The Directorate-General for Informatics
Article 7
In relation to the overall IT security of the Commission, the Directorate-General for Informatics has the following responsibilities. It shall: (1) develop IT security standards and guidelines, except as provided in Article 6, in close cooperation with the Directorate-General for Human Resources and Security, in order to assure consistency between the IT security policy and the Commission's information security policy, and propose them to the ISSB; (2) assess the IT security risk management methods, processes and outcomes of all Commission departments and report on this regularly to the ISSB; (3) propose a rolling IT security strategy for revision and approval by the ISSB and further adoption by the Corporate Management Board, and propose a programme, including the planning of projects and activities implementing the IT security strategy; (4) monitor the execution of the Commission's IT security strategy and report on this regularly to the ISSB; (5) monitor the IT security risks and IT security measures implemented in CISs and report on this regularly to the ISSB; (6) report regularly on the overall implementation and compliance with this decision to the ISSB; (7) after consulting with the Directorate-General for Human Resources and Security, request system owners to take specific IT security measures in order to mitigate IT security risks to Commission's CISs; (8) ensure that there is an adequate catalogue of the Directorate-General for Informatics IT security services available for the system owners and data owners to fulfil their responsibilities for IT security and to comply with the IT security policy and standards; (9) provide adequate documentation to system and data owners and consult with them, as appropriate, on the IT security measures implemented for their IT services in order to facilitate compliance with the IT security policy and support the system owners in IT risk management; (10) organise regular meetings of the LISOs network and supporting LISOs in carrying out their duties; (11) define the training needs and coordinate training programmes on IT security in cooperation with the Commission departments, and develop, implement and coordinate awareness-raising campaigns on IT security in close cooperation with the Directorate-General for Human Resources; (12) ensure that system owners, data owners and other roles with IT security responsibilities in Commission departments are made aware of the IT security policy; (13) inform the Directorate-General for Human Resources and Security on specific IT security threats, incidents and exceptions to the Commission's IT security policy notified by the system owners which could have a significant impact on security in the Commission; (14) in respect of its role as an internal IT service provider, deliver to the Commission a catalogue of shared IT services that provide defined levels of security. This shall be done by systematically assessing, managing and monitoring IT security risks to implement the security measures in order to reach the defined security level. The related processes and more detailed responsibilities shall be further defined in implementing rules.