My bookmarksSign up free

Commission Decision (EU) 2022/640 CHAPTER 3 — Commission departments

Article 8–Article 10 · 3 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Heads of Department

Article 8

1.   Each Head of Department shall appoint: (a) an LSO and one or more deputies where appropriate for the department or cabinet; (b) an RCO and one or more deputies where appropriate for each department that operates an EUCI registry; (c) a system owner for each CIS handling EUCI. 2.   The Head of Department shall request approval from the Director of the Security Directorate of the Directorate-General for Human Resources and Security prior to the appointment of LSOs, deputy LSOs, RCOs and deputy RCOs. 3.   The Head of Department shall identify all posts requiring clearance to access EUCI, in consultation with the LSO. Candidates for such posts shall be informed of the requirement for clearance during the recruitment process. 4.   The head of any department holding EUCI shall be responsible for activating emergency destruction and evacuation plans when necessary. The plans shall include an alternative for situations when the Head of Department cannot be contacted.

System owners of CIS handling EUCI

Article 9

1.   The system owner shall contact the Security Accreditation Authority as early as possible in a project to implement a CIS handling EUCI in order to determine the relevant security standards and requirements, and to begin the process of security accreditation. 2.   The system owner shall ensure that the security measures satisfy the requirements of the Security Accreditation Authority and that the CIS does not handle EUCI before it has been accredited. 3.   The system owner shall contact the Crypto Approval Authority for approval to use any encrypting technologies. System owners shall not operate encrypting technologies in production systems without prior approval. 4.   The system owner shall consult the department’s LISO for matters relating to the security of CISs. 5.   The system owner shall review the security measures that are applied to a system, including its security plan, at least annually. 6.   Where a security incident occurs in a CIS whereby it is indicated that the CIS can no longer adequately protect EUCI, the system owner shall inform the LSO and immediately contact the Security Accreditation Authority for advice on how to proceed. In this case, accreditation may be suspended and the system may be taken out of operation until suitable corrective action has been taken. 7.   The system owner shall give the Security Accreditation Authority full support at all times in the latter’s duties relating to the accreditation of the CIS.

Information Assurance Operational Authority

Article 10

The Information Assurance Operational Authority for each CIS shall: (a) establish security documentation in line with security policies and guidelines, in particular the security plan, the SecOPs related to the system and the cryptographic documentation within the CIS accreditation process; (b) participate in selecting and testing the system-specific technical security measures, devices and software, to supervise their implementation and to ensure that they are securely installed, configured and maintained in accordance with the relevant security documentation; (c) participate in selecting TEMPEST security measures and devices, if required in the security plan, and, in cooperation with the TEMPEST Authority, ensure that they are securely installed and maintained; (d) monitor implementation and application of the SecOPs related to the operation of the system; (e) manage and handle cryptographic products, in collaboration with the Crypto Distribution Authority, to ensure the proper custody of cryptographic materials and controlled items and, if required, ensure the generation of cryptographic variables; (f) conduct security analysis, reviews and tests, in particular to produce the relevant risk reports, as required by the Security Accreditation Authority; (g) provide CIS-specific Information Assurance training; (h) implement and operate CIS-specific security measures.

Back to Commission Decision (EU) 2022/640 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next