Commission Security Authority
1. The Director of the Security Directorate in the Directorate-General for Human Resources and Security shall be the Commission Security Authority (CSA) referred to in Article 7 of Decision (EU, Euratom) 2015/444.
2. The CSA shall perform its functions in the following areas as laid down in Decision (EU, Euratom) 2015/444, in accordance with Articles 3 to 7 of this Decision:
(a)
personnel security;
(b)
physical security;
(c)
management of EUCI;
(d)
accreditation of any communication and information system (CIS) handling EUCI;
(e)
industrial security; and
(f)
exchange of classified information.
3. The CSA shall provide mandatory training for the Local Security Officers (LSOs), deputy LSOs, Registry Control Officers (RCOs) and deputy RCOs on their responsibilities and duties.
Information Assurance Authority
The Information Assurance Authority shall be responsible for the following activities in relation to the protection of EUCI:
(a)
developing information assurance security policies and security guidelines and monitoring their effectiveness and pertinence;
(b)
safeguarding and administering technical information related to cryptographic products;
(c)
ensuring that information assurance measures comply with the Commission’s security and procurement policies as appropriate;
(d)
ensuring that cryptographic products are selected in compliance with policies governing their eligibility and selection;
(e)
consulting with system owners, system providers, security actors and representatives of users with respect to information assurance security policies and security guidelines.
Security Accreditation Authority
1. The CSA shall be responsible for accrediting Secured Areas that meet the requirements of Article 18 of Decision 2015/444 and CISs for handling EUCI.
2. Commission departments shall consult the Security Accreditation Authority in coordination with their LSO and their LISO as appropriate whenever a department intends to:
(a)
construct a Secured Area;
(b)
implement a CIS to handle EUCI;
(c)
install any other equipment for the handling of classified information, including connections to a third party CIS.
The SAA shall provide advice in respect of these activities during both the planning and the construction or development processes.
3. EUCI shall not be handled in a Secured Area or CIS before the Security Accreditation Authority has issued an accreditation at the appropriate level of EUCI.
4. The requirements for accrediting a Secured Area shall include:
(a)
approval of the plans for the Secured Area;
(b)
approval of any contracts for works performed by external contractors, taking into consideration the provisions on industrial security such as any requirements for security clearances of the contractors and their staff;
(c)
availability of all requisite declarations and certificates of conformity;
(d)
a physical inspection of the Secured Area to verify that the building materials and methods, access controls, security equipment and any other items comply with the requirements issued by the CSA;
(e)
validation of the countermeasures against electromagnetic radiation for any technically Secured Area;
(f)
approval of the security operating procedures (SecOPs) for the Secured Area.
5. The requirements for accrediting a CIS handling EUCI shall include:
(a)
creation of a System Accreditation Strategy;
(b)
validation of the CIS’s security plan, based on a risk management approach;
(c)
validation of the SecOPs for the CIS;
(d)
validation of all other required security documentation, as determined by the Security Accreditation Authority;
(e)
approval of any use of encrypting technologies;
(f)
validation of the countermeasures against electromagnetic radiation for a CIS handling information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above;
(g)
an inspection of the CIS to verify that the documented security measures are correctly implemented.
6. Following successful fulfilment of the requirements for accreditation, the Security Accreditation Authority shall issue a formal authorisation for the handling of EUCI in the Secured Area or CIS, for a stated maximum level of EUCI and for up to 5 years, depending on the levels of EUCI handled and the risks involved.
7. Upon notification of a security breach or a significant change in the design or security measures of a Secured Area or CIS, the Security Accreditation Authority shall review and, if necessary, may revoke the authorisation to handle EUCI until any identified issues are resolved.
TEMPEST Authority
1. TEMPEST security measures shall be implemented to protect CIS handling information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above, and may be implemented for information classified RESTREINT UE/EU RESTRICTED.
2. The TEMPEST Authority shall be responsible for approving the measures taken to protect against compromise of EUCI through unintentional electronic emanations.
3. Upon request from a system owner of a CIS handling EUCI, the TEMPEST Authority shall issue specifications for TEMPEST security measures as appropriate for the classification level of the information.
4. The TEMPEST Authority shall perform technical testing during the accreditation of Secured Areas and CIS for handling EUCI at the level of CONFIDENTIAL UE/EU CONFIDENTIAL or above and, upon successful testing, issue a TEMPEST certificate.
5. A TEMPEST certificate shall specify at least:
(a)
the date of the test;
(b)
a description of the TEMPEST security measures, with plans of the premises;
(c)
the expiry date of the certificate;
(d)
any changes that will invalidate the certification;
(e)
the signature of the TEMPEST Authority.
6. An LSO or a meeting organiser with the responsibility for organising a classified meeting, in coordination with the LSO, may request the TEMPEST Authority to test meeting rooms in order to ensure that they are technically secured.
Crypto Approval Authority
1. The Crypto Approval Authority shall be responsible for approving the use of encrypting technologies.
2. The Crypto Approval Authority shall issue guidance on the requirements for the use and approval of encrypting technologies.
3. The Crypto Approval Authority shall approve the use of encryption solutions on the basis of a request from the system owner. The approval shall be based upon a satisfactory evaluation of at least:
(a)
the security needs of the information to be protected;
(b)
an overview of the CIS involved in the solution;
(c)
an assessment of the inherent and residual risks;
(d)
a description of the proposed solution;
(e)
the SecOPs for the encryption solution.
4. The Crypto Approval Authority shall keep a register of approved encryption solutions.
Crypto Distribution Authority
1. The Crypto Distribution Authority shall be responsible for distributing cryptographic materials used for protecting EUCI (mainly encryption equipment, cryptographic keys, certificates and related authenticators) to the following:
(a)
users or departments inside the Commission for CIS that are administered by external parties;
(b)
users or organisations outside the Commission for CIS that are administered by the Commission.
2. The Crypto Distribution Authority may delegate the distribution of cryptographic materials for third parties to other departments in line with Article 17(3) of Decision 2015/443.
3. The Crypto Distribution Authority shall ensure that all cryptographic materials are sent via secure channels that protect against and show evidence of any tampering, in line with the security rules applicable for the level of classification of the EUCI that will be protected by those materials.
4. The Crypto Distribution Authority shall provide guidance to the LSO and, where relevant, the Local Informatics Security Officer of each Commission department that is involved in the production, distribution or use of the cryptographic materials.
5. The Crypto Distribution Authority shall ensure that suitable SecOPs are established for the distribution process.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.