COUNCIL OF THE EUROPEAN UNION. Brussels, 22 November /13. Interinstitutional File: 2013/0027 (COD)

Similar documents
COUNCIL OF THE EUROPEAN UNION. Brussels, 16 May /14. Interinstitutional File: 2013/0027 (COD)

PUBLIC COUNCILOF THEEUROPEANUNION. Brusels,22May /14. InterinstitutionalFile: 2013/0027(COD) LIMITE

14491/18 KM/ek 1 TREE.2.B LIMITE EN

Council of the European Union Brussels, 17 November 2017 (OR. en)

Council of the European Union Brussels, 25 May 2018 (OR. en)

COU CIL OF THE EUROPEA U IO. Brussels, 28 May /13 Interinstitutional File: 2012/0340 (COD) TELECOM 140 CO SOM 101 MI 451 CODEC 1215

10109/14 KM/ek 1 DG E2B

Council of the European Union Brussels, 9 March 2018 (OR. en)

9823/17 MH/mk 1 DG B 1C

14838/18 VK/vk 1 TREE.2.A

5965/18 OM/vc 1 DGG 1B

ECB-PUBLIC OPINION OF THE EUROPEAN CENTRAL BANK. of 25 July 2014

Council of the European Union Brussels, 25 November 2016 (OR. en)

COUNCIL OF THE EUROPEAN UNION. Brussels, 1 June /10 Interinstitutional File: 2008/0240 (COD) ENV 356 MI 182 CODEC 494

Council of the European Union Brussels, 18 November 2016 (OR. en)

9101/15 TG/LM/add 1 DG G 3 A

CONTEXT AND CONTENT OF THE PROPOSAL

7402/10 ADD 1 1 DQPG

9768/16 BM/dd 1 DG D 2A

COUNCIL OF THE EUROPEAN UNION. Brussels, 26 November 2013 (OR. en) 16162/13 Interinstitutional File: 2013/0213 (COD)

12346/18 ML/el 1 TREE.2.A

EUROPEAN UNION. Brussels, 25 April 2014 (OR. en) 2013/0084 (COD) PE-CONS 63/14 STATIS 39 SOC 185 ECOFIN 237 CODEC 711

9578/17 AT/BL/GW/ns 1 DGE 2B

Council of the European Union Brussels, 22 June 2017 (OR. en)

COUNCIL OF THE EUROPEAN UNION. Brussels, 3 December /1/10 REV 1. Interinstitutional File: 2008/0241 (COD) ENV 824 MI 510 CODEC 1413

15489/14 TA/il 1 DG E 2 A

7546/09 TG/ts 1 DG C III

Council of the European Union Brussels, 30 November 2017 (OR. en)

14060/1/14 REV 1 AM/am 1 DG E 1A

Council of the European Union Brussels, 4 February 2019 (OR. en)

COUNCIL OF THE EUROPEAN UNION. Brussels, 27 October /06 Interinstitutional File: 2006/ 0018(COD) ENT 124 ENV 569 CODEC 1173 OC 826

14226/18 VK/el 1 TREE.2.A

15724/1/17 REV 1 KM/CB/ek 1 DGE2B

COUNCIL OF THE EUROPEAN UNION. Brussels, 20 November /08 Interinstitutional File: 2007/0247 (COD)

Council of the European Union Brussels, 10 November 2016 (OR. en)

COUNCIL OF THE EUROPEAN UNION. Brussels, 1 June /10 Interinstitutional File: 2008/0241 (COD) ENV 357 MI 183 CODEC 495

NOTE Terminology to be used in Council and COREPER agendas for legislative items under the Ordinary Legislative Procedure (OLP)

PUBLIC COUNCILOF THEEUROPEANUNION. Brusels,11March /14. InterinstitutionalFile: 2012/0011(COD) LIMITE

Delegations will find attached document D045830/03.

PE-CONS 52/17 DGE 2 EUROPEAN UNION. Brussels, 21 November 2017 (OR. en) 2017/0060 (COD) PE-CONS 52/17 TRANS 415 DELACT 189 CODEC 1608

Council of the European Union Brussels, 22 May 2017 (OR. en)

9138/17 CB/ek 1 DGE 2B LIMITE EN

9726/17 ADD 1 1 GIP 1B

ANNEXES. to the COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL

Council of the European Union Brussels, 11 January 2017 (OR. en)

8867/17 UM/mj 1 DG E - 1C

JAI.1 EUROPEAN UNION. Brussels, 30 August 2018 (OR. en) 2016/0357 B (COD) PE-CONS 22/18 FRONT 110 VISA 95 DAPIX 117 DATAPROTECT 69 COMIX 223 CODEC 628

DGD 2 EUROPEAN UNION. Brussels, 2 December 2015 (OR. en) 2014/0339 (COD) PE-CONS 56/15 PROAPP 20 CATS 97 CODEC 1284

Council of the European Union Brussels, 3 May 2018 (OR. en)

European Parliament resolution of 8 March 2011 on the revision of the General Product Safety Directive and market surveillance (2010/2085(INI))

Council of the European Union Brussels, 5 October 2017 (OR. en) Mr Jeppe TRANHOLM-MIKKELSEN, Secretary-General of the Council of the European Union

COUNCIL OF THE EUROPEAN UNION. Brussels, 18 March /11 Interinstitutional File: 2010/0303 (COD) MAR 36 CODEC 398

OUTCOME OF PROCEEDINGS from: Working Party on Information Exchange and Data Protection (DAPIX) on: February 2012 Subject: Summary of discussions

Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (eidas)

COUNCIL OF THE EUROPEAN UNION. Brussels, 23 May 2014 (OR. en) 9371/14 Interinstitutional File: 2010/0208 (COD) LIMITE

9355/17 CB/ek 1 DGE 2B

6515/18 AM/am 1 DG E 1A

DGE 2 EUROPEAN UNION. Brussels, 21 March 2018 (OR. en) 2016/0149 (COD) PE-CONS 69/17

15868/13 JB/mf 1 DGG 1B

***I DRAFT REPORT. EN United in diversity EN. European Parliament 2018/0110(COD)

Committee on Civil Liberties, Justice and Home Affairs WORKING DOCUMENT. Committee on Civil Liberties, Justice and Home Affairs

9020/1/15 REV 1 PL/mz 1 DG B 3A

EUROPEAN UNION. Brussels, 3 April 2014 (OR. en) 2012/0184 (COD) 2012/0185 (COD) 2012/0186 (COD) LEX 1487 PE-CONS 11/2/14 REV 2 TRANS 18 CODEC 113

Council of the European Union Brussels, 15 December 2017 (OR. en)

COUNCIL OF THE EUROPEAN UNION. Brussels, 26 November /10 Interinstitutional File: 2010/0817 (COD) COPEN 266 EJN 68 EUROJUST 135 CODEC 1369

Council of the European Union Brussels, 29 October 2015 (OR. en)

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Delegations Recast of Regulation (EC) No 1049/2001 regarding public access to European Parliament, Council and Commission documents

PUBLIC LIMITE EN COUNCIL OF THE EUROPEAN UNION. Brussels, 23 November /07 LIMITE PV/CONS 48 TRANS 291 TELECOM 113 ENER 232

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Commission expert group on INSPIRE Implementation and Maintenance Terms of Reference

7209/18 CM/IC/sr DGE 2

EUROPEAN ECONOMIC AREA

Proposal for a COUNCIL DECISION

14820/12 ADD 1 REV 3 dre/ps/ck 1 DQPG

Council of the European Union Brussels, 25 June 2018 (OR. en)

10728/4/16 REV 4 ADD 1 psc 1 DRI

New model of governance and accountability of data protection by Union institutions and bodies

COUNCIL OF THE EUROPEAN UNION. Brussels, 2 March /09 ADD 1 REV 1. Interinstitutional File: 2008/0002 (COD) DENLEG 51 CODEC 893

Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

Council of the European Union Brussels, 11 June 2018 (OR. en)

DRAFT OPINION. EN United in diversity EN. European Parliament 2017/0224(COD) of the Committee on Industry, Research and Energy

POLICY ON CONSULTATIONS IN THE FIELD OF SUPERVISION AND ENFORCEMENT. 1. Aim of this paper

Civil Society Europe welcomes this timely consultation in a context of growing citizens distrust in 1

ARTICLE 29 Data Protection Working Party

12583/5/17 REV 5 RS/dk 1 DGD 1C LIMITE EN

DRAFT RULES OF PROCEDURE OF THE JOINT PARLIAMENTARY SCRUTINY GROUP ON EUROPOL (version 6 September 2017) PREAMBLE

ARTICLE 29 Data Protection Working Party

***I POSITION OF THE EUROPEAN PARLIAMENT

Official Journal of the European Union REGULATIONS

NEGOTIATING FRAMEWORK. Principles governing the negotiations

Council of the European Union Brussels, 25 February 2016 (OR. en)

EUROPEAN UNION. Brussels, 27 May 2002 (OR. en) PE-CONS 3626/02. Interinstitutional File: 2001/0044 (COD) DRS 28 CODEC 544

***I DRAFT REPORT. EN United in diversity EN. European Parliament 2018/0040(COD)

COUNCIL OF THE EUROPEAN UNION. Brussels, 28 February /05 COMPET 33 MI 22 IND 13 RECH 38 ECOFIN 63 SOC 85 AG 10 EDUC 33 ENV 86 POLGEN 8

EDPS Opinion on safeguards and derogations under Article 89 GDPR in the context of a proposal for a Regulation on integrated farm statistics

6798/14 GS/np 1 DG D 2B

COMMISSION OPINION. of

Veterinary Medicines Legislation and Maximum Residue Limits in the EU

TEXTS ADOPTED. European Parliament resolution of 28 October 2015 on the European Citizens Initiative (2014/2257(INI))

Transcription:

COUNCIL OF THE EUROPEAN UNION Brussels, 22 November 2013 Interinstitutional File: 2013/0027 (COD) 16630/13 TELECOM 322 DATAPROTECT 178 CYBER 33 MI 1064 CODEC 2676 NOTE from: Presidency to: Delegations No. Cion prop.: 6342/13 TELECOM 24 DATAPROTECT 14 CYBER 2 MI 104 CODEC 313 + ADD1 +ADD2 No. prev. doc.: 16333/13 TELECOM 313 DATAPROTECT 170 CYBER 30 MI 1039 CODEC 2717 Subject: Proposal for a Directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security across the Union - Progress report The present report has been drawn up under the responsibility of the Lithuanian Presidency. It sets out the work done so far in the Council's preparatory bodies and gives an account of the state of play in the examination of the above mentioned proposal. 16630/13 HVW/ek 1

PROCEDURAL ASPECTS 1. On 12 February, the Commission submitted its proposal for a Directive of the European Parliament and of the Council concerning measures to ensure a high common level of network and information security across the Union (hereinafter: NIS Directive) with art. 114 TfEU as legal basis. 1 The proposal was part of the Cybersecurity Strategy of the European Union: An Open, Safe and Secure Cyberspace 2, concerning which the Council adopted conclusions on 25 June 2013. 3 The TTE Council of 6 June 2013 took note of the progress made with the examination of the proposal for a NIS Directive. 4 2. The European Economic and Social Committee 5 and the Committee of the Regions 6 adopted opinions on the proposal on 22 May and on 3-4 July respectively. In the European Parliament, the internal market (IMCO) committee is the leading committee with the industry (ITRE) and civil liberties (LIBE) committees as 'associated committees'. In terms of timing, the LIBE committee is planning to take a vote in November, ITRE in December and IMCO is planning to adopt a report and a set of amendments on 22-23 January 2014. 3. Under the Lithuanian Presidency, the Working Group on Telecommunications and the Information Society (WP TELE) examined the proposal in 5 meetings 7. As many delegations were only able to express preliminary views and maintained scrutiny reservations on (parts of the) text, it has not been possible for the Lithuanian Presidency to attach a revised text to this progress report. However, in the discussions, delegations raised a number of key issues and concerns, as set out below, which will need to be reflected in a revision of the text of the proposal. 1 2 3 4 5 6 7 Doc. 6342/13. Doc. 6225/13. Doc. 11357/13. Doc. 10076/13 and doc. 10457/13. T/513. 2013/C 280/05. On 18/7, 26/9, 8/10, 5/11 and 19/11/2013. 16630/13 HVW/ek 2

SUBSTANCE 4. A general description of the main elements of the proposed NIS Directive was given in the progress report for the June TTE Council. 8 Although all delegations fully acknowledge the need for action to face NIS incidents and curb cyber attacks, views differ as to how best to ensure network security throughout the EU. Whereas some delegations confirm in the article-by-article examination of the proposal that they would prefer a flexible approach, with EU-wide binding rules limited to critical infrastructure and basic requirements, complemented by optional, voluntary measures, other delegations as well as the Commission consider that only legally binding measures would bring about the necessary EU security levels. This difference in philosophy explains the differences in positions taken on the detailed provisions in the proposal, as explained below. 5. NIS strategy and NIS competent body: in view of the objective to have in place a minimum level of capability to prevent, handle and respond to risks and incidents affecting information systems, EU Member States would be required to adopt national NIS strategies, designate national competent authorities on NIS, and set up computer emergency response teams (CERTs) for NIS. Delegations acknowledge that a substantial disruption in one Member State can also affect other Member States and could support the principle of a coordinating entity at national level. However, in particular those Member States, which already adopted NIS strategies, designated competent bodies and set up a national CERT, seem to critically look at chapter II of the proposal, which deals with the national framework on NIS: they wish to make sure that the requirements that will have to be met by Member States are consistent with and do not go beyond the current national practice. Some delegations believe that the competent body should be a contact point and delegate tasks to national regulators, which have the necessary sectorspecific expertise. This should also ensure that the imposed requirements are in accordance with national security provisions. Some delegations point out that more confidence-building measures are needed in order to build trust, rather than putting the focus on administrative and bureaucratic arrangements. 8 Doc. 10076/13. 16630/13 HVW/ek 3

Other delegations seek further clarification about the terminology used in this chapter, such as 'risks' and 'threats' and wonder what the exact requirements are and also question whether these requirements should only concern the private sector or also the public sector. With regard to the competent authority and its task description, many issues require further clarification, such as whether the authority should assume operational tasks, which is something many Member States object to, and what should be the division of responsibilities with the national CERT. 6. Risk management and incident notification: 'market operators' and public administrations should properly assess the risks posed to their information systems, take appropriate measures to prevent and deal with incidents and report any serious incident having a significant impact on the core services provided to the competent authorities. On chapter IV of the proposal on security of networks and information systems of public administrations and market operators, several delegations doubt whether in addition to 'operators of critical infrastructures', also 'information society service providers' should be covered by the proposal. This concern about scope is closely linked to the definition of market operators in Chapter I and the non-exhaustive list in Annex II. Many delegations called for more clarity on the definition and for more flexibility for Member States to define which sectors constitute national critical infrastructures. Some delegations wish to limit the proposed requirements to the private sector only and others call for the security breach reporting requirements in this chapter to be voluntary in line with current national practices. The question is also raised why hardware/software manufacturers and micro enterprises are not covered and Member States also have concerns about the consistency of the proposed notification requirements related to security breaches with those in other pieces of EU legislation, such as in the regulatory framework for electronic communications, as a result of which providers of electronic communications networks or services or trust service providers are not subject to the requirements of the current proposal. In general, many delegations question whether or how Member States could actually "ensure" that parties secure their networks and notify incidents; in this regard, the appropriateness of Article 114 TfEU as a legal basis has been brought up as an issue for clarification. There are also concerns with regard to the implications of notifications on matters of privacy and confidentiality of information. 16630/13 HVW/ek 4

7. Cooperation network: in order to ensure a coordinated response to incidents, where necessary, a cooperation network on NIS risks and incidents should be created to allow permanent communication between the Commission and the 28 competent authorities. Chapter III of the proposal on cooperation between competent authorities will require further examination. Further discussion will be needed on the tasks of the cooperation network although many delegations are of the opinion that it should not assume any operational tasks; some argue in this respect that it would be better to refer to a mechanism rather than to a network. A number of organisational issues also require further clarification, such as who will chair the cooperation network, what its costs would be, and what the relationship and division of responsibilities would be with the cooperation of national CERTs with ISA and with Europol. Some delegations argue that the sharing of information in the network should be done on a voluntary basis and question the need for the proposed and dedicated 'secure information-sharing system'. The proposed early warning mechanism raises many queries and concerns, e.g. which information shall be shared at what point in time and with what possible consequences for the incident or risk. Also, many Member States question the scope of the proposed coordinated response mechanism, and call for a framework of cooperation on NIS rather than an operational incident response plan. When and under what conditions a coordinated response would be required requires further discussion. 8. With regard to the two chapters I and V of the proposal, i.e. the general provisions (which were examined under the Irish Presidency) and the final provisions respectively, a first general exchange of views took place but some provisions will need to be revisited for further consideration, such as; the application of the proposed security requirements in relation to those in the Framework Directive (2002/21/EC); the definitions of 'risk', 'incident' and 'market operator' (in connection with Annex II List of market operators); enforcement (such as notification of incidents to the police); standardisation; implementing acts (all delegations opposed the use of delegated acts in this field of work) and the transposition period (for the transposition into national law as well as for the publication of the national NIS strategy). 16630/13 HVW/ek 5

OUTLOOK 9. The article-by-article examination of the proposal shows that delegations are seeking from the Commission clarification on, but also justification for, the proposed measures as compared to the current national situations and (national and international) voluntary incident reporting and cooperation mechanisms, such as those which exist within European and international CERT communities (such as the European Government CERT Group) and which could encompass the facilitation role of ISA. In the further examination of the proposal in the WP TELE, it appears that the main challenge will be to agree on an approach, which strikes the right balance between EU-wide binding rules and optional, voluntary measures, all of which should lead to similar levels of NIS preparedness among the Member States and allow the EU to respond effectively to NIS challenges. 10. Delegations are most welcome to provide the Presidency with further drafting suggestions, which will be given due consideration in the further examination of the proposal. * * * Following its consideration by Coreper on 27 November, the Presidency presents this progress report to Council with the invitation to take note of it. 16630/13 HVW/ek 6