Cybersecurity1 min readSample article
Chile’s cybersecurity framework law: what essential services must do now
Law 21.663 created a national cybersecurity agency and new duties for essential services. Here is what changes for energy, telecom, health and public bodies.
Trivick editorial team
Chile’s Framework Cybersecurity Law, Law 21.663, set up a national agency and a national CSIRT, and gave organisations that provide essential services clear duties to manage cyber risk and report incidents.
What it asks of essential services
- Manage cybersecurity risk continuously, with measures in proportion to the risk
- Report significant incidents to the national CSIRT quickly, and follow up as they develop
- For operators of vital importance: an information security management system, continuity plans and regular reviews
A practical first step
Map which of your services count as essential, and who is responsible for each. Most organisations already have part of the answer in their continuity planning; the law asks them to connect it to security.