Dan Tofan | Expert in NIS 21st Art. 13a WG| LISBON | 08.03.2017 Mandatory incident reporting in EU. Particularities for telecom (Art. 13a). Dan Tofan | Expert in NIS 21st Art. 13a WG| LISBON | 08.03.2017
Summary 01 02 03 04 05 General info about ENISA Incident reporting activities in EU 03 About Art. 13a 04 Art. 13a Expert Group 05 Art. 13a Annual Incident Report Incident reporting in EU | Dan Tofan
Securing Europe’s Information Society Operational Office in Athens The European Union Agency for Network & Information Security (ENISA) was formed in 2004. The Agency is a Centre of Expertise that supports the Commission and the EU Member States in the area of information security. We facilitate the exchange of information between EU institutions, the public sector and the private sector ENISA is as a body of expertise, set up by the EU to carry out very specific technical, scientific tasks in the field of Information Security, working as a "European Agency". EU agencies are distinct bodies from the EU institutions – separate legal entities set up to perform specific tasks under EU law The Agency also assists the European Commission in the technical preparatory work for updating and developing Community legislation in the field of Network and Information Security.
Positioning ENISA activities CAPACITY Hands on activities POLICY Support MS & COM in policy implementation Harmonisation across EU Mobilizing EU communities COMMUNITY EXPERTISE Recommendations Independent Advice Incident reporting in EU | Dan Tofan
Summary 01 02 03 04 05 General info about ENISA Mandatory incident reporting in EU 03 About Art. 13a 04 Art. 13a Expert Group 05 Art. 13a Annual Incident Report Incident reporting in EU | Dan Tofan
Mandatory incident reporting in EU 01 Article 19 of the trust services and e-ID regulation: “Security requirements” 02 Article 4 of the e-Privacy directive: “Security of processing” 03 Articles 30, 31 and 32 of the Data Protection regulation 04 The NIS Directive (OES and DSP) 05 Article 13a of the Telecom Framework directive “Security and Integrity” Incident reporting in EU | Dan Tofan
Summary 01 02 03 04 05 General info about ENISA Mandatory incident reporting in EU 03 About Art. 13a 04 Art. 13a Expert Group 05 Art. 13a Annual Incident Report Incident reporting in EU | Dan Tofan
Art. 13a and the telecom package Article 13a of the Framework Directive (2009/140/EC), is a new article introduced in the 2009 reform of the EU regulatory framework for electronic communications. The reform was transposed by most EU countries around May 2011. Article 13a addresses the security and integrity of public electronic communications networks and services (availability of the service). It concerns National Regulatory Authorities (NRAs) and providers of public electronic communications networks and services (providers). Incident reporting in EU | Dan Tofan
Art. 13a content Providers of public communication networks and services should take measures to guarantee security and integrity (i.e. availability) of their networks. Providers must report to competent national authorities about significant security breaches. National authorities should inform ENISA and authorities abroad when necessary, for example in case of incidents with impact across borders. National authorities should report to ENISA and the EC about the incident reports annually (February). Incident reporting in EU | Dan Tofan
ENISA’s role within the context As requested by the directive, every country submits yearly to EC and ENISA a report with significant incidents that had an impact on their networks and services. Where appropriate, the NRA concerned shall inform the national regulatory authorities in other Member States and the ENISA. To achieve a harmonised implementation, in 2010, ENISA, Ministries and NRAs initiated a series of meetings (the Article 13a Expert Group). Developed an online platform for incident reporting (CIRAS). Incident reporting in EU | Dan Tofan
Art. 13a incident reporting process Incident reporting in EU | Dan Tofan
Art. 13a incident reporting procedure Reporting interval: between January 1st and December 31st the previous year. Deadline: end of February. Reporting modality: Online: CIRAS platform. Alternate means: email. Incident reporting in EU | Dan Tofan
Art. 13a incident reporting procedure (thresholds) Relative thresholds (relative to user base and duration) Absolute thresholds: 60 Million user minutes, or 1 Million user hours. Incident reporting in EU | Dan Tofan
Art. 13a incident reporting procedure STEP 1: Determine causes STEP 2: Determine the impact STEP 3: Identify actions taken Incident reporting in EU | Dan Tofan
Art. 13a incident reporting procedure STEP 1: Determine causes STEP 2: Determine the impact STEP 3: Identify actions taken Incident reporting in EU | Dan Tofan
Art. 13a incident reporting procedure STEP 1: Determine causes STEP 2: Determine the impact STEP 3: Identify actions taken Incident reporting in EU | Dan Tofan
Art. 13a incidents examples Incident reporting in EU | Dan Tofan
Art. 13a incidents examples Incident reporting in EU | Dan Tofan
Summary 01 02 03 04 05 General info about ENISA Mandatory incident reporting in EU 03 About Art. 13a 04 Art. 13a Expert Group 05 Art. 13a Annual Incident Report Incident reporting in EU | Dan Tofan
Art. 13a Expert group To achieve a harmonised implementation, in 2010, ENISA, Ministries and NRAs initiated a series of meetings (the Article 13a Expert Group). They reached agreement on three non-binding technical documents providing guidance to the NRAs in the EU Member States: Technical Guideline on Incident Reporting Technical Guideline on Security Measures Technical Guideline on Threats and Assets The Article 13a Expert Group continues to meet three times a year to develop guidelines, to discuss the implementation of Article 13a (for example, on how to supervise the electronic communications sector) and to share knowledge and views about past incidents, and how to address them. Other work: Impact evaluation on the implementation of Article 13a incident reporting scheme within EU Analysis of security measures deployed by e-communication providers Security incidents indicators - measuring the impact of incidents affecting electronic communications Incident reporting in EU | Dan Tofan
Summary 01 02 03 04 05 General info about ENISA Mandatory incident reporting in EU 03 About Art. 13a 04 Art. 13a Expert Group 05 Art. 13a Annual Incident Report 2011-2015 Incident reporting in EU | Dan Tofan
Annual Incident Reports Annual Reports 2011-2015 available ENISA web. 2016 available by the end of May 2017. Incident reporting in EU | Dan Tofan
Thank you