L 239/38 EN Official Journal of the European Union 19.9.2017 supports the cooperation among the CSIRTs. The national CSIRTs and the CERT-EU cooperate and exchange information on a voluntary basis including, when necessary, in response to cybersecurity incidents that affect one or more Member States. At the request of a representative of a Member State's CSIRT, they may discuss and, where possible, identify a coordinated response to an incident that has been identified within the jurisdiction of that same Member State. Relevant procedures will be set out in CSIRTs Network's Standard Operating Procedures (SOPs) (1). (17) The CSIRTs network is also tasked with discussing, exploring and identifying further forms of operational cooperation, including in relation to categories of risks and incidents, early warnings, mutual assistance, principles and modalities for coordination, when Member States respond to cross-border risks and incidents. (18) The Cooperation Group established by Article 11 of the NIS Directive is tasked with providing strategic guidance for the activities of the CSIRTs network and discussing capabilities and preparedness of the Member States, and, on a voluntary basis, evaluating national strategies on the security of network and information systems and the effectiveness of CSIRTs, and identifying best practice. (19) A dedicated work stream within the Cooperation Group is preparing incident notification guidelines, pursuant to Article 14(7) of the NIS Directive, concerning the circumstances in which operators of essential services are required to notify incidents pursuant to Article 14(3) and the format and procedure for such notifications (2). (20) Awareness and understanding of the real-time situation, risk posture, and threats gained through reporting, assessments, research, investigation, and analysis, is vital to enable well-informed decisions This ‘situational awareness’ — by all relevant stakeholders — is essential for an effective coordinated response. Situational awareness includes elements about the causes as well as the impact and origin of the incident. It is recognised that this depends on exchange and sharing of information between relevant parties in a suitable format, using a common taxonomy to describe the incident and in an appropriately secure manner. (21) Responding to cybersecurity incidents may take many forms, ranging from identifying technical measures which may entail two or more entities jointly investigating the technical causes of the incident (e.g. malware analysis) or identifying ways through which organisations may assess whether they have been affected (e.g. indicators of compromise), to operational decisions on applying such measures and, at the political level, deciding on the use of other instruments such as the Framework for a Joint response to malicious cyber activities (3) or the EU operational protocol for countering hybrid threats (4), depending on the incident. (22) European citizens' and businesses' trust in digital services is essential for a flourishing digital single market. Therefore, crisis communication plays a particularly important role in mitigating the negative effects of cyberse­ curity incidents and crises. Communication may also be used in the context of the Framework for a Joint Diplomatic Response as a means to influence the behaviour of (potential) aggressors acting from third countries. Aligning the public communication to mitigate the negative effects of cybersecurity incidents and crises and the public communication to influence an aggressor is essential for a political response to be effective. (23) Providing the public with information on how they can mitigate at user and organisational level the effects of an incident (for example by applying a patch or taking complementary actions to avoid the threat, etc.) could be an effective measure to mitigate a large-scale cybersecurity incident or crisis. (24) The Commission, through the Connecting Europe Facility (CEF) cybersecurity Digital Service Infrastructure, is developing a Core Service Platform cooperation mechanism, known as MeliCERTes, between participating Member States CSIRTs to improve their levels of preparedness, cooperation and response to emerging cyber threats and incidents. The Commission, through competitive calls for proposals for grant awards under CEF is cofunding CSIRTs in the Member States with a view to improving their operational capacities at national level. (1) Under development; expected to be adopted by the end of 2017. (2) The guidelines are intended to be finalised by the end of 2017. (3) Council Conclusions on a Framework for a Joint EU Diplomatic Response to Malicious Cyber Activities (‘Cyber Diplomacy Toolbox’), Doc. 9916/17 (4) Joint Staff Working Document EU operational protocol for countering hybrid threats, ‘EU Playbook’, SWD(2016) 227 final, 5 July 2016.

Select target paragraph3