DIGIT Directorate-General for Informatics DIGIT Directorate-General for Informatics ISO 27k security standards What does it mean for ECI? 29 November 2012.

Slides:



Advertisements
Similar presentations
COMMON ASSESSMENT METHOD FOR STANDARDS AND SPECIFICATIONS (CAMSS)
Advertisements

THE CERTIFYING AUTHORITY
The European Citizens Initiative Background Preparing the ground rules Key elements of the Commission proposal Lucy Swan – Secretariat General – Unit E.
Regional Policy Delegated Act on the methodology for the quality review of major projects 1 Expert Group on Delegated and Implementing Acts for the ESI.
Developing a Risk-Based Information Security Program
Reference Document Management 1 European Railway Agency (ERA) Cross-Acceptance Unit P. Mihm 17/11/2010.
Directive 97/68/EC on the approximation of the laws of the Member States relating to measures against the emission of gaseous and particulate pollutants.
Accreditation 1. Purpose of the Module - To create knowledge and understanding on accreditation system - To build capacity of National Governments/ focal.
Introduction to PPDs Regulatory requirements and rationale.
The IPPC Recast. New environmental requirements for explosives production sites.
DoD Information Technology Security Certification and Accreditation Process (DITSCAP) Phase III – Validation Thomas Howard Chris Pierce.
Supervision of the quality of water intended for human consumption by State Sanitary Inspection bodies Małgorzata Kedzierska Environmental Hygiene Dept.
ISO/IEC Winnie Chan BADM 559 Professor Shaw 12/15/2008.
1 Reform of the EU regulatory framework for electronic communications What it means for Access to Emergency Services Reform of the EU regulatory framework.
© 2006 IBM Corporation Introduction to z/OS Security Lesson 9: Standards and Policies.
Secure System Administration & Certification DITSCAP Manual (Chapter 6) Phase 4 Post Accreditation Stephen I. Khan Ted Chapman University of Tulsa Department.
First Practice - Information Security Management System Implementation and ISO Certification.
The New EMC Directive 2004/108/EC and the DTI transposition Brian Jones and Peter Howick.
Existing EU Regulations concerning pesticide statistics and Latvia experience in pesticide statistics Guna Karlsone, CSB of Latvia.
S3: Module D Physikalisch-Technische Bundesanstalt Session 3: Conformity Assessment Module D Peter Ulbig, Harry Stolz Belgrade, 31 October.
Evolving IT Framework Standards (Compliance and IT)
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
Overview report of a series of FVO fact- finding missions and audits carried out in 2012 and 2013 in order to evaluate the systems put in place to give.
Ludovic Aigrot Chair, MiFID Task Force, Federation of European Securities Exchanges Bürgenstock, 6 September How.
Overview of the EU Food Safety Requirements
© 2013 Cambridge Technical CommunicatorsSlide 1 ISO/IEC Standard for Information Security Management Systems.
Introduction to the ISO series ISO – principles and vocabulary (in development) ISO – ISMS requirements (BS7799 – Part 2) ISO –
FOURTH EUROPEAN QUALITY ASSURANCE FORUM "CREATIVITY AND DIVERSITY: CHALLENGES FOR QUALITY ASSURANCE BEYOND 2010", COPENHAGEN, NOVEMBER IV FORUM-
XIV th Florence Forum 24/25 September 2007 Tahir Kapetanovic / Nicolas Bonnesoeur Chairmen of the CEER Electricity Security of Supply TF C07-SOS-03-03a.
IAEA International Atomic Energy Agency School of Drafting Regulations – November 2014 Government and Regulatory Body Functions and Responsibilities IAEA.
Data Governance 101. Agenda  Purpose  Presentation (Elijah J. Bell) Data Governance Data Policy Security Privacy Contracts  FERPA—The Law  Q & A.
European Commission Living in an area of freedom, security and justice Directorate-General Justice and Home affairs Silvia Kolligs DG Justice and Home.
A national authority's perspective on the European Citizens' Initiative.
International Security Management Standards. BS ISO/IEC 17799:2005 BS ISO/IEC 27001:2005 First edition – ISO/IEC 17799:2000 Second edition ISO/IEC 17799:2005.
European Aviation Safety Agency Head of Aircraft Product Certification
Information Security Measures Confidentiality IntegrityAccessibility Information cannot be available or disclosed to unauthorized persons, entities or.
PRODCOM methodology Inge Feldbaek, PRODCOM November 2002.
Deconstructing the EU NIS Directive: model, architecture, interfaces, expressions Tony Rutkowski, 08.
ESA UNCLASSIFIED – For Official Use INSPIRE Orthoimagery TWG Status Report Antonio Romeo ESRIN 15/02/2012.
QUALITY REQUIREMENTS FOR OFFICIAL FOOD LABORATORIES WITHIN EURL AND NRL (LABORATORY NETWORKS IN EUROPE) dr. Tina Pirš, dr. vet. med. Quality Manager, Veterinary.
Workshop on Standard operating procedures in the phytosanitary field, September Belgrad Serbia Monica Maria COJANU, Romania.
Harmonised use of accreditation for assessing the competence of various Conformity Assessment Bodies Dr Andreas Steinhorst, EA ERA workshop 13 April 2016,
The European Citizens’ Initiative Legal framework Rules and procedures The procedure at a glance Initiatives Online collection Signatories The ECI in the.
Department of Computer Science Introduction to Information Security Chapter 8 ISO/IEC Semester 1.
1 Cristian Dobre Team Leader DIGIT.B.1 Information Systems and Interoperability Solutions OCS - Workshop 29/11/2012 Online Collection Software for European.
On completion of the scenario, students will be able to: Learning Outcomes 1 Critically analyse and prioritise information security risks. 2 Systematically.
WIGOS regulatory and guidance material
What Is ISO ISO 27001, titled "Information Security Management - Specification With Guidance for Use", is the replacement for BS It is intended.
Introducing ICA-Requirements Module 3: Functional Requirements for Records in Business Systems
The European Citizens’ Initiative
Learn Your Information Security Management System
Data Protection Act.
Session II: System authority for ERTMS 4RP Trackside approval
ECI OCS Workshop 29/11/2012.
Proposal for a Regulation on medical devices and Proposal for a Regulation on in vitro diagnostic medical devices Key Provisions and GIRP Assessment.
ISO/IEC 27001:2005 A brief introduction Kaushik Majumder
Amendment to the NUTS Regulation Oliver Heiden Eurostat.E4
[draft] Conclusions, actions & next steps
Legal framework of territorial classifications and typologies for European statistics – state of play NUAC meeting, Brussels June 2015 Gorja Bartsch.
Art. 17 EGTC Indicators 13th Meeting of the Expert Group on Delegated and Implementing Acts for the ESI Funds 4th July 2013.
Commission Regulation (EC)
Hans Dufourmont Eurostat Unit E4 – Structural Funds
Neopay Practical Guides #2 PSD2 (Should I be worried?)
Noor Vergeer, Wojtek Kalocinski Border management and Schengen
[draft] Conclusions, actions & next steps
Hans Dufourmont Eurostat Unit E4 – Structural Funds
Philippe QUEVAUVILLER
Awareness and Auditor training kit
… Two-step approach Conceptual Framework Annex I Annex II Annex III
Meeting Of The European Directors of Social Statistics
Presentation transcript:

DIGIT Directorate-General for Informatics DIGIT Directorate-General for Informatics ISO 27k security standards What does it mean for ECI? 29 November 2012

DIGIT Directorate-General for Informatics Legal base Regulation (EU) No 211/2011 of the European Parliament and of the Council of 16 February 2011 on the citizens' initiative Commission Implementing Regulation (EU) No 1179/2011 of 17 November 2011 laying down technical specifications for online collection systems pursuant to Regulation (EU) No 211/2011 of the European Parliament and of the Council on the citizens' initiative

DIGIT Directorate-General for Informatics (EU) No 211/ Article 6 Online collection systems 1.Where statements of support are collected online, the data obtained through the online collection system shall be stored in the territory of a Member State. The online collection system shall be certified in accordance with paragraph 3 in the Member State in which the data collected through the online collection system will be stored.

DIGIT Directorate-General for Informatics (EU) No 211/2011 (ctd.) 4 Article 6 Online collection systems 4. Online collection systems shall have adequate security and technical features in place in order to ensure that: a)only natural persons may submit a statement of support form online; b)the data provided online are securely collected and stored, c)the system can generate statements of support in a form complying with the models set out in Annex III

DIGIT Directorate-General for Informatics (EU) No 1179/ Provides technical specifications to address Article 6(4) of REGULATION (EU) No 211/2011.  (a) and (c) are addressed by the Online Collection Software provided by the European Commission (Section 1 and 3 of the annex)  (b) is addressed in section 2 of the annex that details requirements which  have to be addressed by the Organisers  are addressed by the Online Collection Software provided by the European Commission  have to be addressed by the hosting infrastructure

DIGIT Directorate-General for Informatics (EU) No 1179/2011 (ctd.) 6 Section 2 of the annex provides technical specifications for the following domains: Information assurance standards ( → Organisers) Functional requirements ( → OCS) Application level security ( → OCS + hosting infrastructure) Database security and data integrity ( → OCS + hosting infrastructure) Infrastructure security ( → hosting infrastructure) Organiser client security ( → Organisers)

DIGIT Directorate-General for Informatics 7 July, 18th

DIGIT Directorate-General for Informatics EC as hosting provider … only? 8 The main objective was to provide a suitable hosting infrastructure (compliant with 1179/2011 section 2 requirements) However, it quickly appeared that EC could also help: in drafting documents required by 2.1 and 2.2 in fulfilling Organiser client security requirements (Live-DVD)

DIGIT Directorate-General for Informatics 9

DIGIT Directorate-General for Informatics Information assurance standards Organisers provide documentation showing that they fulfil the requirements of standard ISO/IEC 27001, short of adoption. For that purpose, they have: a)performed a full risk assessment, …; b)designed and implemented measures for treating risks …; c)identified the residual risks in writing; d)provided the organisational means to receive feedback on new threats and security improvements.

DIGIT Directorate-General for Informatics Information assurance standards (ctd) Organisers choose security controls based on the risk analysis in 2.1(a) from the following standards: 1)ISO/IEC 27002; or 2)the Information Security Forum’s ‘Standard of Good Practice’ to address the following issues: a)risk assessments (ISO/IEC or another specific and suitable risk assessment methodology are recommended); b)physical and environmental security; c)human resources security; d)communications and operations management; e)…

DIGIT Directorate-General for Informatics ISO security standards ISO formally specifies a management system that is intended to bring information security under explicit management control ISO ISO provides best practice recommendations on information security management for use by those responsible for initiating, implementing or maintaining Information Security Management Systems (ISMS) ISO 27002

DIGIT Directorate-General for Informatics ISO27002 domains

DIGIT Directorate-General for Informatics ISO27001 ISMS

DIGIT Directorate-General for Informatics ECI Documentation package 15 To fulfil the above requirements, EC agreed with the Luxembourgish Authorities to build the following security documentation package : 1.the Security Scope 2.the Business Impact Analysis (BIA) 3.the Risk Assessment Report (RAR) 4.the Risk Treatment Plan (including Residual Risks) (RTP) 5.the Statement of Applicability (SoA)

DIGIT Directorate-General for Informatics ECI Documentation package (ctd) 16 EC also built guidance documents to help the Organisers drafting their part of the security documentation, i.e.: 1.Organiser Risk Assessment Guidance 2.Organiser Risk Treatment Plan Guidance 3.Organiser Statement of Applicability Guidance The guidance documents have been drafted to be reusable as much as possible and thus to minimize Organiser's documentation effort.

DIGIT Directorate-General for Informatics Organiser client security Organiser client security For the sake of end-to-end security, the organisers take necessary measures to secure their client application/ device that they use to manage and access the online collection system, such as: Users run non-maintenance tasks (such as office automation) with the lowest set of privileges that they require to run When relevant updates and patches of the OS, any installed applications, or anti-malware become public, then such updates or patches are installed expediently.

DIGIT Directorate-General for Informatics 18 And finally …

DIGIT Directorate-General for Informatics Q&A