Information Assurance Authority
Article 3
The Information Assurance Authority shall be responsible for the following activities in relation to the protection of EUCI: (a) developing information assurance security policies and security guidelines and monitoring their effectiveness and pertinence; (b) safeguarding and administering technical information related to cryptographic products; (c) ensuring that information assurance measures comply with the Commission’s security and procurement policies as appropriate; (d) ensuring that cryptographic products are selected in compliance with policies governing their eligibility and selection; (e) consulting with system owners, system providers, security actors and representatives of users with respect to information assurance security policies and security guidelines.