14 Amendments of Antanas GUOGA related to 2017/0225(COD)
Amendment 63 #
Proposal for a regulation
Recital 5 a (new)
Recital 5 a (new)
(5a) While certification and other forms of conformity assessment for ICT products, services, and processes plays an important role, improving cybersecurity requires a multi-faceted approach spanning people, processes, and technologies. The EU must also continue to strongly emphasise and promote other efforts including cybersecurity education, training, and skills development; raising awareness at corporate executive and board-levels; promoting voluntary cyber threat information sharing; and shifting the EU from a reactive to a proactive approach to responding to threats by emphasising the prevention of successful cyber-attacks.
Amendment 180 #
Proposal for a regulation
Article 8 – paragraph 1 – point a – point 1
Article 8 – paragraph 1 – point a – point 1
(1) in cooperation with industry stakeholders in a formal, standardised, and transparent process, identifying and preparing candidate European cybersecurity certification schemes for ICT products and services in accordance with Article 44 of this Regulation;
Amendment 183 #
Proposal for a regulation
Article 8 – paragraph 1 – point a – point 3
Article 8 – paragraph 1 – point a – point 3
(3) compiling and publishing guidelines and developing good practices concerning the cybersecurity requirements of ICT products and services, in cooperation with national certification supervisory authorities and the industry; in a formal, standardised, and transparent process;
Amendment 184 #
Proposal for a regulation
Article 8 – paragraph 1 – point a – point 3 a (new)
Article 8 – paragraph 1 – point a – point 3 a (new)
(3a) in consultation with all relevant stakeholders, identifying whether standards or certification processes do not yet exist globally for identified needs, and if such gaps are determined to exist, requesting that standards development organisations to develop standards or processes;
Amendment 186 #
Proposal for a regulation
Article 8 – paragraph 1 – point b
Article 8 – paragraph 1 – point b
(b) facilitate the establishment and take-up of European andor international standards for risk management and for the security of ICT products and services, as well as draw up, in collaboration with Member States, advice and guidelines regarding the technical areas related to the security requirements for operators of essential services and digital service providers, as well as regarding already existing standards, including Member States’ national standards, pursuant to Article 19(2) of Directive (EU) 2016/1148;
Amendment 188 #
Proposal for a regulation
Article 8 – paragraph 1 – point b a (new)
Article 8 – paragraph 1 – point b a (new)
(ba) prioritise its work on inventorying existing national level schemes as well as developing guidelines for a possible harmonisation of these schemes in order to create mutual recognition within the Union;
Amendment 237 #
Proposal for a regulation
Article 44 – paragraph 2
Article 44 – paragraph 2
2. When preparing candidate schemes referred to in paragraph 1 of this Article, ENISA shall consult all relevant stakeholders in a formal, standardised, and transparent process and closely cooperate with the Group. The Group and all relevant stakeholders shall provide ENISA with the assistance and expert advice required by ENISA in relation to the preparation of the candidate scheme, including by providing opinions where necessary.
Amendment 279 #
Proposal for a regulation
Article 46 – paragraph 1
Article 46 – paragraph 1
1. A European cybersecurity certification scheme may specify one or more of the following assurance levels: basic, substantial and/or high, for ICT products and services issued under that In consultation with relevant stakeholders, ENISA shall identify or develop assurance levels to be specified in European cybersecurity certification schemes.
Amendment 288 #
Proposal for a regulation
Article 46 – paragraph 2
Article 46 – paragraph 2
Amendment 294 #
Proposal for a regulation
Article 46 – paragraph 2 – point a
Article 46 – paragraph 2 – point a
Amendment 300 #
Proposal for a regulation
Article 46 – paragraph 2 – point b
Article 46 – paragraph 2 – point b
Amendment 304 #
Proposal for a regulation
Article 46 – paragraph 2 – point c
Article 46 – paragraph 2 – point c
Amendment 315 #
Proposal for a regulation
Article 47 – paragraph 1 – introductory part
Article 47 – paragraph 1 – introductory part
1. AThe following elements shall be considered when preparing a European cybersecurity certification scheme shall include the following elements:
Amendment 326 #
Proposal for a regulation
Article 47 – paragraph 1 – point b a (new)
Article 47 – paragraph 1 – point b a (new)
(ba) relevance of promoting “security by design”;