IT security assurance – 2018 and beyond Item 2 of the agenda DIME/ITDG Steering Group June 2018 Pascal JACQUES ESTAT B2/LISO.

Slides:



Advertisements
Similar presentations
Date: in 12 pts 28 th Meeting EQF Advisory Group Brussels 2 -3 December 2014.
Advertisements

1 Owner-Occupied Housing Summary of the pilot Item 5 of the Agenda D4 – Price Statistics HICP Working Group Luxembourg October 2007.
8th meeting of the Task Force on Health Expectancies Session 1 – Update from the Commission SILC/EHIS update/EDSIM.
Eurostat ESS Security and Secure exchange of information Expert Group (E4SWG) Report of the activity of the Task Force in 2015 Pascal Jacques ESTAT B0.
ESS Slide 1 Quality assessment of MEHM in SILC Eurostat Unit F5 “Health and Food Safety Statistics” 4 th meeting of the Task Force on Health Expectancies.
Agenda item 5 ESS Vision 2020: other activities DIGICOM and SIMSTAT DIME-ITDG joint plenary Luxembourg,
Eurostat Ag.no "Annex 2" supplement to Eurostat Annual Report, October 2015 Working Group on Article 64 and Article 65 of the Staff Regulations Meeting.
TRADE CONTACT GROUP Brussels 9th June 2009 Agenda item 3a) State of play of IT systems: Import Control System (ICS); Export Control System (ECS); New.
Eurojust cases involving crimes against children
Phasing out the use of lead shot in wetlands (1)
Update on the UOE 2012 data collection
5. Areas under organic farming
Working Party “Cooperation on Land Cover/Use Statistics”
Ag.no. 15 Lessons from the 2015 A65 exercise
No document Ag 08 ESA2010 (SNA 2008)
Concrete actions for improving cooperation with countries
GBV survey: progress EUROSTAT 20 March 2018.
Natura 2000 – SCI Union Lists
2.1. ESS Agreement on Learning Mobility (IVET & Youth)
Education and Training Statistics Working Group, May 2011
ESS Security and Secure exchange of information Expert Group (E4SEG) DIME/ITDG Item 8 ESS Security Assurance Pascal Jacques ESTAT B2 Local Security Officer.
ESS Security and Secure exchange of information Expert Group (E4SEG) DIME/ITDG SG ESS IT Security Framework Pascal Jacques ESTAT B2 Local Security Officer.
State of legal transposition (1)
Ag.no.16 A65 country manuals and country assessments
Report on WISE Art.8 and GIS issues
Habides update (May 2011).
State of play Article 5 reports
Education and Training Statistics Working Group
Agenda Item 2.1 SES 2014: follow-up
ETS Working Group, 5-6th June 2012
Marine Strategy Framework Directive: Transposition and Implementation
Marine Strategy Framework Directive: Status of reporting
LAMAS Working Group 29 June-1 July 2016
2a. Status of WFD reporting
Item 7.1 Implementation of the 2016 Adult Education Survey
Item 8.1 Implementation of the 2016 Adult Education Survey
2b. Status of WFD reporting
Programme adoptions Cohesion Policy:
Ag.no. 15 Lessons from the 2016 A65 exercise
Item 7.1 – Overview of 2012 UOE data collection
ETS Working Group meeting 24-25/9/2007 Agenda point 7 CVTS3 brief update /09/ 2007 ETS working group.
Steering Committee, Eurostat, Luxembourg, 4 February 2011
Update on legal issues Strategic Coordination Group
LAMAS Working Group 7 – 8 December 2016
WFD River Basin Management Plans :
3.6. Impact of population and housing census results on population stocks and on LFS and SILC–follow-up DSS Meeting September 2012.
2015 Update of Union Lists of Sites of Community Interest
Water scarcity & droughts
ESS Security and Secure exchange of information Expert Group (E4SEG) Item 1 of the agenda IT security assurance DIME/ITDG SG Meeting London 15/2/20189.
State of Play RBMPs and WISE reporting (9/07/10)
Gender Based Violence State of Play Item 5 of the draft agenda
FISIM State of play Agenda Item 3.
Update on implementation WG F 27 April 2010 Maria Brättemark
European Statistical Training Programme (ESTP)
Update on legal issues Strategic Coordination Group 23 February 2010
Update on legal issues Strategic Coordination Group
Item 3 Observed consistency and revisions
LAMAS October 2018 Agenda Item 4.1 LMI Review – main scenarios
Update on status of reporting and validation process
Doc.A6465/16/03 Ag.no.16 A65 country manuals
LAMAS Working Group 7-8 December 2016
Doc.A6465/14/04 Ag.16 A65 country manuals
LAMAS Working Group 5-6 October 2016
LAMAS Working Group June 2015
LAMAS Working Group June 2018
Item 11 Preliminary results of the second phase of the Cost analysis of European Statistics (by products) in the ESS Walter Sura, A.2 – Strategy and.
Connectivity to secure networks
IT security assurance – new role of ITDG Item 3 of the agenda DIME/ITDG Steering Group June 2018 Pascal JACQUES ESTAT B2/LISO.
Project objectives and benefits
EDAMIS3: CURRENT STATUS
Presentation transcript:

IT security assurance – 2018 and beyond Item 2 of the agenda DIME/ITDG Steering Group June 2018 Pascal JACQUES ESTAT B2/LISO

Outline ESS IT security Assurance mechanism 2017 certification results 2018 Certification process 2019 Certification schedule Actions resulting from the 2016 self-assesment exercise Grants Workshops

ESS Assurance mechanism Scope: exchange of data to produce intra-EU trade in goods statistics Coverage: 26 ESS members + ESTAT+ 5 ONAs (BE, ES, FI, FR, UK) Reporting: Summary of certification process submitted to ESSC annually (February) Deadline: All members to be certified end 2019 New certification round: 2020 and beyond

2017 Certification results Certification ESS countries phase 1 NL: November 2017 On-site visit and feedback provided to CBS Corrective actions implemented by April 2018 IT : December 2017 On-site visit 4-6/12/17 Feedback provided to ISTAT on 18/12/2017 Corrective actions and deadlines expected from ISTAT Report to May 2018 ESSC May'18 ESSC endorsed certification of CBS (NL) IT to be endorsed by ITDG under new procedure

Feedback on 2017 certification Better define the perimeter of the certification based on a "Scope Document" to be drafted by NSI and provided to PWC prior to certification Scope document finalised by ESS IT expert group to be endorsed by ITDG by written consultation Non disclosure Agreement under discussions with all MS Improve PWC feedback to NSI through a standard "Assessment Report" Risk: Lot of MS postponing certification towards 2019

Certification 2018 Certification ESS countries phase 2 (6 countries + ESTAT) SI: 05/18 done – feedback provided to SURS BE (NBB): 07/18 LT: 09/18 ESTAT: 10/18 EE, SE: 10/18 DE: 11/18 ??

Certification 2019 Certification ESS countries phase 3 20 countries : AT, BG, CZ, CY, DK, EL, ES (Customs), FI (NSI + Customs), FR, HR, HU, IE, LU, LV, MT, PL, PT, RO, SK, UK(NSI+Customs) Countries have been contacted by PWC on 31/5/18 for 2019 scheduling To start early 2019 To be finished end 09/19

Additional actions endorsed by May 2018 ESSC Each MS to publish publicly the Information Security Policy Each MS to appoint an IT security officer in

2016 Grants country Start date end date amount duration DE 06/03/2017 05/03/2018 44,150.08 12 95% GR 01/03/2017 30/01/2018 80,957.97 10 HR 22/02/2017 21/02/2018 164,260.85 IT 23/02/2107 22/02/2018 136,266.31 LU 15/12/2016 14/12/2017 138,879.06 LV 01/11/2017 66,168.20 8 NL 01/01/2017 31/12/2017 254,396.13 PL 21/03/2017 20/03/2018 100,783.00 SI 01/04/2017 31/03/2018 129,702.48 SK 03/03/2017 02/03/2018 150,588.00

2017 Grants country Start date end date amount duration AT 01/09/2017 31/8/2018 60,644.96 12 95% BG 01/10/2017 30/09/2018 121,553.32 CY 21/12/2017 20/12/2018 74,053.91 DK 15/12/2017 14/12/2018 67,500.00 70% EE 01/11/2017 29,059.49 11 HR 163,191.25 HU 01/02/2018 31/01/2019 206,980.87 LT 78,532.82 LU 01/01/2018 31/12/2018 176,896.37 MT 18/12/2017 17/12/2018 126,764.02 PL 27/12/2017 26/12/2018 102,358.33 PT 20/12/2017 19/12/2018 191,272.96

2018-2019 Grants 17th May 2018 – Closing of 3rd Call for proposals for mono-beneficiary grants Grants to start Q3 2018 1.200.000 € available 13 proposals received for an amount of 3M€ Under evaluation February 2019 – Launch of 4th Call for proposals for mono-beneficiary grants Grants to start Q3 2019

Workshops 1st workshop on Information Classification – 5-6 October 2017 Madrid Harmonise practices in terms of data classification and controls Comparisons of the different classification schemes in the MS guidelines for data classification and lookup tables for existing classifications Countries requested to classify all datasets sent to ESTAT according to national classification schemes. Consolidation undergoing at ESTAT side

2nd workshop on incident management and putting in place a structure for exchanging within the ESS security incidents May 2018 Barcelona Define incidents types and identify important types of incidents relevant for the microdata exchange business case Rapid exchange of information regarding any incident compromising the security of the information exchanged and systems dealing with it Define terms and conditions for setting up an ESS incident management service Excel sheet with type of incidents to exchange in the ESS including actions and response time Ongoing discussions on the use of ASSIST for exchange

3rd workshop Potential subject: ESS guidelines on harmonized security policies and on harmonized rules for staff recruitment policies Spain - October 2019