Risk treatment measures
Article 4
1. In accordance with the policies referred to in Article 2, non-qualified trust service providers shall plan, document and implement risk treatment measures, and shall, in particular, carry out the following tasks: (a) identify and prioritise appropriate risk treatment measures; (b) select, approve and document the chosen risk treatment measures, including their security requirements and operational procedures, in a risk treatment plan, identify who is responsible for implementing the risk treatment measures and when they are to be implemented; (c) continuously monitor the implementation of the risk treatment measures. 2. The risk treatment plan set out in paragraph 1, point (b), shall provide reasons justifying the acceptance of residual risks in a comprehensible manner. 3. As part of the risk treatment measures referred to in paragraph 1, non-qualified trust service providers shall also: (a) verify, where applicable, the identity of the users of the trust service directly or by means of a third party and publish information on the identity verification methods used; (b) for the purposes of providing evidence in legal proceedings and of ensuring service continuity, record and securely retain for as long as necessary in accordance with Union or national laws, including after the activities of the non-qualified trust service provider have ceased, the following information: — all relevant information collected in the process of registration and onboarding of the trust service users, including, where applicable, the identity verification of the users, — authentication data assigned to the user of the trust service, where applicable, and — any change of the status of public key certificates or other cryptographic material used in the provision of the trust service. (c) ensure, where applicable, that authentication data assigned to the user of the trust service are unique. 4. When identifying, selecting, approving and prioritising appropriate risk treatment measures, non-qualified trust service providers shall take into account the following elements: (a) the results of the risk evaluation referred to in Article 3; (b) the effectiveness of the risk treatment measures; (c) conformity assessments; (d) significant incidents; (e) the cost of implementation in relation to the expected benefit; (f) the applicable appropriate asset classification; (g) the analysis of any business impact of the risks identified in accordance with Article 3. 5. The management bodies of non-qualified trust service providers shall approve the residual risks remaining after the implementation of the risk treatment measures as set out in the risk treatment plan. 6. Non-qualified trust service providers shall review, document and, where appropriate, update the risk evaluation results and the risk treatment plan at planned intervals, and at least annually, and when significant changes to the infrastructure, operations or risks, or significant incidents, occur. 7. Non-qualified trust service providers shall ensure the availability, integrity and confidentiality of the information referred to in paragraph 3, point (b).