{"id":129,"date":"2023-08-22T10:09:13","date_gmt":"2023-08-22T08:09:13","guid":{"rendered":"https:\/\/blogs.dlapiper.com\/paragraph\/?p=129"},"modified":"2024-07-26T12:21:55","modified_gmt":"2024-07-26T10:21:55","slug":"nova-uprava-kyberneticke-bezpecnosti","status":"publish","type":"post","link":"https:\/\/blogs.dlapiper.com\/paragraph\/2023\/08\/nova-uprava-kyberneticke-bezpecnosti\/","title":{"rendered":"Nov\u00e1 \u00faprava kybernetick\u00e9 bezpe\u010dnosti"},"content":{"rendered":"\n<p>Vyr\u00e1b\u00edte po\u010d\u00edta\u010de \u010di jin\u00e1 elektronick\u00e1 nebo elektrick\u00e1 za\u0159\u00edzen\u00ed, stroje a p\u0159\u00edstroje, l\u00e9\u010diva a zdravotnick\u00e9 prost\u0159edky nebo potraviny a m\u00e1te pades\u00e1t a v\u00edce zam\u011bstnanc\u016f? Pak se na v\u00e1\u0161 podnik z\u0159ejm\u011b bude vztahovat nov\u00e1 \u00faprava kybernetick\u00e9 bezpe\u010dnosti. Tot\u00e9\u017e plat\u00ed, pokud podnik\u00e1te nap\u0159\u00edklad v oblasti chemick\u00e9ho pr\u016fmyslu nebo poskytujete nejr\u016fzn\u011bj\u0161\u00ed digit\u00e1ln\u00ed slu\u017eby \u2013 cloud computing, slu\u017eby datov\u00e9ho centra \u010di online tr\u017ei\u0161t\u011b\u2026 a mnoh\u00e9 dal\u0161\u00ed<\/p>\n\n\n\n<p>Pozor, pokud je va\u0161e spole\u010dnost sou\u010d\u00e1st\u00ed skupiny spole\u010dnost\u00ed, po\u010d\u00edtaj\u00ed se do v\u00fd\u0161e uveden\u00e9ho po\u010dtu i zam\u011bstnanci ostatn\u00edch spole\u010dnost\u00ed dan\u00e9 skupiny, i mimo \u010ceskou republiku.&nbsp;<\/p>\n\n\n\n<p>Nov\u00e1 pr\u00e1vn\u00ed \u00faprava kybernetick\u00e9 bezpe\u010dnosti bude vych\u00e1zet ze sm\u011brnice EU o opat\u0159en\u00edch k zaji\u0161t\u011bn\u00ed vysok\u00e9 spole\u010dn\u00e9 \u00farovn\u011b kybernetick\u00e9 bezpe\u010dnosti v Unii a (tzv. \u201eNIS2 Directive\u201c) p\u0159ijat\u00e9 na konci roku 2022.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Nov\u00e1 evropsk\u00e1 \u00faprava<\/strong><\/p>\n\n\n\n<p>Hlavn\u00ed zm\u011bnou oproti podob\u011b sou\u010dasn\u00e9ho z\u00e1kona o kybernetick\u00e9 bezpe\u010dnosti je pr\u00e1v\u011b z\u00e1sadn\u00ed roz\u0161\u00ed\u0159en\u00ed okruhu a po\u010dtu subjekt\u016f, na n\u011b\u017e se nov\u00e1 pr\u00e1vn\u00ed \u00faprava uplatn\u00ed. Odhaduje se, \u017ee m\u00edsto dosavadn\u00edch zhruba 150 spole\u010dnost\u00ed p\u016fjde a\u017e o 6000 ekonomick\u00fdch subjekt\u016f. Pro n\u011b p\u016fjde o regula\u010dn\u00ed zm\u011bnu srovnatelnou nap\u0159. se zaveden\u00edm re\u017eimu GDPR p\u0159ed p\u011bti lety. Z\u00e1sadn\u00ed zm\u011bnou jsou pak rovn\u011b\u017e hroz\u00edc\u00ed sankce jdouc\u00ed svoj\u00ed v\u00fd\u0161\u00ed potenci\u00e1ln\u011b do milion\u016f Eur v&nbsp;p\u0159\u00edpadech, kdy regulovan\u00e1 osoba poru\u0161\u00ed nov\u011b ukl\u00e1dan\u00e1 pravidla.<\/p>\n\n\n\n<p>Regulace se dotkne i mnoha dal\u0161\u00edch sektor\u016f, d\u016fle\u017eit\u00fdch pro chod n\u00e1rodn\u00ed ekonomiky a fungov\u00e1n\u00ed spole\u010dnosti \u2013 nap\u0159. tak\u0159ka ve\u0161ker\u00e9 energetiky, d\u00e1le telekomunikac\u00ed, vodn\u00edho a odpadov\u00e9ho hospod\u00e1\u0159stv\u00ed, cel\u00e9 \u0159ady \u010dinnost\u00ed v&nbsp;oblasti dopravy, finan\u010dn\u00edch slu\u017eeb, zdravotnictv\u00ed nebo v\u00fdzkumu a v\u00fdvoje.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<p class=\"has-medium-font-size\">Povinn\u00e9 osoby tak budou muset zejm\u00e9na:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Pot\u00e9, co ur\u010d\u00ed, \u017ee se na n\u011b nov\u00e1 \u00faprava vztahuje, registrovat se jako poskytovatel\u00e9 regulovan\u00fdch slu\u017eeb u N\u00e1rodn\u00edho \u00fa\u0159adu pro kybernetickou a informa\u010dn\u00ed bezpe\u010dnost (N\u00daKIB);<\/li>\n\n\n\n<li>Identifikovat aktiva (tj. informace a data, procesy, zam\u011bstnance a fyzick\u00e1 aktiva), kter\u00e1 jsou kl\u00ed\u010dov\u00e1 z&nbsp;hlediska kybernetick\u00e9 bezpe\u010dnosti;<\/li>\n\n\n\n<li>Zav\u00e1d\u011bt p\u0159\u00edslu\u0161n\u00e1 organiza\u010dn\u00ed opat\u0159en\u00ed, nap\u0159. vytvo\u0159en\u00ed syst\u00e9mu bezpe\u010dnostn\u00edho \u0159\u00edzen\u00ed a bezpe\u010dnostn\u00ed dokumentace, stanoven\u00ed bezpe\u010dnostn\u00edch rol\u00ed, \u0159\u00edzen\u00ed rizik, aktiv a dodavatel\u016f;<\/li>\n\n\n\n<li>Zav\u00e1d\u011bt p\u0159\u00edslu\u0161n\u00e1 technick\u00e1 opat\u0159en\u00ed, zahrnuj\u00edc\u00edh nap\u0159. \u0159\u00edzen\u00ed p\u0159\u00edstupov\u00fdch opr\u00e1vn\u011bn\u00ed, detekce kybernetick\u00fdch bezpe\u010dnostn\u00edch ud\u00e1lost\u00ed, pou\u017e\u00edv\u00e1n\u00ed kryptografick\u00fdch algoritm\u016f;<\/li>\n\n\n\n<li>Identifikovat, \u0159e\u0161it a oznamovat kybernetick\u00e9 bezpe\u010dnostn\u00ed incidenty;<\/li>\n\n\n\n<li>Podrobit se pravideln\u00e9mu auditu ze strany autorizovan\u00e9ho inspektora (na z\u00e1klad\u011b smlouvy s&nbsp;n\u00edm), p\u0159\u00edpadn\u011b st\u00e1tn\u00ed kontrole N\u00daKIB. Autorizovan\u00fdm inspektorem se m\u016f\u017ee st\u00e1t soukrom\u00e1 fyzick\u00e1 osoba s&nbsp;p\u0159\u00edslu\u0161n\u00fdm vzd\u011bl\u00e1n\u00edm a prax\u00ed v&nbsp;oblasti kyberbezpe\u010dnosti, kter\u00e1 slo\u017e\u00ed u N\u00daKIB zkou\u0161ku a bude n\u00e1sledn\u011b jako inspektor zaps\u00e1na. D\u016fvody pro zaveden\u00ed tohoto konceptu jsou kapacitn\u00ed \u2013 nebude v&nbsp;sil\u00e1ch N\u00daKIB nov\u011b monitorovat v\u0161echny regulovan\u00e9 osoby.<\/li>\n<\/ul>\n<\/div>\n<\/div>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Sou\u010dasn\u00fd stav v \u010cR<\/strong><\/p>\n\n\n\n<p>V&nbsp;tuto chv\u00edli se p\u0159\u00edslu\u0161n\u00e1 pr\u00e1vn\u00ed \u00faprava v&nbsp;\u010cesk\u00e9 republice teprve p\u0159ipravuje. N\u00daKIB ned\u00e1vno na sv\u00fdch webov\u00fdch str\u00e1nk\u00e1ch uve\u0159ejnil n\u00e1vrh nov\u00e9ho z\u00e1kona o kybernetick\u00e9 bezpe\u010dnosti a jeho prov\u00e1d\u011bc\u00edch p\u0159edpis\u016f, kter\u00e9 maj\u00ed zcela nahradit dosavadn\u00ed pr\u00e1vn\u00ed \u00fapravu. N\u00e1vrh z\u00e1kona zohled\u0148uj\u00edc\u00ed \u0159adu p\u0159ipom\u00ednek odborn\u00e9 ve\u0159ejnosti je nyn\u00ed v&nbsp;meziresortn\u00edm p\u0159ipom\u00ednkov\u00e9m \u0159\u00edzen\u00ed s&nbsp;p\u0159edpokl\u00e1dan\u00fdm vstupem do \u010dten\u00ed v&nbsp;Parlamentu \u010cR teprve b\u011bhem l\u00e9ta 2023. Platnost nov\u00e9 \u00fapravy lze za p\u0159edpokladu obvykl\u00e9ho v\u00fdvoje legislativn\u00edho procesu o\u010dek\u00e1vat na podzimu p\u0159\u00ed\u0161t\u00edho roku.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Dopad\u00e1 to na m\u011b a kdy?<\/strong><\/p>\n\n\n\n<p>Ji\u017e te\u010f je nicm\u00e9n\u011b s&nbsp;p\u0159ihl\u00e9dnut\u00edm k&nbsp;jedn\u00e1n\u00ed s&nbsp;p\u00e9\u010d\u00ed \u0159\u00e1dn\u00e9ho hospod\u00e1\u0159e obez\u0159etn\u00e9 se v p\u0159edstihu zaj\u00edmat, zda se na moji spole\u010dnost nov\u00e1 \u00faprava do budoucna vztahuje \u010di nikoliv \u2013 bude tedy praktick\u00e9 p\u0159i p\u0159\u00edprav\u011b rozpo\u010dtu na oblast compliance pro p\u0159\u00ed\u0161t\u00ed rok zahrnout zv\u00fd\u0161en\u00e9 n\u00e1klady na implementaci NIS2, person\u00e1ln\u00ed a technick\u00e9 zabezpe\u010den\u00ed cel\u00e9ho procesu, p\u0159\u00edpadn\u011b tak\u00e9 na extern\u00ed odborn\u00e9 poradce, kte\u0159\u00ed mohou s&nbsp;touto mimo\u0159\u00e1dn\u011b d\u016fle\u017eitou agendou pomoct. Nab\u00edz\u00ed se proto k&nbsp;zodpov\u011bzen\u00ed ot\u00e1zka, jakou \u010d\u00e1st nov\u00fdch povinnost\u00ed je moje spole\u010dnost schopna dlouhodob\u011b zajistit st\u00e1vaj\u00edc\u00edmi vlastn\u00edmi silami a kde mus\u00edme nav\u00fd\u0161it kapacity, p\u0159\u00edpadn\u011b jak\u00e9 procesy bude mo\u017en\u00e9 nakonec rozumn\u011b outsourcovat?<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Auto\u0159i \u010dl\u00e1nku<\/strong><\/p>\n\n\n\n<p><a href=\"https:\/\/www.dlapiper.com\/en-CZ\/people\/s\/scerba-tomas\" data-type=\"link\" data-id=\"https:\/\/www.dlapiper.com\/en-CZ\/people\/s\/scerba-tomas\">Tom\u00e1\u0161 \u0160\u010derba<\/a>, <a href=\"https:\/\/www.dlapiper.com\/en-CZ\/people\/m\/metelka-jan\">Jan Metelka<\/a>, <a href=\"https:\/\/www.dlapiper.com\/en-CZ\/people\/r\/rataj-jan\">Jan Rataj<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p class=\"has-small-font-size\"><strong>Informa\u010dn\u00ed zdroje:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sm\u011brnice 2022\/2555, NIS2 &#8211; <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/CS\/TXT\/PDF\/?uri=CELEX:32022L2555&amp;from=CS\">Publications Office (europa.eu)<\/a>;<\/li>\n\n\n\n<li>Doporu\u010den\u00ed Komise EU o definici mikropodnik\u016f, mal\u00fdch a st\u0159edn\u00edch podnik\u016f (2003\/361\/ES) &#8211; <a href=\"https:\/\/www.cmzrb.cz\/wp-content\/uploads\/2018\/10\/Doporuceni_komise_o_definici_MSP.pdf\">Doporuceni_komise_o_definici_MSP.pdf (cmzrb.cz)<\/a>, <a href=\"https:\/\/www.tacr.cz\/wp-content\/uploads\/documents\/2023\/03\/24\/1679649164_U%C5%BEivatelsk%C3%A1%20p%C5%99%C3%ADru%C4%8Dka%20k%20definici%20mal%C3%BDch%20a%20st%C5%99edn%C3%ADch%20podnik%C5%AF.pdf\">U\u017eivatelsk\u00e1 p\u0159\u00edru\u010dka k definici mal\u00fdch a st\u0159edn\u00edch podnik\u016f (tacr.cz)<\/a><\/li>\n\n\n\n<li>N\u00e1vrh nov\u00e9ho z\u00e1kona o kybernetick\u00e9 bezpe\u010dnosti, doprovodn\u00fdch vyhl\u00e1\u0161ek a souvisej\u00edc\u00ed materi\u00e1ly (nap\u0159. od\u016fvodn\u011bn\u00ed jednotliv\u00fdch n\u00e1vrh\u016f p\u0159edpis\u016f) na webov\u00fdch str\u00e1nk\u00e1ch N\u00daKIB &#8211; <a href=\"https:\/\/osveta.nukib.cz\/course\/view.php?id=145\">Course: Nov\u00e1 sm\u011brnice EU o bezpe\u010dnosti s\u00edt\u00ed a informac\u00ed (nukib.cz)<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Vyr\u00e1b\u00edte po\u010d\u00edta\u010de \u010di jin\u00e1 elektronick\u00e1 nebo elektrick\u00e1 za\u0159\u00edzen\u00ed, stroje a p\u0159\u00edstroje, l\u00e9\u010diva a zdravotnick\u00e9 prost\u0159edky nebo potraviny a m\u00e1te pades\u00e1t a v\u00edce zam\u011bstnanc\u016f? Pak se na v\u00e1\u0161 podnik z\u0159ejm\u011b bude vztahovat nov\u00e1 \u00faprava kybernetick\u00e9 bezpe\u010dnosti. Tot\u00e9\u017e plat\u00ed, pokud podnik\u00e1te nap\u0159\u00edklad v oblasti chemick\u00e9ho pr\u016fmyslu nebo poskytujete nejr\u016fzn\u011bj\u0161\u00ed digit\u00e1ln\u00ed slu\u017eby \u2013 cloud computing, slu\u017eby datov\u00e9ho centra [&hellip;]<\/p>\n","protected":false},"author":792,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[14],"tags":[20,19],"coauthors":[22,21,23],"class_list":["post-129","post","type-post","status-publish","format-standard","hentry","category-it-data-protection","tag-cybersecurity","tag-nis2-directive"],"_links":{"self":[{"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/posts\/129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/users\/792"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/comments?post=129"}],"version-history":[{"count":0,"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/posts\/129\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/media?parent=129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/categories?post=129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/tags?post=129"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/blogs.dlapiper.com\/paragraph\/wp-json\/wp\/v2\/coauthors?post=129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}