul>
<li>A “Data Management Host&#8221; certificate;</li>
<li>A &#8220;Physical Infrastructure Host&#8221; certificate</li>
</ul>
<p>The diagram below, taken from <a href="http://esante.gouv.fr/sites/default/files/asset/document/hds_referentiel_daccreditation_asip_v1.0.0.pdf">requirements for Health Data Hosting</a>, provides the relevant detail on the certificate required for the type of health data hosting activity to be carried out.</p>
<figure id="post-11218 media-11218" class="align-none">
<figure id="post-11220 media-11220" class="align-none"><img loading="lazy" decoding="async" class="wp-image-11220 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data.png" alt="" width="473" height="482" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data.png 975w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-188x191.png 188w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-768x782.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-38x39.png 38w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-32x32.png 32w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-64x64.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-70x70.png 70w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/04/health-data-30x30.png 30w" sizes="auto, (max-width: 473px) 100vw, 473px" /></figure>
</figure>
<figure id="post-10644 media-10644" class="align-none"></figure>
<p><em>Activities requiring Health Data Host certification (diagram from accreditation requirements reference material v1.0, accessed on 04/04/2018)</em></p>
<p>A certificate is required if at least one activity within the scope of the certification type is to be carried out. For example, a hosting provider offering the outsourced backup of health data (Activity 6) will need to have a &#8220;Data Management Host&#8221; certificate; it will therefore have to comply with for requirements of the Health Data Host certification for this form of certification. Similarly, a p  rovider supplying premises (Activity 1) must have a &#8220;Physical Infrastructure Host&#8221; certificate and comply with the requirements applying to that type of certification.</p>
<p>Every hosting provider will have to acquire one or both certificates, depending on the health data hosting services it plans to offer to its clients.</p>
<h2>FUTURE CERTIFICATION FOR APPROVED HEALTH DATA HOSTS&#8230;</h2>
<p>Health Data Hosting approvals remain valid until they expire (withdrawal or suspension notwithstanding, as was the case when this was the regime in force). The period of validity will be extended by six months for approvals due to expire before March 31, 2019. After this date, all Health Data Hosts will have to obtain Health Data Host certification.</p>
<p>The mandatory nature of certification will boost the French market for ISO 27001 certifications, which is currently sluggish, according to <a href="https://www.iso.org/fr/the-iso-survey.html?certificate=ISO%209001&amp;countrycode=FR#countrypick">ISO’s most recent study</a>: in 2016, only 209 valid ISO 27001 certificates were awarded, compared with 227 in 2015.</p>
<p>120 Health Data Hosts have already been approved and <a href="http://esante.gouv.fr/services/referentiels/securite/hebergeurs-agrees">logged on ASIP Santé’s (the French government’s digital health agency) website</a> . Although some are already ISO 27001 certified (and assuming that the scope of the Information Security Management System includes the hosting of health data), additional certification will be required to become a certified Health Data Host. For the rest, certification covering all requirements will be needed, and this development should, in itself, lead to growth in the market for ISO 27001 certifications in future years.</p>
<p>&nbsp;</p>
<h2>&#8230; AND SOME FACILITIES THAT ARE PART OF AREA HOSPITAL GROUPS (GHTs)</h2>
<p>Another consequence of the act to modernize the French health system is that public health facilities are currently coming together as Area Hospital Groups (GHTs) to share aspects of their work. Each of the <a href="http://solidarites-sante.gouv.fr/professionnels/gerer-un-etablissement-de-sante-medico-social/groupements-hospitaliers-de-territoire/article/les-ght-par-region">135 GHTs</a> is organized around a support facility, which provides a range of services to the GHT, including &#8220;Strategy, optimization, and joint management of a combined hospital information system&#8221; (<a href="https://www.legifrance.gouv.fr/affichTexteArticle.do;jsessionid=81E2ECCAB9BD22DD0E7856EF59FD159C.tplgfr31s_1?idArticle=JORFARTI000031913559&amp;cidTexte=JORFTEXT000031912641&amp;dateTexte=29990101&amp;categorieLien=id">Article 107 of the act</a>). This provision requires the implementation of unique applications for all GHT facilities and each functional area (computerized patient files, medication circuits, biology, imaging, etc.).</p>
<p>GHTs have two main (though not exclusive) options:</p>
<ul>
<li>Contract a certified third-party Health Data Host to host their data; or</li>
<li>Host their data within one of the GHT’s facilities (for example, the support facility).</li>
</ul>
<p>In the latter case, the host establishment will need to be a certified Health Data Host. While the majority of GHTs are still considering whether to outsource all, or part, of their combined information system, <a href="http://www.ticsante.com/story.php?story=3846">in late 2017, 57% of them were still planning to outsource hosting</a>. Nevertheless, large numbers of GHTs may well, in the end, choose to maintain their health information system within the GHT and certify the host facility, in order to maintain full control of the information system and health data. This choice is likely to be seen mainly among GHTs that have large support facilities (a large central hospital, for example). This, then, will also drive strong growth in the number of ISO 27001 certificates issued in France.</p>
<h2>FINANCIAL HELP TO SUPPORT THE TRANSFORMATION OF GHTs</h2>
<p>To support the creation of their combined ISs, <a href="http://www.ticsante.com/story.php?story=3747">GHTs can draw on various forms of financial support</a>. €20m has already been invested through Regional Health Agencies (ARSs), and a call for projects, with a scope of €25m, was announced at the end of 2017 by the French government agency, DGOS. The scope of the <a href="http://www.hospimedia.fr/actualite/articles/20170315-e-sante-hopital-numerique-et-territoire-de-soins">e-Hôp 2.0 Program</a> , the successor to the 2012-2017 Digital Hospitals Program, should have seen funding, to a level of €400m, to support the development of health-care facilities to 2021. Given that it has been recently replaced by the <a href="https://www.ticsante.com/la-suite-du-programme-Hopital-numerique-soutiendra-l-ouverture-des-etablissements-vers-la-ville-(DGOS)-NS_4002.html">Hop&#8217;EN Program</a>, the eventual level of funding remains unknown at present.</p>
<p>Part of this funding may be used by GHTs to configure their combined information systems, for example by financing an outsourcing program with a certified hosting provider, or by financing the Health Data Host certification of one of the GHT’s facilities.</p>
<p>By changing the regulations related to the health data hosting <a href="http://esante.gouv.fr/sites/default/files/asset/document/asip-sante_point_detape-convergence_si_ght_v04.pdf">at a time when the GHTs are configuring their combined ISs</a>, the government is seizing the opportunity to strengthen the data security of patients treated by the public health service. Indirectly, this provides a dual driver for growth in the French market for ISO 27001 certification, which will result in the standardization, and dissemination of good practice, in information-security management across the healthcare sector.</p>
<p>Although the result of long-awaited developments, this growth is likely to lead to an explosion of applications for ISO 27001 certification and health data hosting in the coming years: will COFRAC, and the companies that will be accredited to deliver Health Data Host certification, be able to meet demand? &#8230;There could be a bottleneck on the horizon.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/08/health-data-hosts-iso-27001/">“HEALTH DATA HOSTS&#8221;: HEALTH PROVIDES A SHOT IN THE ARM FOR THE FRENCH ISO 27001 CERTIFICATION MARKET</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to turn Records Management into a business asset</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/02/turn-records-management-business-asset/</link>
		
		<dc:creator><![CDATA[AlexMerc3er]]></dc:creator>
		<pubDate>Tue, 20 Feb 2018 10:35:04 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[business asset]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Records management]]></category>
		<category><![CDATA[records policy]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=10376/</guid>

					<description><![CDATA[<p>Firstly, let’s introduce what Records Management is: it is the management of data generated while doing business from generation to deletion. Your company might not have a Records Management department, let alone a Records Management policy, but it already does...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/02/turn-records-management-business-asset/">How to turn Records Management into a business asset</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Firstly, let’s introduce what Records Management is: it is the management of data generated while doing business from generation to deletion. Your company might not have a Records Management department, let alone a Records Management policy, but it already does Records Management anyway: when you decide what data to store, where to store it and how to store it, you do Records Management. When you have procedures in place to delete documents, you do Records Management. If you provide financial services, you must keep certain records of business as required by regulation. If you handle personal data, you must be able to provide on request all records related to an individual (Subject Access Request).</p>
<p>So why should we care about Records Management? Records Management matters now more than ever with the incoming General Data Privacy Regulation (GDPR). It is a unique opportunity to turn a compliance issue into a business enabler by taking matters at a strategic level: by mapping out what data your company holds, where it is stored, and how it is processed, you accomplish many positive outcomes. First, you comply with Data Protection laws, which is the primary driver ahead of May 2018 when GDPR comes into force. But you also bring clarity to the Business as to what they do, you bring clarity to Information Security as to what they protect, and you bring clarity to clients and partners as to what information you hold about them and what you do with it. This in turn enables your company to save on storage costs and information security costs because you can now differentiate essential information that needs to be kept, maintained and protected, from information that is not required or that requires less protection. Your customers will welcome your transparency and control as they become more demanding in terms of respecting their privacy and understanding why you require such information.</p>
<p>So where should you start? You shouldn’t feel the need to hire a department full of Records Management experts to achieve your goals. You will find that employees that have been around for several years have a deep knowledge and understanding of how your company works. You can leverage their expertise through targeted interviews as you build your strategy.</p>
<p>The 3 steps to creating and implementing your Records Management strategy are as follows:</p>
<ol>
<li>Create a Records Management Policy for your company</li>
<li>Create a register of applications and vendors in use by your company (which can be based on your service catalogue)</li>
<li>Implement the Records Management Policy across your applications and vendors – this is where you will realize savings and efficiencies</li>
</ol>
<p>&nbsp;</p>
<h2>Records management policy</h2>
<p>Every business has legal, regulatory and operational reasons for keeping records. For example, you could be recording customer phone conversations with your customer service for training and quality purposes (business reason), because of a regulatory requirement when selling financial products (MiFID), or because of legislation.</p>
<p>The Records Management Policy will synthesize these business, regulatory and legal purposes for keeping records during the course of doing business.</p>
<p>Each Business Unit should be able to tell you what type of data they process and where it is held, so that the Policy can be built from the ground-up efficiently through a round of targeted interviews with long-standing employees or key business managers.</p>
<p>Once you have an inventory of types of records processed by your business, you then need to balance legal, regulatory and business imperatives for choosing the retention period for each record type: regulation will usually force a floor retention period (for example keep phone conversation audio records for 5 years minimum with MiFID II). Legislation will either force a minimum or a maximum retention period (e.g. Data Protection Act states you should not keep personal data for longer than required for the stated business purpose).</p>
<p>The combination of the record types, their retention periods and the purposes for which these records are held form your Records Management Policy.</p>
<p>&nbsp;</p>
<h2>Register of applications and vendors</h2>
<p>Once you have a Records Management Policy, you will need to align your IT systems so they support the implementation of the Policy. Thus, you need to build a top-down view by collecting the list of applications in use in your company through your IT and sourcing team. This will be your starting point. You should then cross-reference this list with the Information Security team to check it corresponds to applications they see end-users requesting access to. Finally, you can further corroborate this list with Business Heads which will usually be aware of any shadow IT applications there may be. The final list thus complied will support the implementation of your Records Management Policy. You can take advantage of the completeness of this list to feedback Information Security and Sourcing to plug in gaps you may have uncovered, which will help reduce risk of data loss through unsupervised vendors or systems.</p>
<p>You will then need to map the IT systems to the records they hold and that you have identified in your Records Management Policy. This will help to implement your Records Management Policy.</p>
<p>&nbsp;</p>
<h2>Implementation of your Records Management Policy</h2>
<p>Having a Records Management Policy and a mapping of your data is only a compliance tick-box exercise if you don’t follow through with implementation. Additionally, this step is where you will realise any savings and efficiencies. A good example is back-up tapes. If you can agree that the purpose of back-up tapes is only for network restoration in case of major disaster recovery, and you state it in your policy, then you can confidently state in your policy that their retention period should be, for example, no more than a week for daily tapes, no more than a month for weekly tapes, no more than a year for monthly tapes, and no more than 3 years for end-of-year tapes. Applying this will save you a lot of storage space and will bring clarity of purpose for your operations team. Certainly, you must in parallel define in your policy what other records will serve for satisfying record keeping obligations from a business, regulatory and legal perspective.</p>
<p>Companies that do not have a Records Management policy will struggle to agree on retention periods, and will tend to over-store records, which leads to unnecessary costs and even raises the risk of liability: old back-up tapes, to stick to this example, might not be encrypted or readable in current technology media, so that they are no longer of use to the business. If they get stolen, however, the data might still be exploitable and lead to reputation damage if not litigation for the firm.</p>
<p>Once you have a Records Management strategy in place and being implemented, you can review your Information Security, Legal, Compliance and Business strategies to align with the data you know you own and the operations around it. This will bring added benefits beyond the Records Management realm: focus Information Security Resources on areas of sensitive data, identify high risk operations currently being performed and change them to a lower risk alternative or drop them altogether if the business case is negative.</p>
<p>&nbsp;</p>
<p><em>It is now clearer what businesses stand to gain from having a clear Records Management strategy: better compliance with data protection laws, heightened operational efficiency, and more focused and efficient information security. To maximize the benefits of a Records Management strategy, it should also be integrated with the Information Security, Legal, Compliance and Business strategies to enable the business to operate in an efficient, compliant and secure environment going forward.</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/02/turn-records-management-business-asset/">How to turn Records Management into a business asset</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The SOC &#8211; a department undergoing a full regulatory overhaul</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/01/soc-regulatory-overhaul/</link>
		
		<dc:creator><![CDATA[Benoît Marion]]></dc:creator>
		<pubDate>Thu, 18 Jan 2018 10:32:57 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[Military Programming Act]]></category>
		<category><![CDATA[overhaul]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[règlementation]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[security surveillance]]></category>
		<category><![CDATA[SOC]]></category>
		<category><![CDATA[standardization]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=10304/</guid>

					<description><![CDATA[<p>Faced with increasingly insistent and advanced threats, Security Operations Centers (SOCs) must be able to detect security incidents as quickly as possible in order to be able to react ever more effectively. However, they are also facing increasingly stringent measures...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/01/soc-regulatory-overhaul/">The SOC &#8211; a department undergoing a full regulatory overhaul</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Faced with increasingly insistent and advanced threats, Security Operations Centers (SOCs) must be able to detect security incidents as quickly as possible in order to be able to react ever more effectively.</p>
<p>However, they are also facing increasingly stringent measures under new regulations such as the General Data Protection Regulation (GDPR), which covers all personal data, or the various new regulations on the protection of critical national infrastructures. <a href="https://www.ssi.gouv.fr/en/cybersecurity-in-france/ciip-in-france">France is in the vanguard of this activity with its Military Programming Act</a> which applies to the organizations classed as “most critical” in terms of the country’s functioning.</p>
<p>But how can you put in place increasingly sophisticated detection systems, while, at the same time, complying with an ever-stricter regulatory framework?</p>
<p>&nbsp;</p>
<h2><strong>SOC</strong><strong>s ARE BEING STANDARDIZED AT THE EUROPEAN LEVEL—AND GLOBALLY</strong></h2>
<p>In the mid-2000s, the implementation of the first SOCs consisted, for the most part, of deploying log collectors based on geographical hubs and the setting up of a central alert management system. However, recent regulatory changes may require modifications to architecture. In France, in particular, within the context of the Military Programming Act, the requirement to set up a &#8220;system of log correlation and analysis&#8221; (i.e. a SOC equipped by a SIEM system) has been accompanied by a strict regulatory framework, which is set out in its <a href="https://www.ssi.gouv.fr/uploads/2014/12/pdis_referentiel_v1.0_en.pdf#referentiel-pdis">PDIS (Security Incident Detection Service Providers) Requirements Reference Document</a>.</p>
<p>In terms of standardization, this addresses three points in particular:</p>
<ul>
<li>First, the <strong>framework for surveillance</strong>: there is now an obligation to detect certain types of common attacks and implement controls, following recommendations made through audits carried out by qualified bodies, in accordance with the <a href="https://www.ssi.gouv.fr/en/cybersecurity-in-france/ciip-in-france/faq">PASSI (Cybersecurity Audit Service Providers) Reference Document</a>. Companies must also put in place a permanent surveillance unit to notify ANSSI (the French national agency for information system security) in the event of an IS being critically compromised.</li>
<li>The second area addresses <strong>the securing of the SOC&#8217;s assets</strong>: new security measures described in the PDIS Requirements Reference Document demand, in particular, more robust measures for SOC operators and administrators (two-factor authentication, limitations on internet access, etc.). These security measures will be verified by ANSSI through audits, or retrospectively, following the compromise of an IS being notified to it.</li>
</ul>
<p><strong>Finally—the architecture—where there&#8217;s a requirement for greater complexity</strong>: partitioning into trust zones and an enlargement to the perimeter of the monitored network are introduced (going beyond the traditional scope of equipment under security surveillance: business servers and handheld devices must also now be monitored). Information related to security incidents (events, analysis reports, and their associated notifications) must also now be retained for as long as the service is provided.</p>
<p>&nbsp;</p>
<h2><strong>STRONG SECURITY AND CAREFUL HANDLING OF PERSONAL DATA: INCOMPATIBLE GOALS?</strong></h2>
<p>To carry out retrospective analyses and, in particular, to determine the origin of cyber-attacks, a good deal of personal and critical data must be collected, stored, and exploited. However, this data is covered by the GDPR, which tends to limit its collection and use.</p>
<p>Google&#8217;s recent fine by the AGPD (Spain&#8217;s personal data protection authority) highlights the types of issue that a SOC may encounter regarding the processing of personal data:</p>
<ul>
<li>Google’s obligations in the <strong>processing of personal data</strong> and the user&#8217;s<strong> right to be forgotten</strong> were the prime causes of Google’s penalty. In fact, the GDPR intends to offer European citizens the option to access, modify, or delete their data wherever it is stored (including in the cloud). This means that, in practice, companies must know exactly what data is being collected by their SOC, so that they can inform their customers, employees, etc. accordingly—and offer them the option of having it removed at any time. Having said that, the GDPR seems to indicate that preservation of some data is acceptable, where this is necessary for the protection of companies. The details of exactly how this provision will operate are expected to be worked out over the next few years.</li>
<li>An <strong>obligation of transparency</strong> with respect to the exploitation of data is the second issue that the AGPD’s action raises. Yet, for PDISs, the obligation to monitor a wide range of equipment gives rise to the collection of a large and varied amount of data. The content of logs will therefore have to be addressed to ensure that only the data needed for security-monitoring activity is collected.</li>
<li>Finally, the GDPR imposes a requirement to <strong>justify the preservation of the data</strong>. Yet, PDIS requirements are for data to be kept for at least six months, in order to have the ability to carry out long-term or retrospective analysis; this creates regulatory uncertainty: how far can a company go in ensuring the protection of its IS?</li>
</ul>
<p>Looking beyond the example of Spain, it’s instructive to compare the different legislative approaches to the notification of incidents. Those dedicated to the protection of personal data target rapid notification in order to limit the impacts on people&#8217;s lives; while legislation concerning the protection of critical infrastructure requires limited and highly confidential notifications in order to allow sufficient time for incidents to be correctly managed, without revealing to an attacker the fact that they have been discovered. In the end, the GDPR took into account this type of scenario, but that’s not to say that other texts won’t result in contradictory obligations.</p>
<p>&nbsp;</p>
<h2><strong>A STRICT—BUT BENEFICIAL—REGULATORY FRAMEWORK</strong></h2>
<p>The tightening of the regulatory framework for SOCs, whether direct (via PDIS requirements) or indirect (through the GDPR), will result in a transformation of the IS ecosystem. New types of profiles could thus be integrated into teams, such as the Data Privacy Officer (DPO), which the SOC could consider as a key player in maintaining its long-term compliance.</p>
<p>In addition, these regulations will raise maturity levels among the players who have to comply with them, as well as among those who draw inspiration from them. Already, there are numerous moves toward compliance involving SOC architecture, as well as its processes and governance.</p>
<p>In complying with the regulations, tools also count—and that means looking at innovations such as data-based surveillance (with Data Leakage Prevention [DLP] tools), which can help ensure compliance with respect to the protection of sensitive data.</p>
<p>&nbsp;</p>
<h2><strong>TOWARD MORE REALISTIC REGULATIONS&#8230;</strong></h2>
<p>The value of the requirements for many organizations, both as standards and objectives to be met, cannot be disputed.</p>
<p>While the bar may seem high, and regulatory inconsistencies remain, one thing is for sure: the next round of regulatory updates will provide a solid framework for the design and improvement of SOC.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/01/soc-regulatory-overhaul/">The SOC &#8211; a department undergoing a full regulatory overhaul</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The trends of Trump&#8217;s Cyber Regulation</title>
		<link>https://www.riskinsight-wavestone.com/en/2017/04/trends-trumps-cyber-regulation/</link>
		
		<dc:creator><![CDATA[CyRilKor3Beuss3r]]></dc:creator>
		<pubDate>Fri, 28 Apr 2017 11:32:43 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[sectoral regulations]]></category>
		<category><![CDATA[US]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=9702/</guid>

					<description><![CDATA[<p>On January 31, 2017, President Trump postponed the signature of the Executive Order on cybersecurity, which was expected to lay the groundwork of the United States’ efforts to fight cyber threats in the coming years. The presidential race was marked...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/04/trends-trumps-cyber-regulation/">The trends of Trump&#8217;s Cyber Regulation</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>On January 31, 2017, President Trump postponed the signature of the Executive Order on cybersecurity, which was expected to lay the groundwork of the United States’ efforts to fight cyber threats in the coming years.</em></p>
<p>The presidential race was marked by a strong emphasis on cybersecurity. The topic, considered during the campaigns as “one of the most important challenges the next president is going to face” (Hilary Clinton, Derry, New Hampshire, February 3, 2016) and “an immediate and top priority,” (Donald Trump, Herndon, Virginia, October 3, 2016) was on the agendas of both final candidates, who expressed a strong willingness to better protect the country’s “cyberspace.” Furthermore, the leakages from various political organizations during the electoral process highlighted the weaknesses of the society against cyber threats.</p>
<p>&nbsp;</p>
<h2>U.S. critical infrastructure sectors, such as financial services, transportation systems, and energy, will inevitably have a role to play.</h2>
<p>The cyber community is now eager to see the new government’s cybersecurity plan. In addition to federal agencies, private institutions that are heavily involved in U.S. critical infrastructure sectors, such as financial services, transportation systems, and energy, will inevitably have a role to play.</p>
<p>Significant efforts have been made to increase cybersecurity in the U.S. and abroad. A common trend is to improve protection of what is generally called critical infrastructure. To that end, the previous U.S. administration launched several governmental initiatives, including the development of the Framework for Improving Critical Infrastructure Cybersecurity by NIST (“<a href="https://www.nist.gov/cyberframework">NIST Cybersecurity Framework</a>”). The framework is used worldwide aside major standards and is now being updated. In 2016, the <a href="https://obamawhitehouse.archives.gov/the-press-office/2016/02/09/fact-sheet-cybersecurity-national-action-plan">Cybersecurity National Action Plan</a> (CNAP), planned to increase the country’s Federal budget for cybersecurity to $19 billion in 2017. In Europe, <a href="https://ec.europa.eu/digital-single-market/en/network-and-information-security-nis-directive">the Directive on Security of Network and Information Systems</a> (“NIS Directive”) requires Member States to adopt and publish sufficient laws and regulations to protect essential services. This is a global trend which is already visible in many countries such as France with the <a href="https://www.legifrance.gouv.fr/eli/loi/2013/12/18/DEFX1317084L/jo/texte">LPM</a> law and China through the recently enacted <a href="http://www.chinalawtranslate.com/cybersecuritydraft/?lang=en">Cybersecurity Law</a>. Even international organizations such as NATO are promoting critical infrastructure cybersecurity protection.</p>
<p><strong>Will President Trump focus the country’s cybersecurity program on critical infrastructure?</strong></p>
<h2></h2>
<h2>The two draft Executive Orders released show the new administration is seriously considering the issue.</h2>
<p>The first draft <a href="https://apps.washingtonpost.com/g/documents/world/read-the-trump-administrations-draft-of-the-executive-order-on-cybersecurity/2306/">Executive Order Strengthening U.S. Cyber Security and Capabilities</a> suggests President Trump will order an extensive review of the country’s weaknesses, strengths, and enemies within an aggressive timeline. The previous administration initiated similar effort less than a month after taking office in 2009, resulting in the rather theoretical <a href="http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf">Cyberspace Policy Review</a>.</p>
<p>This draft focuses on the following initiatives:</p>
<ul>
<li><strong>Vulnerabilities</strong> – Review most critical cyber vulnerabilities and submit a list of initial recommendations for enhanced protection of national security systems and most critical infrastructure;</li>
<li><strong>Adversaries</strong> – Review principal cyber adversaries and submit a first report on their identities, capabilities, and vulnerabilities;</li>
<li><strong>Capabilities</strong> – Review relevant cyber capabilities and identify an initial set needing improvements to adequately protect critical infrastructure; review efforts to educate and train the cyber workforce and make recommendations for the future;</li>
<li><strong>Incentives</strong> – Propose options to incentivize private sector adoption of effective cybersecurity measures and submit recommendations.</li>
</ul>
<p>&nbsp;</p>
<h2>Leveraging incentives reduces the immediate need for additional regulation or legislation.</h2>
<p>While the review of vulnerabilities, adversaries, and capabilities is consistent with actions taken by foreign governments, a more original approach may be taken to ensure adoption of cybersecurity measures by the private sector. Indeed, the focus on Leveraging incentives reduces the immediate need for additional regulation or legislation, which echoes well President Trump’s “Two-for-One” Regulation Executive Order. On the contrary, in Europe, the NIS Directive calls for “effective, proportionate, and dissuasive penalties” to ensure requirements are fulfilled.</p>
<p>Based on currently available information, it is difficult to discern how and to what extent the government would be able to fully execute these initiatives, as they are relatively sweeping in scope. However, the assessment of tangible vulnerabilities and adversaries may indicate a willingness to focus on launching concrete actions.</p>
<p>The second draft <a href="https://lawfareblog.com/revised-draft-trump-eo-cybersecurity">Executive Order Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure</a> is similarly ambitious, ordering the government to produce no less than 11 reports and requiring the involvement of the whole executive branch of the Federal Government and critical infrastructure actors.</p>
<p>This draft retains the initiatives on vulnerabilities and capabilities from the first draft, but the scopes are quite different. It suggests more stringent effort will be made on the protection of executive branch and less on critical infrastructure. Among other things, the government here aims to:</p>
<ul>
<li>Hold heads of executive departments and agencies accountable for managing cyber risk. This follows a trend already adopted by regulators in the financial services sector, for example through the <a href="http://www.dfs.ny.gov/about/press/pr1702161.htm">NYS-DFS 23 NYCRR 500 Cybersecurity Requirements for Financial Services Companies</a>  and the <a href="https://www.nfa.futures.org/nfamanual/NFAManual.aspx?RuleID=9070&amp;Section=9">NFA Interpretive Notice on Information Systems Security Programs</a> (ISSP). Bringing accountability to the senior management level is a necessary step toward reinforced focus on cybersecurity and inclusion at the enterprise level, beyond technology departments;</li>
<li>Generalize the use of the NIST Cybersecurity Framework. While the framework was originally intended for critical infrastructure, it is easy to imagine it applied to federal agencies. It would likely complement and structure the usage of other materials such as <a href="https://www.nist.gov/publications/minimum-security-requirements-federal-information-and-information-systems">the NIST FIPS PUB 200 Minimum Security Requirements for Federal Information and Information Systems</a> and <a href="https://www.nist.gov/news-events/news/2013/04/nist-issues-major-revision-core-computer-security-guide-sp-800-53">the NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations</a>, which agencies are already required to leverage under <a href="https://www.gpo.gov/fdsys/pkg/STATUTE-116/pdf/STATUTE-116-Pg2899.pdf">the Federal Information Security Management Act of 2002</a> (FISMA). It would also increase alignment of practices between the public and private sectors;</li>
<li>Review executive departments’ and agencies’ risk management practices and actual risk decisions, assess whether they are appropriate and sufficient, as well as develop a plan for improvement. Such effort is consistent with the first draft but this time applies only to the executive branch;</li>
<li>Develop a plan to modernize IT architecture by transitioning to shared IT services and consolidating network architecture, especially for National Security Systems. Shared IT services allow for increased security through industrialization, and consolidated network architectures are easier to protect and monitor.</li>
<li>Identify authorities and capabilities to support cybersecurity efforts of entities managing critical infrastructure at greatest risk in case of cyber attack, in collaboration with those entities. The notion of critical infrastructure at greatest risk originates from <a href="https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity">President Obama’s Executive Order 13636 Improving Critical Infrastructure Cybersecurity</a>;</li>
<li>Assess the Federal policies and practices efficiency to promote market transparency of cyber risk management. No more incentives here, but a market-driven approach to foster extended cybersecurity measures among the private sector, and no reference to any new regulation;</li>
<li>Identify and promote initiatives to improve resiliency of core telecommunications infrastructure. Those initiatives, likely at the Internet service provider level, would mainly focus on <a href="https://media.licdn.com/mpr/mpr/AAEAAQAAAAAAAA1xAAAAJDAzZmJkMGZkLWQ2NTctNDk0ZC05YmI1LTZkZmE2NDg1YTRkZQ.png">preventing continuously increasing distributed attacks</a>.</li>
</ul>
<figure id="post-9703 media-9703" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-9703 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/04/US-article-Trump.png" alt="" width="910" height="513" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/04/US-article-Trump.png 910w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/04/US-article-Trump-339x191.png 339w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/04/US-article-Trump-768x433.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/04/US-article-Trump-69x39.png 69w" sizes="auto, (max-width: 910px) 100vw, 910px" /></figure>
<h2></h2>
<h2>The initiatives described in the two drafts are aligned with general market practices and are headed in the right direction.</h2>
<p>Overall, the initiatives described in the two drafts are aligned with general market practices and are headed in the right direction. However, some uncertainty remains on a number of topics such as privacy and protection of PII, and private-public collaboration. Moreover, as American technology companies that have historically stored their data in the U.S. are opening more and more data centers abroad to meet local regulatory requirements, the U.S. will have to define their own data localization requirements.</p>
<p>&nbsp;</p>
<h2>The challenge for the new administration is to develop unified data protection policies to drive consistent regulations</h2>
<p>The U.S. has led the effort in defining modern cybersecurity tools such as the NIST Cybersecurity Framework and the <a href="https://www.ffiec.gov/cyberassessmenttool.htm">FFIEC Cybersecurity Assessment Tool</a> but now needs to focus on execution. The challenge for the new administration is to develop unified data protection policies to drive consistent regulations, and move from a theoretical approach to concrete results.</p>
<p>If we are to expect actual results, the effort should enable a country-wide response that is transversal and coordinated, with sufficient oversight. Putting in charge a single agency, as announced by White House officials moments before the President’s signature was called off, may well be a first step in that direction. The new administration will have to define clear roles and responsibilities between the public and private sectors, a governance for collaboration, and a strategy to drive implementation.</p>
<p>Beyond this transformation, the upcoming challenge will be on the collaboration with other countries to align with foreign initiatives with a NATO-like approach, with the objective to drive harmonization of standards and requirements for a more efficient approach to cybersecurity. Stakes and expectations are higher than ever.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/04/trends-trumps-cyber-regulation/">The trends of Trump&#8217;s Cyber Regulation</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Privacy: which legal frameworks should be implemented on an international scale?</title>
		<link>https://www.riskinsight-wavestone.com/en/2017/02/privacy-which-legal-frameworks-should-be-implemented-on-an-international-scale/</link>
		
		<dc:creator><![CDATA[Raphaël Brun]]></dc:creator>
		<pubDate>Thu, 23 Feb 2017 15:59:17 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[digital trust]]></category>
		<category><![CDATA[european regulation]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[regulation]]></category>
		<category><![CDATA[synthesis]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=9655/</guid>

					<description><![CDATA[<p>Since the introduction of digital privacy in legislative literature, regulations have become increasingly stringent. The European Union is the engine driving this trend with the General Data Protection Regulation (GDPR), although other countries have not flatered behind as we sitness...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/02/privacy-which-legal-frameworks-should-be-implemented-on-an-international-scale/">Privacy: which legal frameworks should be implemented on an international scale?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Since the introduction of digital privacy in legislative literature, regulations have become increasingly stringent. The European Union is the engine driving this trend with the General Data Protection Regulation (GDPR), although other countries have not flatered behind as we sitness a global effort in establishing regulation for the handling of personal data. </em></p>
<p><em>This blog post is a part of a series of articles which is itself the result of a<a href="https://www.wavestone.com/en/insight/privacy-digital-world-compliance-trust/"> synthesis on Privacy at the digital age</a> published on our website. </em></p>
<h2>An increasingly international regulatory framework</h2>
<p>The concept of privacy, as understood in history, <strong>can be understood across several centuries of legislation</strong>. It began <strong>taking shape in 1948, inscribed in Article 12 of the Universal Declaration of Human Rights: </strong>“No one will be the object of arbitrary interference in his private life (&#8230;). Everyone has the right to be protected by law against such interference or attacks”.</p>
<p><strong>Regulation around the protection of personal data is a more recent phenomenon.</strong> It is directly <strong>linked to the development of information technology and the increased collection</strong> of data by organisations. In addition, the<strong> market valu</strong>e of data adds a further layer of complexity with the emergence of an international regulatory consensus. Sweden was the first state to establish legislation on the subject in 1973. In France, the “Loi Informatique et Libertés” was enacted in 1978, following debates over the Safari project, aimed at creating a centralised database of information about individuals.</p>
<p>Without reviewing each national law and its timeliness, an analysis of the initiatives implemented on regional scales provides a holistic view of the main privacy trends.</p>
<h2>European Union: the state protecting its citizens</h2>
<p>The European Union was <strong>the first institution to establish legislation on the subject in 1995 with the publication of Directive 1995/46/EC.</strong> This first attempt at creating legislative harmony on an institutional and European scale has been followed by the implementation of <strong>numerous principles, defined in the law</strong> of various Member States, including the establishment of <strong>supervisory authorities</strong>. This legislation is rooted in the “Guidelines for the Protection of Privacy and Transborder Flows of Personal Data” published by the OECD in 1980, which were non-binding.</p>
<p>In April 2016, the European Union elected to strengthen its legislation with the General Data Protection Regulation (GDPR), which, <strong>unlike the 1995 directive, will be directly applicable in the law of the Member States of the European Union</strong>.</p>
<figure id="post-9669 media-9669" class="align-none"><img loading="lazy" decoding="async" class="alignnone wp-image-9669" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-406x191.png" alt="" width="638" height="300" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-406x191.png 406w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-768x361.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework.png 1530w" sizes="auto, (max-width: 638px) 100vw, 638px" /></figure>
<p>Its implementation is planned for <strong>May 2018</strong>, when organisations must ensure their compliance with the requirements of the regulation. Developments will soon take place in <strong>e-privacy</strong> in the near future, aligning traditional requirements on privacy with more recent developments and innovation, thus addressing the topics of secrecy and correspondence in the digital age. Through such literature, the European Union will adopt the position as a protector of citizen data.</p>
<h2>US: Making people aware of their responsilities</h2>
<p><strong>There is no specific regulation nor regulator within American law</strong> which oversees the collection and use of personal data at a federal level. Instead, the United States operates under a <strong>combination of laws which apply to certain sectors or states.</strong> Some regulation covers specific categories of personal data, such as financial data or health-related data, while others regulate activities which exploit such data, such as digital marketing. In addition to such regulations, best practices developed by federal agencies and industrial groups are also used as a means of auto-regulation.<strong> The Fourth Amendment of the US Constitution</strong> can also be referenced for the protection of personal privacy. Finally, <strong>laws around consumer protection</strong>, while they do not regulate personal privacy, forbid practices around the disclosure of personal data. Nevertheless, American citizens display a certain degree of flexibility regarding the distribution of their personal data.</p>
<p>As shown by the evolution of <strong>“Safe Harbor”,</strong> differences exist between the American and the European vision. This legal mechanism was implemented to ensure the protection of data transfer between the EU and the USA until October 2015, thereafter invalidated by the Court of Justice of the European Union (CJEU). According to the CJEU, the level of data protection offered by the United States was no longer satisfactory in light of the information leaked by Edward Snowden regarding the global surveillance programme operated by the American government. In February 2016, the United States and the EU drew up a new arrangement, the Privacy Shield, which came into force in August 2016 and is designed to offer better protection for data transfers.</p>
<h2>Asia: a situation under development</h2>
<p>With respect to data protection, <strong>we can categorise Asian countries and territories in two ways.</strong> Some are relatively mature on the subject, including South Korea, Singapore, Hong Kong or Taiwan. Until recently, China did not have any specific personal data protection legislation. However, in November 2016, new regulations applicable to operators from June 2017 were implemented. This new regulation will integrate widely agreed principles on respecting personal privacy and will require the storage of personal data on Chinese territory. On the other hand, other countries in the area are yet to implement regulations regarding the protection of personal data on a large scale, despite on-going debates.</p>
<h2>Rest of the world: regional initiatives under development</h2>
<p>In Africa, the first legislation on the subject was implemented in 2001, in Cape Verde. In 2004, Burkina Faso was the first state to establish a national regulator. At the regional level, the African Union Convention on Cybersecurity and Personal Data Protection, signed by 18 countries in 2014, <strong>incorporates notions derived from European legislation, with no legal binding. </strong></p>
<p>In the Middle East, states such as the United Arab Emirates (UAE) and Saudi Arabia do not have specific legislation regarding the protection of personal data. <strong>Specific to these countries is the application of Sharia law</strong>, stating that damage can be claimed if the disclosure of personal data leads to abuse or damage.</p>
<p>In South America, several countries implement independent regulators. Moreover, they benefit from<strong> constitutional guarantees</strong> regarding personal data protection. This is particularly the case in Uruguay and Argentina, two countries recognised by the European Union as providing sufficient levels of data protection. <em><br />
</em></p>
<figure id="post-9671 media-9671" class="align-none">
<figure id="post-9672 media-9672" class="align-none"><img loading="lazy" decoding="async" class="alignnone wp-image-9672" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-3-366x191.png" alt="" width="606" height="316" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-3-366x191.png 366w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-3-768x400.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-3-71x37.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/legal-framework-3.png 1086w" sizes="auto, (max-width: 606px) 100vw, 606px" /></figure>
</figure>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/02/privacy-which-legal-frameworks-should-be-implemented-on-an-international-scale/">Privacy: which legal frameworks should be implemented on an international scale?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
