Real Decreto 43/2021, de 26 de enero, por el que se desarrolla el Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de información. | BOE-A-2021-1192 — Spain law | Esheria

Real Decreto 43/2021, de 26 de enero, por el que se desarrolla el Real Decreto-ley 12/2018, de 7 de septiembre, de seguridad de las redes y sistemas de información.

This article states the decree’s purpose: to develop the cited 2018 law on network and information systems security.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
Spain
Instrument
Regulation
Citation
BOE-A-2021-1192
Version
Undated source snapshot
Language
es
Updated
Official source
View official record ↗
audit reports bank supervision consultations with authorities contact with authority cooperación entre equipos CSIRT coordinación entre autoridades coordination with authorities critical infrastructure cross-border incident information sharing cybersecurity cybersecurity incident handling data protection coordination energy sector administration essential services exclusions financial system resilience gestión de incidentes gestión de incidentes cibernéticos incident management incident notification incident reporting information security information security governance information sharing +26 more

Publicly available, excluded from search-engine indexing

This page remains available for direct access and API use, but this release emits noindex,follow for the following reason:

  • The record does not meet this release's canonical indexing criteria. (market-indexing-disabled)

Statute overview

About this statute

Regulates how incident notifications must be made, including who notifies, timing of initial/intermediate/final notices, and cross-border information sharing. Se crea una plataforma nacional de notificación y seguimiento de ciberincidentes, que debe estar disponible para los actores involucrados y permitir intercambio seguro de información, seguimiento de incidentes y acceso de las autoridades competentes. Los CSIRT de referencia, y también las autoridades competentes en algunos casos, deben dar información relevante sobre incidentes a operadores de servicios esenciales y proveedores de servicios digitales afectados o notificantes, cuando sea posible. OCC must promptly report security incidents that are notified to it and appear to be criminal to the Prosecutor’s Office and, where applicable, to the competent judicial police units; it may also request needed incident information from affected operators or reference CSIRTs. Certain consultations with public safety authorities must be made through the OCC; other consultations under Article 14 must be made directly to the relevant competent authorities.