TEMPEST Authority
Article 5
1. TEMPEST security measures shall be implemented to protect CIS handling information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above, and may be implemented for information classified RESTREINT UE/EU RESTRICTED. 2. The TEMPEST Authority shall be responsible for approving the measures taken to protect against compromise of EUCI through unintentional electronic emanations. 3. Upon request from a system owner of a CIS handling EUCI, the TEMPEST Authority shall issue specifications for TEMPEST security measures as appropriate for the classification level of the information. 4. The TEMPEST Authority shall perform technical testing during the accreditation of Secured Areas and CIS for handling EUCI at the level of CONFIDENTIAL UE/EU CONFIDENTIAL or above and, upon successful testing, issue a TEMPEST certificate. 5. A TEMPEST certificate shall specify at least: (a) the date of the test; (b) a description of the TEMPEST security measures, with plans of the premises; (c) the expiry date of the certificate; (d) any changes that will invalidate the certification; (e) the signature of the TEMPEST Authority. 6. An LSO or a meeting organiser with the responsibility for organising a classified meeting, in coordination with the LSO, may request the TEMPEST Authority to test meeting rooms in order to ensure that they are technically secured.