BETA

14 Amendments of Antanas GUOGA related to 2017/0225(COD)

Amendment 63 #
Proposal for a regulation
Recital 5 a (new)
(5a) While certification and other forms of conformity assessment for ICT products, services, and processes plays an important role, improving cybersecurity requires a multi-faceted approach spanning people, processes, and technologies. The EU must also continue to strongly emphasise and promote other efforts including cybersecurity education, training, and skills development; raising awareness at corporate executive and board-levels; promoting voluntary cyber threat information sharing; and shifting the EU from a reactive to a proactive approach to responding to threats by emphasising the prevention of successful cyber-attacks.
2018/03/02
Committee: IMCO
Amendment 180 #
Proposal for a regulation
Article 8 – paragraph 1 – point a – point 1
(1) in cooperation with industry stakeholders in a formal, standardised, and transparent process, identifying and preparing candidate European cybersecurity certification schemes for ICT products and services in accordance with Article 44 of this Regulation;
2018/03/02
Committee: IMCO
Amendment 183 #
Proposal for a regulation
Article 8 – paragraph 1 – point a – point 3
(3) compiling and publishing guidelines and developing good practices concerning the cybersecurity requirements of ICT products and services, in cooperation with national certification supervisory authorities and the industry; in a formal, standardised, and transparent process;
2018/03/02
Committee: IMCO
Amendment 184 #
Proposal for a regulation
Article 8 – paragraph 1 – point a – point 3 a (new)
(3a) in consultation with all relevant stakeholders, identifying whether standards or certification processes do not yet exist globally for identified needs, and if such gaps are determined to exist, requesting that standards development organisations to develop standards or processes;
2018/03/02
Committee: IMCO
Amendment 186 #
Proposal for a regulation
Article 8 – paragraph 1 – point b
(b) facilitate the establishment and take-up of European andor international standards for risk management and for the security of ICT products and services, as well as draw up, in collaboration with Member States, advice and guidelines regarding the technical areas related to the security requirements for operators of essential services and digital service providers, as well as regarding already existing standards, including Member States’ national standards, pursuant to Article 19(2) of Directive (EU) 2016/1148;
2018/03/02
Committee: IMCO
Amendment 188 #
Proposal for a regulation
Article 8 – paragraph 1 – point b a (new)
(ba) prioritise its work on inventorying existing national level schemes as well as developing guidelines for a possible harmonisation of these schemes in order to create mutual recognition within the Union;
2018/03/02
Committee: IMCO
Amendment 237 #
Proposal for a regulation
Article 44 – paragraph 2
2. When preparing candidate schemes referred to in paragraph 1 of this Article, ENISA shall consult all relevant stakeholders in a formal, standardised, and transparent process and closely cooperate with the Group. The Group and all relevant stakeholders shall provide ENISA with the assistance and expert advice required by ENISA in relation to the preparation of the candidate scheme, including by providing opinions where necessary.
2018/03/02
Committee: IMCO
Amendment 279 #
Proposal for a regulation
Article 46 – paragraph 1
1. A European cybersecurity certification scheme may specify one or more of the following assurance levels: basic, substantial and/or high, for ICT products and services issued under that In consultation with relevant stakeholders, ENISA shall identify or develop assurance levels to be specified in European cybersecurity certification schemes.
2018/03/02
Committee: IMCO
Amendment 288 #
Proposal for a regulation
Article 46 – paragraph 2
2. The assurance levels basic, substantial and high shall meet the following criteria respectively: (a) assurance level basic shall refer to a certificate issued in the context of a European cybersecurity certification scheme, which provides a limited degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of cybersecurity incidents; (b) assurance level substantial shall refer to a certificate issued in the context of a European cybersecurity certification scheme, which provides a substantial degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease substantially the risk of cybersecurity incidents; (c) assurance level high shall refer to a certificate issued in the context of a European cybersecurity certification scheme, which provides a higher degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service than certificates with the assurance level substantial, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent cybersecurity incidents.deleted
2018/03/02
Committee: IMCO
Amendment 294 #
Proposal for a regulation
Article 46 – paragraph 2 – point a
(a) assurance level basic shall refer to a certificate issued in the context of a European cybersecurity certification scheme, which provides a limited degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of cybersecurity incidents;deleted
2018/03/02
Committee: IMCO
Amendment 300 #
Proposal for a regulation
Article 46 – paragraph 2 – point b
(b) assurance level substantial shall refer to a certificate issued in the context of a European cybersecurity certification scheme, which provides a substantial degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease substantially the risk of cybersecurity incidents;deleted
2018/03/02
Committee: IMCO
Amendment 304 #
Proposal for a regulation
Article 46 – paragraph 2 – point c
(c) assurance level high shall refer to a certificate issued in the context of a European cybersecurity certification scheme, which provides a higher degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service than certificates with the assurance level substantial, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent cybersecurity incidents.deleted
2018/03/02
Committee: IMCO
Amendment 315 #
Proposal for a regulation
Article 47 – paragraph 1 – introductory part
1. AThe following elements shall be considered when preparing a European cybersecurity certification scheme shall include the following elements:
2018/03/02
Committee: IMCO
Amendment 326 #
Proposal for a regulation
Article 47 – paragraph 1 – point b a (new)
(ba) relevance of promoting “security by design”;
2018/03/02
Committee: IMCO