2. Enhancing the protection of CSDP communication networks used by EU entities
Without prejudice to the role of the CERT-EU as the central EU cyber incident response
coordination structure for all Union institutions, bodies and agencies and within the framework of
the relevant rules concerning the Union budget, the EEAS shall develop an adequate and
autonomous understanding of security and network defence matters and develop its own IT security
capacity. It will aim to improve the resilience of the EEAS CSDP networks, with a focus on
prevention, detection, incident response, situational awareness, information exchange and early
warning mechanisms.
The protection of EEAS communication and information systems and the development of
Information Technology (IT) security capacities are led by the EEAS MDR (Managing Directorate
for Resources). Additional dedicated resources and support will also be provided by the European
Union Military Staff (EUMS), Crisis Management and Planning Directorate (CMPD) and Civilian
Planning and Conduct Capability (CPCC). This IT security capability will cover both classified and
unclassified systems and will be an integral part of the existing operational entities.
There is also a need to streamline security rules for the information systems provided by different
EU institutional actors during the conduct of CSDP operations and missions. In this context, a
unified chain of command could be considered with the aim to improve the resilience of networks
used for CSDP.
15585/14
ANNEX
FP/oza
DG C 2B
6
EN