The EU Cybersecurity Act and 3 Things That Will Help Businesses

Introduction:

The EU is home to a variety of distinct cybersecurity acts for ICT devices, there is a rising risk of fragmentation and hurdles between the Member States, a hurdle the EU Cybersecurity Act hopes to negate. The EU cybersecurity certification framework for ICT devices allows for the development of customised and risk-based EU certification schemes. ICT (Information and communication technology) refers to all of the technology needed to handle telecommunications, broadcast media, intelligent building management systems, audiovisual processing and transmission systems, and network-based control and monitoring tasks.

The EU Cybersecurity Act gives the European Network and Information Systems Agency (ENISA) a permanent mission and renames it the EU Agency for Cybersecurity, while significantly increasing its authority and resources. In 2017, the European Parliament initiated the process of establishing a security agency.

As part of that effort, the Act was formally enacted in 2019. The European Cybersecurity Act went into effect on June 27, establishing the new mandate of ENISA, the EU Agency for Cybersecurity, as well as the European cybersecurity certification framework. This expanded role of ENISA, the EU Agency for Cybersecurity, and may have considerable implications for international businesses.

The EU Cybersecurity Act at a glance:

The framework will be based on an EU-level agreement on assessing the security features of a specific ICT-based product or service. It will certify that ICT products and services that have been certified under such a scheme meet the required requirements.

Many of the provisions of the Act supplement or enhance the provisions of the NIS Directive. But, most importantly, the Act:

  1. Establishes a framework for EU cybersecurity certification for information and communication technology (ICT) products, services, and processes.
  2. The Member States must appoint one or more national cybersecurity certification authorities.
  3. Establishes assessment bodies to ensure compliance with the Act.
  4. Member States are required to establish penalties for certification infractions including violations of European cybersecurity certification systems.

This legislative framework includes the Directive on Network and Information System Security, which establishes notification and security standards for operators of critical services as well as digital service providers such as cloud providers.

The Act aims to promote confidence by establishing a Europe-wide certification system comprised of cybersecurity certification schemes that contain similar cybersecurity requirements and evaluation criteria across national markets and sectors. The Act’s opening provisions provide a thorough argument for the need to construct such a certification mechanism.

The Act also states that “the limited use of certification leads to individual, organisational, and business users having insufficient information about the cybersecurity features of ICT products, ICT services, and ICT processes, undermining trust in digital solutions.”

3 things to know about the EU Cybersecurity Act:

Critical industries such as transportation, energy, health care, and finance have become increasingly reliant on digital technologies to manage their basic operations. While digitization gives significant prospects and solutions to many of Europe’s difficulties, particularly during the COVID-19 crisis, it also exposes the economy and society to cyber attacks

Cyberattacks and cybercrime are on the rise in Europe, both in terms of volume and sophistication. Given that 22.3 billion devices are predicted to be connected to the Internet of Things by 2024, this tendency is expected to continue. The need of the hour becomes graver therefore it is important to understand the EU Cybersecurity Act alongside other measures to mitigate future deleterious instances:

1. What is the ENISA mandate?

The EU Cybersecurity Act gives the agency a permanent mandate, assigning increased resources and new objectives.

ENISA will play a vital role in establishing and maintaining the European cybersecurity certification framework by laying the technological groundwork for specific certification schemes and educating the public about the certification schemes and issued certificates via a dedicated website.

ENISA is also tasked with increasing operational collaboration at the EU level, assisting EU Member States that request it to tackle cybersecurity issues and assisting the EU’s coordination in the event of large-scale cross-border cyber-attacks and crises.

2. What is the EU Cybersecurity Framework certification?

The Title III of the Act establishes the Cybersecurity Certification Framework with the purpose of increasing cybersecurity in the EU and developing a standardised approach to cybersecurity certification of ICT goods, services, and procedures.

Certification will be tackled through the formation of an EU rolling work programme that outlines key goals for product, service, and process certification.

Multiple schemes will be developed under the framework for various types of ICT products, processes, and services. Each certification scheme will provide the following information:

  1. The product categories that will be covered
  2. Each organization’s cybersecurity requirements (referencing standards or technical specifications)
  3. The kind of review that was required (self-assessment or third-party evaluation)
  4. The desired level of confidence (Basic, Substantial, or High).

Two expert groups will lead the governance for the certification framework’s implementation:

  1. The European Cybersecurity Certification Group (ECCG) is made up of representatives from national cybersecurity certification agencies,
  2.  While the Stakeholder Cybersecurity Certification Group is made up of stakeholders (SCCG).

The SCCG is made up of representatives from all key parties. Both organisations provide cybersecurity certification framework advice to the European Commission, certification and standards advice to ENISA, and assistance to the Commission with a rolling work programme for certification schemes.

3. How is the EU Cybersecurity Framework structured?

All national cybersecurity certification regimes are effectively superseded by the European cybersecurity certification framework. There are three degrees of assurance for these items within the framework:

Act
Source:jstec.org

For each level of cybersecurity certification, the European Commission intends to propose different methods. ENISA will create these schemes, which will outline the types of ICT items included, the purpose, required security requirements, evaluation procedures, and certificate validity periods.

The public will be given access to the details of these programmes in the coming months. However, we can anticipate that they will address concerns such as:

  1. Preventing data from being stored, processed, accessed, disclosed, destroyed, lost, or modified without permission.
  2. Access to protected data is restricted to approved people, programmes, and devices.
  3. Disaster recovery strategies, which ensure that transactions involving protected data are tracked and may be examined.

These certification procedures must subsequently be enforced by each EU member state after they have been adopted. Then ENISA will be in charge of examining adopted certification schemes on a regular basis - every five years – to ensure that they fit the EU Cybersecurity Act.

Conclusion:

This historic regulatory mandate will have far-reaching implications for the international standards community; now is the moment to start anticipating and participating in ongoing changes. We at Security Pilgrim are here to guide you in your journey of ensuring a secure and robust business.

Please follow and like us:

Leave a Comment

Your email address will not be published. Required fields are marked *

RSS
Follow by Email
Facebook
Facebook
fb-share-icon
Twitter
Visit Us
Follow Me
Tweet
YouTube
YouTube
LinkedIn
LinkedIn
Share
WhatsApp