2. Enhancing the protection of CSDP communication networks used by EU entities Without prejudice to the role of the CERT-EU as the central EU cyber incident response coordination structure for all Union institutions, bodies and agencies and within the framework of the relevant rules concerning the Union budget, the EEAS shall develop an adequate and autonomous understanding of security and network defence matters and develop its own IT security capacity. It will aim to improve the resilience of the EEAS CSDP networks, with a focus on prevention, detection, incident response, situational awareness, information exchange and early warning mechanisms. The protection of EEAS communication and information systems and the development of Information Technology (IT) security capacities are led by the EEAS MDR (Managing Directorate for Resources). Additional dedicated resources and support will also be provided by the European Union Military Staff (EUMS), Crisis Management and Planning Directorate (CMPD) and Civilian Planning and Conduct Capability (CPCC). This IT security capability will cover both classified and unclassified systems and will be an integral part of the existing operational entities. There is also a need to streamline security rules for the information systems provided by different EU institutional actors during the conduct of CSDP operations and missions. In this context, a unified chain of command could be considered with the aim to improve the resilience of networks used for CSDP. 15585/14 ANNEX FP/oza DG C 2B 6 EN

Select target paragraph3