CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
Technical Measures and Mitigation for OIVs General Instruction No 4 provides a detailed set of technical requirements that OIVs must deploy imme - diately when an incident is detected. These include isolating affected segments of the network and restricting access to compromised systems or user accounts. Institutions must change all passwords for administrative accounts within three hours of detect - ing an incident that impacts confidentiality or integrity. Network security is further reinforced through manda - tory segmentation, both logical and physical, to limit the lateral movement of an attack between different environments. OIVs must also install and operate fire - walls configured under the principle of whitelisting, meaning all incoming connections are blocked by default unless explicitly allowed. Supply-Chain Security and Outsourcing Controls When reporting incidents with “significant effects”, entities must consider if the event was capable of interrupting the service provided by their own sup - pliers. This perspective forces OIVs to extend their risk management to the third parties that support their essential functions. 2.3 Incident Response and Notification Obligations Incident Classification and Thresholds The obligation to report is triggered when a cyber - security incident is classified as having “significant effects”. Under Article 27 of the Cybersecurity Frame - work Law, an incident meets this threshold if it is capable of interrupting the continuity of an essential service or affecting the physical health or integrity of individuals. Furthermore, any event affecting comput - er systems that contain personal data is automatically deemed to have a significant effect. To determine the magnitude of an incident, regulated entities must evaluate specific criteria including the number of persons affected, the duration of the event and its geographical extent. The Agency has further refined these thresholds through a formal Taxonomy of Incident, which categorises events based on observ - able effects such as unauthorised use of resources, exfiltration of data or total loss of service availability.
Timelines for Notification The notification process follows a strict, multi-stage timeline intended to keep the CSIRT Nacional informed as a threat evolves. • Early warning – regulated entities must submit an initial alert within a maximum period of three hours after becoming aware of the incident or cyberat - tack. • Second report (update) – a more detailed update is required within 72 hours of initial awareness. How - ever, if the affected entity is an OIV and the incident has interrupted its essential service, this deadline is significantly reduced to 24 hours. • Plan of action – specifically, for OIVs, a formal plan of action must be implemented and communicated to the CSIRT Nacional within seven days of the incident discovery. • Final report – a comprehensive final report is due within 15 days of the initial early warning, provided the incident has been managed. If the incident remains active, entities must provide status updates every 15 days until final resolution. Notification Channels and Supervisory Authorities The primary competent authority for receiving and co- ordinating incident responses is the CSIRT Nacional , which operates under the ANCI. The official and man - datory channel for all notifications is the electronic platform provided by the Agency. Access to the reporting platform requires robust authentication, typically through the use of a Unique Key ( Clave Única ) and a mandatory second factor of authentication, such as TOTP or passkeys. Entities are required to designate a specific person in charge of reporting who serves as the formal counterpart to the Agency. Required Content of Reports The content of the reports becomes progressively more technical as the notification stages advance. • Initial alert – focuses on the identification of the institution, contact details for the delegate, the date and time of discovery and the initial symp - toms or indicators of the incident.
64 CHAMBERS.COM
Powered by FlippingBook