ANNEX IISupplementary provisions
ANNEX II PHYSICAL SECURITY I. INTRODUCTION 1. This Annex sets out provisions for implementing Article 8 of the decision. It lays down minimum requirements for the physical protection of the FIDUCIA office premises in which FIDUCIA information is handled and stored. 2. Physical security measures shall be designed to prevent unauthorised access to FIDUCIA information by: (a) ensuring that FIDUCIA information is properly handled and stored; (b) enabling a distinction to be drawn between persons with and without authorisation to have access to FIDUCIA information, in accordance with the need-to-know principle; (c) deterrence, by preventing and detecting unauthorised acts; and (d) preventing or delaying surreptitious or forced entry into the FIDUCIA office premises. 3. Physical security measures shall be chosen in the light of an appraisal of the threats posed to FIDUCIA information. These measures shall take into consideration the environment and structure of the FIDUCIA office premises. The security authority shall determine the degree of security to be attained for every one of the following physical measures: (a) a perimeter barrier defending the boundaries of the area to be protected; (b) an intrusion detection system connected to the security command post of the Court of Justice of the European Union; (c) an access control system exercised by electronic or electro-mechanical means, and operated by a member of the security staff; (d) security staff trained, supervised and holding authorisation to have access to FIDUCIA information; (e) closed-circuit video-surveillance system operated by security staff and connected to the intrusion detection and access control systems; (f) security lighting allowing effective surveillance directly, or indirectly through a video-surveillance system; (g) any other appropriate physical measures designed to deter unauthorised access or to detect it, or to prevent consultation or loss of, or damage to, FIDUCIA information. II. PREMISES IN WHICH FIDUCIA INFORMATION IS STORED AND CONSULTED Creation of physically protected premises for storage and consultation 4. Secured premises shall be created for the purpose of storage and consulting FIDUCIA information. FIDUCIA information may be stored and consulted only in FIDUCIA office premises which comply in all respects with the rules on the protection of EUCI applicable within the EU institutions. 5. Within those premises, FIDUCIA information shall be kept in security containers also complying in all respects with the rules on the protection of EUCI applicable within the EU institutions. 6. No communications system (telephone or other electronic device) may be brought into the FIDUCIA office premises. 7. The FIDUCIA office meeting room shall be protected against eavesdropping. Electronic security inspections of them shall be carried out at regular intervals. Access to storage and consultation premises 8. Access to the FIDUCIA office premises shall be controlled by an identification security door under video surveillance. 9. Persons who have been authorised to have access to FIDUCIA information and persons deemed to be so authorised may gain access to the FIDUCIA office premises in order to consult FIDUCIA information on the conditions laid down in Article 7(1) and (2) of this decision. 10. The security authority may in exceptional cases issue access authorisation to persons without FIDUCIA authorisation if it is essential that they should enter the FIDUCIA office premises, provided that access to those premises does not involve access to FIDUCIA information which is to remain protected from sight in security containers. Those persons may gain access only if they are accompanied, and continuously watched, by a member of the FIDUCIA office with authorisation for access to FIDUCIA information. 11. All access to FIDUCIA office premises shall be recorded in an access logbook. This logbook shall be kept at a work station in those premises. The communication and information system used for this purpose shall be compatible with the security requirements laid down in Article 10 of, and Annex IV to, this decision. 12. The protection measures governing the written use of FIDUCIA information shall apply in the case of oral use of that information. III. CONTROL OF KEYS AND COMBINATIONS USED TO PROTECT FIDUCIA INFORMATION 13. The security authority shall define procedures for managing keys and combination settings for the FIDUCIA office premises and security containers. Such procedures shall protect against unauthorised access. 14. Combination settings shall be committed to memory by the smallest possible number of persons needing to know them. Combination settings for security containers storing FIDUCIA information shall be changed; (a) on receipt of a new container; (b) when there is a change in personnel knowing the combination; (c) when compromise has occurred or is suspected; (d) when a lock has undergone maintenance or repair; (e) at least every 12 months. 15. Technical equipment intended for the physical protection of FIDUCIA information shall comply with the rules on the protection of EUCI applicable within the EU institutions. The security authority shall be responsible for the observance of these rules. 16. Technical equipment shall be periodically inspected and maintained at regular intervals. Maintenance shall take account of the inspection results in order that the best possible operation of the equipment may be guaranteed. 17. At every inspection the efficiency of the various security measures and of the security system as a whole is to be reappraised.