Critical Infrastructure Protection in the European Union

Similar documents
Legislative Framework

H2020 Opportunities in the Area of Security and Critical Infrastructure Protection

GENERIC CONTROL SYSTEM ARCHITECTURE FOR CRITICAL INFRASTRUCTURE PROTECTION

Directive on security of network and information systems (NIS): State of Play

Gas Infrastructure Europe. Security Risk Assessment Methodology

The NIS Directive and Cybersecurity in

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

Valérie Andrianavaly European Commission DG INFSO-A3

Security and resilience in Information Society: the European approach

NIS-Directive and Smart Grids

Directive on Security of Network and Information Systems

Energy Assurance Plans

The Role of ENISA in the Implementation of the NIS Directive Anna Sarri Officer in NIS CIP Workshop Vienna 19 th September 2017

Information sharing in the EU policy on NIS & CIIP. Andrea Servida European Commission DG INFSO-A3

Creating NIS Compliant Country in a Non-Regulated Environment. Jurica Čular

SCADA and Smart Grid Security Tests

Secure Societies Work Programme Call

ehealth action in the EU

EU policy on Network and Information Security & Critical Information Infrastructures Protection

CRITICAL INFRASTRUCTURE PROTECTION-THE FOUNDATION OF NATIONAL SECURITY (2)

Cybersecurity & Digital Privacy in the Energy sector

FINNISH APPROACH TO CRITICAL INFRASTRUCTURE PROTECTION

The European Policy on Critical Information Infrastructure Protection (CIIP) Andrea SERVIDA European Commission DG INFSO.A3

Securing Europe's Information Society

A Strategy for a secure Information Society Dialogue, Partnership and empowerment

Security and resilience in the Information Society: the role of CERTs/CSIRTs in the context of the EU CIIP policy

Enhancing the cyber security &

Network and Information Security Directive

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

Cyber Security in Europe and CEER s new PEER initiative

Critical Infrastructure Protection & Resilience Europe / Asia. Conference Discussion Reviews

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

Cyber Security in Europe

Final Report. Study on Critical Dependencies of Energy, Finance and Transport Infrastructures on ICT Infrastructure. European Commission

COMMISSION RECOMMENDATION. of on Coordinated Response to Large Scale Cybersecurity Incidents and Crises

INSPIRE status report

Critical Information Infrastructure Protection. Role of CIRTs and Cooperation at National Level

H2020 & THE FRENCH SECURITY RESEARCH

Infrastructures and Service Dimitra Liveri Network and Information Security Expert, ENISA

COUNCIL OF THE EUROPEAN UNION. Brussels, 24 May /13. Interinstitutional File: 2013/0027 (COD)

INSPIRE in a nutshell, and overview of the European Union Location Framework

ENISA s Position on the NIS Directive

Security Liaison Officer - SLO. All-Hazard Guide for Transport Infrastructure - ALLTRAIN

EISAS Enhanced Roadmap 2012

Action Plan to enhance preparedness against CBRN security risks

PROTECTING NATIONAL CRITICAL INFRASTRUCTURE AGAINST CYBER ATTACKS BEST PRACTICES RELATED TO TECHNOLOGY AND STANDARDS FROM EUROPE BANGKOK

European Responsible Care Forum. Security & Safe Maintenance

21ST OSCE ECONOMIC AND ENVIRONMENTAL FORUM

STRATEGY ATIONAL. National Strategy. for Critical Infrastructure. Government

EUROPEAN COMMISSION JOINT RESEARCH CENTRE. Information Note. JRC activities in the field of. Cybersecurity

Executive Order on Coordinating National Resilience to Electromagnetic Pulses

Exploring the European Commission s Network and Information Security Directive (NIS) What every CISO should know

2 The BEinGRID Project

Shaping the Cyber Security R&D Agenda in Europe, Horizon 2020

The Network and Information Security Directive - ENISA's contribution

Khoen LIEM. Industrial Policy. A systematic approach for Civil Security: From EU Security- Research Policy

Physical Security Reliability Standard Implementation

Cybersecurity Policy in the EU: Security Directive - Security for the data in the cloud

Resolution adopted by the General Assembly. [on the report of the Second Committee (A/60/488/Add.3)]

Seventh Framework Programme Security Research. Health Security Committee CBRN Section. 30 September by Clément Williamson

European Union Agency for Network and Information Security

National Infrastructure Protection Plan (NIPP) Transportation Sector Specific Plan (TSSP) and The TSSP R&D Working Group

The Australian Government s Approach to Critical Infrastructure Resilience

Energy Assurance State Examples and Regional Markets Jeffrey R. Pillon, Director of Energy Assurance National Association of State Energy Officials

National Policy and Guiding Principles

Cybersecurity Presidential Policy Directive Frequently Asked Questions. kpmg.com

Brussels, 19 May 2011 COUNCIL THE EUROPEAN UNION 10299/11 TELECOM 71 DATAPROTECT 55 JAI 332 PROCIV 66. NOTE From : COREPER

Europeanizing Transport Security

European Cybersecurity PPP European Cyber Security Organisation - ECSO November 2016

ehealth Ministerial Conference 2013 Dublin May 2013 Irish Presidency Declaration

Presidential Documents

Discussion on MS contribution to the WP2018

PIPELINE SECURITY An Overview of TSA Programs

The Office of Infrastructure Protection

Resilience at JRC. Naouma Kourti. Dep. Head of Unit. Technology Innovation in security Security, Space and Migration Directorate

COMMISSION STAFF WORKING DOCUMENT EXECUTIVE SUMMARY OF THE IMPACT ASSESSMENT. Accompanying the document

EU Civil Protection Mechanism

The CIPRNet Project and the EISAC. Perspective. Bernhard M. Hämmerli& CIPRNet team Co-ordinator Erich Rome, Fraunhofer IAIS (Sankt Augustin, Germany)

Dr. Emadeldin Helmy Cyber Risk & Resilience Bus. Continuity Exec. Director, NTRA. The African Internet Governance Forum - AfIGF Dec 2017, Egypt

INCEPTION IMPACT ASSESSMENT. A. Context, Problem definition and Subsidiarity Check

Building A Disaster Resilient Quebec

Research Infrastructures and Horizon 2020

Implementation Strategy for Cybersecurity Workshop ITU 2016

The Federal Council s Basic Strategy. for Critical Infrastructure Protection

Research Infrastructures and Horizon 2020

United States Energy Association Energy Technology and Governance Program REQUEST FOR PROPOSALS

EUROPEAN ORGANISATION FOR SECURITY SUPPLY CHAIN SECURITY WHITE PAPER

Strategic Transport Research and Innovation Agenda - STRIA

CIPMA CRITICAL INFRASTRUCTURE PROTECTION MODELLING & ANALYSIS. Overview of CIP in Australia

Internet copy. EasyGo security policy. Annex 1.3 to Joint Venture Agreement Toll Service Provider Agreement

Building a Europe of Knowledge. Towards the Seventh Framework Programme

All-Hazards Approach to Water Sector Security & Preparedness ANSI-HSSP Arlington, VA November 9, 2011

INSPIRE relevant policy developments in the EU's digital economy initiatives

H Work programme SC7 Secure Societies. October 2017, Trondheim

PD 7: Homeland Security Presidential Directive 7: Critical Infrastructure Identification, Prioritization, and Protection

MDS1 SESAR. The Single European Sky Programme DG TREN

EU LEIT-ICT program and SE position on FP9

EU Research for Secure Societies

SPACE for SDGs a Global Partnership

COUNCIL OF THE EUROPEAN UNION. Brussels, 28 January 2003 (OR. en) 15723/02 TELECOM 78 JAI 307 PESC 593

Transcription:

20 January, 2015 The European GNSS Programmes 1 ICG9, Prague 9-14 November 2014 Critical Infrastructure Protection in the European Union

20 January, 2015 The European GNSS Programmes 2 Each EU Member State is responsible for its own critical infrastructures Since 2006, the European Commission is taking EU-wide inititiatives (coordination, legislation)

20 January, 2015 The European GNSS Programmes 3 The European Programme for Critical Infrastructure Protection (EPCIP) of 12 December 2006 sets the overall framework for activities aimed at improving the protection of critical infrastructure in Europe - across all EU States and in all relevant sectors of economic activity.

20 January, 2015 The European GNSS Programmes 4 The four main focus areas of the current EPCIP are: 1. A procedure for the identification and designation of European critical infrastructures and assessment of the need to improve their protection, addressed in detail in Council Directive 2008/114/EC; 2. Measures designed to facilitate the implementation of EPCIP, including an Action Plan, the Critical Infrastructure Warning Information Network (CIWIN), the use of CIP expert groups at EU level, a CIP information-sharing process, and the identification and analysis of interdependencies; 3. Funding for CIP-related measures and projects focussing on Prevention, Preparedness and Consequence Management of Terrorism and other Security- Related Risks for the period 2007-2013; and 4. The development of an EPCIP external dimension.

20 January, 2015 The European GNSS Programmes 5 1. A key pillar of this programme is the COUNCIL DIRECTIVE 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection

20 January, 2015 The European GNSS Programmes 6 Following Directive 2008/114/EC, a 'Critical infrastructure means an asset, system or part thereof located in Member States which is essential for the maintenance of vital societal functions, health, safety, security, economic or social well-being of people, and the disruption or destruction of which would have a significant impact in a Member State as a result of the failure to maintain those functions; European critical infrastructure or ECI means critical infrastructure located in Member States the disruption or destruction of which would have a significant impact on at least two Member States. The significance of the impact shall be assessed in terms of cross-cutting criteria. This includes effects resulting from crosssector dependencies on other types of infrastructure

20 January, 2015 The European GNSS Programmes 7 List of ECI sectors I Energy 1. Electricity Infrastructures and facilities for generation and transmission of electricity in respect of supply electricity 2. Oil production, refining, treatment, storage and transmission by pipelines 3. Gas production, refining, treatment, storage and transmission by pipelines LNG terminals II Transport 4. Road transport 5. Rail transport 6. Air transport 7. Inland waterways transport 8. Ocean and short-sea shipping and port

20 January, 2015 The European GNSS Programmes 8 2. The Commission has developed a Critical Infrastructure Warning Information Network (CIWIN), providing an internet based multi-level system for exchanging critical infrastructure protection ideas, studies and good practices. The CIWIN portal, which has been up and running since mid-january 2013, also serves as a repository for CIP related information.

20 January, 2015 The European GNSS Programmes 9 NEW APPROACH Taking into account the developments since the adoption of the 2006 EPCIP Communication, an updated approach to the EU CIP policy has become necessary

20 January, 2015 The European GNSS Programmes 10 On 28 August 2013 a 'COMMISSION STAFF WORKING DOCUMENT on a new approach to the European Programme for Critical Infrastructure Protection Making European Critical Infrastructures more secure' was adopted This document sets out a revised and more practical implementation of the European Programme for Critical Infrastructure Protection (EPCIP).

20 January, 2015 The European GNSS Programmes 11 It provides a stocktaking analysis of the elements of the current programme and proposes a reshaped EU CIP approach, based on the practical implementation of activities under the prevention, preparedness and response work streams. A part of our new approach is looking at the interdependencies between critical infrastructures, industry, and state actors. Threats to a single critical infrastructure can have a very significant impact on a broad range of actors in different infrastructures and more widely.

20 January, 2015 The European GNSS Programmes 12 Of course, the effects of those interdependencies are not limited to single countries. Many critical infrastructures have a cross border dimension. In addition to interdependencies between sectors, there are also many interdependencies within the same sector but spanning a number of European countries, e.g. the interconnected national high-voltage electricity grids

20 January, 2015 The European GNSS Programmes 13 Pilot phase The review process of the current EPCIP, conducted in close cooperation with the Member States and other stakeholders, revealed that there has not been enough consideration of the links between critical infrastructures in different sectors, nor indeed across national boundaries. In order to properly protect our critical infrastructures, and in order to build their resilience, we need a new approach which will tackle this gap. To pilot the new approach, the Commission will start by working with four critical infrastructures of European dimension: Eurocontrol (EU Air Traffic Management Network Manager), Galileo, the electricity transmission grid and the gas transmission network.

20 January, 2015 The European GNSS Programmes 14 I. Prevention. Setting up tools for risk assessment and risk management, II. Preparedness. How can EU and Member States prepare in response to events affecting European critical infrastructures. III. Response Which mechanisms for long-term recovery of critical services

20 January, 2015 The European GNSS Programmes 15 WAY AHEAD The pilot phase for the ECI projects has started. The Commission will continue to develop protection and resilience measures. The Commission's role remains one of facilitating and supporting the work of critical infrastructures, Member States, and industry and providing services which those actors can use to improve CIP across Europe.