Security of common services and national components
Article 28
1. The Commission shall ensure the security of the common services referred to in Article 4(1) and the integration elements and interfaces referred to in Article 2, point (h), for which it is responsible. 2. Member States shall ensure the security of the national components of the OOTS and the integration elements and interfaces referred to in Article 2, point (h), for which they are responsible. 3. For the purposes referred to in paragraphs 1 and 2, Member States and the Commission shall, at least, and each for the component for which they are responsible, take the necessary measures to: (a) prevent any unauthorised person from having access to components for which they are responsible; (b) prevent the entry of data and any consultation, modification or deletion of data by unauthorised persons; (c) detect any of the activities referred to in points (a) and (b); and (d) ensure logging of security events in line with recognised international security standards for information technology. 4. Member States shall ensure, in particular: (a) that the connections they operate into and out of the eDelivery Access Points and all internal communication between different national authorities fulfil at least the same level of security requirements as the eDelivery electronic delivery service to protect the security and confidentiality of the exchange and the integrity of evidence exchanged through the OOTS; (b) the non-repudiation of origin of the evidence request transmitted from the access point of the evidence requester, and of the evidence response exchanged or error message transmitted from the access point of the evidence provider. 5. In accordance with paragraph 4, the Member State of the evidence provider in any given exchange of evidence shall be responsible for the quality, confidentiality, integrity and availability of the requested evidence until it reaches the eDelivery Access Point of the evidence requester or an intermediary platform, where applicable. The Member State of the evidence requester in any given exchange of evidence shall be responsible for the confidentiality and integrity of the requested evidence from the moment it reaches its eDelivery Access Point. 6. Member States and the Commission shall ensure the confidentiality, integrity and availability of the logs referred to in Article 17(1), (2) and (3) through appropriate and proportionate security measures, each for the logs that they have recorded.