keyboard_tab Cyber Resilience Act 2023/2841 EN
BG CS DA DE EL EN ES ET FI FR GA HR HU IT LV LT MT NL PL PT RO SK SL SV print pdf
- 1 Art. 3 Definitions
CHAPTER I
GENERAL PROVISIONS
CHAPTER II
MEASURES FOR A HIGH COMMON LEVEL OF CYBERSECURITY
CHAPTER III
INTERINSTITUTIONAL CYBERSECURITY BOARD
CHAPTER IV
CERT-EU
CHAPTER V
COOPERATION AND REPORTING OBLIGATIONS
CHAPTER VI
FINAL PROVISIONS
- Union entities
- network and information system
- security of network and information systems
- cybersecurity
- highest level of management
- near miss
- incident
- major incident
- large-scale cybersecurity incident
- incident handling
- cyber threat
- significant cyber threat
- vulnerability
- cybersecurity risk
- cloud computing service
- means 30
- article 26
- defined 24
- eu / 24
- point 20
- directive 20
- union 12
- cybersecurity 10
- incident 10
- management 6
- regulation 6
- incident’ 6
- treaty 6
- european 6
- body 4
- which 4
- entity 4
- significant 4
- level 4
- definitions 4
- risk 4
- functioning 4
- cyber_threat’ 4
- cyber_threat 4
- point 4
- responsibility 2
- areas 2
- near_miss’ 2
- respective 2
- near_miss 2
- compliance 2
- ‘major 2
- levels 2
- risk’ 2
- capacity 2
- causes 2
- least 2
- vulnerability’ 2
- ‘significant 2
- handling 2
- handling’ 2
- large-scale 2
- ‘large-scale 2
- union_entities 2
- impact 2
- disruption 2
- cloud_computing_service’ 2
- formal 2
- respond 2
- vulnerability 2
Article 3
Definitions
For the purposes of this Regulation, the following definitions apply:
(1) | ‘ Union_entities’ means the Union institutions, bodies, offices and agencies set up by or pursuant to the Treaty on European Union, the Treaty on the Functioning of European Union (TFEU) or the Treaty establishing the European Atomic Energy Community; |
(2) | ‘ network_and_information_system’ means a network_and_information_system as defined in Article 6, point (1), of Directive (EU) 2022/2555; |
(3) | ‘security of network_and_information_systems’ means security of network_and_information_systems as defined in Article 6, point (2), of Directive (EU) 2022/2555; |
(4) | ‘ cybersecurity’ means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; |
(5) | ‘ highest_level_of_management’ means a manager, management body or coordination and oversight body that is responsible for the functioning of a Union entity, at the most senior administrative level, with a mandate to adopt or authorise decisions in line with the high-level governance arrangements of that Union entity, without prejudice to the formal responsibilities of other levels of management for compliance and cybersecurity risk management in their respective areas of responsibility; |
(6) | ‘ near_miss’ means a near_miss as defined in Article 6, point (5), of Directive (EU) 2022/2555; |
(7) | ‘ incident’ means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; |
(8) | ‘major incident’ means an incident which causes a level of disruption that exceeds a Union entity’s and CERT-EU’s capacity to respond to it or which has a significant impact on at least two Union_entities; |
(9) | ‘large-scale cybersecurity incident’ means a large-scale cybersecurity incident as defined in Article 6, point (7), of Directive (EU) 2022/2555; |
(10) | ‘ incident handling’ means incident handling as defined in Article 6, point (8), of Directive (EU) 2022/2555; |
(11) | ‘ cyber_threat’ means a cyber_threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; |
(12) | ‘significant cyber_threat’ means a significant cyber_threat as defined in Article 6, point (11), of Directive (EU) 2022/2555; |
(13) | ‘ vulnerability’ means a vulnerability as defined in Article 6, point (15), of Directive (EU) 2022/2555; |
(14) | ‘ cybersecurity risk’ means a risk as defined in Article 6, point (9), of Directive (EU) 2022/2555; |
(15) | ‘ cloud_computing_service’ means a cloud_computing_service as defined in Article 6, point (30), of Directive (EU) 2022/2555. |
Article 3
Definitions
For the purposes of this Regulation, the following definitions apply:
(1) | ‘ Union_entities’ means the Union institutions, bodies, offices and agencies set up by or pursuant to the Treaty on European Union, the Treaty on the Functioning of European Union (TFEU) or the Treaty establishing the European Atomic Energy Community; |
(2) | ‘ network_and_information_system’ means a network_and_information_system as defined in Article 6, point (1), of Directive (EU) 2022/2555; |
(3) | ‘security of network_and_information_systems’ means security of network_and_information_systems as defined in Article 6, point (2), of Directive (EU) 2022/2555; |
(4) | ‘ cybersecurity’ means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; |
(5) | ‘ highest_level_of_management’ means a manager, management body or coordination and oversight body that is responsible for the functioning of a Union entity, at the most senior administrative level, with a mandate to adopt or authorise decisions in line with the high-level governance arrangements of that Union entity, without prejudice to the formal responsibilities of other levels of management for compliance and cybersecurity risk management in their respective areas of responsibility; |
(6) | ‘ near_miss’ means a near_miss as defined in Article 6, point (5), of Directive (EU) 2022/2555; |
(7) | ‘ incident’ means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; |
(8) | ‘major incident’ means an incident which causes a level of disruption that exceeds a Union entity’s and CERT-EU’s capacity to respond to it or which has a significant impact on at least two Union_entities; |
(9) | ‘large-scale cybersecurity incident’ means a large-scale cybersecurity incident as defined in Article 6, point (7), of Directive (EU) 2022/2555; |
(10) | ‘ incident handling’ means incident handling as defined in Article 6, point (8), of Directive (EU) 2022/2555; |
(11) | ‘ cyber_threat’ means a cyber_threat as defined in Article 2, point (8), of Regulation (EU) 2019/881; |
(12) | ‘significant cyber_threat’ means a significant cyber_threat as defined in Article 6, point (11), of Directive (EU) 2022/2555; |
(13) | ‘ vulnerability’ means a vulnerability as defined in Article 6, point (15), of Directive (EU) 2022/2555; |
(14) | ‘ cybersecurity risk’ means a risk as defined in Article 6, point (9), of Directive (EU) 2022/2555; |
(15) | ‘ cloud_computing_service’ means a cloud_computing_service as defined in Article 6, point (30), of Directive (EU) 2022/2555. |
whereas