Document colectat · PNRR România, plan și decizii
Preliminary assessment of the fourth payment request of Romania
- Instituția sau publicația sursă
- PNRR România, plan și decizii
- Data preluării
- 26.09.2026 17:54
- Dimensiunea materialului
- 2.677,1 KB
Conținutul documentului colectat
Secțiuni și tabele
- - Reputation and filtering mechanisms for malicious traffic based on reputation and malicious
residence at the level of DNS services provided to beneficiaries
- - Sandbox analysis for the provided services.
The Financing Contract (Evidence No. 4), Article 1 (1), stipulates that the contractor must ensure that hubs provide ISP services to public interest institutions and entities at both central and local levels. By connecting the central and local level, a national Internet distribution network is created connecting the county hubs with the central hub. According to Law No. 92/1996 of 30 July 1996, published in Official Journal No. 169 of 30 July 1996 the Special Telecommunication Service (STS) is responsible for ensuring secure, reliable and continuous telecommunications services for public authorities. In addition, under Emergency Ordinance No. 104 of 27 June 2021, operators of essential services are required to implement appropriate technical and organisational measures to guarantee the resilience, redundancy, availability and continuity of network and information systems, meaning that they would need to rely on multiple suppliers for their networks. Moreover, the Justification Document No. 75209 of 4 February 2025 (Evidence No. 2) on the Implementation of Investment 14 (hereinafter referred to as “the justification document”) mention on page 2 that the internet access
services are carried out centrally through the Bucharest Hub. The Bucharest Hub is interconnected with several Tier I suppliers The implementation of the required security mechanisms is documented in the Entry-into-Operation Report (Evidence No. 3), which details the activation of the relevant services and the associated subscriptions covering Anti-DoS protection, Associated Computer Emergency Response Team (CERT) and (Security Operations Centres) SOC support, reputation-based filtering, and sandbox analysis. These software solutions are implemented centrally and the interconnection between the locations allows all hubs to benefit from these services. The On-site Inspection Report (Evidence No. 5) signed by the Ministry of Economy, Digitalisation, Entrepreneurship and Tourism verification committee certifies that all installed hardware and software components were operational and that the project had been completed in accordance with the contractual specifications and technical requirements mentioned in Financing Contract (Evidence No. 4) and the Entry-into-operation report (Evidence No. 3). Hence, the On-site Inspection Report
confirms that hubs provide ISP services to public interest institutions and that the security mechanisms, as described in the Entry-into-operation report, are completed and operational.
In addition to the above, the Justification Document (Evidence No. 2) further details the implementation of the investment in compliance with the target description, as follows: Anti-dos (denial-of-service) protection at multiples of 10Gbps are presented in a screenshot in figure 1 (page 4). Sandbox analysis for the services provided is presented in figure 14 (page 17-18). On pages 5 - 7 the CERT services implemented at national level are presented in figures 2, 3 and 4. On pages 12 - 13 the SIEM console is presented for detection and escalation of cyberthreats ensuring the Associated Security Operations Centres services (notification and escalation mechanisms for beneficiaries). For the reputation and filtering mechanisms for malicious traffic the screenshots on page 8 and 15 show the DNS filtering while on page 9 the filtering and blocking suspicious domains is shown.
The investment consists in updating and expanding the gigabit internet access network for the public administration, upgrading the cybersecurity capabilities and securing the ISP services (DNS, web, e-mail, hosting).
As stated above, the beneficiary, Special Telecommunication Services, is responsible for ensuring secure, reliable and continuous telecommunications services for public authorities and is required to implement appropriate technical and organisational measures to guarantee the resilience, redundancy, availability and continuity of network and information systems. With the installed CISCO and Juniper routers at STS locations, presented in the justification document (Evidence No. 2) and the Report No. 1 on entry into operation (Evidence No. 3) the existing network has been updated and expanded as also confirmed by the verification committee of the Ministry of Economy,
72
Valorile și formulările aparțin documentului citat. Data preluării nu reprezintă perioada datelor sau data publicării de către instituție.
Identificarea exactă a documentului colectat
Amprenta SHA-256 permite identificarea versiunii preluate.
6d92c2a23abea1ff81530993192d55903e8d84809fbd0b497db72a28a8fa2b84