Article content
In briefShow moreShow lessThe Ministry of Justice and Public Security opened consultation on regulations under the Digital Security Act.
- The Ministry of Justice and Public Security opened consultation on regulations under the Digital Security Act.
- This was a consultation draft, not final duties.
- This was a Norwegian consultation proposal, not binding regulation at the publication date. The Act and final regulations still needed to enter into force before the duties applied.
What happened
The Ministry of Justice and Public Security opened consultation on regulations under the Digital Security Act. The proposal clarified scope and described management systems, risk assessments, organisational and technical measures, and incident reporting.
This was a consultation draft, not final duties. Its detail nevertheless gave affected organisations a basis for comparing their security processes with the expected framework.
Legal status in Norway
This was a Norwegian consultation proposal, not binding regulation at the publication date. The Act and final regulations still needed to enter into force before the duties applied.
What the sources clarify
The proposal described a management system showing how an organisation identified risks, selected measures and followed them over time. Incident notification needed defined thresholds, contacts and information that could be assembled quickly. Preparation was therefore more than writing a policy: critical services had to be connected to systems, data, suppliers and recovery needs. The consultation status also had to remain visible in the decision record. Controls could be tested against the draft, but contracts and duty statements needed a final check against the adopted regulation before being treated as binding.
A realistic exercise can begin with loss of a critical cloud service or compromise at a supplier. It should show who detects the incident, how severity is determined, which facts can be reported within the deadline and who decides recovery. The result can improve readiness now, while legal citations remain subject to a final check against the adopted regulations.
Practical implications
After the exercise, management should approve concrete improvements to monitoring, contact lists, log access and fallback procedures. Each action needs an owner and date, and the next test should prove closure. Before a final compliance statement, every legal reference and threshold must be checked against the adopted regulations.
Sources
Norwegian Government: “Høring: forslag til digitalsikkerhetsforskriften,” 11 September 2024.
Lovdata: “Lov om digital sikkerhet,” 20 December 2023.
For discussion
Where is the largest gap between documented control and actual practice?

