The Network and Information System Security Act — NISG (see publications) only concerns defined sectors defined in §2 of the Act:
Energy, transport, banking, financial market infrastructures, healthcare, drinking water supply, digital infrastructures as operators of essential services. In addition, providers of digital services, such as online marketplaces, online search engines and cloud computing services, as well as public administration bodies.
Whether a company must meet the requirements of the Network and Information Systems Security Act as an operator of essential services will be determined by the Federal Chancellor and sent to the affected companies by notice, probably starting in Q2 2019. However, due to the new composition of the Austrian Federal Government, we assume a later delivery.
As a provider of digital services, you have to take action yourself and check whether the requirements of the NISG have to be met.
There is no ISO 27001 certification obligation for operators of essential services in Austria, but there is an obligation in the specified areas of
- Governance and risk managemen
- Dealing with suppliers and third parties
- Security architecture
- System administration
- Identity and access management
- System maintenance and operations
- Physical security
- Incident detection
- Incident management
- Business continuity
- Crisis management
Implement appropriate measures and provide evidence of operational effectiveness through regular audits within a 3‑year period.

In our next article of the ISO 27001 series, we will highlight the importance of implementing an ISMS system according to ISO 27001 for suppliers of large customers and what advantages this has in supplier management.