Standardization mandate addressed to CEN, CENELEC and ETSI in the field of Information Society Standardization

Similar documents
EUROPEAN COMMISSION Enterprise Directorate-General

European Standards- preparation, approval and role of CEN. Ashok Ganesh Deputy Director - Standards

European Standards & Community Specifications

EUROPEAN COMMISSION DIRECTORATE GENERAL FOR INTERPRETATION

CEN and CENELEC Position Paper on the draft regulation ''Cybersecurity Act''

European Commission Directorate General Enterprise and Industry INSTITUTIONAL FRAMEWORK ON

NIS Standardisation ENISA view

Status of activities Joint Working Group on standards for Smart Grids in Europe

New CEN-CENELEC Technical Committees for Infosec and Data Protection Standardization (TC8) Brussels - 19 September 2017 Alessandro GUARINO Chair,

Electronic Commerce Working Group report

Mandate to CEN, CENELEC and ETSI for Standardisation in the field of electric motors

Standardization and Regulations in the EU/EFTA

The emerging EU certification framework: A role for ENISA Dr. Andreas Mitrakas Head of Unit EU Certification Framework Conference Brussels 01/03/18

New cybersecurity landscape in the EU Sławek Górniak 9. CA-Day, Berlin, 28th November 2017

M403 ehealth Interoperability Overview

EUROPEAN COMMISSION DIRECTORATE-GENERAL INFORMATION SOCIETY AND MEDIA

Coordination Meeting of Standardisation Activities for assessing the Environmental Impact of ICT

EUROPEAN COMMISSION ENTERPRISE AND INDUSTRY DIRECTORATE-GENERAL

INSPIRE status report

This report was prepared by the Information Commissioner s Office, United Kingdom (hereafter UK ICO ).

Recent developments CEN and CENELEC

eidas Regulation (EU) 910/2014 eidas implementation State of Play

EU EHEALTH INTEROPERABILITY,

EUROPEAN ACCREDITATION LEGAL FRAMEWORK

Cyber Security in Europe

The European Single Electronic Format (ESEF)

Friedrich Smaxwil CEN President. CEN European Committee for Standardization

The European System of Standardization in the Globalized Economy. AFSEC General Assembly Johannesburg, 10 August 2010

Cybersecurity Policy in the EU: Security Directive - Security for the data in the cloud

CEN/ISSS Workshop on Document Processing for accessibility (WS DPA) Business Plan V1. Approved at the Kick-off meeting

Memorandum of Understanding

ISO/IEC INTERNATIONAL STANDARD. Information technology EAN/UCC Application Identifiers and Fact Data Identifiers and Maintenance

EC Mandate: Adaptation to climate change use of standards to make key infrastructures more resilient. Ab de Buck/ Caroline van Hoek

The European Standards Organisations (ESOs) Outreach Activities

13967/16 MK/mj 1 DG D 2B

1- ASECAP participation

Some keynote messages on standardization and trade between US and EU

The role of Standardization in support of harmonization

ARTICLE 29 DATA PROTECTION WORKING PARTY

dpmr MEMORANDUM OF UNDERSTANDING

Standard Setting and Revision Procedure

ACCAB. Accreditation Commission For Conformity Assessment Bodies

The European approach of using standards in support of regional legislation and free circulation of goods/services

VdTÜV Statement on the Communication from the EU Commission A Digital Single Market Strategy for Europe

COUNCIL OF THE EUROPEAN UNION. Brussels, 28 January 2003 (OR. en) 15723/02 TELECOM 78 JAI 307 PESC 593

ASSESSMENT SUMMARY XHTML 1.1 (W3C) Date: 27/03/ / 6 Doc.Version: 0.90

This document is a preview generated by EVS

Norme NET 4 Européenne de Télécommunication

Collective Letter 17_3382 CEL/GC/grg 20 July 2017 page 1 of 24

RESOLUTION 45 (Rev. Hyderabad, 2010)

e-invoicing, the standards approach

Revised November EFESC Handbook

CEN Workshop Standards Compliant Formats for Fatigue Test Data (FaTeDa) Project Plan

Global Specification Protocol for Organisations Certifying to an ISO Standard related to Market, Opinion and Social Research.

II) Overview of the draft VA on the basis of the criteria included in Annex VIII of Directive 2005/32/EC

How the European Commission is supporting innovation in mobile health technologies Nordic Mobile Healthcare Technology Congress 2015

ISO/IEC/ IEEE INTERNATIONAL STANDARD. Systems and software engineering Architecture description

Electronic signature framework

Directive on security of network and information systems (NIS): State of Play

Standardization of Knowledge and Skills for IT Security

ENISA s Position on the NIS Directive

COMMISSION STAFF WORKING DOCUMENT EXECUTIVE SUMMARY OF THE IMPACT ASSESSMENT. Accompanying the document

ehealth Interoperability Workshop the Government and Expert View CEN/ISSS ehealth Standardization Focus Group, targets and work plan

Overview on the Project achievements

Belgrade Serbia November 2010 Jan Coenraads,

Conformity Assessment Schemes and Interoperability Testing (1) Keith Mainwaring ITU Telecommunication Standardization Bureau (TSB) Consultant

SG-CG/SGIS SG-CG/SGIS. ETSI Cyber Security Workshop Sophia Antipolis, France, January the 16th, 2013 Jean-Pierre Mennella, Alstom Grid

eidas Regulation eid and assurance levels Outcome of eias study

First Set of Standards for the grid. ISGF Webinar : 11th July 2013 Dinesh Chand Sharma Director Standardization, Policy and Regulation

THE REGULATORY ENVIRONMENT IN EUROPE

ETSI Electronic Signatures and Infrastructures (ESI) TC

ICB Industry Consultation Body

This document is a preview generated by EVS

Information technology - Security techniques - Privacy framework

ENISA And Standards Adri án Belmonte ETSI Security Week Event Sophia Antipolis (France) 22th June

DIRECTORS OF METHODOLOGY/IT DIRECTORS JOINT STEERING GROUP 18 NOVEMBER 2015

A comprehensive approach on personal data protection in the European Union

Valérie Andrianavaly European Commission DG INFSO-A3

ISO/IEC TR Information technology Security techniques Guidelines for the use and management of Trusted Third Party services

DIGITAL AGENDA FOR EUROPE

Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679)

Code Administration Code of Practice

ISO/IEC INTERNATIONAL STANDARD

Audit Report. English Speaking Board (ESB)

Information sharing in the EU policy on NIS & CIIP. Andrea Servida European Commission DG INFSO-A3

Resolution adopted by the General Assembly on 21 December [on the report of the Second Committee (A/64/422/Add.3)]

Cybersecurity. Quality. security LED-Modul. basis. Comments by the electrical industry on the EU Cybersecurity Act. manufacturer s declaration

CONCLUSIONS OF THE WESTERN BALKANS DIGITAL SUMMIT APRIL, SKOPJE

Support-EAM. Publishable Executive Summary SIXTH FRAMEWORK PROGRAMME. Project/Contract no. : IST SSA. the 6th Framework Programme

Promoting accountability and transparency of multistakeholder partnerships for the implementation of the 2030 Agenda

ehealth Network ehealth Network Governance model for the ehealth Digital Service Infrastructure during the CEF funding

This document is a preview generated by EVS

IETF TRUST. Legal Provisions Relating to IETF Documents. February 12, Effective Date: February 15, 2009

DIGITIZING INDUSTRY, ICT STANDARDS TO

Kingdom of Saudi Arabia. Licensing of Data Telecommunications Services

Plenipotentiary Conference (PP- 14) Busan, 20 October 7 November 2014

ETSI TC GRID in 5mn!

FIRE REDUCTION STRATEGY. Fire & Emergency Services Authority GOVERNMENT OF SAMOA April 2017

Brussels, 19 May 2011 COUNCIL THE EUROPEAN UNION 10299/11 TELECOM 71 DATAPROTECT 55 JAI 332 PROCIV 66. NOTE From : COREPER

Raising standards for consumers

Transcription:

Mandate/ 290 EN Standardization mandate addressed to CEN, CENELEC and ETSI in the field of Information Society Standardization 1 Title Mandate addressed to CEN, CENELEC and ETSI in support of the European legal framework for electronic signatures- Phase 2: Implementation of the work programme resulting from mandate M279 and presented in Section 8.3 of the (draft) report prepared by EESSI (http//www.ict.etsi.org) 2 Rationale 2.1 Background The development and use of electronic signature products and services is still in its introductory stage. Systems exist that use electronic signatures for commerce, administration and public services. However, there is no complete set of agreed standards or technical specifications for their use. Without a set of internationally agreed standards and specifications it will be difficult to provide a common level of security which can be recognised as being legally valid for use of electronic signatures across Europe. The aim of the Directive for electronic signatures is to provide a common framework for the legal recognition of electronic signatures; it sets requirements for trusted service providers supporting electronic signatures as well as requirements for signature-creating devices. These requirements need to be underpinned by standards and specifications that can be used for claiming compliance to the requirements set by the Directive, so that products and services supporting electronic signatures can be known to provide legally valid signatures. A consistent and coherent approach, both at European and international level is necessary so that the legal framework for electronic signatures in Europe can be built upon internationally agreed standards and other voluntary agreements which can be used to provide signatures which can be recognised legally across Europe.

2.2 Mandate M 279 (SOGITS 1107) With the view to providing timely standards and specifications permitting full and efficient implementation of the European legal framework, based on consistent Member States legislation, standardization initiatives have been encouraged at an early stage. Emphasis was put on the need to involve all economic players and to obtain adequate international coordination. To further this objective, CEN, CENELEC, ETSI and other involved associations within the framework of the ICTSB were invited, by Mandate 279 to set the scene in view of preparing standardization initiatives in support of the implementation of the Directive. The Mandate addressed following issues in particular: Creation of adequate and open platforms permitting participation of all involved economic players. Analysis of the standardization requirements in support of the Directive, including the off-line use of electronic signatures and in relation to electronic signature products and services to be made available to the end user. Assessment of available standards/specifications and current initiatives at global and regional level, both by formal standardization bodies and industry consortia. Identification of gaps and needs for additional standardization initiatives in all relevant forms of consensus building such as standards, specifications, agreements, workshops etc. Creation of adequate international liaisons with the view to achieve internationally agreed standards. In response to the Mandate, the European standardization organisations, under the auspices of the ICT Standards Board, have launched the European Electronic Signature Standardization Initiative (EESSI); EESSI has prepared a report on the issues requested by the Mandate. An open meeting will be organised in view of obtaining broad consensus on the work programme on 1 July; the results will be submitted to the ICT Standards Board for approval on 20 July.

3 Scope and objective of the next phase The objective of the next phase is to implement the workprogramme resulting from Mandate 279, as prepared by EESSI and adopted by the ICT Standards Board with a view to providing the market with standards and specifications in support of the implementation of the Directive. Following a decision by the Committee described in Article 9 of the Directive, products and services supporting electronic signatures, compliant with these specifications would subsequently be compliant to the requirements set be Directive and provide legally valid signatures. 4 Description of the mandated work CEN, CENELEC and ETSI are invited to implement the work programme resulting from the execution of Mandate M279. This includes the following tasks : The further standardization work shall be carried out on the basis of the work programme defined in the final report of EESSI, which should be considered as the European focal point for standardization work in the domain of electronic signatures. The European standardization organisations CEN, CENELEC and ETSI shall, in the context of EESSI, ensure the continuation of open and transparent liaison arrangements with all stakeholders; emphasis should be given to the involvement of national organisations/authorities concerned with the implementation of the Directive. Every effort shall be made to ensure that the standards and specifications proposed in support of the Directive are internationally accepted. Therefore, the execution of the EESSI work programme needs to be perfomed in close co-operation and liaison with relevant international organisations. With the view to obtaining broad participation of all stakeholders at European and international level, appropriate awareness and promotion initiatives shall be undertaken CEN, CENELEC and ETSI shall ensure that EESSI maintains appropriate monitoring of the execution of the work programme

including adequate liaisons with external organisations involved such as: EA, W3C, ICC, IETF, ISO/IEC/JTC1-SC27, ABA and ITU. 5 Execution of the Mandate 5.1 Within three months of the date of acceptance of this mandate, CEN, CENELEC and ETSI shall present to the Commission a report setting out the arrangements they have made for the execution of this mandate. Particular attention shall be given to the involvement of all relevant parties and to the international working arrangements set up to identify and adopt internationally agreed standards. 5.2 CEN, CENELEC and ETSI, are invited to put in place as soon as possible, adequate monitoring mechanims for the execution of the work programme and for the international co-ordination. 5.3 CEN, CENELEC and ETSI shall present progress reports to the Commission. SOGITS will be informed on a regular basis.. 5.4 Three years after the commencement of the work, an evaluation report shall be presented by CEN, CENELEC and ETSI to the Commission on the results achieved in terms of market impact. The terms of reference of the report shall be agreed between the three European standards bodies and the Commission services, after consultations with SOGITS. 5.5 CEN, CENELEC and ETSI will present to the Commission the standards listed in the programme in accordance with the Mandate. 5.6 Acceptance by CEN,CENELEC and ETSI of the work programme noted in 4 above starts as appropriate the standstill period in accordance with Article 6 of Directive 98/34/EEC as amended.