My bookmarksSign up free

Commission Decision (EU, Euratom) 2018/559 of 6 April 2018… CHAPTER 3 — IT SECURITY PROCESSES

Article 5–Article 8 · 4 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Encrypting technologies

Article 5

1.   The use of encrypting technologies for the protection of EU classified information (EUCI) shall comply with Decision (EU, Euratom) 2015/444. 2.   The decisions on the use of encrypting technologies for the protection of non-EUCI data shall be taken by the system owner of each CIS, taking into account both the risks that are intended to be mitigated through encryption and the risks that it introduces. 3.   Prior approval from the CAA is required for all uses of encrypting technologies, unless the encryption is used only to protect the confidentiality of non-EUCI data in transit and uses standard network communications protocols. 4.   With the exception noted in paragraph 3 of this Article, Commission departments shall ensure that back-ups of any decryption keys are stored in key escrow for the purpose of recovering stored data in the event that the decryption key is not available. The recovery of encrypted data using back-ups of decryption keys shall be carried out only when authorised in line with the standard defined by the CAA. 5.   Requests for approval for the use of encrypting technologies shall be formally documented and shall include details of the CIS and data to be protected, the technologies to be used and the related security operating procedures. These requests for approval shall be signed by the system owner. 6.   Requests for approval for the use of encrypting technologies shall be evaluated by the CAA in line with the published standards and requirements.

IT security inspections

Article 6

1.   The Directorate-General for Human Resources and Security shall undertake IT security inspections in order to verify whether IT security measures comply with the Commission's IT security policies and to check the integrity of these control measures. 2.   The Directorate-General for Human Resources and Security may perform an IT security inspection: (a) on its own initiative; (b) on request from the Information Security Steering Board (ISSB); (c) on a request received from a system owner; (d) further to a security incident; or (e) further to the identification of a high risk to a particular system. 3.   Data owners may request an IT security inspection before storing their information in a CIS. 4.   The results of an inspection shall be documented in a formal report to the system owner, and copied to the LISO, that includes findings and recommendations for improving the CIS's compliance with the IT security policy. The Directorate-General for Human Resources and Security shall report significant issues and recommendations to the ISSB. 5.   The Directorate-General for Human Resources and Security shall monitor the implementation of the recommendations. 6.   Where appropriate, IT security inspections shall include the inspection of services, premises and equipment provided to the system owner, including both internal and external service providers.

Access from external networks

Article 7

1.   The Directorate-General for Human Resources and Security shall lay down the rules in a standard on authorising access between Commission CISs and external networks. 2.   The rules shall distinguish different types of external network connections and lay down appropriate security rules for each type of connection, including whether a prior authorisation for the connection is required from the relevant authority as noted in paragraph 4 of this Article. 3.   If required, authorisation shall be granted on the basis of a formal request and approval process. The approval shall be valid for a specified duration and shall be obtained before the connection is activated. 4.   The Directorate-General for Human Resources and Security shall have the overall responsibility for authorising requests, but may delegate the responsibility for authorising some types of connection at its own discretion in line with Article 17(3) of Decision (EU, Euratom) 2015/443 and subject to the conditions laid down under (8). 5.   The authorising entity may impose additional security requirements as a prerequisite for approval, in order to protect the Commission's CIS and networks from the risks of unauthorised access or other security breaches. 6.   The Directorate-General for Informatics is the standard provider of network services for the Commission. Any other Commission department operating a network that is not provided by the Directorate-General for Informatics shall first obtain the agreement of the ISSB. The Commission department shall document the business justification for the request and demonstrate that the network controls are sufficient to meet the requirements for controlling incoming and outgoing flows of information. 7.   The system owner of a CIS shall determine the security requirements for external access to that CIS and shall ensure the implementation of appropriate measures to protect its security, with the support of the LISO. 8.   The security measures implemented for external network connections shall be based on the principles of need-to-know and least privilege, which ensure that individuals only receive the information and access rights that they need to perform their official duties for the Commission. 9.   All external network connections shall be filtered and monitored to detect potential security breaches. 10.   Where connections are established to allow the outsourcing of a CIS, the authorisation shall be conditional on the successful completion of the procedure described in Article 8.

Outsourcing of CISs

Article 8

1.   For the purposes of this Decision, a CIS is considered to be outsourced when it is provided on the basis of a contract with a third party contractor, under which the CIS is housed on non-Commission premises. This includes the outsourcing of individual or multiple CISs or other IT services, data centres on non-Commission premises, and the handling of Commission data sets by external services. 2.   The outsourcing of a CIS shall take into account the sensitivity or classification of the information handled as follows: (a) CISs handling EUCI shall be accredited in accordance with Decision (EU, Euratom) 2015/444, and the Commission Security Accreditation Authority (SAA) shall be consulted in advance. Systems handling EUCI shall not be outsourced. (b) The system owner of a CIS handling non-EUCI information shall implement proportionate measures to address the security needs in line with the relevant legal obligations or the sensitivity of the information, taking into account the risks of outsourcing. The Directorate-General for Human Resources and Security may impose additional requirements. (c) Outsourced development projects shall take into account the sensitivity of the developed code and any test data used during development. 3.   The following principles shall apply to outsourced CIS in addition to those laid down in Article 3 of Decision (EU, Euratom) 2017/46: (a) outsourcing arrangements shall be designed to avoid dependency on specific suppliers; (b) outsourcing security arrangements shall minimise the possibilities for third party staff to access or modify Commission information; (c) third party staff that have access to an outsourced CIS shall provide confidentiality agreements; (d) the outsourcing of a CIS shall be indicated in the inventory of CISs. 4.   The system owner with the participation of the data owner shall: (a) assess and document the risks relating to outsourcing; (b) lay down relevant security requirements; (c) consult with the system owners of all other connected CISs to ensure that their security requirements are included; (d) ensure that appropriate security requirements and rights are included in the outsourcing contract; (e) fulfil any other requirements laid down in the detailed procedure as noted in paragraph 8 of this Article. These actions shall be completed before the contract or other agreement is signed for the outsourcing of one or more CISs. 5.   System owners shall manage the risks relating to outsourcing during the lifetime of the CIS in order to meet the defined security requirements. 6.   System owners shall ensure that third party contractors are obliged to immediately notify the Commission of all IT security incidents affecting an outsourced Commission CIS. 7.   The system owner is responsible for ensuring the compliance of the CIS, the outsourcing contract and the security arrangements with the Commission's rules on information security and IT security. 8.   The Directorate-General for Human Resources and Security shall lay down the detailed standard related to the responsibilities and activities set out in points (1) to (7) in accordance with Article 10 below.

Back to Commission Decision (EU, Euratom) 2018/559 of 6 April 2018… — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next