“Towards a common declaration form for ACPR/AMF + ANSSI + CNIL? [..] Companies are waiting for it.”
The deputy Philippe Latombe recently addressed, in these words, the director-general of ANSSI, Vincent Strubel.
He replied that he is wary of single gateways or forms, which “can quickly serve as a cover-up.” If European law creates conflicting injunctions, it must be harmonized rather than relying on a “administrative plumbing.”
A common DORA / NIS 2 form is nevertheless planned. According to Vincent Strubel, two frameworks are sufficiently compatible. Thus, a single document would not harm the “speed required to reach the ‘cyber firefighters’ before it’s too late.”
The alignment with the GDPR is more delicate, explains the ANSSI DG. Whether it concerns deadlines, impact assessments, or the notification cadence, the requirements are different enough that a “brutal fusion” of gateways and forms “puts companies in an impossible situation, forcing them to satisfy in one notification several contradictory injunctions.”
The cyber offensive, recently endorsed by the State
Backdrop to this exchange: an agreement between ANSSI, the Bank of France and the ACPR (the institution integrated into the latter). It provides for a strengthening of their information security cooperation around four axes… including “advanced intrusion tests.”
This orientation echoes the recent remarks of Sébastien Lecornu. During a visit to ANTS, hacked in mid-April, the Prime Minister said he had urged the state services to test their vulnerabilities. On the same occasion, he had also mentioned a project to merge the DINUM and the DITP.
ANSSI and ACPR had already signed a similar agreement in 2018. They had not detailed the axes, simply explaining they intended a “regular exchange of information.”
To consult in addition :
Regulators order banks to brace for AI
NIS 2 on hold: CISOs wait, the market too
Bercy creates a Directorate of AI and Digital
Should the AI Act be the affair of the DPOs?
Digital sovereignty: and if we refocus the concept?