The draft law on information security is in the parliamentary procedure, but it has shortcomings

The reform of the law on the protection of personal data in Montenegro represents not only a legal and regulatory imperative, but also an essential need to strengthen institutional capacities in order to effectively protect the rights of citizens in the digital space, said Andreja Mihailović, teaching assistant at the Faculty of Law of the UCG.

17303 views 0 comment(s)
Illustration, Photo: Shutterstock
Illustration, Photo: Shutterstock
Disclaimer: The translations are mostly done through AI translator and might not be 100% accurate.

Before the adoption of the Law on Information Security, which is in the parliamentary procedure, a new Law on the Protection of Personal Data should have been adopted, which would be in accordance with the General Data Protection Regulation (GDPR).

This is what Andreja Mihailović, a teaching assistant at the Faculty of Law of the University of Montenegro, told "Vijesta".

Mihailović is a lecturer, researcher and consultant in the field of commercial and criminal law with a special focus on information security, cyber crime, digital investigations, electronic evidence, cyber diplomacy and legal and political aspects of digital transformation.

Explaining why it is necessary, before adopting the new Law on Information Security, to pass a new Law on Protection of Personal Data, she said that it is because "the current law is a decade older than the Regulation".

"With the latest changes from 2017, which means that it does not provide an adequate legal basis for the effective implementation of the new Law on Information Security. The NIS2 directive itself (EU Directive on Network and Information Security 2022/2555) explicitly refers to the GDPR in several places, emphasizing the need for coherence between information security measures and protection of personal data," she told "Vijesti".

The proposal of the law on information security was adopted by the government in May. A public hearing on the Draft was organized last year, in the period from March 20 to 96, when nine participants submitted XNUMX comments.

The first Law on Information Security in Montenegro was adopted in 2010, and six years later amendments were adopted.

The interlocutor of "Vijesti" said that the Proposal, which is in the parliamentary procedure, compared to the current solution, introduces certain changes for the better, but also has shortcomings.

"The proposal introduces significant changes with the aim of increasing national capacities in the field of cyber security and harmonization with the NIS2 directive. Compared to the previous NIS directive from 2016, NIS2 significantly expands the scope of application, both in terms of identifying key and important subjects, as well as in terms of prescribed obligations, as well as penal provisions for non-compliance. NIS2 expands the domain of activity from the original seven to a total of 15 sectors, which, according to the Bill, are categorized into basic and important subjects," said Mihailović.

According to her, this represents a significant innovation in the existing legislative framework.

"Bearing in mind that according to the new law, all state bodies, local self-government bodies, as well as all legal and natural persons who manage or use network and information systems, will be obliged to implement a set of prescribed information security measures and appoint a responsible person for their implementation ", the interlocutor of "Vijesti" said.

Stricter measures for both the public and private sectors

According to the Bill, as she said, the definition of "key" and "important" subjects includes entities from critical sectors from energy and transport, through healthcare, the financial market, digital service providers, all the way to food distribution and production and waste management.

"Who are expected to maintain a high level of information security preparedness in order to minimize risks and ensure the continuity of critical services. Therefore, it is an extensive range that introduces new obligations to almost all public and private sector entities operating in Montenegro in terms of harmonizing their operations with strict regulatory information security requirements," she said.

Primarily, Mihailović added, the law prescribes the mandatory implementation of comprehensive technical and organizational measures to protect network and information systems, which include cyber security risk management, encrypted data protection, and regular updating of security policies in accordance with the ISO 27001 standard.

In addition, according to her, the law introduces the obligation to report to competent authorities about detected cyber threats and incidents, along with submitting regular reports and up-to-date information to users about risks and measures taken in order to eliminate them and minimize harmful consequences.

Perhaps the current CIRT model should have been retained

"The law also introduces an innovative institutional framework, in terms of the establishment of the Agency for Cyber ​​Security, as a central body responsible for key and important subjects and the formation of the CIRT of state bodies within the Ministry of Public Administration, instead of the existing national CIRT that was established in 2012, in cooperation with the International Telecommunication Union (ITU). In the light of the requirements of the NIS2 directive and a more precise demarcation of competences, it was perhaps more pragmatic to retain the model of the national CIRT, as an organizational agency for cyber security, since this would achieve greater operational autonomy and flexibility of the CIRT, without administrative burden, bearing in mind numerous competence of the Ministry", Mihailović said.

In addition, as she added, and bearing in mind the cross-border character of cyber threats and the inevitable need for information exchange, this would achieve more effective coordination with other national and international bodies in this area, and consistent implementation of the national cyber security strategy.

Andreja Mihailović
Andreja Mihailovićphoto: Boris Pejović

Personnel not (un)prepared for such a regulation

The "Vijesti" interlocutor said that, although the transposition of the NIS2 directive into the national legislative framework brings numerous benefits for Montenegro, in terms of strategically raising the collective level of cyber defense and protection of critical infrastructure, there are also potential challenges during implementation.

"Given the national cyber security index, which is significantly below the EU average, the traditional lack of financial, technical and human resources, the question is whether it is realistic to expect that the capacities of the state and private sector in Montenegro are really ready to absorb such an ambitious regulation" , she said.

Clarifying that position, she added that the primary reason for the adoption of the NIS2 directive was the inadequate implementation of the initial NIS directive from 2016, which provided for much milder requirements, bearing in mind that only 23 EU countries managed to fully implement the prescribed measures.

"Such inconsistency resulted in unsustainable fragmentation in the EU cyber defense system in the form of different standards by certain countries, which speaks volumes about the demands of this act. Therefore, when we talk about the harmonization of national legislation with the NIS2 directive, we should bear in mind that it is the most comprehensive European directive on cyber security so far with rigorous requirements for risk management, incident reporting, the obligation to implement the ISO 27001 standard, which covers all verticals of social and economic functioning", Mihailović said.

Broad surveillance powers

It is enough, as she added, to point out strengthened supervisory mechanisms in the form of inspection and expert supervision, which include policies and procedures related to information security management with broad powers of competent authorities.

"Specifically, Article 54 of the new law prescribes the obligation for subjects to provide the supervisor with access to the space, computer equipment and devices during professional supervision, as well as to make available for inspection or submit the necessary data and documentation related to the subject of supervision without delay," Mihailović said. and added that such authorizations are necessary to ensure effective supervision, but at the same time create potential risks for misuse of access and violation of privacy, "especially bearing in mind the significant volume of sensitive data operated by key and important subjects".

"Taking into account all the positive and negative implications of such a solution, before its adoption in Montenegro it was necessary to approach the adoption of a new Law on the Protection of Personal Data, which would be in accordance with the General Regulation on Data Protection, bearing in mind that the current the law is a decade older than the Regulation, with the last amendments from 2017, which means that it does not provide an adequate legal basis for the effective implementation of the new Law. The NIS2 directive itself explicitly references the GDPR in several places, emphasizing the need for coherence between information security measures and personal data protection," she said.

In the context of the harmonization of Montenegrin legislation with the GDPR, according to her, it is crucial to emphasize the importance of data subject rights and transparency in the processing of such data, along with the regulation of their transfer, as essential elements that contribute to increasing the level of privacy and protection of citizens in the digital environment.

"The data subject's rights, which are elaborated in detail in the GDPR, including the right to access, correct, delete and transfer data, need to be equally protected in Montenegrin legislation. Bearing in mind the potential abuses that can arise from widely set competences in the supervision procedure, the role of the DPO in organizations is also crucial, as the person responsible for monitoring the compliance of data processing with the law," she said.

In addition, the "Vijesti" interlocutor adds, the process of data protection impact assessment (DPIA) stands out as a necessary instrument for identification, analysis and minimization of risks arising from the processing of personal data within inspection and supervision activities.

"This process is mandatory under the GDPR when data processing operations carry a high risk for the rights and freedoms of individuals, which is often the case in the context of the supervision of key and important entities, which include sectors such as energy, health, finance and digital infrastructure, where inadequate data protection can have serious consequences for the privacy and security of citizens", said Mihailović.

The DPIA, she explained, "is not only a procedural requirement, but also a key component of corporate responsibility and risk management, which enables the competent authorities to achieve a double goal: effective supervision while ensuring that the rights and freedoms of individuals are respected in accordance with the law." .

"In this sense, it would be expedient to prescribe the obligation of competent authorities to record all data processing actions they undertake in the supervision process, in particular: input, modification, access, disclosure (including transfer), comparison and deletion of data. These records should enable the identification of the reasons for each processing action, the date and time of undertaking those actions, as well as the identity of the person who inspected or disclosed the data, and the identity of the recipient of the data," Mihailović said, adding that this would enable citizens and organizations to have control over the legality of processing their data, which is the basis for protecting their privacy and building trust between users and those who come into contact with their data.

"The reform of the law on the protection of personal data in Montenegro represents not only a legal and regulatory imperative, but also an essential need to strengthen institutional capacities in order to effectively protect the rights of citizens in the digital space. Also, raising the level of data protection at the national level and compliance with the GDPR would position Montenegro as a reliable partner in international relations and economic transactions where the protection of personal data is a global priority," said Mihailović.

The law alone does not protect anyone, one must constantly learn about cyber threats

The lack of adequate education and awareness of security threats is the main challenge in the field of information security, and in this sense, it is necessary to constantly invest in the education of all - institutions, businesses and citizens.

"As well as strengthening the infrastructure and resources for incident response. We believe that constant education and raising awareness is a key element for improving security at all levels of society," said "One" company to "Vijesti", talking about the Draft Law on Information Security.

In connection with the Draft, questions were sent to other telecommunication companies, the Central Bank of Montenegro... The Central Bank of Montenegro said that at this stage they do not want to comment on the text. From the point of view of the company "One", which, among others, made suggestions on the proposed text in the public discussion phase, the establishment of the Agency and CIRT is "a significant step towards improving coordination and efficiency in responding to incidents in the field of information security".

"Our previous experience with the existing CIRT is positive, but we believe that the structure and powers of state bodies responsible for information security as defined by the Bill will enable even more effective and comprehensive cyber security, not only in state bodies and institutions, but also within economic societies", they told "Vijesti". They added that "it is important to continuously work on harmonizing the law with other relevant regulations in order to ensure its full and effective application".

See more: