19.9.2017 EN Official Journal of the European Union L 239/39 (25) Cybersecurity exercises at EU level are essential to stimulate and improve cooperation among the Member States and the private sector. To this end, since 2010, ENISA organises regular pan-European cyber incident exercises (‘Cyber Europe’). (26) The Council Conclusions (1) on the Implementation of the Joint Declaration by the President of the European Council, the President of the European Commission and the Secretary-General of the North Atlantic Treaty Organisation calls for the strengthening cooperation in cyber exercises through reciprocal staff participation in respective exercises, including in particular Cyber Coalition and Cyber Europe. (27) The constantly evolving threat landscape and recent cybersecurity incidents are an indication of the increasing risk faced by the Union, Member States should act on the present recommendation without further delay and in any case by the end of 2018, HAS ADOPTED THIS RECOMMENDATION: (1) Member States and EU institutions should establish an EU Cybersecurity Crisis Response Framework integrating the objectives and modalities of cooperation presented in the Blueprint following the guiding principles described therein. (2) The EU Cybersecurity Crisis Response Framework should in particular identify the relevant actors, EU institutions and Member State authorities, at all necessary levels — technical, operational, strategic/political — and develop, where necessary, standard operating procedures that define the way in which these cooperate within the context of EU crisis management mechanisms. Emphasis should be placed on enabling the exchange of information without undue delay and coordinating the response during large-scale cybersecurity incidents and crises. (3) To this end, Member States' competent authorities should work together towards further specifying informationsharing and cooperation protocols. The Cooperation Group should exchange experiences on these matters with relevant EU institutions. (4) Member States should ensure that their national crisis management mechanisms adequately address cybersecurity incident response as well as provide necessary procedures for cooperation at EU level within the context of the EU Framework. (5) As regards existing EU crisis management mechanisms, in line with the Blueprint, Member States should, together with Commission services and the EEAS, establish practical implementation guidelines as regards the integration of their national crisis management and cybersecurity entities and procedures into existing EU crisis management mechanisms, namely the IPCR and EEAS CRM. In particular, Member States should ensure that appropriate structures are in place to enable the efficient flow of information between their national crisis management authorities and their representatives at EU level in the context of EU crisis mechanisms. (6) Member States should make full use of the opportunities offered by the Cybersecurity Digital Service Infrastructures (DSI) programme of the Connecting Europe Facility (CEF), and cooperate with the Commission to ensure that the Core Service Platform cooperation mechanism, currently under development, provides the necessary functionalities and fulfils their requirements for cooperation also during cybersecurity crises. (7) Member States, with the assistance of ENISA and building on previous work in this area, should cooperate in developing and adopting a common taxonomy and template for situational reports to describe the technical causes and impacts of cybersecurity incidents to further enhance their technical and operational cooperation during crises. In this regard, Member States should take into account the ongoing work within the Cooperation Group on incident notification guidelines and in particular aspects related to the format of national notifications. (8) The procedures laid out in the Framework should be tested and when necessary revised following lessons learnt from Member State participation in national, regional, and Union as well as cyber diplomacy and NATO cyberse­ curity exercises. In particular, they should be tested in the context of the Cyber Europe exercises organised by ENISA. Cyber Europe 2018 presents a first such opportunity. (1) ST 15283/16, 6 December 2016.

Select target paragraph3