What is the Norwegian Security Act?
The Norwegian Security Act is Norway's legislation on national security. Its purposes include protecting Norway's sovereignty, territorial integrity, democratic system of government, and other national security interests, as well as preventing, detecting, and countering activities that threaten national security. The Act entered into force on January 1, 2019.
The Act applies to state, county, and municipal authorities and to suppliers involved in security-classified procurements. Ministries may also decide that other organizations are fully or partly subject to the Act, including organizations that handle classified information or are of critical importance to fundamental national functions.
Organizations subject to the Act must carry out systematic preventive security work. This includes security management, regular risk assessments, and measures necessary to maintain an adequate level of security. Risk assessments must consider areas such as threats, vulnerabilities, consequences, and dependencies on other organizations.
The Act also regulates the protection of security-sensitive information, information systems, objects, and infrastructure, as well as personnel security, security-classified procurements, and ownership control.
Sicra and the Norwegian Security Act
For organizations subject to the Security Act, risk management, security management, and maintaining an adequate level of security are central requirements. This requires visibility into assets, threats, vulnerabilities, dependencies, and existing security controls.
Sicra provides security analyses based on NSM principles, assessing an organization's current security posture, risks, and areas for improvement. Sicra also supports organizations through security strategy and maturity assessments that can provide a structured foundation for further security work.
Services
Security analysis – NSM principles
Security maturity assessment
Security strategy
NIS2 and ISO27001
Related terms: NSM (Norwegian National Security Authority), Security classification, Security management, Security audits, Compliance, Governance, ISO 27001 (International Organization of Standardization), NIS2 (Network and Information Systems Directive 2), Cybersecurity, Supply chain