My bookmarksSign up free

Commission Decision (EU, Euratom) 2017/46 of 10 January… Article 9

Commission Decision (EU, Euratom) 2017/46 of 10 January… Article 9

System owners

Article 9

1.   The system owner is responsible for the IT security of the CIS, and reports to the Head of the Commission department. 2.   In relation to IT security, the system owner shall: (a) ensure the compliance of the CIS with the IT security policy; (b) ensure that the CIS is accurately recorded in the relevant inventory; (c) assess IT security risks and determine the IT security needs for each CIS, in collaboration with the data owners and in consultation with the Directorate-General for Informatics; (d) prepare a security plan, including, where appropriate, details of the assessed risks and any additional security measures required; (e) implement appropriate IT security measures, proportionate to the IT security risks identified and follow recommendations endorsed by the ISSB; (f) identify any dependencies on other CISs or shared IT services and implement security measures as appropriate based on the security levels proposed by those CISs or shared IT services; (g) manage and monitor IT security risks; (h) report regularly to the head of the Commission department on the IT security risk profile of their CIS and report to the Directorate-General for Informatics on the related risks, risk management activities and security measures taken; (i) consult the LISO of the relevant Commission department(s) on aspects of IT Security; (j) issue instructions for users on the use of the CIS and associated data as well as on the responsibilities of users related to CIS; (k) request authorisation from the Directorate-General for Human Resources and Security, acting as the Crypto Authority, for any CIS that uses encrypting technology. (l) consult the Commission Security Authority in advance concerning any system processing EU classified information; (m) ensure that back-ups of any decryption keys are stored in an escrow account. The recovery of encrypted data shall be carried out only when authorised in accordance with the framework defined by the Directorate-General for Human Resources and Security; (n) respect any instructions from the relevant Data Controller(s) concerning the protection of personal data and the application of data protection rules on security of the processing; (o) notify the Directorate-General for Informatics of any exceptions to the Commission's IT security policy including relevant justifications; (p) report any unresolvable disagreements between the data owner and the system owner to the head of the Commission department, communicate IT security incidents to the relevant stakeholders in a timely manner as appropriate according to their severity as laid down in Article 15; (q) for outsourced systems, ensure that appropriate IT security provisions are included in the outsourcing contracts and that IT security incidents occurring in the outsourced CIS are reported in accordance with Article 15; (r) for CIS providing shared IT services, ensure that a defined security level is provided, clearly documented and security measures are implemented for that CIS in order to reach the defined security level. 3.   System owners may formally delegate some or all of their IT security tasks but they remain responsible for the IT security of their CIS The processes related to these responsibilities and activities shall be further detailed in implementing rules.

Read the full instrument → · Read this in context: CHAPTER 2 — ORGANISATION AND RESPONSIBILITIES →

Other provisions in CHAPTER 2 — ORGANISATION AND RESPONSIBILITIES

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 9 of Commission Decision (EU, Euratom) 2017/46 of 10 January… (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next