My bookmarksSign up free

Commission Decision (EU, Euratom) 2017/46 of 10 January… CHAPTER 3 — SECURITY REQUIREMENTS AND OBLIGATIONS

Article 13–Article 15 · 3 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Implementation of this Decision

Article 13

1.   The adoption of the implementing rules on Article 6, and of the related standards and guidelines, will be subject to an empowerment decision by the Commission in favour of the Member of the Commission responsible for security matters. 2.   The adoption of all other implementing rules in relation to this decision, and of the related IT security standards and guidelines, will be subject to an empowerment decision by the Commission in favour of the Member of the Commission responsible for informatics. 3.   The ISSB shall approve the implementing rules, standards and guidelines mentioned under paragraphs 1 and 2 above prior to their adoption.

Obligation to comply

Article 14

1.   Compliance with the provisions outlined in the IT security policy and standards is mandatory. 2.   Non-compliance with the IT security policy and standards may trigger liability to disciplinary action in accordance with the Treaties, the Staff Regulations and the CEOS, to contractual sanctions and/or to legal action under national laws and regulations. 3.   The Directorate-General for Informatics shall be notified of any exceptions to the IT security policy. 4.   In the event the ISSB decides there is a persistent unacceptable risk to a CIS of the Commission, the Directorate-General for Informatics in cooperation with the system owner shall propose mitigating measures to the ISSB for approval. These measures may, amongst others, include reinforced monitoring and reporting, service limitations and disconnection. 5.   The ISSB shall impose the implementation of approved mitigating measures wherever necessary. The ISSB may also recommend to the Director-General of the Directorate-General for Human Resources and Security to open an administrative enquiry. The Directorate-General for Informatics shall report to the ISSB on every situation when mitigating measures are imposed. The processes related to these responsibilities and activities shall be further detailed in implementing rules

IT security incident handling

Article 15

1.   The Directorate-General for Informatics is responsible for providing the principal operational IT security incident response capability within the European Commission. 2.   The Directorate-General for Human Resources and Security as contributing stakeholders to the IT security incident response shall: (a) have the right to access summary information for all incident records and full records upon request; (b) participate in IT security incidents crisis management groups and IT security emergency procedures; (c) be in charge of relations with law enforcement and intelligence services; (d) perform forensic analysis regarding cyber-security in accordance with Article 11 of Decision (EU, Euratom) 2015/443; (e) decide on the need to launch a formal inquiry; (f) inform the Directorate-General for Informatics of any IT security incidents that may present a risk to other CISs. 3.   Regular communications shall take place between the Directorate-General for Informatics and the Directorate-General for Human Resources and Security to exchange information and coordinate the handling of security incidents, in particular any IT security incident that may require a formal inquiry. 4.   The incident coordination services of Computer Emergency Response Team for the European institutions, bodies and agencies (‘CERT-EU’) may be used to support the incident handling process when appropriate and for knowledge sharing with other EU institutions and agencies that may be affected. 5.   System owners involved in an IT security incident shall: (a) immediately notify their Head of Commission Departments, the Directorate-General for Informatics, the Directorate-General for Human Resources, the LISO and, where appropriate, the data owner of any major IT security incidents, in particular those involving a breach of data confidentiality; (b) cooperate and follow the instructions of the relevant Commission authorities on incident communication, response and remediation. 6.   Users shall report all actual or suspected IT security incidents to the relevant IT helpdesk in a timely manner. 7.   Data owners shall report all actual or suspected IT security incidents to the relevant IT security incident response team in a timely manner. 8.   The Directorate-General for Informatics, with support from the other contributing stakeholders, is responsible for handling any IT security incident detected in relation to Commission CISs that are not outsourced systems. 9.   The Directorate-General for Informatics shall inform affected Commission departments about IT security incidents, the relevant LISOs and, where appropriate, the CERT-EU on a need-to-know basis. 10.   The Directorate-General for Informatics shall regularly report on major IT security incidents affecting the Commission's CIS to the ISSB. 11.   The relevant LISO shall, upon request, have access to IT security incident records concerning the CIS of the Commission department. 12.   In case of a major IT security incident, the Directorate-General for Informatics shall be the contact point for the management of the crisis situations by coordinating the IT security incidents crisis management groups. 13.   In case of an emergency the Director-General of the Directorate-General for Informatics can decide to launch an IT security emergency procedure. The Directorate-General for Informatics shall develop emergency procedures to be approved by the ISSB. 14.   The Directorate-General for Informatics shall report on the execution of emergency procedures to the ISSB and the heads of Commission departments affected. The processes related to these responsibilities and activities shall be further detailed in implementing rules.

Back to Commission Decision (EU, Euratom) 2017/46 of 10 January… — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next