EU Network Code on Cybersecurity for the Electricity Sector
NCCS: Information Protection, Supply Chain and Audits

EU Network Code on Cybersecurity for the Electricity Sector NCCS-Art.48_49_50: Information protection and classification (NCCS Articles 48-50)

Article 48 establishes the INFORMATION PROTECTION regime for sensitive electricity-grid + cybersecurity information shared under NCCS. Information is classified at one of four levels: (1) PUBLIC; (2) RESTRICTED; (3) CONFIDENTIAL; (4) HIGHLY CONFIDENTIAL. Each level has specific handling + storage + transmission + access-control requirements. Article 49 establishes the access-rights regime: only persons with a documented 'need-to-know' + appropriate security clearance (where applicable) may access classified NCCS information. Article 50 sets the security-clearance requirements for personnel handling CONFIDENTIAL + HIGHLY CONFIDENTIAL information including TS or equivalent national clearance. Information-protection requirements apply to both transit + at-rest + cross-border sharing scenarios.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NCCS: Information Protection, Supply Chain and Audits

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.