$
./attiffet laws.sh
[OSI-style layers, L7 → L1, from the international framework to technical implementation]
Legislation in clear language.
Latvian and European Union cybersecurity package, which applies to information systems. Acti arranged in OSI model layers: from the top of the abstract frame to the technical implementation at the bottom.
L7
NIS 2
A common EU cybersecurity framework
Directive (EU) 2022/2555 - Security of network and information systems
Set a common framework for high level cyber security requirements in the European Union. Defines the relevant and relevant entities, the risk management measures applicable to them, management responsibilities and incident reporting obligations. The size of an undertaking is not the only criterion: some entities, including domain name systems and providers of electronic communications services, are subject to requirements regardless of size. This is a directive, so each Member State transposes it into national law.
Detailed: L4, Covers with L6 sectors, LV transposition: L2
L6
DORA, Part-IS, NCCS
Directly applicable EU financial, aviation and energy legislation
Sector specific EU regulations
These European Union laws are directly applicable in Latvia, not transposed by the National Cyber Security Law. The financial sector of DORA is lex specialis in relation to NIS 2 and determines risk management of information and communication technologies, incident reporting, stress testing and supervision of external service providers. Part-IS concerns aviation organisations regulated by the European Union Aviation Safety Agency. The NCCS determines cyber security of cross-border electricity flows.
Complements L7 sectors, NOT included in L2 NKDL (directly applicable EU acts)
L5
CRA
Security of digital products
Regulation (EU) 2024/2847 - Cyber Resilience Act
Defines cyber security requirements for products with digital features. The hardware and software must be secure by design principle and by default, with vulnerability management and security updates during the support period. The manufacturer must report on injuries actively used. The CE marking now confirms not only the physical but also cyber security of the product.
Parallel: L7 (products, not services)
L4
Reg. (EU) 2024/2690
Technical and methodological conditions for NIS 2
Commission Implementing Regulation (EU) 2024/2690
Specify the NIS 2 risk management measures and determine when an incident is considered significant. For digital infrastructure and digital service providers: domain name system services, top-level domain registers, cloud computing, data centres, content delivery networks, managed services and managed security services, online marketplaces, search engines, social network platforms and trust services. The technical requirements are based on international standards. The Regulation is directly applicable without transposition into national law.
Base: L7 (technical detail)
L3
VDAR (GDPR)
Protection of personal data
Regulation (EU) 2016/679 - General Data Protection Regulation (EU) 2016/679
Protects personal data. The processing of personal data requires a legal basis, the data subject must be informed and the data deleted upon request. A personal data breach must be reported to the supervisory authority, but also to the people themselves in case of high risk. This is not a step in the hierarchy of other layers, but a parallel axis: one incident can simultaneously create a cybersecurity and personal data reporting obligation, and two separate messages with different addressees and deadlines.
Coating with: L7 (incident reporting)
L2
NKDL
Acquisition of NIS 2 in Latvia
National Cybersecurity Law
Latvian law transposing the NIS 2 Directive. Defines essential and important services in Latvia, entity inventory, cyber security management obligations, incident reporting procedures, self-assessment reports, compliance audits and responsibility of entities. In addition to the NIS 2 minimum, domain name registration services, cyber security of data centres, centralised protection against service attack and a single national internet traffic exchange point are regulated separately.
Base: L7, Technical execution: L1
L1
MK 397
Minimum cyber security requirements
Cabinet of Ministers Regulations No. 397
Minimum technical and organisational cyber security requirements are established, which in practice fulfil the obligations laid down in the National Cybersecurity Law. The requirements shall cover cybersecurity managers, management documentation and policies, information and communication technology resources catalogue, cyber risk management plan, cyber incident management, access rights, network and log file management, backup copies, cyberhygiene and encryption. Individually regulated outsourcing, additional requirements for critical infrastructure and supervision of entities. The scope of the requirements depends on the security class of the information system.
Base: L2
// DISCLAIMER:
Clarifications are informative and no legal advice. In a specific case, you should consult the official legislation or the specialist.