Decision 2013/488 - 2013/488/EU: Council Decision of 23 September 2013 on the security rules for protecting EU classified information - Main contents
15.10.2013 |
EN |
Official Journal of the European Union |
L 274/1 |
COUNCIL DECISION
of 23 September 2013
on the security rules for protecting EU classified information
(2013/488/EU)
THE COUNCIL OF THE EUROPEAN UNION,
Having regard to the Treaty on the Functioning of the European Union, and in particular Article 240(3) thereof,
Having regard to Council Decision 2009/937/EU of 1 December 2009 adopting the Council’s Rules of Procedure (1), and in particular Article 24 thereof,
Whereas:
(1) |
In order to develop Council activities in all areas which require handling classified information, it is appropriate to establish a comprehensive security system for protecting classified information covering the Council, its General Secretariat and the Member States. |
(2) |
This Decision should apply where the Council, its preparatory bodies and the General Secretariat of the Council (GSC) handle EU classified information (EUCI). |
(3) |
In accordance with national laws and regulations and to the extent required for the functioning of the Council, the Member States should respect this Decision where their competent authorities, personnel or contractors handle EUCI, in order that each may be assured that an equivalent level of protection is afforded to EUCI. |
(4) |
The Council, the Commission and the European External Action Service (EEAS) are committed to applying equivalent security standards for protecting EUCI. |
(5) |
The Council underlines the importance of associating, where appropriate, the European Parliament and other Union institutions, bodies, offices or agencies with the principles, standards and rules for protecting classified information which are necessary in order to protect the interests of the Union and its Member States. |
(6) |
The Council should determine the appropriate framework for sharing EUCI held by the Council with other Union institutions, bodies, offices or agencies, as appropriate, in accordance with this Decision and interinstitutional arrangements in force. |
(7) |
Union bodies and agencies established under Title V, Chapter 2, of the Treaty on European Union (TEU), Europol and Eurojust should apply, in the context of their internal organisation, the basic principles and minimum standards laid down in this Decision for protecting EUCI, where so provided in the act establishing them. |
(8) |
Crisis management operations established under Title V, Chapter 2, of the TEU and their personnel should apply the security rules adopted by the Council for protecting EUCI where so provided in the Council act establishing them. |
(9) |
EU Special Representatives and the members of their teams should apply the security rules adopted by the Council for protecting EUCI where so provided in the relevant Council act. |
(10) |
This Decision is taken without prejudice to Articles 15 and 16 of the Treaty on the Functioning of the European Union (TFEU) and to instruments implementing them. |
(11) |
This Decision is taken without prejudice to existing practices in Member States with regard to informing their national Parliaments about the activities of the Union. |
(12) |
In order to ensure the application of the security rules for protecting EUCI in a timely manner as regards the accession of the Republic of Croatia to the European Union, this Decision should enter into force on the date of its publication, |
HAS ADOPTED THIS DECISION:
Article 1
Purpose, scope and definitions
-
1.This Decision lays down the basic principles and minimum standards of security for protecting EUCI.
-
2.These basic principles and minimum standards shall apply to the Council and the GSC and be respected by the Member States in accordance with their respective national laws and regulations, in order that each may be assured that an equivalent level of protection is afforded to EUCI.
-
3.For the purposes of this Decision, the definitions set out in Appendix A shall apply.
Article 2
Definition of EUCI, security classifications and markings
-
1.‘EU classified information’ (EUCI) means any information or material designated by a EU security classification, the unauthorised disclosure of which could cause varying degrees of prejudice to the interests of the European Union or of one or more of the Member States.
-
2.EUCI shall be classified at one of the following levels:
(a) |
TRÈS SECRET UE/EU TOP SECRET: information and material the unauthorised disclosure of which could cause exceptionally grave prejudice to the essential interests of the European Union or of one or more of the Member States; |
(b) |
SECRET UE/EU SECRET: information and material the unauthorised disclosure of which could seriously harm the essential interests of the European Union or of one or more of the Member States; |
(c) |
CONFIDENTIEL UE/EU CONFIDENTIAL: information and material the unauthorised disclosure of which could harm the essential interests of the European Union or of one or more of the Member States; |
(d) |
RESTREINT UE/EU RESTRICTED: information and material the unauthorised disclosure of which could be disadvantageous to the interests of the European Union or of one or more of the Member States. |
-
3.EUCI shall bear a security classification marking in accordance with paragraph 2. It may bear additional markings to designate the field of activity to which it relates, identify the originator, limit distribution, restrict use or indicate releasability.
Article 3
Classification management
-
1.The competent authorities shall ensure that EUCI is appropriately classified, clearly identified as classified information and retains its classification level for only as long as necessary.
-
2.EUCI shall not be downgraded or declassified nor shall any of the markings referred to in Article 2(3) be modified or removed without the prior written consent of the originator.
-
3.The Council shall approve a security policy on creating EUCI which shall include a practical classification guide.
Article 4
Protection of classified information
-
1.EUCI shall be protected in accordance with this Decision.
-
2.The holder of any item of EUCI shall be responsible for protecting it in accordance with this Decision.
-
3.Where Member States introduce classified information bearing a national security classification marking into the structures or networks of the Union, the Council and the GSC shall protect that information in accordance with the requirements applicable to EUCI at the equivalent level as set out in the table of equivalence of security classifications contained in Appendix B.
-
4.An aggregate of EUCI may warrant a level of protection corresponding to a higher classification than that of its individual components.
Article 5
Security risk management
-
1.Risk to EUCI shall be managed as a process. This process shall be aimed at determining known security risks, defining security measures to reduce such risks to an acceptable level in accordance with the basic principles and minimum standards set out in this Decision and at applying those measures in line with the concept of defence in depth as defined in Appendix A. The effectiveness of such measures shall be continuously evaluated.
-
2.Security measures for protecting EUCI throughout its life-cycle shall be commensurate in particular with its security classification, the form and the volume of the information or material, the location and construction of facilities housing EUCI and the locally assessed threat of malicious and/or criminal activities, including espionage, sabotage and terrorism.
-
3.Contingency plans shall take account of the need to protect EUCI during emergency situations in order to prevent unauthorised access, disclosure or loss of integrity or availability.
-
4.Preventive and recovery measures to minimise the impact of major failures or incidents on the handling and storage of EUCI shall be included in business continuity plans.
Article 6
Implementation of this Decision
-
1.Where necessary, the Council, on recommendation by the Security Committee, shall approve security policies setting out measures for implementing this Decision.
-
2.The Security Committee may agree at its level security guidelines to supplement or support this Decision and any security policies approved by the Council.
Article 7
Personnel security
-
1.Personnel security is the application of measures to ensure that access to EUCI is granted only to individuals who have:
— |
a need-to-know, |
— |
been security cleared to the relevant level, where appropriate, and |
— |
been briefed on their responsibilities. |
-
2.Personnel security clearance procedures shall be designed to determine whether an individual, taking into account his loyalty, trustworthiness and reliability, may be authorised to access EUCI.
-
3.All individuals in the GSC whose duties require them to have access to or handle EUCI classified CONFIDENTIEL UE/EU CONFIDENTIAL or above shall be security cleared to the relevant level before being granted access to such EUCI. Such individuals must be authorised by the GSC Appointing Authority to access EUCI up to a specified level and up to a specified date.
-
4.Member States’ personnel referred to in Article 15(3) whose duties may require access to EUCI classified CONFIDENTIEL UE/EU CONFIDENTIAL or above shall be security cleared to the relevant level or otherwise duly authorised by virtue of their functions, in accordance with national laws and regulations, before being granted access to such EUCI.
-
5.Before being granted access to EUCI and at regular intervals thereafter, all individuals shall be briefed on and acknowledge their responsibilities to protect EUCI in accordance with this Decision.
-
6.Provisions for implementing this Article are set out in Annex I.
Article 8
Physical security
-
1.Physical security is the application of physical and technical protective measures to prevent unauthorised access to EUCI.
-
2.Physical security measures shall be designed to deny surreptitious or forced entry by an intruder, to deter, impede and detect unauthorised actions and to allow for segregation of personnel in their access to EUCI on a need-to-know basis. Such measures shall be determined based on a risk management process.
-
3.Physical security measures shall be put in place for all premises, buildings, offices, rooms and other areas in which EUCI is handled or stored, including areas housing communication and information systems as defined in Article 10(2).
-
4.Areas in which EUCI classified CONFIDENTIEL UE/EU CONFIDENTIAL or above is stored shall be established as Secured Areas in accordance with Annex II and approved by the competent security authority.
-
5.Only approved equipment or devices shall be used for protecting EUCI at the level CONFIDENTIEL UE/EU CONFIDENTIAL or above.
-
6.Provisions for implementing this Article are set out in Annex II.
Article 9
Management of classified information
-
1.The management of classified information is the application of administrative measures for controlling EUCI throughout its life-cycle to supplement the measures provided for in Articles 7, 8 and 10 and thereby help deter and detect deliberate or accidental compromise or loss of such information. Such measures relate in particular to the creation, registration, copying, translation, downgrading, declassification, carriage and destruction of EUCI.
-
2.Information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above shall be registered for security purposes prior to distribution and on receipt. The competent authorities in the GSC and in the Member States shall establish a registry system for this purpose. Information classified TRÈS SECRET UE/EU TOP SECRET shall be registered in designated registries.
-
3.Services and premises where EUCI is handled or stored shall be subject to regular inspection by the competent security authority.
-
4.EUCI shall be conveyed between services and premises outside physically protected areas as follows:
(a) |
as a general rule, EUCI shall be transmitted by electronic means protected by cryptographic products approved in accordance with Article 10(6); |
(b) |
when the means referred to in point (a) are not used, EUCI shall be carried either:
|
-
5.Provisions for implementing this Article are set out in Annexes III and IV.
Article 10
Protection of EUCI handled in communication and information systems
-
1.Information Assurance (IA) in the field of communication and information systems is the confidence that such systems will protect the information they handle and will function as they need to, when they need to, under the control of legitimate users. Effective IA shall ensure appropriate levels of confidentiality, integrity, availability, non-repudiation and authenticity. IA shall be based on a risk management process.
-
2.‘Communication and Information System’ (CIS) means any system enabling the handling of information in electronic form. A CIS shall comprise the entire assets required for it to operate, including the infrastructure, organisation, personnel and information resources. This Decision shall apply to CIS handling EUCI.
-
3.CIS shall handle EUCI in accordance with the concept of IA.
-
4.All CIS shall undergo an accreditation process. Accreditation shall aim at obtaining assurance that all appropriate security measures have been implemented and that a sufficient level of protection of the EUCI and of the CIS has been achieved in accordance with this Decision. The accreditation statement shall determine the maximum classification level of the information that may be handled in a CIS as well as the corresponding terms and conditions.
-
5.Security measures shall be implemented to protect CIS handling information classified CONFIDENTIEL UE/EU CONFIDENTIAL and above against compromise of such information through unintentional electromagnetic emanations (‘TEMPEST security measures’). Such security measures shall be commensurate with the risk of exploitation and the level of classification of the information.
-
6.Where the protection of EUCI is provided by cryptographic products, such products shall be approved as follows:
(a) |
the confidentiality of information classified SECRET UE/EU SECRET and above shall be protected by cryptographic products approved by the Council as Crypto Approval Authority (CAA), upon recommendation by the Security Committee; |
(b) |
the confidentiality of information classified CONFIDENTIEL UE/EU CONFIDENTIAL or RESTREINT UE/EU RESTRICTED shall be protected by cryptographic products approved by the Secretary-General of the Council (‘the Secretary-General‘) as CAA, upon recommendation by the Security Committee. |
Notwithstanding point (b), within Member States’ national systems, the confidentiality of EUCI classified CONFIDENTIEL UE/EU CONFIDENTIAL or RESTREINT UE/EU RESTRICTED may be protected by cryptographic products approved by a Member State’s CAA.
-
7.During transmission of EUCI by electronic means, approved cryptographic products shall be used. Notwithstanding this requirement, specific procedures may be applied under emergency circumstances or specific technical configurations as specified in Annex IV.
-
8.The competent authorities of the GSC and of the Member States respectively shall establish the following IA functions:
(a) |
an IA Authority (IAA); |
(b) |
a TEMPEST Authority (TA); |
(c) |
a Crypto Approval Authority (CAA); |
(d) |
a Crypto Distribution Authority (CDA). |
-
9.For each system, the competent authorities of the GSC and of the Member States respectively shall establish:
(a) |
a Security Accreditation Authority (SAA); |
(b) |
an IA Operational Authority. |
-
10.Provisions for implementing this Article are set out in Annex IV.
Article 11
Industrial security
-
1.Industrial security is the application of measures to ensure the protection of EUCI by contractors or subcontractors in pre-contract negotiations and throughout the life-cycle of classified contracts. Such contracts shall not involve access to information classified TRÈS SECRET UE/EU TOP SECRET.
-
2.The GSC may entrust by contract tasks involving or entailing access to or the handling or storage of EUCI by industrial or other entities registered in a Member State or in a third State which has concluded an agreement or an administrative arrangement in accordance with point (a) or (b) of Article 13(2).
-
3.The GSC, as contracting authority, shall ensure that the minimum standards on industrial security set out in this Decision, and referred to in the contract, are complied with when awarding classified contracts to industrial or other entities.
-
4.The National Security Authority (NSA), the Designated Security Authority (DSA) or any other competent authority of each Member State shall ensure, to the extent possible under national laws and regulations, that contractors and subcontractors registered in their territory take all appropriate measures to protect EUCI in pre-contract negotiations and when performing a classified contract.
-
5.The NSA, DSA or any other competent security authority of each Member State shall ensure, in accordance with national laws and regulations, that contractors or subcontractors registered in the respective Member State participating in classified contracts or sub-contracts which require access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET within their facilities, either in the performance of such contracts or during the pre-contractual stage, hold a Facility Security Clearance (FSC) at the relevant classification level.
-
6.Contractor or subcontractor personnel who, for the performance of a classified contract, require access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET shall be granted a Personnel Security Clearance (PSC) by the respective NSA, DSA or any other competent security authority in accordance with national laws and regulations and the minimum standards laid down in Annex I.
-
7.Provisions for implementing this Article are set out in Annex V.
Article 12
Sharing EUCI
-
1.The Council shall determine the conditions under which it may share EUCI held by it with other Union institutions, bodies, offices or agencies. An appropriate framework may be put in place to that effect, including by entering into interinstitutional agreements or other arrangements where necessary for that purpose.
-
2.Any such framework shall ensure that EUCI is given protection appropriate to its classification level and according to basic principles and minimum standards which shall be equivalent to those laid down in this Decision.
Article 13
Exchange of classified information with third States and international organisations
-
1.Where the Council determines that there is a need to exchange EUCI with a third State or international organisation, an appropriate framework shall be put in place to that effect.
-
2.In order to establish such a framework and define reciprocal rules on the protection of classified information exchanged:
(a) |
the Union shall conclude agreements with third States or international organisations on security procedures for exchanging and protecting classified information (‘security of information agreements’); or |
(b) |
the Secretary-General may enter into administrative arrangements on behalf of the GSC in accordance with paragraph 17 of Annex VI where the classification level of EUCI to be released is as a general rule no higher than RESTREINT UE/EU RESTRICTED. |
-
3.Security of information agreements or administrative arrangements referred to in paragraph 2 shall contain provisions to ensure that when third States or international organisations receive EUCI, such information is given protection appropriate to its classification level and according to minimum standards which are no less stringent than those laid down in this Decision.
-
4.The decision to release EUCI originating in the Council to a third State or international organisation shall be taken by the Council on a case-by-case basis, according to the nature and content of such information, the recipient’s need-to-know and the measure of advantage to the Union. If the originator of the classified information for which release is desired is not the Council, the GSC shall first seek the originator’s written consent to release. If the originator cannot be established, the Council shall assume the former’s responsibility.
-
5.Assessment visits shall be arranged to ascertain the effectiveness of the security measures in place in a third State or international organisation for protecting EUCI provided or exchanged.
-
6.Provisions for implementing this Article are set out in Annex VI.
Article 14
Breaches of security and compromise of EUCI
-
1.A breach of security occurs as the result of an act or omission by an individual which is contrary to the security rules laid down in this Decision.
-
2.Compromise of EUCI occurs when, as a result of a breach of security, it has wholly or in part been disclosed to unauthorised persons.
-
3.Any breach or suspected breach of security shall be reported immediately to the competent security authority.
-
4.Where it is known or where there are reasonable grounds to assume that EUCI has been compromised or lost, the NSA or other competent authority shall take all appropriate measures in accordance with the relevant laws and regulations to:
(a) |
inform the originator; |
(b) |
ensure that the case is investigated by personnel not immediately concerned with the breach in order to establish the facts; |
(c) |
assess the potential damage caused to the interests of the Union or of the Member States; |
(d) |
take appropriate measures to prevent a recurrence; and |
(e) |
notify the appropriate authorities of the action taken. |
-
5.Any individual who is responsible for a breach of the security rules laid down in this Decision may be liable to disciplinary action in accordance with the applicable rules and regulations. Any individual who is responsible for compromising or losing EUCI shall be liable to disciplinary and/or legal action in accordance with the applicable laws, rules and regulations.
Article 15
Responsibility for implementation
-
1.The Council shall take all necessary measures to ensure overall consistency in the application of this Decision.
-
2.The Secretary-General shall take all necessary measures to ensure that, when handling or storing EUCI or any other classified information, this Decision is applied in premises used by the Council and within the GSC, by GSC officials and other servants, by personnel seconded to the GSC and by GSC contractors.
-
3.Member States shall take all appropriate measures, in accordance with their respective national laws and regulations, to ensure that when EUCI is handled or stored, this Decision is respected by:
(a) |
personnel of Member States’ Permanent Representations to the European Union, and national delegates attending meetings of the Council or of its preparatory bodies, or participating in other Council activities; |
(b) |
other personnel in Member States’ national administrations, including personnel seconded to those administrations, whether they serve on the territory of the Member States or abroad; |
(c) |
other persons in the Member States duly authorised by virtue of their functions to have access to EUCI; and |
(d) |
Member States’ contractors, whether on the territory of the Member States or abroad. |
Article 16
The organisation of security in the Council
-
1.As part of its role in ensuring overall consistency in the application of this Decision, the Council shall approve:
(a) |
agreements referred to in Article 13(2)(a); |
(b) |
decisions authorising or consenting to the release of EUCI originating in or held by the Council to third States and international organisations, in accordance with the principle of originator consent; |
(c) |
an annual assessment visit programme recommended by the Security Committee for visits to assess Member States’ services and premises, Union bodies, agencies and entities which apply this Decision or the principles thereof, and for assessment visits to third States and international organisations in order to ascertain the effectiveness of measures implemented for protecting EUCI; and |
(d) |
security policies as foreseen in Article 6(1). |
-
2.The Secretary-General shall be the GSC’s Security Authority. In that capacity, the Secretary-General shall:
(a) |
implement the Council’s security policy and keep it under review; |
(b) |
coordinate with Member States’ NSAs on all security matters relating to the protection of classified information relevant for the Council’s activities; |
(c) |
grant GSC officials, other servants and seconded national experts authorisation for access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above in accordance with Article 7(3); |
(d) |
as appropriate, order investigations into any actual or suspected compromise or loss of classified information held by or originating in the Council and request the relevant security authorities to assist in such investigations; |
(e) |
undertake periodic inspections of the security arrangements for protecting classified information on GSC premises; |
(f) |
undertake periodic visits to assess the security arrangements for protecting EUCI in Union bodies, agencies and entities which apply this Decision or the principles thereof; |
(g) |
undertake, jointly and in agreement with the NSA concerned, periodic assessments of the security arrangements for protecting EUCI in Member States’ services and premises; |
(h) |
ensure that security measures are coordinated as necessary with the competent authorities of the Member States which are responsible for protecting classified information and, as appropriate, third States or international organisations, including on the nature of threats to the security of EUCI and the means of protection against them; and |
(i) |
enter into the administrative arrangements referred to in Article 13(2)(b). |
The Security Office of the GSC shall be at the disposal of the Secretary-General to assist in those responsibilities.
-
3.For the purposes of implementing Article 15(3), Member States should:
(a) |
designate an NSA, as listed in Appendix C, responsible for security arrangements for protecting EUCI in order that:
|
(b) |
ensure that their competent authorities provide information and advice to their governments, and through them to the Council, on the nature of threats to the security of EUCI and the means of protection against them. |
Article 17
Security Committee
-
1.A Security Committee is hereby established. It shall examine and assess any security matter within the scope of this Decision and make recommendations to the Council as appropriate.
-
2.The Security Committee shall be composed of representatives of the Member States’ NSAs and be attended by a representative of the Commission and of the EEAS. It shall be chaired by the Secretary-General or by his designated delegate. It shall meet as instructed by the Council, or at the request of the Secretary-General or of an NSA.
Representatives of Union bodies, agencies and entities which apply this Decision or the principles thereof may be invited to attend when questions concerning them are discussed.
-
3.The Security Committee shall organise its activities in such a way that it can make recommendations on specific areas of security. It shall establish an expert sub-area for IA issues and other expert sub-areas as necessary. It shall draw up terms of reference for such expert sub-areas and receive reports from them on their activities including, as appropriate, any recommendations for the Council.
Article 18
Replacement of previous decision
-
1.This Decision shall repeal and replace Council Decision 2011/292/EU (2).
-
2.All EUCI classified in accordance with Council Decision 2001/264/EC (3) and with Decision 2011/292/EU shall continue to be protected in accordance with the relevant provisions of this Decision.
Article 19
Entry into force
This Decision shall enter into force on the date of its publication in the Official Journal of the European Union.
Done at Brussels, 23 September 2013.
For the Council
The President
-
V.JUKNA
-
Council Decision 2011/292/EU of 31 March 2011 on the security rules for protecting EU classified information (OJ L 141, 27.5.2011, p. 17).
-
Council Decision 2001/264/EC of 19 March 2001 adopting the Council’s security regulations (OJ L 101, 11.4.2001, p. 1).
ANNEXES
ANNEX I
Personnel security
ANNEX II
Physical security
ANNEX III
Management of classified information
ANNEX IV
Protection of EUCI handled in CIS
ANNEX V
Industrial security
ANNEX VI
Exchange of classified information with third States and international organisations
ANNEX I
PERSONNEL SECURITY
-
I.INTRODUCTION
1. |
This Annex sets out provisions for implementing Article 7. It lays down criteria for determining whether an individual, taking into account his loyalty, trustworthiness and reliability, may be authorised to have access to EUCI and the investigative and administrative procedures to be followed to that effect. |
II. GRANTING ACCESS TO EUCI
2. |
An individual shall only be granted access to classified information after:
|
3. |
Each Member State and the GSC shall identify the positions in their structures which require access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above and therefore require security clearance to the relevant level. |
III. PERSONNEL SECURITY CLEARANCE REQUIREMENTS
4. |
After having received a duly authorised request, NSAs or other competent national authorities shall be responsible for ensuring that security investigations are carried out on their nationals who require access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above. Standards of investigation shall be in accordance with national laws and regulations with a view to issuing a PSC or providing an assurance for the individual to be granted authorisation for access to EUCI, as appropriate. |
5. |
Should the individual concerned reside in the territory of another Member State or of a third State, the competent national authorities shall seek assistance from the competent authority of the State of residence in accordance with national laws and regulations. Member States shall assist one another in carrying out security investigations in accordance with national laws and regulations. |
6. |
Where permissible under national laws and regulations, NSAs or other competent national authorities may conduct investigations on non-nationals who require access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above. Standards of investigation shall be in accordance with national laws and regulations. |
Security investigation criteria
7. |
The loyalty, trustworthiness and reliability of an individual for the purposes of being security cleared for access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above shall be determined by means of a security investigation. The competent national authority shall make an overall assessment based on the findings of such a security investigation. The principal criteria used for that purpose include, to the extent possible under national laws and regulations, an examination of whether the individual:
|
8. |
Where appropriate and in accordance with national laws and regulations, an individual’s financial and medical background may also be considered relevant during the security investigation. |
9. |
Where appropriate and in accordance with national laws and regulations, a spouse’s, cohabitant’s or close family member’s conduct and circumstances may also be considered relevant during the security investigation. |
Investigative requirements for access to EUCI
Initial granting of a security clearance
10. |
The initial security clearance for access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET shall be based on a security investigation covering at least the last 5 years, or from age 18 to the present, whichever is the shorter, which shall include the following:
|
11. |
The initial security clearance for access to information classified TRÈS SECRET UE/EU TOP SECRET shall be based on a security investigation covering at least the last 10 years, or from age 18 to the present, whichever is the shorter. If interviews are conducted as stated in point (e), investigations shall cover at least the last 7 years, or from age 18 to the present, whichever is the shorter. In addition to the criteria indicated in paragraph 7 above, the following elements shall be investigated, to the extent possible under national laws and regulations, before granting a TRÈS SECRET UE/EU TOP SECRET PSC; they may also be investigated before granting a CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET PSC, where required by national laws and regulations:
|
12. |
Where necessary and in accordance with national laws and regulations, additional investigations may be conducted to develop all relevant information available on an individual and to substantiate or disprove adverse information. |
Renewal of a security clearance
13. |
After the initial granting of a security clearance and provided that the individual has had uninterrupted service with a national administration or the GSC and has a continuing need for access to EUCI, the security clearance shall be reviewed for renewal at intervals not exceeding 5 years for a TRÈS SECRET UE/EU TOP SECRET clearance and 10 years for SECRET UE/EU SECRET and CONFIDENTIEL UE/EU CONFIDENTIAL clearances, with effect from the date of notification of the outcome of the last security investigation on which they were based. All security investigations for renewing a security clearance shall cover the period since the previous such investigation. |
14. |
For renewing security clearances, the elements outlined in paragraphs 10 and 11 shall be investigated. |
15. |
Requests for renewal shall be made in a timely manner taking account of the time required for security investigations. Nevertheless, where the relevant NSA or other competent national authority has received the relevant request for renewal and the corresponding personnel security questionnaire before a security clearance expires, and the necessary security investigation has not been completed, the competent national authority may, where admissible under national laws and regulations, extend the validity of the existing security clearance for a period of up to 12 months. If, at the end of this 12-month period, the security investigation has still not been completed, the individual shall be assigned to duties which do not require a security clearance. |
Authorisation procedures in the GSC
16. |
For officials and other servants in the GSC, the GSC Security Authority shall forward the completed personnel security questionnaire to the NSA of the Member State of which the individual is a national requesting that a security investigation be undertaken for the level of EUCI to which the individual will require access. |
17. |
Where information relevant for a security investigation becomes known to the GSC concerning an individual who has applied for a security clearance for access to EUCI, the GSC, acting in accordance with the relevant rules and regulations, shall notify the relevant NSA thereof. |
18. |
Following completion of the security investigation, the relevant NSA shall notify the GSC Security Authority of the outcome of such an investigation, using the standard format for the correspondence prescribed by the Security Committee.
|
19. |
The security investigation together with the results obtained shall be subject to the relevant laws and regulations in force in the Member State concerned, including those concerning appeals. Decisions by the GSC Appointing Authority shall be subject to appeals in accordance with the Staff Regulations of Officials of the European Union and the Conditions of Employment of Other Servants of the European Union, laid down in Council Regulation (EEC, Euratom, ECSC) No 259/68 (1) (‘the Staff Regulations and Conditions of Employment’). |
20. |
National experts seconded to the GSC for a position requiring access to EUCI classified CONFIDENTIEL UE/EU CONFIDENTIAL and above shall present a valid Personnel Security Clearance Certificate (PSCC) for access to EUCI to the GSC Security Authority prior to taking up their assignment, on the basis of which the Appointing Authority shall issue an authorisation for access to EUCI. |
21. |
The GSC will accept the authorisation for access to EUCI granted by any other Union institution, body or agency, provided it remains valid. Authorisation will cover any assignment by the individual concerned within the GSC. The Union institution, body or agency in which the individual is taking up employment will notify the relevant NSA of the change of employer. |
22. |
If an individual’s period of service does not commence within 12 months of the notification of the outcome of the security investigation to the GSC Appointing Authority, or if there is a break of 12 months in an individual’s service, during which time he has not been employed in the GSC or in a position with a national administration of a Member State, this outcome shall be referred to the relevant NSA for confirmation that it remains valid and appropriate. |
23. |
Where information becomes known to the GSC concerning a security risk posed by an individual who has authorisation for access to EUCI, the GSC, acting in accordance with the relevant rules and regulations, shall notify the relevant NSA thereof and may suspend access to EUCI or withdraw authorisation for access to EUCI. |
24. |
Where an NSA notifies the GSC of withdrawal of an assurance given in accordance with paragraph 18(a) for an individual who has authorisation for access to EUCI, the GSC Appointing Authority may ask for any clarification the NSA can provide according to its national laws and regulations. If the adverse information is confirmed, authorisation shall be withdrawn and the individual shall be excluded from access to EUCI and from positions where such access is possible or where he might endanger security. |
25. |
Any decision to withdraw or suspend an authorisation from a GSC official or other servant for access to EUCI and, where appropriate, the reasons for doing so shall be notified to the individual concerned, who may ask to be heard by the Appointing Authority. Information provided by an NSA shall be subject to the relevant laws and regulations in force in the Member State concerned, including those concerning appeals. Decisions by the GSC Appointing Authority shall be subject to appeals in accordance with the Staff Regulations and Conditions of Employment. |
Records of security clearances and authorisations
26. |
Records of PSCs and authorisations granted for access to information classified as CONFIDENTIEL UE/EU CONFIDENTIAL or above shall be maintained respectively by each Member State and by the GSC. These records shall contain as a minimum the level of EUCI to which the individual may be granted access, the date the security clearance was granted and its period of validity. |
27. |
The competent security authority may issue a PSCC showing the level of EUCI to which the individual may be granted access (CONFIDENTIEL UE/EU CONFIDENTIAL or above), the date of validity of the relevant PSC for access to EUCI or authorisation for access to EUCI and the date of expiry of the certificate itself. |
Exemptions from the PSC requirement
28. |
Access to EUCI by individuals in Member States duly authorised by virtue of their functions shall be determined in accordance with national laws and regulations; such individuals shall be briefed on their security obligations in respect of protecting EUCI. |
IV. SECURITY EDUCATION AND AWARENESS
29. |
All individuals who have been granted a security clearance shall acknowledge in writing that they have understood their obligations in respect of protecting EUCI and the consequences if EUCI is compromised. A record of such a written acknowledgement shall be kept by the Member State and by the GSC, as appropriate. |
30. |
All individuals who are authorised to have access to, or required to handle EUCI, shall initially be made aware, and periodically briefed on the threats to security and must report immediately to the appropriate security authorities any approach or activity that they consider suspicious or unusual. |
31. |
All individuals who cease to be employed in duties requiring access to EUCI shall be made aware of, and where appropriate acknowledge in writing, their obligations in respect of the continued protection of EUCI. |
-
V.EXCEPTIONAL CIRCUMSTANCES
32. |
Where permissible under national laws and regulations, security clearance granted by a competent national authority of a Member State for access to national classified information may, for a temporary period pending the granting of a PSC for access to EUCI, allow access by national officials to EUCI up to the equivalent level specified in the table of equivalence in Appendix B where such temporary access is required in the interests of the Union. NSAs shall inform the Security Committee where national laws and regulations do not permit such temporary access to EUCI. |
33. |
For reasons of urgency, where duly justified in the interests of the service and pending completion of a full security investigation, the GSC Appointing Authority may, after consulting the NSA of the Member State of whom the individual is a national and subject to the outcome of preliminary checks to verify that no adverse information is known, grant a temporary authorisation for GSC officials and other servants to access EUCI for a specific function. Such temporary authorisations shall be valid for a period not exceeding 6 months and shall not permit access to information classified TRÈS SECRET UE/EU TOP SECRET. All individuals who have been granted a temporary authorisation shall acknowledge in writing that they have understood their obligations in respect of protecting EUCI and the consequences if EUCI is compromised. A record of such a written acknowledgement shall be kept by the GSC. |
34. |
When an individual is to be assigned to a position that requires a security clearance at one level higher than that currently possessed by the individual, the assignment may be made on a provisional basis, provided that:
|
35. |
The above procedure shall be used for one-time access to EUCI at one level higher than that to which the individual has been security cleared. Recourse to this procedure shall not be made on a recurring basis. |
36. |
In very exceptional circumstances, such as missions in hostile environments or during periods of mounting international tension when emergency measures require it, in particular for the purposes of saving lives, Member States and the Secretary-General may grant, where possible in writing, access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET to individuals who do not possess the requisite security clearance, provided that such permission is absolutely necessary and there are no reasonable doubts as to the loyalty, trustworthiness and reliability of the individual concerned. A record shall be kept of this permission describing the information to which access was approved. |
37. |
In the case of information classified TRÈS SECRET UE/EU TOP SECRET, this emergency access shall be confined to Union nationals who have been authorised access to either the national equivalent of TRÈS SECRET UE/EU TOP SECRET or information classified SECRET UE/EU SECRET. |
38. |
The Security Committee shall be informed of cases when recourse is made to the procedure set out in paragraphs 36 and 37. |
39. |
Where national laws and regulations of a Member State stipulate more stringent rules with respect to temporary authorisations, provisional assignments, one-time access or emergency access by individuals to classified information, the procedures foreseen in this Section shall be implemented only within any limitations set forth in the relevant national laws and regulations. |
40. |
The Security Committee shall receive an annual report on recourse to the procedures set out in this Section. |
VI. ATTENDANCE AT MEETINGS IN THE COUNCIL
41. |
Subject to paragraph 28, individuals assigned to participate in meetings of the Council or of Council preparatory bodies at which information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above is discussed may only do so upon confirmation of the individual’s security clearance status. For delegates, a PSCC or other proof of security clearance shall be forwarded by the appropriate authorities to the GSC Security Office, or exceptionally be presented by the delegate concerned. Where applicable, a consolidated list of names may be used, giving the relevant proof of security clearance. |
42. |
Where a PSC for access to EUCI is withdrawn for security reasons from an individual whose duties require attendance at meetings of the Council or of Council preparatory bodies, the competent authority shall inform the GSC thereof. |
VII. POTENTIAL ACCESS TO EUCI
43. |
Couriers, guards and escorts shall be security cleared to the relevant level or otherwise appropriately investigated in accordance with national laws and regulations, be briefed on security procedures for protecting EUCI and be instructed on their duties for protecting such information entrusted to them. |
-
Council Regulation (EEC, Euratom, ECSC) No 259/68 of 29 February 1968 laying down the Staff Regulations and the Conditions of Employment of Other Servants of the European Communities and instituting special measures temporarily applicable to officials of the Commission (OJ L 56, 4.3.1968, p. 1.).
ANNEX II
PHYSICAL SECURITY
-
I.INTRODUCTION
1. |
This Annex sets out provisions for implementing Article 8. It lays down minimum requirements for the physical protection of premises, buildings, offices, rooms and other areas where EUCI is handled and stored, including areas housing CIS. |
2. |
Physical security measures shall be designed to prevent unauthorised access to EUCI by:
|
II. PHYSICAL SECURITY REQUIREMENTS AND MEASURES
3. |
Physical security measures shall be selected on the basis of a threat assessment made by the competent authorities. The GSC and Member States shall each apply a risk management process for protecting EUCI on their premises to ensure that a commensurate level of physical protection is afforded against the assessed risk. The risk management process shall take account of all relevant factors, in particular:
|
4. |
The competent security authority, applying the concept of defence in depth, shall determine the appropriate combination of physical security measures to be implemented. These can include one or more of the following:
|
5. |
The competent authority can be authorised to conduct entry and exit searches to act as a deterrent to the unauthorised introduction of material or the unauthorised removal of EUCI from premises or buildings. |
6. |
When EUCI is at risk from overlooking, even accidentally, appropriate measures shall be taken to counter this risk. |
7. |
For new facilities, physical security requirements and their functional specifications shall be defined as part of the planning and design of the facilities. For existing facilities, physical security requirements shall be implemented to the maximum extent possible. |
III. EQUIPMENT FOR THE PHYSICAL PROTECTION OF EUCI
8. |
When acquiring equipment (such as security containers, shredding machines, door locks, electronic access control systems, IDS, alarm systems) for the physical protection of EUCI, the competent security authority shall ensure that the equipment meets approved technical standards and minimum requirements. |
9. |
The technical specifications of equipment to be used for the physical protection of EUCI shall be set out in security guidelines to be approved by the Security Committee. |
10. |
Security systems shall be inspected at regular intervals and equipment shall be maintained regularly. Maintenance work shall take account of the outcome of inspections to ensure that equipment continues to operate at optimum performance. |
11. |
The effectiveness of individual security measures and of the overall security system shall be re-evaluated during each inspection. |
IV. PHYSICALLY PROTECTED AREAS
12. |
Two types of physically protected areas, or the national equivalents thereof, shall be established for the physical protection of EUCI:
In this Decision, all references to Administrative Areas and Secured Areas, including technically Secured Areas, shall be understood as also referring to the national equivalents thereof. |
13. |
The competent security authority shall establish that an area meets the requirements to be designated as an Administrative Area, a Secured Area or a technically Secured Area. |
14. |
For Administrative Areas:
|
15. |
For Secured Areas:
|
16. |
Where entry into a Secured Area constitutes, for all practical purposes, direct access to the classified information contained in it, the following additional requirements shall apply:
|
17. |
Secured Areas protected against eavesdropping shall be designated technically Secured Areas. The following additional requirements shall apply:
|
18. |
Notwithstanding point (d) of paragraph 17, before being used in areas where meetings are held or work is being performed involving information classified SECRET UE/EU SECRET and above, and where the threat to EUCI is assessed as high, any communications devices and electrical or electronic equipment shall first be examined by the competent security authority to ensure that no intelligible information can be inadvertently or illicitly transmitted by such equipment beyond the perimeter of the Secured Area. |
19. |
Secured Areas which are not occupied by duty personnel on a 24-hour basis shall, where appropriate, be inspected at the end of normal working hours and at random intervals outside normal working hours, unless an IDS is in place. |
20. |
Secured Areas and technically Secured Areas may be set up temporarily within an Administrative Area for a classified meeting or any other similar purpose. |
21. |
Security operating procedures shall be drawn up for each Secured Area stipulating:
|
22. |
Strong rooms shall be constructed within Secured Areas. The walls, floors, ceilings, windows and lockable doors shall be approved by the competent security authority and afford protection equivalent to a security container approved for the storage of EUCI of the same classification level. |
-
V.PHYSICAL PROTECTIVE MEASURES FOR HANDLING AND STORING EUCI
23. |
EUCI which is classified RESTREINT UE/EU RESTRICTED may be handled:
|
24. |
EUCI which is classified RESTREINT UE/EU RESTRICTED shall be stored in suitable locked office furniture in an Administrative Area or a Secured Area. It may temporarily be stored outside a Secured Area or an Administrative Area provided the holder has undertaken to comply with compensatory measures laid down in security instructions issued by the competent security authority. |
25. |
EUCI which is classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET may be handled:
|
26. |
EUCI which is classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET shall be stored in a Secured Area either in a security container or in a strong room. |
27. |
EUCI which is classified TRÈS SECRET UE/EU TOP SECRET shall be handled in a Secured Area. |
28. |
EUCI which is classified TRÈS SECRET UE/EU TOP SECRET shall be stored in a Secured Area under one of the following conditions:
|
29. |
Rules governing the carriage of EUCI outside physically protected areas are set out in Annex III. |
VI. CONTROL OF KEYS AND COMBINATIONS USED FOR PROTECTING EUCI
30. |
The competent security authority shall define procedures for managing keys and combination settings for offices, rooms, strong rooms and security containers. Such procedures shall protect against unauthorised access. |
31. |
Combination settings shall be committed to memory by the smallest possible number of individuals needing to know them. Combination settings for security containers and strong rooms storing EUCI shall be changed:
|
ANNEX III
MANAGEMENT OF CLASSIFIED INFORMATION
-
I.INTRODUCTION
1. |
This Annex sets out provisions for implementing Article 9. It lays down the administrative measures for controlling EUCI throughout its life-cycle in order to help deter and detect deliberate or accidental compromise or loss of such information. |
II. CLASSIFICATION MANAGEMENT
Classifications and markings
2. |
Information shall be classified where it requires protection with regard to its confidentiality. |
3. |
The originator of EUCI shall be responsible for determining the security classification level, in accordance with the relevant classification guidelines, and for the initial dissemination of the information. |
4. |
The classification level of EUCI shall be determined in accordance with Article 2(2) and by reference to the security policy to be approved in accordance with Article 3(3). |
5. |
The security classification shall be clearly and correctly indicated, regardless of whether the EUCI is on paper, oral, electronic or in any other form. |
6. |
Individual parts of a given document (i.e. pages, paragraphs, sections, annexes, appendices, attachments and enclosures) may require different classifications and shall be marked accordingly, including when stored in electronic form. |
7. |
The overall classification level of a document or file shall be at least as high as that of its most highly classified component. When information from various sources is collated, the final product shall be reviewed to determine its overall security classification level, since it may warrant a higher classification than its component parts. |
8. |
To the extent possible, documents containing parts with different classification levels shall be structured so that parts with a different classification level may be easily identified and detached if necessary. |
9. |
The classification of a letter or note covering enclosures shall be as high as the highest classification of its enclosures. The originator shall indicate clearly at which level it is classified when detached from its enclosures by means of an appropriate marking, e.g.: CONFIDENTIEL UE/EU CONFIDENTIAL Without attachment(s) RESTREINT UE/EU RESTRICTED |
Markings
10. |
In addition to one of the security classification markings set out in Article 2(2), EUCI may bear additional markings, such as:
|
Abbreviated classification markings
11. |
Standardised abbreviated classification markings may be used to indicate the classification level of individual paragraphs of a text. Abbreviations shall not replace the full classification markings. |
12. |
The following standard abbreviations may be used within EU classified documents to indicate the classification level of sections or blocks of text of less than a single page:
|
Creation of EUCI
13. |
When creating an EU classified document:
|
14. |
Where it is not possible to apply paragraph 13 to EUCI, other appropriate measures shall be taken in accordance with security guidelines to be established pursuant to Article 6(2). |
Downgrading and declassification of EUCI
15. |
At the time of its creation, the originator shall indicate, where possible, and in particular for information classified RESTREINT UE/EU RESTRICTED, whether EUCI can be downgraded or declassified on a given date or following a specific event. |
16. |
The GSC shall regularly review EUCI held by it to ascertain whether the classification level still applies. The GSC shall establish a system to review the classification level of EUCI which it has originated no less frequently than every five years. Such a review shall not be necessary where the originator has indicated from the outset that the information will automatically be downgraded or declassified and the information has been marked accordingly. |
III. REGISTRATION OF EUCI FOR SECURITY PURPOSES
17. |
For every organisational entity within the GSC and Member States’ national administrations in which EUCI is handled, a responsible registry shall be identified to ensure that EUCI is handled in accordance with this Decision. Registries shall be established as Secured Areas as defined in Annex II. |
18. |
For the purposes of this Decision, registration for security purposes (‘registration’) means the application of procedures which record the life-cycle of material, including its dissemination and destruction. |
19. |
All material classified CONFIDENTIEL UE/EU CONFIDENTIAL and above shall be registered in designated registries when it arrives at or leaves an organisational entity. |
20. |
The Central Registry within the GSC shall keep a record of all classified information released by the Council and the GSC to third States and international organisations, and of all classified information received from third States or international organisations. |
21. |
In the case of a CIS, registration procedures may be performed by processes within the CIS itself. |
22. |
The Council shall approve a security policy on the registration of EUCI for security purposes. |
TRÈS SECRET UE/EU TOP SECRET registries
23. |
A registry shall be designated in the Member States and in the GSC to act as the central receiving and dispatching authority for information classified TRÈS SECRET UE/EU TOP SECRET. Where necessary, subordinate registries may be designated to handle such information for registration purposes. |
24. |
Such subordinate registries may not transmit TRÈS SECRET UE/EU TOP SECRET documents directly to other subordinate registries of the same central TRÈS SECRET UE/EU TOP SECRET registry or externally without the express written approval of the latter. |
IV. COPYING AND TRANSLATING EU CLASSIFIED DOCUMENTS
25. |
TRÈS SECRET UE/EU TOP SECRET documents shall not be copied or translated without the prior written consent of the originator. |
26. |
Where the originator of documents classified SECRET UE/EU SECRET and below has not imposed caveats on their copying or translation, such documents may be copied or translated on instruction from the holder. |
27. |
The security measures applicable to the original document shall apply to copies and translations thereof. |
-
V.CARRIAGE OF EUCI
28. |
Carriage of EUCI shall be subject to the protective measures set out in paragraphs 30 to 41. When EUCI is carried on electronic media, and notwithstanding Article 9(4), the protective measures set out below may be supplemented by appropriate technical countermeasures prescribed by the competent security authority so as to minimise the risk of loss or compromise. |
29. |
The competent security authorities in the GSC and in Member States shall issue instructions on the carriage of EUCI in accordance with this Decision. |
Within a building or self-contained group of buildings
30. |
EUCI carried within a building or self-contained group of buildings shall be covered in order to prevent observation of its contents. |
31. |
Within a building or self-contained group of buildings, information classified TRÈS SECRET UE/EU TOP SECRET shall be carried in a secured envelope bearing only the addressee’s name. |
Within the Union
32. |
EUCI carried between buildings or premises within the Union shall be packaged so that it is protected from unauthorised disclosure. |
33. |
The carriage of information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET within the Union shall be by one of the following means:
In the case of carriage from one Member State to another, the provisions of point (c) shall be limited to information classified up to CONFIDENTIEL UE/EU CONFIDENTIAL. |
34. |
Information classified RESTREINT UE/EU RESTRICTED may also be carried by postal services or commercial courier services. A courier certificate is not required for the carriage of such information. |
35. |
Material classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET (e.g. equipment or machinery) which cannot be carried by the means referred to in paragraph 33 shall be transported as freight by commercial carrier companies in accordance with Annex V. |
36. |
The carriage of information classified TRÈS SECRET UE/EU TOP SECRET between buildings or premises within the Union shall be by military, government or diplomatic courier, as appropriate. |
From within the Union to the territory of a third State
37. |
EUCI carried from within the Union to the territory of a third State shall be packaged in such a way that it is protected from unauthorised disclosure. |
38. |
The carriage of information classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET from within the Union to the territory of a third State shall be by one of the following means:
|
39. |
The carriage of information classified CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET released by the Union to a third State or international organisation shall comply with the relevant provisions under a security of information Agreement or an administrative arrangement in accordance with Article 13(2)(a) or (b). |
40. |
Information classified RESTREINT UE/EU RESTRICTED may also be carried by postal services or commercial courier services. |
41. |
The carriage of information classified TRÈS SECRET UE/EU TOP SECRET from within the Union to the territory of a third State shall be by military or diplomatic courier. |
VI. DESTRUCTION OF EUCI
42. |
EU classified documents which are no longer required may be destroyed, without prejudice to the relevant rules and regulations on archiving. |
43. |
Documents subject to registration in accordance with Article 9(2) shall be destroyed by the responsible registry on instruction from the holder or from a competent authority. The logbooks and other registration information shall be updated accordingly. |
44. |
For documents classified SECRET UE/EU SECRET or TRÈS SECRET UE/EU TOP SECRET, destruction shall be performed in the presence of a witness who shall be cleared to at least the classification level of the document being destroyed. |
45. |
The registrar and the witness, where the presence of the latter is required shall sign a destruction certificate, which shall be filed in the registry. The registry shall keep destruction certificates of TRÈS SECRET UE/EU TOP SECRET documents for a period of at least 10 years and of documents CONFIDENTIEL UE/EU CONFIDENTIAL and SECRET UE/EU SECRET for a period of at least five years. |
46. |
Classified documents, including those classified RESTREINT UE/EU RESTRICTED, shall be destroyed by methods which meet relevant Union or equivalent standards or which have been approved by Member States in accordance with national technical standards so as to prevent reconstruction in whole or in part. |
47. |
The destruction of computer storage media used for EUCI shall be in accordance with paragraph 37 of Annex IV. |
48. |
In the event of an emergency, if there is an imminent risk of unauthorised disclosure EUCI shall be destroyed by the holder in such a way that it cannot be reconstructed in whole or in part. The originator and originating registry shall be informed of the emergency destruction of registered EUCI. |
VII. ASSESSMENT VISITS
49. |
The term ‘assessment visit’ shall be used hereinafter to designate any:
to evaluate the effectiveness of measures implemented for protecting EUCI. |
50. |
Assessment visits shall be carried out, inter alia, to:
|
51. |
Before the end of each calendar year, the Council shall adopt the assessment visit programme foreseen in point (c) of Article 16(1) for the following year. The actual dates for each assessment visit shall be determined in agreement with the Union body or agency, Member State, third State or international organisation concerned. |
Conduct of assessment visits
52. |
Assessment visits shall be conducted in order to check the relevant rules, regulations and procedures in the visited entity and verify whether the entity’s practices comply with the basic principles and minimum standards laid down in this Decision and in the provisions governing the exchange of classified information with that entity. |
53. |
Assessment visits shall be conducted in two phases. Prior to the visit itself a preparatory meeting shall be organised, if necessary, with the entity concerned. After this preparatory meeting the assessment team shall establish, in agreement with the entity concerned, a detailed assessment visit programme covering all areas of security. The assessment visit team should have access to any location where EUCI is handled, in particular registries and CIS points of presence. |
54. |
Assessment visits to Member States’ national administrations, third States and international organisations shall be conducted in full cooperation with the officials of the entity, third State or international organisation being visited. |
55. |
Assessment visits to Union bodies, agencies and entities which apply this Decision or the principles thereof shall be conducted with assistance from experts of the NSA on whose territory the body or agency is located. |
56. |
In the case of assessment visits to Union bodies, agencies and entities which apply this Decision or the principles thereof, and to third States and international organisations, assistance and contributions from NSA experts may be requested in accordance with detailed arrangements to be agreed by the Security Committee. |
Reports
57. |
At the end of the assessment visit the main conclusions and recommendations shall be presented to the visited entity. Thereafter, a report on the assessment visit shall be drawn up. Where corrective action and recommendations have been proposed, sufficient details shall be included in the report to support the conclusions reached. The report shall be forwarded to the appropriate authority of the visited entity. |
58. |
For assessment visits conducted in Member States’ national administrations:
A regular report shall be prepared under the responsibility of the GSC Security Authority (Security Office) to highlight the lessons learned from the assessment visits conducted in Member States over a specified period and examined by the Security Committee. |
59. |
For assessment visits of third States and international organisations, the report shall be distributed to the Security Committee. The report shall be classified at least RESTREINT UE/EU RESTRICTED. Any corrective action shall be verified during a follow-up visit and reported to the Security Committee. |
60. |
For assessment visits to any Union bodies, agencies and entities which apply this Decision or the principles thereof, assessment visit reports shall be distributed to the Security Committee. The draft assessment visit report shall be forwarded to the agency or body concerned to verify that it is factually correct and that it contains no information classified higher than RESTREINT UE/EU RESTRICTED. Any corrective action shall be verified during a follow up visit and reported to the Security Committee. |
61. |
The GSC Security Authority shall conduct regular inspections of organisational entities in the GSC for the purposes laid down in paragraph 50. |
Checklist
62. |
The GSC Security Authority (Security Office) shall draw up and update a checklist of items to be verified in the course of an assessment visit. This checklist shall be forwarded to the Security Committee. |
63. |
The information to complete the checklist shall be obtained in particular during the visit from the security management of the entity being inspected. Once completed with the detailed responses, the checklist shall be classified in agreement with the inspected entity. It shall not form part of the inspection report. |
ANNEX IV
PROTECTION OF EUCI HANDLED IN CIS
-
I.INTRODUCTION
1. |
This Annex sets out provisions for implementing Article 10. |
2. |
The following IA properties and concepts are essential for the security and correct functioning of operations on CIS:
|
II. INFORMATION ASSURANCE PRINCIPLES
3. |
The provisions set out below shall form the baseline for the security of any CIS handling EUCI. Detailed requirements for implementing these provisions shall be defined in IA security policies and security guidelines. |
Security risk management
4. |
Security risk management shall be an integral part of defining, developing, operating and maintaining CIS. Risk management (assessment, treatment, acceptance and communication) shall be conducted as an iterative process jointly by representatives of the system owners, project authorities, operating authorities and security approval authorities, using a proven, transparent and fully understandable risk assessment process. The scope of the CIS and its assets shall be clearly defined at the outset of the risk management process. |
5. |
The competent authorities shall review the potential threats to CIS and shall maintain up-to-date and accurate threat assessments which reflect the current operational environment. They shall constantly update their knowledge of vulnerability issues and periodically review the vulnerability assessment to keep up with the changing information technology (IT) environment. |
6. |
The aim of security risk treatment shall be to apply a set of security measures which results in a satisfactory balance between user requirements, cost and residual security risk. |
7. |
The specific requirements, scale and the degree of detail determined by the relevant SAA for accrediting a CIS shall be commensurate with the assessed risk, taking account of all relevant factors, including the classification level of the EUCI handled in the CIS. Accreditation shall include a formal residual risk statement and acceptance of the residual risk by a responsible authority. |
Security throughout the CIS life-cycle
8. |
Ensuring security shall be a requirement throughout the entire CIS life-cycle from initiation to withdrawal from service. |
9. |
The role and interaction of each actor involved in a CIS with regard to its security shall be identified for each phase of the life-cycle. |
10. |
Any CIS, including its technical and non-technical security measures, shall be subject to security testing during the accreditation process to ensure that the appropriate level of assurance is obtained and to verify that they are correctly implemented, integrated and configured. |
11. |
Security assessments, inspections and reviews shall be performed periodically during the operation and maintenance of a CIS and when exceptional circumstances arise. |
12. |
Security documentation for a CIS shall evolve over its life-cycle as an integral part of the process of change and configuration management. |
Best practice
13. |
The GSC and the Member States shall cooperate to develop best practice for protecting EUCI handled on CIS. Best practice guidelines shall set out technical, physical, organisational and procedural security measures for CIS with proven effectiveness in countering given threats and vulnerabilities. |
14. |
The protection of EUCI handled on CIS shall draw on lessons learned by entities involved in IA within and outside the Union. |
15. |
The dissemination and subsequent implementation of best practice shall help achieve an equivalent level of assurance for the various CIS operated by the GSC and by Member States which handle EUCI. |
Defence in depth
16. |
To mitigate risk to CIS, a range of technical and non-technical security measures, organised as multiple layers of defence, shall be implemented. These layers shall include: (a) Deterrence: security measures aimed at dissuading any adversary planning to attack the CIS; (b) Prevention: security measures aimed at impeding or blocking an attack on the CIS; (c) Detection: security measures aimed at discovering the occurrence of an attack on the CIS; (d) Resilience: security measures aimed at limiting impact of an attack to a minimum set of information or CIS assets and preventing further damage; and (e) Recovery: security measures aimed at regaining a secure situation for the CIS. The degree of stringency of such security measures shall be determined following a risk assessment. |
17. |
The NSA or other competent authority shall ensure that:
|
Principle of minimality and least privilege
18. |
Only the essential functionalities, devices and services to meet operational requirements shall be implemented in order to avoid unnecessary risk. |
19. |
CIS users and automated processes shall be given only the access, privileges or authorisations they require to perform their tasks in order to limit any damage resulting from accidents, errors, or unauthorised use of CIS resources. |
20. |
Registration procedures performed by a CIS, where required, shall be verified as part of the accreditation process. |
Information Assurance awareness
21. |
Awareness of the risks and available security measures is the first line of defence for the security of CIS. In particular all personnel involved in the life-cycle of CIS, including users, shall understand:
|
22. |
To ensure that security responsibilities are understood, IA education and awareness training shall be mandatory for all personnel involved, including senior management and CIS users. |
Evaluation and approval of IT-security products
23. |
The required degree of confidence in the security measures, defined as a level of assurance, shall be determined following the outcome of the risk management process and in line with the relevant security policies and security guidelines. |
24. |
The level of assurance shall be verified by using internationally recognised or nationally approved processes and methodologies. This includes primarily evaluation, controls and auditing. |
25. |
Cryptographic products for protecting EUCI shall be evaluated and approved by a national CAA of a Member State. |
26. |
Prior to being recommended for approval by the Council or the Secretary-General in accordance with Article 10(6), such cryptographic products shall have undergone a successful second party evaluation by an Appropriately Qualified Authority (AQUA) of a Member State not involved in the design or manufacture of the equipment. The degree of detail required in a second party evaluation shall depend on the envisaged maximum classification level of EUCI to be protected by these products. The Council shall approve a security policy on the evaluation and approval of cryptographic products. |
27. |
Where warranted on specific operational grounds, the Council or the Secretary-General as appropriate may, upon recommendation by the Security Committee, waive the requirements under paragraphs 25 or 26 of this Annex and grant an interim approval for a specific period in accordance with the procedure laid down in Article 10(6). |
28. |
The Council, acting upon recommendation by the Security Committee, may accept the evaluation, selection and approval process of cryptographic products of a third State or international organisation and accordingly deem such cryptographic products approved for protecting EUCI released to that third state or international organisation. |
29. |
An AQUA shall be a CAA of a Member State that has been accredited on the basis of criteria laid down by the Council to undertake the second evaluation of cryptographic products for protecting EUCI. |
30. |
The Council shall approve a security policy on the qualification and approval of non-cryptographic IT security products. |
Transmission within Secured and Administrative Areas
31. |
Notwithstanding the provisions of this Decision, when transmission of EUCI is confined within Secured Areas or Administrative Areas, unencrypted transmission or encryption at a lower level may be used based on the outcome of a risk management process and subject to the approval of the SAA. |
Secure interconnection of CIS
32. |
For the purposes of this Decision, an interconnection shall mean the direct connection of two or more IT systems for the purpose of sharing data and other information resources (e.g. communication) in a unidirectional or multidirectional way. |
33. |
A CIS shall treat any interconnected IT system as untrusted and shall implement protective measures to control the exchange of classified information. |
34. |
For all interconnections of CIS with another IT system the following basic requirements shall be met:
|
35. |
There shall be no interconnection between an accredited CIS and an unprotected or public network, except where the CIS has approved BPS installed for such a purpose between the CIS and the unprotected or public network. The security measures for such interconnections shall be reviewed by the competent IAA and approved by the competent SAA. When the unprotected or public network is used solely as a carrier and the data is encrypted by a cryptographic product approved in accordance with Article 10, such a connection shall not be deemed to be an interconnection. |
36. |
The direct or cascaded interconnection of a CIS accredited to handle TRÈS SECRET UE/EU TOP SECRET to an unprotected or public network shall be prohibited. |
Computer storage media
37. |
Computer storage media shall be destroyed in accordance with procedures approved by the competent security authority. |
38. |
Computer storage media shall be reused, downgraded or declassified in accordance with security guidelines to be established pursuant to Article 6(2). |
Emergency circumstances
39. |
Notwithstanding the provisions of this Decision, the specific procedures described below may be applied in an emergency, such as during impending or actual crisis, conflict, war situations or in exceptional operational circumstances. |
40. |
EUCI may be transmitted using cryptographic products which have been approved for a lower classification level or without encryption with the consent of the competent authority if any delay would cause harm clearly outweighing the harm entailed by any disclosure of the classified material and if:
|
41. |
Classified information transmitted under the circumstances set out in paragraph 39 shall not bear any markings or indications distinguishing it from information which is unclassified or which can be protected by an available cryptographic product. Recipients shall be notified of the classification level, without delay, by other means. |
42. |
Should recourse be made to paragraph 39 a subsequent report shall be made to the competent authority and to the Security Committee. |
III. INFORMATION ASSURANCE FUNCTIONS AND AUTHORITIES
43. |
The following IA functions shall be established in the Member States and the GSC. These functions do not require single organisational entities. They shall have separate mandates. However, these functions, and their accompanying responsibilities, may be combined or integrated in the same organisational entity or split into different organisational entities, provided that internal conflicts of interests or tasks are avoided. |
Information Assurance Authority
44. |
The IAA shall be responsible for:
|
TEMPEST Authority
45. |
The TEMPEST Authority (TA) shall be responsible for ensuring compliance of CIS with TEMPEST policies and guidelines. It shall approve TEMPEST countermeasures for installations and products to protect EUCI to a defined level of classification in its operational environment. |
Crypto Approval Authority
46. |
The Crypto Approval Authority (CAA) shall be responsible for ensuring that cryptographic products comply with national cryptographic policy or the Council’s cryptographic policy. It shall grant the approval of a cryptographic product to protect EUCI to a defined level of classification in its operational environment. As regards the Member States, the CAA shall in addition be responsible for evaluating cryptographic products. |
Crypto Distribution Authority
47. |
The Crypto Distribution Authority (CDA) shall be responsible for:
|
Security Accreditation Authority
48. |
The SAA for each system shall be responsible for:
|
49. |
The GSC SAA shall be responsible for accrediting all CIS operating within the remit of the GSC. |
50. |
The relevant SAA of a Member State shall be responsible for accrediting CIS and components thereof operating within the remit of a Member State. |
51. |
A joint Security Accreditation Board (SAB) shall be responsible for accrediting CIS within the remit of both the GSC SAA and Member States’ SAAs. It shall be composed of an SAA representative from each Member State and be attended by an SAA representative of the Commission. Other entities with nodes on a CIS shall be invited to attend when that system is under discussion. The SAB shall be chaired by a representative of the GSC SAA. It shall act by consensus of SAA representatives of institutions, Member States and other entities with nodes on the CIS. It shall make periodic reports on its activities to the Security Committee and shall notify all accreditation statements to it. |
Information Assurance Operational Authority
52. |
The IA Operational Authority for each system shall be responsible for:
|
ANNEX V
INDUSTRIAL SECURITY
-
I.INTRODUCTION
1. |
This Annex sets out provisions for implementing Article 11. It lays down general security provisions applicable to industrial or other entities in pre-contract negotiations and throughout the life-cycle of classified contracts let by the GSC. |
2. |
The Council shall approve guidelines on industrial security outlining in particular detailed requirements regarding FSCs, Security Aspects Letters (SALs), visits, transmission and carriage of EUCI. |
II. SECURITY ELEMENTS IN A CLASSIFIED CONTRACT
Security classification guide (SCG)
3. |
Prior to launching a call for tender or letting a classified contract, the GSC, as the contracting authority, shall determine the security classification of any information to be provided to bidders and contractors, as well as the security classification of any information to be created by the contractor. For that purpose, the GSC shall prepare an SCG to be used for the performance of the contract. |
4. |
In order to determine the security classification of the various elements of a classified contract, the following principles shall apply:
|
Security aspects letter (SAL)
5. |
The contract-specific security requirements shall be described in a SAL. The SAL shall, where appropriate, contain the SCG and shall be an integral part of a classified contract or sub-contract. |
6. |
The SAL shall contain the provisions requiring the contractor and/or subcontractor to comply with the minimum standards laid down in this Decision. Non-compliance with these minimum standards may constitute sufficient grounds for the contract to be terminated. |
Programme/Project Security Instructions (PSI)
7. |
Depending on the scope of programmes or projects involving access to or handling or storage of EUCI, specific PSI may be prepared by the contracting authority designated to manage the programme or project. The PSI shall require the approval of the Member States’ NSAs/DSAs or any other competent security authority participating in the PSI and may contain additional security requirements. |
III. FACILITY SECURITY CLEARANCE (FSC)
8. |
An FSC shall be granted by the NSA or DSA or any other competent security authority of a Member State to indicate, in accordance with national laws and regulations, that an industrial or other entity can protect EUCI at the appropriate classification level (CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET) within its facilities. It shall be presented to the GSC, as the contracting authority, before a contractor or subcontractor or potential contractor or subcontractor may be provided with or granted access to EUCI. |
9. |
When issuing an FSC, the relevant NSA or DSA shall, as a minimum:
|
10. |
Where relevant, the GSC, as the contracting authority, shall notify the appropriate NSA/DSA or any other competent security authority that an FSC is required in the pre-contractual stage or for performing the contract. An FSC or PSC shall be required in the pre-contractual stage where EUCI classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET has to be provided in the course of the bidding process. |
11. |
The contracting authority shall not award a classified contract with a preferred bidder before having received confirmation from the NSA/DSA or any other competent security authority of the Member State in which the contractor or subcontractor concerned is registered that, where required, an appropriate FSC has been issued. |
12. |
The NSA/DSA or any other competent security authority which has issued an FSC shall notify the GSC as contracting authority about changes affecting the FSC. In the case of a sub-contract, the NSA/DSA or any other competent security authority shall be informed accordingly. |
13. |
Withdrawal of an FSC by the relevant NSA/DSA or any other competent security authority shall constitute sufficient grounds for the GSC, as the contracting authority, to terminate a classified contract or exclude a bidder from the competition. |
IV. CLASSIFIED CONTRACTS AND SUB-CONTRACTS
14. |
Where EUCI is provided to a bidder at the pre-contractual stage, the invitation to bid shall contain a provision obliging the bidder which fails to submit a bid or which is not selected to return all classified documents within a specified period of time. |
15. |
Once a classified contract or sub-contract has been awarded, the GSC, as the contracting authority, shall notify the contractor’s or subcontractor’s NSA/DSA or any other competent security authority about the security provisions of the classified contract. |
16. |
When such contracts are terminated, the GSC, as the contracting authority (and/or the NSA/DSA or any other competent security authority, as appropriate, in the case of a sub-contract) shall promptly notify the NSA/DSA or any other competent security authority of the Member State in which the contractor or subcontractor is registered. |
17. |
As a general rule, the contractor or subcontractor shall be required to return to the contracting authority, upon termination of the classified contract or sub-contract, any EUCI held by it. |
18. |
Specific provisions for the disposal of EUCI during the performance of the contract or upon its termination shall be laid down in the SAL. |
19. |
Where the contractor or subcontractor is authorised to retain EUCI after termination of a contract, the minimum standards contained in this Decision shall continue to be complied with and the confidentiality of EUCI shall be protected by the contractor or subcontractor. |
20. |
The conditions under which the contractor may subcontract shall be defined in the call for tender and in the contract. |
21. |
A contractor shall obtain permission from the GSC, as the contracting authority, before sub-contracting any parts of a classified contract. No subcontract may be awarded to industrial or other entities registered in a non-EU Member State which has not concluded a security of information Agreement with the Union. |
22. |
The contractor shall be responsible for ensuring that all sub-contracting activities are undertaken in accordance with the minimum standards laid down in this Decision and shall not provide EUCI to a subcontractor without the prior written consent of the contracting authority. |
23. |
With regard to EUCI created or handled by the contractor or subcontractor, the rights incumbent on the originator shall be exercised by the contracting authority. |
-
V.VISITS IN CONNECTION WITH CLASSIFIED CONTRACTS
24. |
Where the GSC, contractors’ or subcontractors’ personnel require access to information classified CONFIDENTIEL UE/EU CONFIDENTIAL or SECRET UE/EU SECRET in each other’s premises for the performance of a classified contract, visits shall be arranged in liaison with the NSAs/DSAs or any other competent security authority concerned. However, in the context of specific projects, the NSAs/DSAs may also agree on a procedure whereby such visits can be arranged directly. |
25. |
All visitors shall hold an appropriate PSC and have a ‘need-to-know’ for access to the EUCI related to the GSC contract. |
26. |
Visitors shall be given access only to EUCI related to the purpose of the visit. |
VI. TRANSMISSION AND CARRIAGE OF EUCI
27. |
With regard to the transmission of EUCI by electronic means, the relevant provisions of Article 10 and Annex IV shall apply. |
28. |
With regard to the carriage of EUCI, the relevant provisions of Annex III shall apply, in accordance with national laws and regulations. |
29. |
For the transport of classified material as freight, the following principles shall be applied when determining security arrangements:
|
VII. TRANSFER OF EUCI TO CONTRACTORS LOCATED IN THIRD STATES
30. |
EUCI shall be transferred to contractors and subcontractors located in third States in accordance with security measures agreed between the GSC, as the contracting authority, and the NSA/DSA of the concerned third State where the contractor is registered. |
VIII INFORMATION CLASSIFIED RESTREINT UE/EU RESTRICTED
31. |
In liaison, as appropriate, with the NSA/DSA of the Member State the GSC, as the contracting authority, shall be entitled to conduct inspections of contractors’/subcontractors’ facilities on the basis of contractual provisions in order to verify that the relevant security measures for the protection of EUCI at the level RESTREINT UE/EU RESTRICTED as required under the contract have been put in place. |
32. |
To the extent necessary under national laws and regulations, NSAs/DSAs or any other competent security authority shall be notified by the GSC as the contracting authority of contracts or subcontracts containing information classified RESTREINT UE/EU RESTRICTED. |
33. |
An FSC or a PSC for contractors or subcontractors and their personnel shall not be required for contracts let by the GSC containing information classified RESTREINT UE/EU RESTRICTED. |
34. |
The GSC, as the contracting authority, shall examine the responses to invitations to tender for contracts which require access to information classified RESTREINT UE/EU RESTRICTED, notwithstanding any requirement relating to FSC or PSC which may exist under national laws and regulations. |
35. |
The conditions under which the contractor may subcontract shall be in accordance with paragraph 21. |
36. |
Where a contract involves handling information classified RESTREINT UE/EU RESTRICTED in a CIS operated by a contractor, the GSC as contracting authority shall ensure that the contract or any subcontract specifies the necessary technical and administrative requirements regarding accreditation of the CIS commensurate with the assessed risk, taking account of all relevant factors. The scope of accreditation of such CIS shall be agreed between the contracting authority and the relevant NSA/DSA. |
ANNEX VI
EXCHANGE OF CLASSIFIED INFORMATION WITH THIRD STATES AND INTERNATIONAL ORGANISATIONS
-
I.INTRODUCTION
1. |
This Annex sets out provisions for implementing Article 13. |
II. FRAMEWORKS GOVERNING THE EXCHANGE OF CLASSIFIED INFORMATION
2. |
Where the Council determines that a long-term need exists to exchange classified information,
in accordance with Article 13(2) and Sections III and IV and based on a recommendation from the Security Committee. |
3. |
Where EUCI generated for the purposes of a CSDP operation is to be provided to third States or international organisations participating in such an operation, and where neither of the frameworks referred to in paragraph 2 exists, the exchange of EUCI with the contributing third State or international organisation shall be regulated, in accordance with Section V, under:
|
4. |
In the absence of a framework referred to in paragraphs 2 and 3, and where a decision is taken to release EUCI to a third State or international organisation on an exceptional ad hoc basis in accordance with Section VI, written assurances shall be sought from the third State or international organisation concerned to ensure that it protects any EUCI released to it in accordance with the basic principles and minimum standards set out in this Decision. |
III. SECURITY OF INFORMATION AGREEMENTS
5. |
Security of information agreements shall establish the basic principles and minimum standards governing the exchange of classified information between the Union and a third State or international organisation. |
6. |
Security of information agreements shall provide for technical implementing arrangements to be agreed between the competent security authorities of the relevant Union institutions and bodies and the competent security authority of the third State or international organisation in question. Such arrangements shall take account of the level of protection provided by the security regulations, structures and procedures in place in the third State or international organisation concerned. They shall be approved by the Security Committee. |
7. |
No EUCI shall be exchanged under a security of information agreement by electronic means unless explicitly provided for in the agreement or in corresponding technical implementing arrangements. |
8. |
When the Council concludes a security of information agreement, a registry shall be designated in each party as the main point of entry and exit for classified information exchanges. |
9. |
In order to assess the effectiveness of the security regulations, structures and procedures in the third State or international organisation concerned, assessment visits shall be conducted in mutual agreement with the third State or international organisation concerned. Such assessment visits shall be conducted in accordance with the relevant provisions of Annex III and shall evaluate:
|
10. |
The team conducting an assessment visit on behalf of the Union shall assess whether the security regulations and procedures in the third State or international organisation in question are adequate for the protection of EUCI at a given level. |
11. |
The findings of such visits shall be set out in a report on the basis of which the Security Committee shall determine the maximum level of EUCI which may be exchanged in hard copy, and where appropriate electronically, with the third party concerned as well as any specific conditions governing exchange with that party. |
12. |
Every endeavour shall be made to conduct a full security assessment visit to the third State or international organisation in question before the Security Committee approves the implementing arrangements in order to establish the nature and the effectiveness of the security system in place. However, where this is not possible the Security Committee shall receive as full a report as possible from the GSC Security Office, based on the information available to it, informing the Security Committee about the security regulations applicable and the way in which security is organised in the third State or international organisation concerned. |
13. |
The report on the assessment visit, or in the absence of such a report the report referred to in paragraph 12, shall be forwarded to, and deemed satisfactory by, the Security Committee before EUCI is actually released to the third State or international organisation in question. |
14. |
The competent security authorities of the Union institutions and bodies shall communicate to the third State or international organisation the date as from when the Union is in a position to release EUCI under the agreement, as well as the maximum level of EUCI which may be exchanged in paper form or by electronic means. |
15. |
Follow-up assessment visits shall be conducted as necessary, in particular if:
|
16. |
Once the security of information agreement is in force and classified information is exchanged with the third State or international organisation concerned, the Security Committee may decide to modify the maximum level of EUCI which may be exchanged in paper form or by electronic means, in particular in the light of any follow-up assessment visit. |
IV. ADMINISTRATIVE ARRANGEMENTS
17. |
Where a long-term need exists to exchange information classified as a general rule no higher than RESTREINT UE/EU RESTRICTED with a third State or international organisation, and where the Security Committee has established that the party in question does not have a sufficiently developed security system for it to be possible to enter into a security of information agreement, the Secretary-General may, subject to approval by the Council, enter into an administrative arrangement on behalf of the GSC with the relevant authorities of the third State or international organisation in question. |
18. |
Where, for urgent operational reasons, a framework for exchanging classified information needs to be put in place rapidly, exceptionally the Council may decide that an administrative arrangement be entered into for exchanging information of a higher classification level. |
19. |
Administrative arrangements shall as a general rule take the form of an Exchange of Letters. |
20. |
An assessment visit referred to in paragraph 9 shall be conducted and the report, or in the absence of such a report the report referred to in paragraph 12, forwarded to, and deemed satisfactory by, the Security Committee before EUCI is actually released to the third State or international organisation in question. |
21. |
No EUCI shall be exchanged under an administrative arrangement by electronic means unless explicitly provided for in the arrangement. |
-
V.EXCHANGE OF CLASSIFIED INFORMATION IN THE CONTEXT OF CSDP OPERATIONS
22. |
Framework participation agreements govern the participation of third States or international organisations in CSDP operations. Such agreements shall include provisions on the release of EUCI generated for the purposes of CSDP operations to the contributing third States or international organisations. The maximum classification level of EUCI which may be exchanged shall be RESTREINT UE/EU RESTRICTED for civilian CSDP operations and CONFIDENTIEL UE/EU CONFIDENTIAL for military CSDP operations, unless otherwise laid down in the Decision establishing each CSDP operation. |
23. |
Ad hoc participation agreements concluded for a specific CSDP operation shall include provisions on the release of EUCI generated for the purposes of that operation to the contributing third State or international organisation. The maximum classification level of EUCI which may be exchanged shall be RESTREINT UE/EU RESTRICTED for civilian CSDP operations and CONFIDENTIEL UE/EU CONFIDENTIAL for military CSDP operations, unless otherwise laid down in the Decision establishing each CSDP operation. |
24. |
In the absence of a security of information agreement and pending the conclusion of a participation agreement, the release of EUCI generated for the purposes of the operation to a third State or international organisation participating in the operation shall be governed by an administrative arrangement to be entered into by the High Representative or subject to a decision on ad hoc release in accordance with Section VI. EUCI shall only be exchanged under such an arrangement as long as the participation of the third State or international organisation is still envisaged. The maximum classification level of EUCI which may be exchanged shall be RESTREINT UE/EU RESTRICTED for civilian CSDP operations and CONFIDENTIEL UE/EU CONFIDENTIAL for military CSDP operations, unless otherwise laid down in the Decision establishing each CSDP operation. |
25. |
The provisions on classified information to be included in framework participation agreements, ad hoc participation agreements and ad hoc administrative arrangements referred to in paragraphs 22 to 24 shall provide that the third State or international organisation in question shall ensure that its personnel seconded to any operation will protect EUCI in accordance with the Council’s security rules and with further guidance issued by the competent authorities, including the operation’s chain of command. |
26. |
If a security of information agreement is subsequently concluded between the Union and a contributing third State or international organisation, the security of information agreement shall supersede the provisions on the exchange of classified information laid down in any framework participation agreement, ad hoc participation agreement or ad hoc administrative arrangement as far as the exchange and handling of EUCI is concerned. |
27. |
No exchange of EUCI by electronic means shall be permitted under a framework participation agreement, ad hoc participation agreement or ad hoc administrative arrangement with a third State or international organisation, unless explicitly provided for in the agreement or arrangement in question. |
28. |
EUCI generated for the purposes of a CSDP operation may be disclosed to personnel seconded to that operation by third States or international organisations in accordance with paragraphs 22 to 27. When authorising access to EUCI in premises or in CIS of a CSDP operation by such personnel, measures shall be applied (including recording of EUCI disclosed) to mitigate the risk of loss or compromise. Such measures shall be defined in relevant planning or mission documents. |
29. |
In the absence of a security of information agreement, the release of EUCI, in the event of a specific and immediate operational need, to the host State on whose territory a CSDP operation is conducted, may be governed by an administrative arrangement to be entered into by the High Representative. This possibility shall be provided for in the Decision establishing the CSDP operation. EUCI released under such circumstances shall be restricted to that generated for the purposes of the CSDP operation and classified no higher than RESTREINT UE/EU RESTRICTED, unless a higher level of classification is laid down in the Decision establishing the CSDP operation. Under such an administrative arrangement, the host State shall be required to undertake to protect EUCI according to minimum standards which are no less stringent than those laid down in this Decision. |
30. |
In the absence of a security of information agreement, the release of EUCI to relevant third States and international organisations, other than those participating in a CSDP operation, may be governed by an administrative arrangement to be entered into by the High Representative. Where appropriate, this possibility, as well as any conditions attached thereto, shall be provided for in the Decision establishing the CSDP operation. EUCI released under such circumstances shall be restricted to that generated for the purposes of the CSDP operation and classified no higher than RESTREINT UE/EU RESTRICTED, unless a higher level of classification is laid down in the Decision establishing the CSDP operation. Under such an administrative arrangement, the third State or international organisation in question shall be required to undertake to protect EUCI according to minimum standards which are no less stringent than those laid down in this Decision. |
31. |
No implementing arrangements or assessment visits are required prior to implementing the provisions on release of EUCI in the context of paragraphs 22, 23 and 24. |
VI. EXCEPTIONAL AD HOC RELEASE OF EUCI
32. |
Where no framework is in place in accordance with Sections III to V, and where the Council or one of its preparatory bodies determines the exceptional need to release EUCI to a third State or international organisation, the GSC shall:
|
33. |
If the Security Committee issues a recommendation in favour of releasing the EUCI, the matter shall be referred to the Committee of Permanent Representatives (Coreper), which shall take a decision on its release. |
34. |
If the Security Committee’s recommendation is not in favour of releasing the EUCI:
|
35. |
Where deemed appropriate, and subject to the prior written consent of the originator, Coreper may decide that the classified information may be released only in part or only if downgraded or declassified beforehand, or that the information to be released shall be prepared without reference to the source or original EU classification level. |
36. |
Following a decision to release EUCI, the GSC shall forward the document concerned, which shall bear a releasability marking indicating the third State or international organisation to which it has been released. Prior to or upon actual release, the third party in question shall undertake in writing to protect the EUCI it receives in accordance with the basic principles and minimum standards set out in this Decision. |
VII. AUTHORITY TO RELEASE EUCI TO THIRD STATES OR INTERNATIONAL ORGANISATIONS
37. |
Where a framework exists in accordance with paragraph 2 for exchanging classified information with a third State or international organisation, the Council shall take a decision to authorise the Secretary-General to release EUCI, in accordance with the principle of originator’s consent, to the third State or international organisation in question. The Secretary-General may delegate such authorisation to senior GSC officials. |
38. |
Where a security of information agreement exists in accordance with paragraph 2, first indent, the Council may take a decision to authorise the High Representative to release EUCI originating in the Council in the area of the Common Foreign and Security Policy, after having obtained the consent of the originator of any source material contained therein, to the third State or international organisation in question. The High Representative may delegate such authorisation to senior EEAS officials or to EUSRs. |
39. |
Where a framework exists in accordance with paragraph 2 or with paragraph 3 for exchanging classified information with a third State or international organisation, the High Representative shall be authorised to release EUCI, in accordance with the Decision establishing the CSDP operation and with the principle of originator’s consent. The High Representative may delegate such authorisation to senior EEAS officials, to EU Operation, Force or Mission Commanders, or to Heads of EU Mission. |
Appendices
Appendix A
Definitions
Appendix B
Equivalence of security classifications
Appendix C
List of national security authorities (NSAs)
Appendix D
List of abbreviations
Appendix A
DEFINITIONS
For the purposes of this Decision, the following definitions shall apply:
‘Accreditation’ means the process leading to a formal statement by the Security Accreditation Authority (SAA) that a system is approved to operate with a defined level of classification, in a particular security mode in its operational environment and at an acceptable level of risk, based on the premise that an approved set of technical, physical, organisational and procedural security measures has been implemented; |
‘Asset’ means anything that is of value to an organisation, its business operations and their continuity, including information resources that support the organisation’s mission; |
‘Authorisation for access to EUCI’ means a decision by the GSC Appointing Authority taken on the basis of an assurance given by a competent authority of a Member State that a GSC official, other servant or seconded national expert may, provided his ‘need-to-know’ has been determined and he has been appropriately briefed on his responsibilities, be granted access to EUCI up to a specified level (CONFIDENTIEL UE/EU CONFIDENTIAL or above) until a specified date; |
‘CIS life-cycle’ means the entire duration of existence of a CIS, which includes initiation, conception, planning, requirements analysis, design, development, testing, implementation, operation, maintenance and decommissioning; |
‘Classified contract’ means a contract entered into by the GSC with a contractor for the supply of goods, execution of works or provision of services, the performance of which requires or involves access to or the creation of EUCI; |
‘Classified subcontract’ means a contract entered into by a contractor of the GSC with another contractor (i.e. the subcontractor) for the supply of goods, execution of works or provision of services, the performance of which requires or involves access to or the creation of EUCI; |
‘Communication and information system’ (CIS) — see Article 10(2); |
‘Contractor’ means an individual or legal entity possessing the legal capacity to undertake contracts; |
‘Cryptographic (Crypto) material’ means cryptographic algorithms, cryptographic hardware and software modules, and products including implementation details and associated documentation and keying material; |
‘Cryptographic product’ means a product whose primary and main functionality is the provision of security services (confidentiality, integrity, availability, authenticity, non-repudiation) through one or more cryptographic mechanisms; |
‘CSDP operation’ means a military or civilian crisis management operation under Title V, Chapter 2, of the TEU; |
‘Declassification’ means the removal of any security classification; |
‘Defence in depth’ means the application of a range of security measures organised as multiple layers of defence; |
‘Designated Security Authority’ (DSA) means an authority responsible to the National Security Authority (NSA) of a Member State which is responsible for communicating to industrial or other entities national policy on all matters of industrial security and for providing direction and assistance in its implementation. The function of DSA may be carried out by the NSA or by any other competent authority; |
‘Document’ means any recorded information regardless of its physical form or characteristics; |
‘Downgrading’ means a reduction in the level of security classification; |
‘EU classified information’ (EUCI) — see Article 2(1); |
‘Facility Security Clearance’ (FSC) means an administrative determination by an NSA or DSA that, from the security viewpoint, a facility can afford an adequate level of protection to EUCI of a specified security classification level; |
‘Handling’ of EUCI means all possible actions to which EUCI may be subject throughout its life-cycle. It comprises its creation, processing, carriage, downgrading, declassification and destruction. In relation to CIS it also comprises its collection, display, transmission and storage; |
‘Holder’ means a duly authorised individual with an established need-to-know who is in possession of an item of EUCI and is accordingly responsible for protecting it; |
‘Industrial or other entity’ means an entity involved in supplying goods, executing works or providing services; this may be an industrial, commercial, service, scientific, research, educational or development entity or a self-employed individual; |
‘Industrial security’ — see Article 11(1); |
‘Information Assurance’ — see Article 10(1); |
‘Interconnection’ — see Annex IV, paragraph 32; |
‘Management of classified information’ — see Article 9(1); |
‘Material’ means any document, data carrier or item of machinery or equipment, either manufactured or in the process of manufacture; |
‘Originator’ means the Union institution, body or agency, Member State, third state or international organisation under whose authority classified information has been created and/or introduced into the Union’s structures; |
‘Personnel security’ — see Article 7(1); |
‘Personnel Security Clearance’ (PSC) means a statement by a competent authority of a Member State which is made following completion of a security investigation conducted by the competent authorities of a Member State and which certifies that an individual may be granted access to EUCI up to a specified level (CONFIDENTIEL UE/EU CONFIDENTIAL or above) until a specified date; |
‘Personnel Security Clearance Certificate’ (PSCC) means a certificate issued by a competent authority establishing that an individual is security cleared and holds a valid security clearance certificate or authorisation from the Appointing Authority for access to EUCI, and which shows the level of EUCI to which that individual may be granted access (CONFIDENTIEL UE/EU CONFIDENTIAL or above), the date of validity of the relevant PSC and the date of expiry of the certificate itself; |
‘Physical security’ — see Article 8(1); |
‘Programme/Project Security Instruction’ (PSI) means a list of security procedures which are applied to a specific programme/project in order to standardise security procedures. It may be revised throughout the programme/project; |
‘Registration’ — see Annex III, paragraph 18; |
‘Residual risk’ means the risk which remains after security measures have been implemented, given that not all threats are countered and not all vulnerabilities can be eliminated; |
‘Risk’ means the potential that a given threat will exploit internal and external vulnerabilities of an organisation or of any of the systems it uses and thereby cause harm to the organisation and to its tangible or intangible assets. It is measured as a combination of the likelihood of threats occurring and their impact.
|
‘Security Aspects Letter’ (SAL) means a set of special contractual conditions issued by the contracting authority which forms an integral part of any classified contract involving access to or the creation of EUCI, that identifies the security requirements or those elements of the contract requiring security protection; |
‘Security Classification Guide’ (SCG) means a document which describes the elements of a programme or contract which are classified, specifying the applicable security classification levels. The SCG may be expanded throughout the life of the programme or contract and the elements of information may be re-classified or downgraded; where an SCG exists it shall be part of the SAL; |
‘Security investigation’ means the investigative procedures conducted by the competent authority of a Member State in accordance with its national laws and regulations in order to obtain an assurance that nothing adverse is known which would prevent an individual from being granted a PSC or an authorisation for access to EUCI up to a specified level (CONFIDENTIEL UE/EU CONFIDENTIAL or above); |
‘Security mode of operation’ means the definition of the conditions under which a CIS operates based on the classification of information handled and the clearance levels, formal access approvals, and need-to-know of its users. Four modes of operation exist for handling or transmitting classified information: dedicated mode, system-high mode, compartmented mode and multilevel mode:
|
‘Security risk management process’ means the entire process of identifying, controlling and minimising uncertain events that may affect the security of an organisation or of any of the systems it uses. It covers the entirety of risk-related activities, including assessment, treatment, acceptance and communication; |
‘TEMPEST’ means the investigation, study and control of compromising electromagnetic emanations and the measures to suppress them; |
‘Threat’ means a potential cause of an unwanted incident which may result in harm to an organisation or any of the systems it uses; such threats may be accidental or deliberate (malicious) and are characterised by threatening elements, potential targets and attack methods; |
‘Vulnerability’ means a weakness of any nature that can be exploited by one or more threats. A vulnerability may be an omission or it may relate to a weakness in controls in terms of their strength, completeness or consistency and may be of a technical, procedural, physical, organisational or operational nature. |
Appendix B
EQUIVALENCE OF SECURITY CLASSIFICATIONS
EU |
TRÈS SECRET UE/EU TOP SECRET |
SECRET UE/EU SECRET |
CONFIDENTIEL UE/EU CONFIDENTIAL |
RESTREINT UE/EU RESTRICTED |
Belgium |
Très Secret (Loi 11.12.1998) Zeer Geheim (Wet 11.12.1998) |
Secret (Loi 11.12.1998) Geheim (Wet 11.12.1998) |
Confidentiel (Loi 11.12.1998) Vertrouwelijk (Wet 11.12.1998) |
nota (1) below |
Bulgaria |
Cтpoгo ceкретно |
Ceкретно |
Поверително |
За служебно ползване |
Czech Republic |
Přísně tajné |
Tajné |
Důvěrné |
Vyhrazené |
Denmark |
YDERST HEMMELIGT |
HEMMELIGT |
FORTROLIGT |
TIL TJENESTEBRUG |
Germany |
STRENG GEHEIM |
GEHEIM |
VS (2)— VERTRAULICH |
VS — NUR FÜR DEN DIENSTGEBRAUCH |
Estonia |
Täiesti salajane |
Salajane |
Konfidentsiaalne |
Piiratud |
Ireland |
Top Secret |
Secret |
Confidential |
Restricted |
Greece |
Άκρως Απόρρητο Abr: ΑΑΠ |
Απόρρητο Abr: (ΑΠ) |
Εμπιστευτικό Αbr: (ΕΜ) |
Περιορισμένης Χρήσης Abr: (ΠΧ) |
Spain |
SECRETO |
RESERVADO |
CONFIDENCIAL |
DIFUSIÓN LIMITADA |
France |
Très Secret Défense |
Secret Défense |
Confidentiel Défense |
nota (3) below |
Croatia |
VRLO TAJNO |
TAJNO |
POVJERLJIVO |
OGRANIČENO |
Italy |
Segretissimo |
Segreto |
Riservatissimo |
Riservato |
Cyprus |
Άκρως Απόρρητο Αbr: (ΑΑΠ) |
Απόρρητο Αbr: (ΑΠ) |
Εμπιστευτικό Αbr: (ΕΜ) |
Περιορισμένης Χρήσης Αbr: (ΠΧ) |
Latvia |
Sevišķi slepeni |
Slepeni |
Konfidenciāli |
Dienesta vajadzībām |
Lithuania |
Visiškai slaptai |
Slaptai |
Konfidencialiai |
Riboto naudojimo |
Luxembourg |
Très Secret Lux |
Secret Lux |
Confidentiel Lux |
Restreint Lux |
Hungary |
Szigorúan titkos! |
Titkos! |
Bizalmas! |
Korlátozott terjesztésű! |
Malta |
L-Ogħla Segretezza Top Secret |
Sigriet Secret |
Kunfidenzjali Confidential |
Ristrett Restricted (4) |
Netherlands |
Stg. ZEER GEHEIM |
Stg. GEHEIM |
Stg. CONFIDENTIEEL |
Dep. VERTROUWELIJK |
Austria |
Streng Geheim |
Geheim |
Vertraulich |
Eingeschränkt |
Poland |
Ściśle Tajne |
Tajne |
Poufne |
Zastrzeżone |
Portugal |
Muito Secreto |
Secreto |
Confidencial |
Reservado |
Romania |
Strict secret de importanță deosebită |
Strict secret |
Secret |
Secret de serviciu |
Slovenia |
STROGO TAJNO |
TAJNO |
ZAUPNO |
INTERNO |
Slovakia |
Prísne tajné |
Tajné |
Dôverné |
Vyhradené |
Finland |
ERITTÄIN SALAINEN YTTERST HEMLIG |
SALAINEN HEMLIG |
LUOTTAMUKSELLINEN KONFIDENTIELL |
KÄYTTÖ RAJOITETTU BEGRÄNSAD TILLGÅNG |
Sweden (5) |
HEMLIG/TOP SECRET HEMLIG AV SYNNERLIG BETYDELSE FÖR RIKETS SÄKERHET |
HEMLIG/SECRET HEMLIG |
HEMLIG/CONFIDENTIAL HEMLIG |
HEMLIG/RESTRICTED HEMLIG |
United Kingdom |
UK TOP SECRET |
UK SECRET |
UK CONFIDENTIAL |
UK RESTRICTED |
-
Diffusion Restreinte/Beperkte Verspreiding is not a security classification in Belgium. Belgium handles and protects ‘RESTREINT UE/EU RESTRICTED’ information in a manner no less stringent than the standards and procedures described in the security rules of the Council of the European Union.
-
Germany: VS = Verschlusssache.
-
France does not use the classification ‘RESTREINT’ in its national system. France handles and protects ‘RESTREINT UE/EU RESTRICTED’ information in a manner no less stringent than the standards and procedures described in the security rules of the Council of the European Union.
-
The Maltese and English markings for Malta can be used interchangeably
-
Sweden: the security classification markings in the top row are used by the defence authorities and the markings in the bottom row by other authorities.
Appendix C
LIST OF NATIONAL SECURITY AUTHORITIES (NSAs)
BELGIUM
|
ESTONIA
|
||||||||||||||||||||||||
BULGARIA
|
IRELAND
|
||||||||||||||||||||||||
CZECH REPUBLIC
|
GREECE
|
||||||||||||||||||||||||
DENMARK
|
SPAIN
|
||||||||||||||||||||||||
GERMANY
|
FRANCE
|
||||||||||||||||||||||||
CROATIA
|
LUXEMBOURG
|
||||||||||||||||||||||||
ITALY
|
HUNGARY
|
||||||||||||||||||||||||
CYPRUS
|
MALTA
|
||||||||||||||||||||||||
LATVIA
|
NETHERLANDS
|
||||||||||||||||||||||||
LITHUANIA
|
AUSTRIA
|
||||||||||||||||||||||||
POLAND
|
SLOVAKIA
|
||||||||||||||||||||||||
PORTUGAL
|
FINLAND
|
||||||||||||||||||||||||
ROMANIA
|
SWEDEN
|
||||||||||||||||||||||||
SLOVENIA
|
UNITED KINGDOM
|
Appendix D
LIST OF ABBREVIATIONS
Acronym |
Meaning |
AQUA |
Appropriately Qualified Authority |
BPS |
Boundary Protection Services |
CAA |
Crypto Approval Authority |
CCTV |
Closed Circuit Television |
CDA |
Crypto Distribution Authority |
CFSP |
Common Foreign and Security Policy |
CIS |
Communication and Information Systems handling EUCI |
Coreper |
Committee of Permanent Representatives |
CSDP |
Common Security and Defence Policy |
DSA |
Designated Security Authority |
ECSD |
European Commission Security Directorate |
EUCI |
EU Classified Information |
EUSR |
EU Special Representative |
FSC |
Facility Security Clearance |
GSC |
General Secretariat of the Council |
IA |
Information Assurance |
IAA |
Information Assurance Authority |
IDS |
Intrusion Detection System |
IT |
Information Technology |
NSA |
National Security Authority |
PSC |
Personnel Security Clearance |
PSCC |
Personnel Security Clearance Certificate |
PSI |
Programme/Project Security Instructions |
SAA |
Security Accreditation Authority |
SAB |
Security Accreditation Board |
SAL |
Security Aspects Letter |
SecOPs |
Security Operating Procedures |
SCG |
Security Classification Guide |
SSRS |
System-Specific Security Requirement Statement |
TA |
TEMPEST Authority |
This summary has been adopted from EUR-Lex.