19.9.2017
EN
Official Journal of the European Union
L 239/39
(25)
Cybersecurity exercises at EU level are essential to stimulate and improve cooperation among the Member States
and the private sector. To this end, since 2010, ENISA organises regular pan-European cyber incident exercises
(‘Cyber Europe’).
(26)
The Council Conclusions (1) on the Implementation of the Joint Declaration by the President of the European
Council, the President of the European Commission and the Secretary-General of the North Atlantic Treaty
Organisation calls for the strengthening cooperation in cyber exercises through reciprocal staff participation in
respective exercises, including in particular Cyber Coalition and Cyber Europe.
(27)
The constantly evolving threat landscape and recent cybersecurity incidents are an indication of the increasing
risk faced by the Union, Member States should act on the present recommendation without further delay and in
any case by the end of 2018,
HAS ADOPTED THIS RECOMMENDATION:
(1) Member States and EU institutions should establish an EU Cybersecurity Crisis Response Framework integrating the
objectives and modalities of cooperation presented in the Blueprint following the guiding principles described
therein.
(2) The EU Cybersecurity Crisis Response Framework should in particular identify the relevant actors, EU institutions
and Member State authorities, at all necessary levels — technical, operational, strategic/political — and develop,
where necessary, standard operating procedures that define the way in which these cooperate within the context of
EU crisis management mechanisms. Emphasis should be placed on enabling the exchange of information without
undue delay and coordinating the response during large-scale cybersecurity incidents and crises.
(3) To this end, Member States' competent authorities should work together towards further specifying informationsharing and cooperation protocols. The Cooperation Group should exchange experiences on these matters with
relevant EU institutions.
(4) Member States should ensure that their national crisis management mechanisms adequately address cybersecurity
incident response as well as provide necessary procedures for cooperation at EU level within the context of the EU
Framework.
(5) As regards existing EU crisis management mechanisms, in line with the Blueprint, Member States should, together
with Commission services and the EEAS, establish practical implementation guidelines as regards the integration of
their national crisis management and cybersecurity entities and procedures into existing EU crisis management
mechanisms, namely the IPCR and EEAS CRM. In particular, Member States should ensure that appropriate
structures are in place to enable the efficient flow of information between their national crisis management
authorities and their representatives at EU level in the context of EU crisis mechanisms.
(6) Member States should make full use of the opportunities offered by the Cybersecurity Digital Service Infrastructures
(DSI) programme of the Connecting Europe Facility (CEF), and cooperate with the Commission to ensure that the
Core Service Platform cooperation mechanism, currently under development, provides the necessary functionalities
and fulfils their requirements for cooperation also during cybersecurity crises.
(7) Member States, with the assistance of ENISA and building on previous work in this area, should cooperate in
developing and adopting a common taxonomy and template for situational reports to describe the technical causes
and impacts of cybersecurity incidents to further enhance their technical and operational cooperation during crises.
In this regard, Member States should take into account the ongoing work within the Cooperation Group on incident
notification guidelines and in particular aspects related to the format of national notifications.
(8) The procedures laid out in the Framework should be tested and when necessary revised following lessons learnt
from Member State participation in national, regional, and Union as well as cyber diplomacy and NATO cyberse
curity exercises. In particular, they should be tested in the context of the Cyber Europe exercises organised by
ENISA. Cyber Europe 2018 presents a first such opportunity.
(1) ST 15283/16, 6 December 2016.