EU policy on Network and Information Security (NIS) and Critical Information Infrastructure Protection (CIIP) 15 March 2012 Valérie ANDRIANAVALY European.

Slides:



Advertisements
Similar presentations
A strategy for a Secure Information Society –
Advertisements

Philippine Cybercrime Efforts
Critical Infrastructure Protection Policy Priorities Sara Pinheiro European Commission DG Home Affairs.
EAC HIGHER EDUCATION POLICY
FP7 Preparations ISTC meeting 31 March Content FP7 preparation approach and timetable Context for FP7 and for ICT in FP7 Research in New Financial.
ENISA Cyber Security Strategies Workshop November 27, 2014 Brussels
22 Feb 2007EU-Russia Co-operation1 Dr. Stephan Pascall Advisor to the Director Directorate G: Components and Systems DG Information Society and Media European.
1 Ideas About the Future of HPC in Europe “The views expressed in this presentation are those of the author and do not necessarily reflect the views of.
Strategy and Policy Unit: Current Activities and Future Tasks
NIS Directive and NIS Platform
Geneva, Switzerland, September 2014 ENISA role in ICT standardization Sławomir Górniak, ENISA ITU Workshop on “ICT.
James Ennis, Department of State, USA ITU-D Question 22/1 Rapporteur.
Matteo Cavallini – ULS MEF/Consip Digital Agenda Assembly – Cybersecurity: barriers and incentives Matteo Cavallini Cybersecurity: State of the Art and.
European Union Agency for Network and Information Security Follow ENISA: ENISA and standards Sławomir Górniak European Union Agency.
Horizon 2020 Secure Societies Security Research and Industry DG Enterprise and Industry 2013.
A Common Immigration Policy for Europe Principles, actions and tools June 2008.
Andrea Servida Deputy Head of Unit European Commission DG INFSO-A3 Security and resilience in Information Society: towards.
Giandonato CAGGIANO ENISA MANAGEMENT BOARD REPRESENTATIVE LEGAL ADVISER ON EUROPEAN AFFAIRS OF THE MINISTRY OF COMMUNICATIONS U. OF ROMA TRE LAW FACULTY.
Development and Cooperation Financial Instruments supporting civil society cooperation initiatives in the Black Sea region Black Sea NGO Forum, 6th Edition.
BITS Proprietary and Confidential © BITS Security and Technology Risks: Risk Mitigation Activities of US Financial Institutions John Carlson Senior.
Overview of NIPP 2013: Partnering for Critical Infrastructure Security and Resilience October 2013 DRAFT.
The Open Method of Coordination in the area of Innovation Policy
BOTSWANA NATIONAL CYBER SECURITY STRATEGY PROJECT
1 INFRA : INFRA : Scientific Information Repository supporting FP7 “The views expressed in this presentation are those of the author.
ICT policies and the Lisbon Agenda Baltic IT&T 2005 Riga, 7 April 2005 Frans de Bruïne Director “Lisbon Strategy and Policies for the Information Society”
European Commission Competitiveness and Innovation Framework Programme (CIP)
Australia Cybercrime Capacity Building Conference April 2010 Brunei Darussalam Ms Marcella Hawkes Director, Cyber Security Policy Australian Government.
Towards a European network for digital preservation Ideas for a proposal Mariella Guercio, University of Urbino.
Mission An alliance of individuals, NGOs, regions and corporations working to provide Europe with easy-to-use, resilient, and ubiquitous communications.
Planned Commission Communication on the role of the Private Sector in Development A contribution to the reflexion on How to Innovate International Cooperation.
European Commission Enterprise and Industry | | ‹#› The Lead Market Initiative and Sustainable Construction CEEC seminar, 8 May 2009 Antonio.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
JOINING UP GOVERNMENTS EUROPEAN COMMISSION Establishing a European Union Location Framework.
THE REPUBLIC OF SLOVENIA MINISTRY OF HIGHER EDUCATION, SCIENCE AND TECHNOLOGY e: Kotnikova 38, 1000 Ljubljana p:
Realising the European Union Lisbon Goal The Copenhagen process and the Maaastricht Communiqué: Martina Ní Cheallaigh DG Education and Culture.
The EU framework programme for research and innovation.
E u r o p e a n C o m m i s s i o nCommunity Research Global Change and Ecosystems EU environmental research : Part B Policy objectives  Lisbon strategy.
Andrea SERVIDA European Commission DG INFSO.A3 Update on EU policy on Network and Information Security & Critical Information.
EU activities against cyber crime Radomír Janský Unit - Fight against Organised Crime Directorate-General Justice, Freedom and Security (DG JLS) European.
China July 2004 The European Union Programmes for EU-China Cooperation in ICT.
Yves Paindaveine DG CONNECT, European Commission
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
EU Cybersecurity Strategy and Proposal for Directive on network and information security (NIS) {JOIN(2013) 1 final} {COM(2013) 48 final} Digital Enlightenment.
ISACA Ireland Cyber Security Policy 9 February 2016.
The 7th Framework Programme for Research: Strategy of international cooperation activities Robert Burmanjer Head of Unit, “International Scientific Cooperation.
Deconstructing the EU NIS Directive: model, architecture, interfaces, expressions Tony Rutkowski, 08.
CEN Workshop on ICT Skills Setting European Standards for ICT Skills & Qualifications And Professionalism Dudley Dolan Chairman of the CEN Workshop on.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 10 – Information society and media.
EUROPEAN SECURITY POLICY A SNAPSHOT ON SURVEILLANCE AND PRIVACY DESSI WORKSHOP, CPH 24 JUNE 2014 Birgitte Kofod Olsen, Chair Danish Council for Digital.
Richard Escritt, Director – Coordination of Community Actions DG Research, European Commission “The development of the ERA: Experiences from FP6 and reflections.
1 Researcher Mobility and Careers: Update on Recent EU Policy Initiatives Dr. Dagmar Meyer European Commission DG Research and Innovation Unit B2 - “Skills”
ANSI – ESOs meeting Washington February 2017
Building Governance for Risk Management
Information Security – Current Challenges
About the NIS directive
Critical Infrastructure Protection Policy Priorities
8 Building Blocks of National Cyber Strategies
14th meeting of Working Group F on Floods
European Cybersecurity Month 2017 kick-off event
The EU Raw Materials Initiative: a short overview
Trust and Security Unit
ICTPSP Call 2007 ICT for ageing well
The role of the ECCP (1) The involvement of all relevant stakeholders – public authorities, economic and social partners and civil society bodies – at.
The European Union response to cyber threats
Community of Users.
Directorate General Information Society & Media
New Services for Ageing Well in the Information Society
Juan Gonzalez eGovernment & CIP operations
European energy policy
FINANCING NATURA 2000 Agenda item 2.1 CGBN Co-ordination Group
Presentation transcript:

EU policy on Network and Information Security (NIS) and Critical Information Infrastructure Protection (CIIP) 15 March 2012 Valérie ANDRIANAVALY European Commission Directorate General Information Society and Media - DG INFSO Unit A3 – Internet Governance; Network and Information Security

Main EU policy initiatives in the NIS & CIIP areas 2004: Establishment of ENISA - Regulation (EC) No 460/ : Commission’s proposal - Strategy for a Secure Information Society - Dialogue, partnership, empowerment 2009: Commission’s proposal - Action Plan on Critical Information Infrastructure protection 2009: Adoption of the revised Regulatory Framework for electronic communications – new security provisions including security breaches notifications (Art. 13 a and b) 2010: Trust and Security chapter of the Digital Agenda for Europe 2010: Commission’s proposal to modernise ENISA 2011: Second Commission Communication on CIIP - 'Achievements and next steps: towards global cyber-security’ Q3/2012: Commission’s proposal – European Strategy for Internet Security

Main EU policy initiatives in the NIS & CIIP areas Strategy for a Secure Information Society COM(2006)251 “Voluntary” approach based on dialogue, partnership and empowerment Comprehensive set of actions – risk management culture Promote openness, diversity, interoperability, usability, competition as inherent security safeguards Reinforce ENISA’s role in implementing the NIS policy Importance of “resilience” of electronic communications Action Plan on Critical Information Infrastructure Protection COM(2009)149 Protect Europe from large scale cyber attacks and disruptions Promote security and resilience as first line of defense Enhance the CIIP preparedness and response capability in EU Foster the adoption of adequate and consistent levels of preventive, detection, emergency and recovery measures Foster International cooperation, in particular on Internet stability and resilience

CIIP Action Plan – Specific Objectives Five specific objectives to be achieved: Foster cooperation and exchange of good policy practices between MS (EFMS) Develop a public-private partnership at the European level on security and resilience of CIIs (EP3R) Enhance incident response capability in the EU Promote national and European cyber contingency plans and exercises on simulated large-scale network security incidents. Reinforce international cooperation on global issues, in particular on resilience and stability of Internet

CIIP Action Plan – Five pillars 1. Preparedness and prevention European Forum for MS to share information & policy practices - EFMS European Public Private Partnership for Resilience EP3R Baseline of capabilities and services for National/Governmental CERTs 2. Detection and response Development of a European Information Sharing and Alert System – EISAS dedicated to EU citizens and SMEs 3. Mitigation and recovery National contingency planning and exercises Pan-European exercises on large-scale network security incidents Reinforced cooperation between National/Governmental CERTs 4. International Cooperation Define European priorities, principles and guidelines for the long term resilience and stability of the Internet Promote the principles and guidelines at global level Global cooperation on exercises on large-scale Internet incidents 5. Definition of criteria for the identification of European Critical Infrastructures in the ICT sector

CIIP COM(2011)163 “Achievements and next steps: towards global cyber- security” Adopted on 31 March 2011 Takes stock of results achieved since 2009 CIIP action plan Builds on existing policy initiatives, in particular Digital Agenda for Europe, Stockholm Action Plan and Internal Security Strategy Highlights next steps at European and International level

CIIP COM(2011)163 “Achievements and next steps: towards global cyber- security” – Areas of achievements European Forum for Member States (EFMS) European Public-Private Partnership for Resilience (EP3R) Baseline of capabilities and services for pan-European cooperation of national/governmental CERTs European Information Sharing and Alert System (EISAS) National contingency planning and exercises Pan-European exercise on large-scale network security incidents Principles and guidelines on Internet resilience and stability Sector specific criteria for identifying European Critical Infrastructures in the ICT sector

Very positive results achieved so far in CIIP within the EU Further efforts are needed and the EC calls upon MS to commit to: -Enhance EU preparedness by establishing a network of well-functioning National/Governmental CERTs by 2012; -A European cyber-incident contingency plan and regular National and pan-European cyber exercises by 2012; -European coordinated efforts in international fora and discussions on enhancing Internet security and resilience. CIIP COM(2011)163 “Achievements and next steps: towards global cyber- security” – The way forward 1/2

Global coordination is important and necessary The Commission will: Promote principles for Internet resilience and stability * developed within the EFMS; Build strategic international partnerships (e.g. EU-US Working Group on Cyber-security and Cyber-crime) and pursue coordination in International fora Develop trust in the cloud * s_internet_fin.pdf CIIP COM(2011)163 “Achievements and next steps: towards global cyber- security” – The way forward 2/2

7th EU Research Framework Programme ( ) ICT Security & Trust

11 Call 7 70 M€ Call 8 70 M€ Call 7 20 M€ Call 8 80 M€ Call M€ FP7 INFSO - Challenge 1.4 Pervasive and Trustworthy ICT Call FI20/07/10 – 02/12/10 Call 728/09/10 – 18/01/11 Call 826/07/11 – 17/01/12 Call 7 30 M€ Call 8 25 M€ Call FI 90 M€

12 ICT - Trust and Security: 58 projects of FP7 Call 1 and Call 5 Networking, Coordination and Support Research roadmaps, metrics and benchmarks, international cooperation, coordination activities 4 projects 2 projects Network infrastructures 4 projects 7 projects Services infrastructures 4 projects 7 projects 4 projects Enabling technologies Biometrics, trusted computing, cryptography, secure SW 9 projects Critical Infrastructure Protection 200 m€ Identity management, privacy, trust 8 projects 5 projects 40M€60M€48M€ 20M€ 27M€ 5M€

BIC: Building International Co-operation for Trustworthy ICT  Identify global trust and security challenges of mutual interest and benefit  Facilitate collaboration fora - funding calls/EU mechanisms info. - people/partner linkages - funding organization linkages - guidance on developing sustained longer-term global collaborations Prioritisation of the visions and research directions amongst the countries, moving towards alignment of work programmes. DG INFSO Unit F5 Coordination Action Jan 2011-Dec For more information, please contact Jim Clarke

Competitiveness and Innovation Framework Programme Competitiveness and Innovation Framework Programme - ICT Policy Support Programme (CIP- ICT PSP) Annual Work Programme:2012 Annual Work Programme −Pilot B (8 M€) to establish a European-wide pilot platform for detecting, measuring, analysing, mitigating and eliminating botnets −Accompanied by Thematic Network (1 M€) −Call 6 open from 03 February until 15 May 2012 −Information day on (presentations and attendance list available at cordis web page infoday-content_en.html) infoday-content_en.html

Commission Work Programme 2012 announced a European Strategy for Internet Security to be adopted by Commission in Q Outline 1.Policy Document Context – EU activities and achievements to date and the need for EU action Objectives of the ESIS and EU core values and principles Strategic priorities and actions Governance framework and monitoring of the implementation of the strategy 2. Legal instrument

European Strategy for Internet Security “To ensure a safe, secure and resilient digital environment to all EU citizens, businesses and public authorities” Specific objectives: Foster close co-operation and early warning between MS' competent authorities, and between competent authorities and the private sector, by ensuring adequate capacities for prevention, detection, mitigation and response at national and EU level Stimulate efforts to improve security of in products, networks and services Ensure a strong EU response to cybercrime Stimulate R&D investments and strengthen the competitiveness of EU’s security industry Foster global responses and reinforce cooperation with international partners Strategic objective:

Elements of the future European Strategy for Internet Security (1/4) An effective network of National competent bodies and Governmental CERTs at EU level (with the necessary protection of confidentiality) Well-functioning National/Governmental CERTs capabilities A "European Forum for Regulators” (towards a model for pan-EU cooperation mechanisms – similarly to what is in place in other sectors) A European cyber-incident contingency plan General security breach notification obligation (extending Article 13a FD beyond Telcos/ISPs) −Adoption of a risk management framework (identification of risks) −Adoption of relevant security measures −Supervision by competent bodies (including via audit) −Notification mechanisms to competent bodies (possibly via CERT function) ensuring confidentiality Mandatory security audits and authorisation mechanisms where this is already required by applicable law (e.g. banking, energy…) Preliminary ideas for legal measures aiming at ensuring the establishment of:

Elements of the future European Strategy for Internet Security (2/4) Preliminary ideas for further measures to improve security in networks and services: Incentives for the private sector to improve security in products and services, e.g. through IT security standards in public procurement −Incentives through the public procurement process (via guidelines and standards) −Stimulating a public-private partnership to reduce the spread of malware −Promotion of transparency and competitiveness in the internal market (benchmarks, trusted data on incidents and vulnerabilities, information to users, compliance with standards, certification and self-certification to develop re- assurance market) −Security of supply chain Awareness raising measures and activities −Mobilisation of Member States and stakeholders towards a EU-wide campaign (for instance, a month for Network and Information Security for all) −National/European Cyber-security Competitions to foster development of skills −International synchronisation and coordination of awareness raising messages and campaigns (US and Japan) −Reinforced role of ENISA in promoting standards, good practices and a risk management culture

Elements of the future European Strategy for Internet Security (3/4) Preliminary ideas for further measures to improve security in networks and services: Making the best use of research and innovation and putting in place a robust industrial policy Adoption of state-of-the-art technologies & processes - Promote take up −stimulate private and public demand (security to be an integral part of the provision of e-services, mandatory for eGov, pre-commercial procurement) −develop standards −improve usability Reinforcing and coordinating R&D for present and future security challenges −H2020 LEIT = 450 M€ for R&D => make the technologies available −H2020 IIS = 700 M€ for Innovation => put technology to work −Underpin the technical feasibility of the cyber security policy and associated actions −Create partnerships in cyber-security

Elements of the future European Strategy for Internet Security (4/4) Preliminary ideas for further measures to improve security in networks and services: Appropriate measures in the area of cybercrime (in cooperation with DG HOME) Putting the EU in the lead of international discussions on Internet security matters - Promotion and engagement in multilateral cooperation - Leveraging EU-US activities towards broader international participation -Fighting Botnets -Cyber-security of Industrial Control Systems and Smart grids - Promotion of EU interests in global Internet security -Multi-stakeholder governance -Market access -European principles and guidelines for Internet resilience and stability -COMPACT for the Internet

European Strategy for Internet Security Consultation process Exchange of views held so far: Within INFSO and Commission-wide (ISG on Cyber- crime and cyber-security, discussions on specific issues with relevant services) Within EP (Roundtable on ; ITRE draft report on Critical Information Infrastructure Protection) With MS via EFMS (on ) – input received from 10 MSs With private sector via EP3R (on ) Informal discussions with MS and private stakeholders  General support for a EU framework and mechanisms to further enhance cooperation and coordination

Thanks!

Web Sites EU policy on Critical Information Infrastructure Protection – CIIP egy/activities/ciip/index_en.htm egy/activities/ciip/index_en.htm A Digital Agenda for Europe agenda/index_en.htm agenda/index_en.htm EU policy on promoting a secure Information Society _en.htm _en.htm European principles and guidelines for Internet resilience and stability /principles_ciip/guidelines_internet_fin.pdf /principles_ciip/guidelines_internet_fin.pdf

Links to policy documents Council conclusions on Critical Information Infrastructure Protection Commission Communication on Critical Information Infrastructure Protection – "Achievements and next steps: towards global cyber-security" - COM(2011) mm_163_en.pdf mm_163_en.pdf Digital Agenda for Europe - COM(2010)245 of 19 May lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2010:0245:FIN:EN:PDF lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2010:0245:FIN:EN:PDF The EU Internal Security Strategy in Action: Five steps towards a more secure Europe COM(2010) /malmstrom/archive/internal_security_strategy_in_action_en.pdf /malmstrom/archive/internal_security_strategy_in_action_en.pdf Commission Communication on Critical Information Infrastructure Protection – "Protecting Europe from large scale cyber-attacks and disruptions: enhancing preparedness, security and resilience" - COM(2009) lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2009:0149:FIN:EN:PDF lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2009:0149:FIN:EN:PDF

25 For more information on Research Projects FP7 Trust & Security Future Internet