login
login
Image header Agence Europe
Europe Daily Bulletin No. 13166
Contents Publication in full By article 15 / 34
SECTORAL POLICIES / Digital

Discussions continue on classified information and timetable regarding cybersecurity in EU institutions, agencies and bodies

On 18 April, the Secretariat-General of the Council of the EU sent delegations a document, of which EUROPE has obtained a copy, in which it gives an update on the position of the Council of the EU and the European Parliament in the context of the ongoing inter-institutional negotiations (‘trilogues’) regarding a common high level of cybersecurity in EU institutions, agencies and bodies (see EUROPE 13138/10).

Agreement has been reached on part of the text, but discussions continue on several aspects, including the role of the Computer Emergency Response Team (CERT-EU) and the timetables for reviews and evaluations.

For example, the European Parliament has yet to take a decision on the EU Council’s proposal that the future regulation should not apply – with the exception of Article 12(7) – to networks and information systems that handle EU classified information.

This seventh paragraph of the twelfth article of the text provides that the EU-CERT may provide assistance to EU institutions, bodies and agencies in the event of incidents in classified IT environments at the specific request of the relevant administration.

In addition, some definitions should be left to the Legal Service, such as the Joint Cyber Unit, which the European Parliament would like to see as “a virtual and physical platform for cooperation for the different cybersecurity communities in the Union, focusing on coordination”.

The Swedish Presidency of the EU Council still needs to receive confirmation from Member States on the timetable for reviewing the internal framework for cyber security risk management, governance and control. The proposed deadline is for a review to take place every three years. The first should take place no later than 15 months before the entry into force of the regulation.

Still on the subject of deadlines, the Commission was asked to present an overview of the timetables for assessing cybersecurity maturity with the help of a specialised third party, institutions, bodies and agencies. This evaluation should also take place at least every three years.

The next trilogue is due to take place on 27 April.

See the document: https://aeur.eu/f/6fc (Original version in French by Thomas Mangin)

Contents

Russian invasion of Ukraine
EUROPEAN PARLIAMENT PLENARY
SECTORAL POLICIES
EXTERNAL ACTION
ECONOMY - FINANCE - BUSINESS
COURT OF JUSTICE OF THE EU
SOCIAL AFFAIRS - EDUCATION
INSTITUTIONAL
COUNCIL OF EUROPE
NEWS BRIEFS