Glossary · Duties and incidents

Network and information systems

Definition

Network and information systems are defined in regulation 1(2) of the NIS Regulations 2018 as electronic communications networks, devices that automatically process digital data, and the data those networks and devices store, process, retrieve or transmit. The Cyber Security and Resilience Bill keeps this definition for Part 2 and uses a similar one for Part 3.

What is the exact definition?

Regulation 1(2) of the NIS Regulations 2018 defines a network and information system as:

  • an electronic communications network within the meaning of the Communications Act 2003;
  • any device or group of interconnected or related devices, one or more of which performs automatic processing of digital data under a program;
  • digital data stored, processed, retrieved or transmitted by those networks or devices for the purposes of their operation, use, protection and maintenance.

How broad is it in practice?

Very broad. It covers corporate IT, cloud workloads, operational technology such as industrial control systems and building management systems, and the data those systems use to run. That breadth is why an operator of essential services must consider OT as well as IT when meeting its security duties.

The duties are not about all systems an organisation owns, though. Each duty is tied to the systems relied on to provide the regulated service, such as the essential service, the relevant digital service or the managed service.

Does Part 3 use the same definition?

Nearly. Clause 24(1) defines a network and information system for Part 3 as an electronic communications network within section 32(1) of the Communications Act 2003, or apparatus programmed to process digital data, and clause 24(2) extends that to data used for operating, using, protecting or maintaining the network or apparatus. The wording differs from the 2018 text, but the scope is similar. Part 3 powers apply to essential activities specified later in regulations.

Where it appears in the Bill

  • NIS reg 1(2)The definition used for Part 2 duties; not amended by the Bill.
  • Cl.15(2)Incident definition refers to operation or security of these systems.
  • Cl.9(5), new reg 1(3B)Managed service defined by access to a customer's systems.
  • Cl.24(1)-(2)Separate Part 3 definition.

References are to HL Bill 32 as brought from the Commons. Read the Bill.

Frequently asked questions

Does the definition include operational technology?

Yes. Any device or group of devices that performs automatic processing of digital data under a program falls within the definition, which covers industrial control systems, SCADA, building management and similar operational technology. Where OT is relied on to provide a regulated service, it is within the scope of the security duties and incident reporting.

Does the Bill change the definition?

No, not for the NIS Regulations regime in Part 2. The Cyber Security and Resilience Bill keeps the 2018 definition in regulation 1(2) but widens the definition of incident that uses it. Part 3 of the Bill has its own, similarly worded definition in clause 24 for the new essential activities powers.

Is data itself a network and information system?

Partly. The definition includes digital data stored, processed, retrieved or transmitted by networks and devices, but only for the purposes of their operation, use, protection and maintenance. So configuration data, credentials and logs are within it. Business data such as customer records is protected indirectly, because incidents compromising its confidentiality or integrity are a reportability factor.

Related guidance

Official sources

More in Duties and incidents

Full glossary