BETA

31 Amendments of Pilar DEL CASTILLO VERA related to 2017/0225(COD)

Amendment 144 #
Proposal for a regulation
Recital 40
(40) The Management Board, composed of the Member States and the Commission, should define the general direction of the Agency’s operations and ensure that it carries out its tasks in accordance with this Regulation. The Management Board should be entrusted with the powers necessary to establish the budget, verify its execution, adopt the appropriate financial rules, establish transparent working procedures for decision making by the Agency, adopt the Agency’s Single Programming Document, adopt its own rules of procedure, appoint the Executive Director and decide on the extension of the Executive Director’s term of office and on the termination thereof. Taking into account the highly technical nature of the Agency's mission, members of the Management Board should have appropriate experience in issues within the scope of the Agency's mission.
2018/04/30
Committee: ITRE
Amendment 163 #
Proposal for a regulation
Recital 47
(47) Conformity assessment is the process demonstrating whether specified requirements relating to a product, process, service, system, person or body have been fulfilled. For the purposes of this Regulation, certification should be considered as a type of conformity assessment regarding the cybersecurity features ofand practices comprised in a product, process, service, system, or a combination of those ("ICT products and services") by an independent third party, other than the product manufacturer or service provider. Certification cannot guarantee per se that certified ICT processes and systems result in ICT products and services that are cyber secure. It is rather a procedure and technical methodology to attest that ICT products and services as well as processes and systems have been tested and that they comply with certain cybersecurity requirements laid down elsewhere, for example as specified in technicalrelevant standards.
2018/04/30
Committee: ITRE
Amendment 203 #
Proposal for a regulation
Article 1 – paragraph 1 – point b
(b) lays down a framework for the establishment of European cybersecurity certification schemes for the purpose of ensuring an adequate level of cybersecurity of ICT products, processes and services in the Union. Such framework shall apply without prejudice to specific provisions regarding voluntary or mandatory certification in other Union acts.
2018/04/30
Committee: ITRE
Amendment 216 #
Proposal for a regulation
Article 2 – paragraph 1 – point 9
(9) ‘European cybersecurity certification scheme’ means the comprehensive set of rules, technical requirements, standards and procedures defined at Union level and according to standards or ICT technical specifications as defined in Regulation (EU) No 1025/2012, applying to the certification of Information and Communication Technology (ICT) products, processes and services falling under the scope of that specific scheme;
2018/04/30
Committee: ITRE
Amendment 221 #
Proposal for a regulation
Article 2 – paragraph 1 – point 9
(9) ‘European cybersecurity certification scheme’ means the comprehensive set of rules, technical requirements, standards and procedures defined at Union level applying to the certification of Information and Communication Technology (ICT) products and services falling under the scope of that specific scheme;
2018/04/30
Committee: ITRE
Amendment 231 #
Proposal for a regulation
Article 2 – paragraph 1 – point 11
(11) ‘ICT product and service’ means any product, process, service that is an element or group of elements of network and information systems;
2018/04/30
Committee: ITRE
Amendment 322 #
Proposal for a regulation
Article 8 – paragraph 1 – point a – point 1
(1) In cooperation with industry stakeholders in a formal, standardised and transparent process, identifying and preparing candidate European cybersecurity certification schemes for ICT products and services in accordance with Article 44 of this Regulation;
2018/04/30
Committee: ITRE
Amendment 330 #
Proposal for a regulation
Article 8 – paragraph 1 – point a – point 3
(3) compiling and publishing guidelines and developing good practices concerning the cybersecurity requirements of ICT products and services, in cooperation with national certification supervisory authorities and the industry in a formal, standardised and transparent process;
2018/04/30
Committee: ITRE
Amendment 341 #
Proposal for a regulation
Article 8 – paragraph 1 – point b – point i (new)
i) b) promote, depending on the level of risk, the use of additional means to certification of conformance to cybersecurity standards
2018/04/30
Committee: ITRE
Amendment 403 #
Proposal for a regulation
Article 43 – paragraph 1
A European cybersecurity certification scheme shall attest that the ICT products, processes and services that have been certified in accordance with such scheme comply with specified requirements according to standards, as regards their ability to resist at a given level of assurance, actions that aim to compromise the availability, authenticity, integrity or confidentiality of stored or transmitted or processed dat a or the functions or services offered by, or accessible via, those products, processes, services and systemsgiven level of assurance.
2018/04/30
Committee: ITRE
Amendment 423 #
Proposal for a regulation
Article 44 – paragraph 2
2. When preparing candidate schemes referred to in paragraph 1 of this Article, ENISA shall consult all relevant stakeholders in a formal, standardised and transparent process, and closely cooperate with the Group. The Group and all relevant stakeholders shall provide ENISA with the assistance and expert advice required by ENISA in relation to the preparation of the candidate scheme, including by providing opinions where necessary.
2018/04/30
Committee: ITRE
Amendment 435 #
Proposal for a regulation
Article 44 – paragraph 4
4. The Commission, based on the candidate scheme proposed by ENISA, may adopt implementing acts, in accordance with Article 55(1), providing for European cybersecurity certification schemes for ICT products, processes and services meeting the requirements of Articles 45, 46 and 47 of this Regulation.
2018/04/30
Committee: ITRE
Amendment 459 #
Proposal for a regulation
Article 45 – paragraph 1 – point g – point i (new)
(i) (h) ensure that ICT products and services are developed according to the security requirements of the particular scheme
2018/04/30
Committee: ITRE
Amendment 470 #
Proposal for a regulation
Article 46 – paragraph 1
1. A European cybersecurity certification scheme may specify one or more of the following assurance levels: basic, substantial and/or high, for ICT products andassurance requirements based on the risks and threats determined by the context in which the product, process or services issued under that schem to operate.
2018/04/30
Committee: ITRE
Amendment 473 #
Proposal for a regulation
Article 46 – paragraph 1 – subparagraph 1 (new)
2. ENISA shall identify or develop assurance levels to be specified in European cybersecurity certification schemes in consultation with interested stakeholders.
2018/04/30
Committee: ITRE
Amendment 475 #
Proposal for a regulation
Article 46 – paragraph 2
2. The assurance levels basic, substantial and high shall meet the following criteria respectively: (a) a certificate issued in the context of a European cybersecurity certification scheme, which provides a limited degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of cybersecurity incidents; (b) refer to a certificate issued in the context of a European cybersecurity certification scheme, which provides a substantial degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease substantially the risk of cybersecurity incidents; (c) a certificate issued in the context of a European cybersecurity certification scheme, which provides a higher degree of confidence in the claimed or asserted cybersecurity qualities of an ICT product or service than certificates with the assurance level substantial, and is characterised with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent cybersecurity incidents.deleted assurance level basic shall refer to assurance level substantial shall assurance level high shall refer to
2018/04/30
Committee: ITRE
Amendment 516 #
Proposal for a regulation
Article 47 – paragraph 1 – point a
(a) subject-matter and scope of the certification, including the type or categories of ICT products, processes and services covered;
2018/04/30
Committee: ITRE
Amendment 518 #
Proposal for a regulation
Article 47 – paragraph 1 – point b
(b) detailed specification of the cybersecurity requirements against which the specific ICT products and services are evaluated, for example by reference to Union or international standards or technical specifications; certification requirements should be defined in such a way that certification can be built into or based on the producer's systematic security processes followed during the development and lifecycle of the product or service in question;
2018/04/30
Committee: ITRE
Amendment 523 #
Proposal for a regulation
Article 47 – paragraph 1 – point b – point i (new)
(i) (c) where appropriate promoting "security by design"
2018/04/30
Committee: ITRE
Amendment 531 #
Proposal for a regulation
Article 47 – paragraph 1 – point h
(h) conditions for granting, maintaining, continuing, renewing, extending and reducing the scope of certification;
2018/04/30
Committee: ITRE
Amendment 536 #
Proposal for a regulation
Article 47 – paragraph 1 – point l
(l) identification of national or international cybersecurity certification schemes covering the same type or categories of ICT products and services, security requirements and evaluation criteria and methods;
2018/04/30
Committee: ITRE
Amendment 537 #
Proposal for a regulation
Article 47 – paragraph 1 – point l
(l) identification of national or international cybersecurity certification schemes or industry-led initiatives covering the same type or categories of ICT products, processes and services;
2018/04/30
Committee: ITRE
Amendment 538 #
Proposal for a regulation
Article 47 – paragraph 1 – point l a (new)
(la) (ma) where applicable, the validity period of the certificate.
2018/04/30
Committee: ITRE
Amendment 549 #
Proposal for a regulation
Article 48 – paragraph 1
1. ICT products, processes and services that have been certified under a European cybersecurity certification scheme adopted pursuant to Article 44 shall be presumed to be compliant with the requirements of such scheme.
2018/04/30
Committee: ITRE
Amendment 568 #
Proposal for a regulation
Article 48 – paragraph 5
5. The natural or legal person which submits its ICT products, processes or services to the certification mechanism shall provide the conformity assessment body referred to in Article 51 with all information necessary to conduct the certification procedure.
2018/04/30
Committee: ITRE
Amendment 572 #
Proposal for a regulation
Article 48 – paragraph 6
6. Certificates shall be issued for a maximum period of three years the period defined by the particular certification scheme and may be renewed, under the same conditions, provided that the relevant requirements continue to be met.
2018/04/30
Committee: ITRE
Amendment 580 #
Proposal for a regulation
Article 49 – paragraph 1
1. Without prejudice to paragraph 3, national cybersecurity certification schemes and the related procedures for the ICT products, processes and services covered by a European cybersecurity certification scheme shall cease to produce effects from the date established in the implementing act adopted pursuant Article 44(4). Existing national cybersecurity certification schemes and the related procedures for the ICT products, processes and services not covered by a European cybersecurity certification scheme shall continue to exist.
2018/04/30
Committee: ITRE
Amendment 583 #
Proposal for a regulation
Article 49 – paragraph 2
2. Member States shall not introduce new national cybersecurity certification schemes for ICT products, processes and services covered by a European cybersecurity certification scheme in force.
2018/04/30
Committee: ITRE
Amendment 596 #
Proposal for a regulation
Article 50 – paragraph 6 – point d
(d) cooperate with other national certification supervisory authorities or other public authorities, including by sharing information on possible non- compliance of ICT products, processes and services with the requirements of this Regulation or specific European cybersecurity certification schemes;
2018/04/30
Committee: ITRE
Amendment 600 #
Proposal for a regulation
Article 50 – paragraph 8
8. National certification supervisory authorities shall cooperate amongst each other and the Commission and, in particular, exchange information, experiences and good practices as regards cybersecurity certification and technical issues concerning cybersecurity of ICT products, processes and services.
2018/04/30
Committee: ITRE
Amendment 612 #
Proposal for a regulation
Article 53 – paragraph 3 – point f – point i (new)
(i) (g) to facilitate alignment of European cybersecurity schemes with internationally recognised standards, including by: reviewing existing European cybersecurity schemes and, where appropriate, making recommendations to ENISA to engage with relevant international standardisation organisations to address insufficiencies or gaps in available internationally recognised standards.
2018/04/30
Committee: ITRE