Principles of security
Article 29
Article 33 of Regulation (EU) 2021/696 shall apply to the Programme.
Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗
Principles of security
Article 33 of Regulation (EU) 2021/696 shall apply to the Programme.
Governance of security
1. The Commission shall, within its field of competence and with the support of the Agency, ensure a high degree of security, in particular, with regard to: (a) the protection of infrastructure, both ground and space, and of the provision of services, particularly against physical or cyberattacks, including interference with data streams; (b) the control and management of technology transfers; (c) the development and preservation within the Union of the competences and know-how acquired; (d) the protection of sensitive non-classified information and classified information. 2. The Commission shall consult the Council and the Member States regarding the specification and design of any aspect of the EuroQCI infrastructure, in particular the QKD that relates to the protection of EUCI. The evaluation and approval of cryptographic products for the protection of EUCI shall be carried out while respecting the respective roles and fields of competence of the Council and the Member States. The security accreditation authority shall verify within the security accreditation process that only approved cryptographic products are used. 3. For the purposes of paragraph 1 of this Article, the Commission shall ensure that a risk and threat analysis is performed for the governmental infrastructure referred to in Article 5(2). On the basis of that analysis, it shall determine, by means of implementing acts, the general security requirements. In doing so, the Commission shall take account of the impact of those requirements on the smooth functioning of the governmental infrastructure, in particular in terms of cost, risk management and schedule, and shall ensure that the general level of security is not reduced, the functioning of the equipment is not undermined and the cybersecurity risks are taken into account. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 47(3). 4. Article 34(3) to (7) of Regulation (EU) 2021/696 shall apply to the Programme. For the purposes of this Regulation, the term ‘component’ in Article 34 of Regulation (EU) 2021/696 shall be read as ‘governmental infrastructure’, including governmental services, and all the references to Article 34(2) of Regulation (EU) 2021/696 shall be construed as references to paragraph 3 of this Article.
Security of the system and services deployed
Whenever the security of the Union or its Member States may be affected by the operation of the system or the provision of the governmental services, Decision (CFSP) 2021/698 shall apply.
Security accreditation authority
The Security Accreditation Board established within the Agency under Article 72(1), point (c), of Regulation (EU) 2021/696 shall be the security accreditation authority for the governmental infrastructure and related governmental services of the Programme.
General principles of security accreditation
Security accreditation activities related to the Programme shall be conducted in accordance with the principles laid down in Article 37, points (a) to (j), of Regulation (EU) 2021/696. For the purposes of this Regulation, the term ‘component’ in Article 37 of Regulation (EU) 2021/696 shall be read as ‘governmental infrastructure’ and all the references to Article 34(2) of Regulation (EU) 2021/696 shall be construed as references to Article 27(2) of this Regulation.
Tasks and composition of the Security Accreditation Board
1. Article 38, with the exception of paragraph 2, points (c) to (f), and of paragraph 3, point (b), and Article 39 of Regulation (EU) 2021/696 shall apply to the Programme. 2. The Security Accreditation Board shall have the following tasks, in addition to those referred to in paragraph 1: (a) examining and, except as regards documents which the Commission is to adopt under Article 30(3), approving all documentation relating to security accreditation; (b) advising, within its field of competence, the Commission on the production of draft texts for the acts referred to in Article 30(3), including for the establishment of security operating procedures, and providing a statement with its concluding position; (c) examining and approving the security risk assessment drawn up in accordance with the monitoring process referred to in Article 37, point (h), of Regulation (EU) 2021/696 and the risk and threat analysis drawn up in accordance with Article 30(3) of this Regulation, and cooperating with the Commission to establish risk mitigation measures. 3. In addition to paragraph 1 and on an exceptional basis, only representatives of the contractors involved in governmental infrastructure and services may be invited to attend the meetings of the Security Accreditation Board, as observers, for matters directly relating to those contractors. The arrangements and conditions for their attendance shall be laid down in the rules of procedure of the Security Accreditation Board.
Voting rules of the Security Accreditation Board
Article 40 of Regulation (EU) 2021/696 shall apply with regard to the voting rules of the Security Accreditation Board.
Communication and impact of decisions of the Security Accreditation Board
1. Article 41(1) to (4) of Regulation (EU) 2021/696 shall apply to the decisions of the Security Accreditation Board. For the purposes of this Regulation, the term ‘component’ in Article 41 of Regulation (EU) 2021/696 shall be read as ‘governmental infrastructure’. 2. The timetable for the work of the Security Accreditation Board shall not hamper the timetable of activities provided in the work programmes referred to in Article 41(1).
Role of the Member States in security accreditation
Article 42 of Regulation (EU) 2021/696 shall apply to the Programme.
Protection of classified information
1. Article 43 of Regulation (EU) 2021/696 shall apply to classified information related to the Programme. 2. Subject to the provisions of the agreement on the security and exchange of classified information between the Union institutions and ESA, ESA may generate EUCI with regard to the tasks entrusted to it pursuant to Article 28(1) and (2).
Articles on this page are reproduced verbatim from official open data. See the attribution line.
Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.