My bookmarksSign up free

Commission Decision (EU) 2022/640 Article 10

Commission Decision (EU) 2022/640 Article 10

Information Assurance Operational Authority

Article 10

The Information Assurance Operational Authority for each CIS shall: (a) establish security documentation in line with security policies and guidelines, in particular the security plan, the SecOPs related to the system and the cryptographic documentation within the CIS accreditation process; (b) participate in selecting and testing the system-specific technical security measures, devices and software, to supervise their implementation and to ensure that they are securely installed, configured and maintained in accordance with the relevant security documentation; (c) participate in selecting TEMPEST security measures and devices, if required in the security plan, and, in cooperation with the TEMPEST Authority, ensure that they are securely installed and maintained; (d) monitor implementation and application of the SecOPs related to the operation of the system; (e) manage and handle cryptographic products, in collaboration with the Crypto Distribution Authority, to ensure the proper custody of cryptographic materials and controlled items and, if required, ensure the generation of cryptographic variables; (f) conduct security analysis, reviews and tests, in particular to produce the relevant risk reports, as required by the Security Accreditation Authority; (g) provide CIS-specific Information Assurance training; (h) implement and operate CIS-specific security measures.

Read the full instrument → · Read this in context: CHAPTER 3 — Commission departments →

Other provisions in CHAPTER 3 — Commission departments

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 10 of Commission Decision (EU) 2022/640 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next