Towards a European Cloud Computing Strategy

Similar documents
R&D on Trust & Security. Vilija Juceviciene European Commission Information Society and Media Directorate General Unit F5 - Trust & Security

Security and resilience in Information Society: the European approach

ENISA EU Threat Landscape

The European Policy on Critical Information Infrastructure Protection (CIIP) Andrea SERVIDA European Commission DG INFSO.A3

Cloud Computing. Rainer Zimmermann

Shaping the Cyber Security R&D Agenda in Europe, Horizon 2020

EU funded research is keeping up trust in digital society

VdTÜV Statement on the Communication from the EU Commission A Digital Single Market Strategy for Europe

EU policy on Network and Information Security & Critical Information Infrastructures Protection

The Future of Solid State Lighting in Europe

Khoen LIEM. Industrial Policy. A systematic approach for Civil Security: From EU Security- Research Policy

Discussion on MS contribution to the WP2018

Commonwealth Cyber Declaration

13967/16 MK/mj 1 DG D 2B

Promoting Digital Economy in the Eastern Partnership. Vassilis Kopanas European Commission, DG CONNECT

The NIS Directive and Cybersecurity in

Information sharing in the EU policy on NIS & CIIP. Andrea Servida European Commission DG INFSO-A3

H2020 & THE FRENCH SECURITY RESEARCH

Harmonisation of Digital Markets in the EaP. Vassilis Kopanas European Commission, DG CONNECT

STANDARDS TO HELP COMPLY WITH EU LEGISLATION. EUROPE HAS WHAT IT TAKES INCLUDING THE WILL?

Valérie Andrianavaly European Commission DG INFSO-A3

Summary. Strategy at EU Level: Digital Agenda for Europe (DAE) What; Why; How ehealth and Digital Agenda. What s next. Key actions

ehealth in Europe: at the convergence of technology, medicine, law and society

EUROPEAN COMMISSION JOINT RESEARCH CENTRE. Information Note. JRC activities in the field of. Cybersecurity

The PICTURE project, ICT R&I priorities in EaP, areas of cooperation

Brussels, 19 May 2011 COUNCIL THE EUROPEAN UNION 10299/11 TELECOM 71 DATAPROTECT 55 JAI 332 PROCIV 66. NOTE From : COREPER

Birgit Morlion. DG Communications Networks, Content and Technology (DG CONNECT)

Call for Expressions of Interest

Cyber Security in Europe

NIS Standardisation ENISA view

Cloud Computing Standards C-SIG Plenary Brussels, 15 February Luis C. Busquets Pérez DG CONNECT E2

COMMISSION STAFF WORKING DOCUMENT EXECUTIVE SUMMARY OF THE IMPACT ASSESSMENT. Accompanying the document

EUROPEAN ORGANISATION FOR SECURITY SUPPLY CHAIN SECURITY WHITE PAPER

INTERMEDIATE EVALUATION

How the European Commission is supporting innovation in mobile health technologies Nordic Mobile Healthcare Technology Congress 2015

HEALTH IN ECSO (European Cyber Security Organisation) 18 October 2017

Security and resilience in the Information Society: the role of CERTs/CSIRTs in the context of the EU CIIP policy

COUNCIL OF THE EUROPEAN UNION. Brussels, 24 May /13. Interinstitutional File: 2013/0027 (COD)

Europe (DAE) for Telehealth

A Strategy for a secure Information Society Dialogue, Partnership and empowerment

Package of initiatives on Cybersecurity

The emerging EU certification framework: A role for ENISA Dr. Andreas Mitrakas Head of Unit EU Certification Framework Conference Brussels 01/03/18

European Union Agency for Network and Information Security

Big Data Value cppp Big Data Value Association Big Data Value ecosystem

Securing Europe's Information Society

DIGITIZING INDUSTRY, ICT STANDARDS TO

13303/17 CB/ek 1 DGE 2B

Research Infrastructures and Horizon 2020

WORK PROGRAMME

EuroHPC and the European HPC Strategy HPC User Forum September 4-6, 2018 Dearborn, Michigan, USA

COMESA CYBER SECURITY PROGRAM KHARTOUM, SUDAN

Trustworthy ICT. FP7-ICT Objective 1.5 WP 2013

NATIONAL PROGRAMME Chapter 15 Telecommunication and Post. Telecommunication and Post

ESFRI Strategic Roadmap & RI Long-term sustainability an EC overview

DIGITAL AGENDA FOR EUROPE

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

ENISA & Cybersecurity. Dr. Udo Helmbrecht Executive Director, European Network & Information Security Agency (ENISA) 25 October 2010

Cybersecurity & Digital Privacy in the Energy sector

Directive on Security of Network and Information Systems

ENISA s Position on the NIS Directive

Third public workshop of the Amsterdam Group and CODECS European Framework for C-ITS Deployment

R&D to shape the networks and services of the future

Critical Information Infrastructure Protection. Role of CIRTs and Cooperation at National Level

Cyber Security Beyond 2020

eidas Regulation (EU) 910/2014 eidas implementation State of Play

The H2020 "Secure societies" WP Policy novelties. EU Liaison Office in Brussels of the Autonomous Province of Trento 4 th February 2016

Future-Proof Security & Privacy in IoT

ENCS The European Network for Cyber Security

Cyber Security in Europe and CEER s new PEER initiative

Bringing EU Cybersecurity & privacy research results closer to the market

Securing Europe s IoT Devices and Services

Transforming Healthcare with mhealth Solutions.

Directive on security of network and information systems (NIS): State of Play

C-ITS in Europe. Gerhard Menzel, DG MOVE 7th ETSI ITS Workshop 26 th of March 2015, Helmond. Transport

European Activities towards Cooperative Mobility

ehealth Network ehealth Network Governance model for the ehealth Digital Service Infrastructure during the CEF funding

Cybersecurity Strategy of the Republic of Cyprus

SMART AND EFFICIENT ENERGY 5G PPP Phase 3 Topics ICT & ICT

The EU Digital Single Market Roadmap

ESRIF & Working Group Innovation WG 9. Alois J. Sieber Chairman ESRIF WG # 9

Interoperability and transparency The European context

H2020 WP Cybersecurity PPP topics

Building a Europe of Knowledge. Towards the Seventh Framework Programme

European Cybersecurity PPP European Cyber Security Organisation - ECSO November 2016

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

ITU Kaleidoscope 2015 Trust in the Information Society

Bradford J. Willke. 19 September 2007

ehealth Ministerial Conference 2013 Dublin May 2013 Irish Presidency Declaration

Helix Nebula Science Cloud Pre-Commercial Procurement pilot. 5 April 2016 Bob Jones, CERN

Systemic Analyser in Network Threats

The commission communication "towards a general policy on the fight against cyber crime"

U.S. Japan Internet Economy Industry Forum Joint Statement October 2013 Keidanren The American Chamber of Commerce in Japan

A comprehensive approach on personal data protection in the European Union

In Accountable IoT We Trust

Identify adequate calls and analyze the call text

New cybersecurity landscape in the EU Sławek Górniak 9. CA-Day, Berlin, 28th November 2017

***I DRAFT REPORT. EN United in diversity EN. European Parliament 2018/0328(COD)

European Directives and reglements for Information security

Between 1981 and 1983, I worked as a research assistant and for the following two years, I ran a Software Development Department.

Transcription:

Towards a European Cloud Computing Strategy Jorge Gasós European Commission Information Society and Media Directorate General Trust and Security Unit

Security, privacy, and trust in the information society Complexity, ease of use Society-protecting business models Role of end-users Technology & innovation End-users & the society Global ICT - national frontiers Economics of security Policies for privacy-respecting T&I? Trustworthy information society? Security Protection of human values Transparency, accountability Auditing and law enforcement Policy & regulation

Critical Information Infrastructure Protection Action Plan (2009) Establishment of National / Governmental CERTs and reinforced cooperation among them Early warning systems against cyber-attacks and disruptions Close collaboration with ENISA Need to coordinate the different European Commission cyber-security related activities

CIP-ICT Call 6: 5.1 Cybersecurity 9 m 01/02/2012 15/05/2012 Botnet: a network of infected computers controlled as a group without the owner s knowledge. Main instrument for cybercrime Pilot: European-wide platform for detecting, analysing, mitigating and eliminating botnets. 8 M Thematic Network to identify common requirements, processes, methods to address cyber threats. 1 M Draws on EU and MS initiatives: ENISA, EFMS, EP3R, CERTs, in collaboration with industry and academia

7th EU Research Framework Programme (2007-2013) Total 50,521 M FP7 Cooperation Programme: 32,413 M The 10 Themes Socio-economics; 623; 2% Space; 1430; 4% Security; 1400; 4% Health; 6100; 19% Transport; 4160; 13% Environment; 1890; 6% Energy; 2350; 7% NMT; 3475; 11% ICT; 9050; 28% Food, ; 1935; 6% ICT Security & Trust

Trust and security: 58 projects of FP7 call 1 and call 5 200 m Network infrastructures Identity management, privacy, trust Services infrastructures 4 projects 7 projects 8 projects 4 projects 40M 5 projects 60M 7 projects 48M Critical infrastructure protection 9 projects 20M Enabling technologies Biometrics, trusted computing, cryptography, secure SW 4 projects 4 projects 27M Networking, coordination and support Research roadmaps, metrics and benchmarks, international cooperation, coordination activities 4 projects 2 projects 5M

European Cloud Strategy January 2011 Vice President Neelie Kroes announced in Davos three axes for action: Legal Framework Data protection, privacy laws, user s rights Technical & Commercial Research & standardisation Market Member states engagement, pilots, public procurement

Cloud Computing Strategy in preparation Industry Recommendations Public Consultation analysis Cloud computing expert group EU Policy framework and many other inputs

Pillar 1: A Coherent and Integrated Approach Legal Framework Single Market Top issues to address arising from the public consultation: Data protection and security Digital content in the cloud Restricted liability for infrastructure and service providers Fair contract terms and conditions Portability and interoperability

Pillar 2: The European Cloud Partnership Public Sector Lead Market Purpose to solve problems caused by fragmentation of markets and legislation in Europe for Cloud Computing. to publish public sector requirements for clouds across Member States, regions or application areas (such as ehealth, taxation, social benefit payments) Benefits better quality of demand and supply, more competition and better interoperability market with harmonised requirements can be addressed by active cloud providers with an assured user community.

Preparing joint PCP ONE joint PCP tender Intermediate Evaluation Selection Intermediate Evaluation Selectiona Lessons learnt Dissemination Commercial Tendering Pre-Commercial Procurement Preparation phase before launching PCP Pre-commercial Procurement Management/Coordination joint PCP Large scale public procurement of end- solutions P5 P1 Formation of joint procurement constellation P2 R&D work P4 P3 Consortia of public bodies e.g. P1->P5 Supplier A Supplier B Supplier C Supplier D Supplier E Phase 1 Solution Exploration Supplier C Supplier D Supplier E Phase 2 Prototyping Supplier C Supplier E Phase 3 Original development of a limited volume of first products/services in the form of a test series Supplier A,B,C,D,E or X Phase 4 Commercialisation of products/services (commercial development) Typical Product Innovation Product Life Cycle Idea Product Solution Solution Idea Design Design Prototype First Test- Products Commercial End-Products VC & other financers Input to standardisation & regulation

Objectives of the European Cloud Partnership Phase 1 Publication of requirements through agreeing common public sector cloud requirements Develop specifications for use in procurement during phase 2 Phase 2 Procure proof-of-concept solutions on phase 1 specifications. Develop specifications for use in procurement during phase 3 Phase 3 Procure reference implementations to demonstrate conformance and performance

European Cloud Partnership Phase 1 Under a separate Grant agreement (FP7 WP13: Obj1.2 2.5M euros for CSAs) Governance (ECP Supervisor) Implementation (ECP Executive) Consortia (industry, academics, others) R&D Specifications consultations EU/Member State Implementations Through Pre-commercial procurement (FP7 WP13, 10Meuro) Tender Specifications

Pillar 3: International Cloud Computing Policy Principles for data flow, security, certification, standards Global solutions Cloud computing, being intrinsically global, calls for global solutions. This includes policy issues like data protection, interoperability, security, etc. The Commission is planning to have an active presence in the global discussions and enhanced collaboration with Member States and International stakeholders. On the International front: EU-US Hearings of experts 1 July 2011 Japan-EU Hearing of experts 19 April 2012 Research issues are discussed through bilateral arrangements in view of future joint calls for research proposals on Cloud Computing. A joint call for proposals is foreseen with Japan

Trust and security: 58 projects of FP7 call 1 and call 5 200 m Network infrastructures Identity management, privacy, trust Services infrastructures 4 projects 7 projects 8 projects 4 projects 40M 5 projects 60M 7 projects 48M Critical infrastructure protection 9 projects 20M Enabling technologies Biometrics, trusted computing, cryptography, secure SW 4 projects 4 projects 27M Networking, coordination and support Research roadmaps, metrics and benchmarks, international cooperation, coordination activities 4 projects 2 projects 5M

Future Research Security and privacy in Cloud Computing Software, services and cloud computing Pre-Commercial Procurement for the European Cloud Partnership Horizon 2020

For more information FP7 http://cordis.europa.eu/fp7/ http://cordis.europa.eu/fp7/ict/ Trust & Security http://cordis.europa.eu/fp7/ict/security/ Cloud Computing http://ec.europa.eu/information_society/activities /cloudcomputing/library/index_en.htm E-mail INFSO-TRUST-SECURITY@ec.europa.eu 17