19.7.2016
EN
Official Journal of the European Union
L 194/7
(39)
In order to promote advanced security of network and information systems, the Cooperation Group should,
where appropriate, cooperate with relevant Union institutions, bodies, offices and agencies, to exchange knowhow and best practice, and to provide advice on security aspects of network and information systems that might
have an impact on their work, while respecting existing arrangements for the exchange of restricted information.
In cooperating with law enforcement authorities regarding the security aspects of network and information
systems that might have an impact on their work, the Cooperation Group should respect existing channels of
information and established networks.
(40)
Information about incidents is increasingly valuable to the general public and businesses, particularly small and
medium-sized enterprises. In some cases, such information is already provided via websites at the national level,
in the language of a specific country and focusing mainly on incidents and occurrences with a national
dimension. Given that businesses increasingly operate across borders and citizens use online services, information
on incidents should be provided in an aggregated form at Union level. The secretariat of the CSIRTs network is
encouraged to maintain a website or to host a dedicated page on an existing website, where general information
on major incidents that have occurred across the Union is made available to the general public, with a specific
focus on the interests and needs of businesses. CSIRTs participating in the CSIRTs network are encouraged to
provide on a voluntary basis the information to be published on that website, without including confidential or
sensitive information.
(41)
Where information is considered to be confidential in accordance with Union and national rules on business
confidentiality, such confidentiality should be ensured when carrying out the activities and fulfilling the objectives
set by this Directive.
(42)
Exercises which simulate real-time incident scenarios are essential for testing Member States' preparedness and
cooperation regarding the security of network and information systems. The CyberEurope cycle of exercises
coordinated by ENISA with the participation of the Member States is a useful tool for testing and drawing up
recommendations on how incident-handling at Union level should improve over time. Considering that the
Member States are not currently under any obligation to either plan or participate in exercises, the creation of the
CSIRTs network under this Directive should enable Member States to participate in exercises on the basis of
accurate planning and strategic choices. The Cooperation Group set up under this Directive should discuss the
strategic decisions regarding exercises, in particular but not exclusively as regards the regularity of the exercises
and the design of the scenarios. ENISA should, in accordance with its mandate, support the organisation and
running of Union-wide exercises by providing its expertise and advice to the Cooperation Group and the CSIRTs
network.
(43)
Given the global nature of security problems affecting network and information systems, there is a need for
closer international cooperation to improve security standards and information exchange, and to promote
a common global approach to security issues.
(44)
Responsibilities in ensuring the security of network and information systems lie, to a great extent, with operators
of essential services and digital service providers. A culture of risk management, involving risk assessment and
the implementation of security measures appropriate to the risks faced, should be promoted and developed
through appropriate regulatory requirements and voluntary industry practices. Establishing a trustworthy level
playing field is also essential to the effective functioning of the Cooperation Group and the CSIRTs network, to
ensure effective cooperation from all Member States.
(45)
This Directive applies only to those public administrations which are identified as operators of essential services.
Therefore, it is the responsibility of Member States to ensure the security of network and information systems of
public administrations not falling within the scope of this Directive.
(46)
Risk-management measures include measures to identify any risks of incidents, to prevent, detect and handle
incidents and to mitigate their impact. The security of network and information systems comprises the security of
stored, transmitted and processed data.