misp-compliance
misp-compliance copied to clipboard
Legal, procedural and policies document templates for operating MISP and information sharing communities
Add additional DORA provisions on information sharing and links with NIS 2.
Following feedback at CNW, a definition of CSIRT must be clarified to ensure that any organisation having a CSIRT team/security are falling into the legitimate interest (recital 49).
A document mentioned during a panel at CPDP: https://edps.europa.eu/sites/edp/files/publication/17-06-01_necessity_toolkit_final_en_0.pdf Aims to help assessing the necessity of measures that limit the fundamental right to the protection of personal data.
"Does the GDPR allow..." I'd be wary of using the 6(1)(e)/6(1)(f) distinction, as there's a risk of creating barriers to sharing between CSIRTs using different legal bases. This came up...