of the European Network and Information Security Agency (ENISA), established in 2004 to
contribute to the goals of ensuring a high and effective level of NIS within the Community
and developing a culture of NIS for the benefit of EU citizens, consumers, enterprises and
administrations.
In 2008 ENISA’s mandate was extended ‘à l’identique’ until March 2012.5 At the same time,
the Council and the European Parliament called for “further discussion on the future of
ENISA and on the general direction of the European efforts towards an increased network
and information security.” To support this debate, the Commission launched last November
an on-line public consultation,6 the analysis of which will be made available shortly.
The activities planned in this Communication are conducted under and in parallel to the
European Programme for Critical Infrastructure Protection (EPCIP)7. A key element of
EPCIP is the Directive8 on the identification and designation of European Critical
Infrastructures,9 which identifies the ICT sector as a future priority sector. Another important
element of EPCIP is the Critical Infrastructure Warning Information Network (CIWIN).10
On the regulatory side, the Commission proposal to reform the Regulatory Framework for
electronic communications networks and services11 contains new provisions on security and
integrity, in particular to strengthen operators’ obligations to ensure that appropriate measures
are taken to meet identified risks, guarantee the continuity of supply of services and notify
security breaches.12 This approach is conducive to the general objective of enhancing the
security and resilience of CIIs. The European Parliament and the Council broadly support
these provisions.
The actions proposed in this Communication complement existing and prospective measures
in the area of police and judicial cooperation to prevent, fight and prosecute criminal and
terrorist activities targeting ICT infrastructures, as envisaged inter alia by the Council
Framework Decision on attacks against information systems13 and its planned update.14
This initiative takes into account NATO activities on common policy on cyber defence, i.e.
the Cyber Defence Management Authority and the Cooperative Cyber Defence Centre of
Excellence.
Lastly, due account is given to international policy developments, in particular to the G8
principles on CIIP15; the UN General Assembly Resolution 58/199 Creation of a global
culture of cybersecurity and the protection of critical information infrastructures and the
recent OECD Recommendation on the Protection of Critical Information Infrastructures.
5
6
7
8
9
10
11
12
13
14
15
EN
Regulation (EC) No 1007/2008
http://ec.europa.eu/information_society/newsroom/cf/itemlongdetail.cfm?item_id=4464
COM(2006) 786 final
2008/114/EC
http://www.consilium.europa.eu/ueDocs/cms_Data/docs/pressData/en/gena/104617.pdf
COM(2008) 676 final
COM(2007) 697, COM(2007) 698, COM(2007) 699
Art. 13 Framework Directive
2005/222/JHA
COM(2008) 712
http://www.usdoj.gov/criminal/cybercrime/g82004/G8_CIIP_Principles.pdf
3
EN