PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados
5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation Portugal has designated the CNCS as the National Cybersecurity Certification Authority, responsible for implementing a national cybersecurity certification framework. In this context, the CNCS has developed the EC QNRCS certification, based on European schemes. The EC QNRCS certification scheme has been designed for central and local administration organi - sations, operators of critical infrastructure, essential and important service providers, digital service provid - ers, and other private and non-governmental organi - sations, whether for profit or not. This certification provides three levels of assurance: basic, substantial and elevated. The CNCS manages and supervises this national certification scheme in co-operation with the Portuguese Quality Institute (IPQ) and the Portuguese Accreditation Institute (IPAC). The CNCS has also created a voluntary Cybersecurity Services Certification Scheme (EC SCS), applicable to all organisations established in Portugal that provide cybersecurity services. Under this scheme, the certifi - cation authority evaluates the following cybersecurity service areas: • incident monitoring and response; • vulnerability management; • threat intelligence; and • penetration testing (“pentesting”). The EC SCS establishes two certification levels: • Basic, which requires compliance with general requirements and service-specific criteria; and • Substantial, which includes all Basic requirements and additionally requires Security Accreditation for cybersecurity service providers, issued by the National Security Office. In addition, a Digital Maturity Certification has been introduced. This certification is based on the QNRCS and sets out national criteria and guidelines that, once
met, allow organisations to obtain the National Digital Maturity Seal in Cybersecurity. It is available to organi - sations across all sectors, with particular emphasis on micro, small and medium-sized enterprises. The seal is awarded at three progressive levels (Bronze, Silver and Gold) and the criteria for obtaining it are defined in Standard DNP TS 4477-1. Finally, under the new Cybersecurity Legal Frame - work, the CNCS may require in-scope entities to obtain cybersecurity certification – whether national, European or international. This provision will likely stimulate growth in the cybersecurity market and pro - mote the ongoing development of national certifica - tion schemes. 6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection The cornerstone of data protection in the EU, and consequently in Portugal, is the GDPR. One of the main principles of the GDPR is the integrity and confidentiality principle, established in Article 5 (1) (f). This principle is enshrined by Article 32 (security of processing) and Articles 33 and 34, which relate to notification and communication obligations in the event of a personal data breach. In light of this legal framework, controllers and proces - sors are required to adopt “appropriate” technical and organisational measures to ensure a level of security that is “appropriate” to the potential risks. The adjec - tive “appropriate” allows for a risk-based approach regarding the controls that should be implemented, considering the state of the art. For this purpose, the Article lists some controls that represent the profes - sional consensus on security controls for process - ing, such as encryption and pseudonimisation. When assessing the adequacy of the technical and opera - tional measures to be implemented, the controller or processor concerned may take into consideration the cost of implementation, the risks associated with the processing activities, and their severity for the rights and freedoms of data subjects.
270 CHAMBERS.COM
Powered by FlippingBook