Lifecycle
- Effective
- Last change
Country / jurisdiction: Morocco · Year: 2020 · Status: In force · Level: National · Type: Voluntary
The law applies to "infrastructures d’importance vitale" which would cover the energy sector. They must ensure their information systems comply with directives from the national authority, implement security policies, manage risks, audit their systems, classify information assets, designate a security officer, establish incident detection mechanisms, report security incidents, prepare continuity plans, adhere to specific rules for outsourcing sensitive systems (including national hosting and Moroccan law contracts), homologate sensitive systems, undergo security audits, implement audit recommendations, and use security-enhancing services and qualified cybersecurity providers as defined by the national authority.
Official source: https://www.dgssi.gov.ma/sites/default/files/legislative/brochure/2023-03/loi%2005-20.pdf
Source
https://www.iea.org/policies/26612Canonical document at the regulator. Always cite this URL — not the Vantage detail page — in compliance evidence.