The Network and Information Systems Regulations 2018
| Year | 2018 |
2018 No. 506
Electronic Communications
The Network and Information Systems Regulations 2018
Made 19th April 2018
Laid before Parliament 20th April 2018
Coming into force 10th May 2018
The Secretary of State is a Minister designated1for the purposes of section 2(2) of the European Communities Act 19722(“the 1972 Act”) in relation to electronic communications.
These Regulations make provision for a purpose mentioned in section 2(2) of the 1972 Act and it appears to the Secretary of State that it is expedient for certain references to provisions of EU instruments to be construed as references to those provisions as amended from time to time.
The Secretary of State makes the following Regulations in exercise of the powers conferred by section 2(2) of, and paragraph 1A3of Schedule 2 to, the 1972 Act and by section 56 of the Finance Act 19734(“the 1973 Act”) and, in the case of section 56 of the 1973 Act, with the consent of the Treasury.
PART 1
Introduction
Citation, commencement, interpretation and application
1.—(1) These Regulations may be cited as the Network and Information Systems Regulations 2018 and come into force on 10th May 2018.
(2) In these Regulations—
“cloud computing service” means a digital service that enables access to a scalable and elastic pool of shareable computing resources;
“the Commission” means the Commission of the European Union;
“Cooperation Group” means the group established under Article 11(1);
“CSIRTs network” means the network established under Article 12(1);
“digital service” means a service within the meaning of point (b) of Article 1(1) of Directive 2015/1535 which is of any the following kinds—
(a) online marketplace;
(b) online search engine;
(c) cloud computing service;
“digital service provider” means any person who provides a digital service;
“Directive 2013/11” means Directive 2013/11/EUof the European Parliament and of the Council on alternative dispute resolution for consumer disputes5, and amending Regulation (EC) No 2006/2004and Directive 2009/22/EC, as amended from time to time;
“Directive 2015/1535” means Directive (EU) 2015/1535 of the European Parliament and of the Council laying down a procedure for the provision of information in the field of technical regulations and of rules on Information Society services6, as amended from time to time;
“Directive 2016/1148” means Directive (EU) 2016/1148 of the European Parliament and of the Council concerning measures for a high common level of security of network and information systems across the Union7, as amended from time to time;
“Drinking Water Quality Regulator for Scotland” means the person appointed by the Scottish Ministers under section 7(1) of the Water Industry (Scotland) Act 20028;
“essential service” means a service which is essential for the maintenance of critical societal or economic activities;
“GCHQ” means the Government Communications Headquarters within the meaning of section 3 of the Intelligence Services Act 19949;
“incident” means any event having an actual adverse effect on the security of network and information systems;
“network and information system” (“NIS”) means—
(a) an electronic communications network within the meaning of section 32(1) of the Communications Act 200310;
(b) any device or group of interconnected or related devices, one or more of which, pursuant to a program, perform automatic processing of digital data; or
(c) digital data stored, processed, retrieved or transmitted by elements covered under paragraph (a) or (b) for the purposes of their operation, use, protection and maintenance;
“online marketplace” means a digital service that allows consumers and/or traders as respectively defined in point (a) and in point (b) of Article 4(1) of Directive 2013/11 to conclude online sales or service contracts with traders either on the online marketplace’s website or on a trader’s website that uses computing services provided by the online marketplace;
“online search engine” means a digital service that allows users to perform searches of, in principle, all websites or websites in a particular language on the basis of a query on any subject in the form of a keyword, phrase or other input, and returns links in which information related to the requested content can be found;
“operator of an essential service” (“OES”) means a person who is deemed to be designated as an operator of an essential service under regulation 8(1) or is designated as an operator of an essential service under regulation 8(3);
“relevant law-enforcement authority” has the meaning given in section 63A(1A) of the Police and Criminal Evidence Act 198411; and
“risk” means any reasonably identifiable circumstance or event having a potential adverse effect on the security of network and information systems.
(3) In these Regulations a reference to—
(a)
(a) an Article, Annex, paragraph of an Article or Annex is a reference to the Article, Annex of paragraph as numbered in Directive 2016/1148;
(b)
(b) a numbered regulation, paragraph or Schedule is a reference to the regulation, paragraph or Schedule as numbered in these Regulations;
(c)
(c) “the relevant authorities in a Member State” is a reference to the designated single point of contact (“SPOC”), computer security incident response team (“CSIRT”) and national competent authorities for that Member State;
(d)
(d) the “designated competent authority for an operator of an essential service” is a reference to the competent authority that is designated under regulation 3(1) for the subsector in relation to which that operator provides an essential service;
(e)
(e) a “relevant digital service provider” (“RDSP”) is a reference to a person who provides a digital service in the United Kingdom and satisfies the following conditions—
(i) the head office for that provider is in the United Kingdom or that provider has nominated a representative who is established in the United Kingdom;
(ii) the provider is not a micro or small enterprise as defined in Commission Recommendation 2003/361/EC12;
(f)
(f) the “NIS enforcement authorities” is a reference to the competent authorities designated under regulation 3(1) and the Information Commissioner;
(g)
(g) “security of network and information systems” means the ability of network and information systems to resist, at a given level of confidence, any action that compromises the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the related services offered by, or accessible via, those network and information systems.
(4) Expressions and words used in these Regulations which are also used in Directive 2016/1148 have the same meaning as in Directive 2016/1148.
(5) Nothing in these Regulations prevents a person from taking an action (or not taking an action) which that person considers is necessary for the purposes of safeguarding the United Kingdom’s essential State functions, in particular—
(a)
(a) safeguarding national security, including protecting information the disclosure of which the person considers is contrary to the essential interests of the United Kingdom’s security; and
(b)
(b) maintaining law and order, in particular, to allow for the investigation, detection and prosecution of criminal offences13.
(6) These Regulations apply to—
(a)
(a) the United Kingdom, including its internal waters;
(b)
(b) the territorial sea adjacent to the United Kingdom;
(c)
(c) the sea (including the seabed and subsoil) in any area designated under section 1(7) of the Continental Shelf Act 196414.
PART 2
The National Framework
The NIS national strategy
2.—(1) A Minister of the Crown must designate and publish a strategy to provide strategic objectives and priorities on the security of network and information systems in the United Kingdom (“the NIS national strategy”).
(2) The strategic objectives and priorities set out in the NIS national strategy must be aimed at achieving and maintaining a high level of security of network and information systems in—
(a)
(a) the sectors specified in column 1 of the table in Schedule 1 (“the relevant sectors”); and
(b)
(b) digital services.
(3) The NIS national strategy may be published in such form and manner as the Minister considers appropriate.
(4) The NIS national strategy may be reviewed by the Minister at any time and, if it is revised following such a review, the Minister must designate and publish a revised NIS national strategy as soon as reasonably practicable following that review.
(5) The NIS national strategy must, in particular, address the following matters—
(a)
(a) the regulatory measures and enforcement framework to secure the objectives and priorities of the strategy;
(b)
(b) the roles and responsibilities of the key persons responsible for implementing the strategy;
(c)
(c) the measures relating to preparedness, response and recovery, including cooperation between public and private sectors;
(d)
(d) education, awareness-raising and training programmes relating to the strategy;
(e)
(e) research and development plans relating to the strategy;
(f)
(f) a risk assessment plan identifying any risks; and
(g)
(g) a list of the persons involved in the implementation of the strategy.
(6) The Minister must communicate the NIS national strategy, including any revised NIS national strategy, to the Commission within three months after the date on which the strategy is designated under paragraph (1).
(7) Before publishing the NIS national strategy or communicating it to the Commission, the Minister may redact any part of it which relates to national security.
(8) In this regulation “a Minister of the Crown” has the same meaning as in section 8(1) of the Ministers of the Crown Act 197515.
Designation of national competent authorities
3.—(1) The person specified in column...
Get this document and AI-powered insights with a free trial of vLex and Vincent AI
Get Started for FreeStart Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting