Security
Article 19
1. eu-LISA shall take the necessary technical and organisational measures to ensure a high level of cybersecurity of the JITs collaboration platform and the information security of data within the JITs collaboration platform, in particular in order to ensure the confidentiality and integrity of operational and non-operational data stored in the centralised information system. 2. eu-LISA shall prevent unauthorised access to the JITs collaboration platform and shall ensure that persons authorised to access the JITs collaboration platform have access only to the data covered by their access authorisation. 3. For the purposes of paragraphs 1 and 2 of this Article, eu-LISA shall adopt a security plan and a business continuity and disaster recovery plan, in order to ensure that the centralised information system can be restored in the event of interruption. eu-LISA shall provide for a working arrangement with the computer emergency response team for the Union’s institutions, bodies and agencies established by the Arrangement between the European Parliament, the European Council, the Council of the European Union, the European Commission, the Court of Justice of the European Union, the European Central Bank, the European Court of Auditors, the European External Action Service, the European Economic and Social Committee, the European Committee of the Regions and the European Investment Bank on the organisation and operation of a computer emergency response team for the Union’s institutions, bodies and agencies (CERT-EU) ( 17 ) . When adopting that security plan, eu-LISA shall take into account the possible recommendations of the security experts present in the Advisory Group referred to in Article 12 of this Regulation. 4. eu-LISA shall monitor the effectiveness of all the measures described in this Article and shall take the necessary organisational measures related to self-monitoring and supervision to ensure compliance with this Regulation.