Description

Adopted CRC order establishing obligations for critical information infrastructure organisations

On 5 February 2024, the Cybersecurity Regulating Committee (CRC) adopted an order on the obligations of obligations for critical information infrastructure (CII). In particular, the CII organisations encompass state and private entities providing essential services in sectors such as national security, finance, and public health. The CII obligations include reporting to the National Cyber Security Agency (NCSA) lists of executive staff and responsible persons, along with emergency contacts. By June 20, 2025, these organizations must develop cybersecurity guidelines, standards frameworks, and internal procedures for risk management. Ongoing compliance requires annual reporting on cyber threats, regular reviews of cybersecurity policies, and conducting audits. In the event of a cybersecurity incident, organisations must follow detection protocols and report to the NCSA within 24 hours. Additionally, CII organizations must mitigate cybersecurity risks, participate in training, and establish a computer emergency response team. The NCSA will review these obligations biannually or as needed.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2024-02-05
adopted

On 5 February 2024, the Cybersecurity Regulating Committee (CRC) adopted an order on the obligation…

2024-06-20
in force

On 20 June 2024, the Cybersecurity Regulating Committee’s (CRC) order on the obligations of obligat…