UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP
6. Cybersecurity in Other Regulations 6.1 Cybersecurity and Data Protection As mentioned in 1.2 Cybersecurity Laws , the UK GDPR and the DPA contain cybersecurity obligations in relation to the processing of personal data. These laws apply to: • all organisations established in the four countries of the UK (ie, England, Northern Ireland, Scotland and Wales); and • organisations not established in the UK processing personal data of data subjects in the UK to offer them goods or services or to monitor their behav - iour. The UK GDPR requires that controllers and processors implement “appropriate” technical and organisational security measures, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of the processing of personal data, as well as the risks of such processing to the data subject’s rights (eg, from accidental or unlawful destruction, loss, alteration or unauthorised disclosure of – or access to – personal data transmitted, stored or otherwise processed by the organisation). The UK GDPR itself sets out examples of “appropri - ate” security measures, which are: • pseudonymisation and encryption of personal data; • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; • the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and • a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of personal data processing. Importantly, according to the ICO, there is no “one size fits all” approach to “appropriate” security and recommends that – before taking a view on what is “appropriate” – organisations should assess the level of risk by reviewing the type of personal data held, whether it is sensitive or confidential, and the damage
mining whether the effect that a security compromise has – or would have – on the operation of a network or service is “significant”, certain matters should be considered, including the length of the period during which the operation of the network or service is or would be affected, the number of affected persons, the geographical size and location affected, and the extent to which activities of persons who use the net - work or service are or would be affected by the effect on the operation of the network or service. 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation There are numerous cybersecurity frameworks that are expressly or implicitly recognised by UK cyber - security regulators. By way of example, the ICO rec - ommends that organisations review the Cyber Essen - tials scheme (a UK government- and industry-backed scheme) for basic guidance on preventing and limiting the impact of cyber-attacks. Similarly, Ofcom repeatedly references the Internation - al Organisation for Standardisation (ISO) standards in its Guidance on Security Requirements. In addition, Ofcom states that the controls in the Cyber Essen - tials scheme should be implemented and exceeded; it adds that obtaining the Cyber Essentials Plus certi - fication is “a powerful way to demonstrate this”. Regarding the NIS Regulations, the NCSC has pub - lished 14 cybersecurity and resilience principles that provide guidance in the form of the Cyber Assessment Framework (CAF). The CAF is particularly relevant to OESs that are subject to the NIS Regulations. Lastly, the most used account and payments data security standard, the Payment Card Industry Data Security Standard (PCI DSS), was most recently revised in June 2024 with the publication of Version 4.0.1.
452 CHAMBERS.COM
Powered by FlippingBook