Skip to content

Text · Opinion parliamentary committee

On the proposal for a regulation of the European Parliament and of the Council Proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

Full title

On the proposal for a regulation of the European Parliament and of the Council Proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union

Document ITRE-AD-738558 · COM(2022)0119 – C90121/2022 – 2022/0084(COD)

Kind
Opinion parliamentary committee ITRE-AD-738558
Date
14 February 2023
Committee
Committee on Industry, Research and Energy
Rapporteur
Henna Virkkunen
Dossier
2022-0084
More facts (3)
Subject matter
PDON, INST, INFO
Reference
COM(2022)0119 – C90121/2022 – 2022/0084(COD)
More

Text

The text as parsed from the official Word file. Every paragraph has a link (¶) and can be saved to a project as a passage.

Jump to an amendment (46)

Short justification

At present, the European Union institutions, bodies, offices and agencies (herein ‘Union entities’) have their own information security rules, that are based on their Rules of procedure or founding act, or they do not have information security rules at all. Small entities in particular might lack any formal information security policies. Simultaneously, the Union entities share increasing amounts of sensitive non-classified and European Union classified information (herein ‘EUCI’) between themselves. Given the evolving cyber and hybrid threat landscape, the European administration is increasingly exposed to attacks. The information handled by Union entities is an attractive target for threats and therefore requires appropriate protection.

The Rapporteur welcomes this proposal, which is part of the EU Security Union Strategy adopted by the Commission in July 2020. Due to the variety of different information security rules across the Union entities and the constantly evolving cyber and threat landscape that they are in, modernizing and streamlining the internal legal frameworks for information security in all Union entities by means of a Regulation is justified. Cooperation on information security between Union entities is advantageous for all actors in order to create an information security culture.

The fair processing of information is crucial for the European industry, in particular regarding trade secrets. Therefore, the rules regarding the processing of information in particular must be elevated to an adequate standard.

By virtue of their mandate, the Members of Union institutions should have access to all necessary information to carry out their tasks, on the basis of a need-to-know principle, which denotes that only those for whom access to that information is necessary to carry out their task effectively have access to it. Moreover, it is crucial to ensure that the Members of the European Parliament are given access to any type of information that is necessary in order to effectively exercise their mandate.

AMENDMENTS

The Committee on Industry, Research and Energy calls on the Committee on Civil Liberties, Justice and Home Affairs, as the committee responsible, to take into account the following amendments:

Amendment 1

Proposal for a regulation

Recital 1

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(1) Union institutions and bodies currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union institution and body invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected.(1) Union entities currently have their own information security rules, based on their rules of procedure or their founding act, or do not have such rules at all. In that context, each Union entity invests significant efforts in adopting different approaches, leading to a situation where exchange of information is not always reliable. The lack of a common approach hinders the deployment of common tools building on an agreed set of rules depending on the security needs of the information to be protected.
(This amendment applies throughout the text except for article 3 (e) and art 42, 4(a). Adopting it will necessitate corresponding changes throughout.)

(See wording of article 3 (e).)

Amendment 2

Proposal for a regulation

Recital 2

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union institutions and bodies. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information and common key handling principles. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union institutions and bodies and with Member States.(2) While progress has been made towards more consistent rules for the protection of European Union classified information (‘EUCI’) and non-classified information, the interoperability of the relevant systems remains limited, preventing a seamless transfer of information between the different Union entities. Further efforts should therefore be made to enable an interinstitutional approach to the sharing of EUCI and sensitive non-classified information, with common categories of information, common key handling principles and where appropriate, common information system infrastructure on which information is handled, stored and transmitted by Union entities. A baseline should also be envisaged to simplify procedures for sharing EUCI and sensitive non-classified information between Union entities and with Member States.

Amendment 3

Proposal for a regulation

Recital 3

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(3) Therefore, relevant rules ensuring a common level of information security in all Union institutions and bodies should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and minimum standards.(3) Therefore, relevant rules ensuring a common level of information security in all Union entities should be laid down. They should constitute a comprehensive and coherent general framework for protecting EUCI and non-classified information, and should ensure equivalence of basic principles and common minimum standards.

Amendment 4

Proposal for a regulation

Recital 3 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(3a) Members of the Union institutions should have access by virtue of their mandate to all necessary information on the basis of the ‘need-to-know principle’ in order to exercise the powers vested to them by the Treaties.

Amendment 5

Proposal for a regulation

Recital 3 b (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(3b) When developing information security rules, Union entities should ensure efficiency and choose the best solutions, in particular as regards return on investments, appropriate levels of flexibility, decrease of administrative burden, minimisation of risks, higher levels of transparency and improvement of the work environment.

Amendment 6

Proposal for a regulation

Recital 3 c (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(3c) In the context of information security, Union entities should increase organisational interoperability and act together to ensure the protection of networks and information systems, data and the assets employed to capture, store, process and transmit the information.

Amendment 7

Proposal for a regulation

Recital 5 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(5a) This Regulation should ensure that any limitation of the right to the protection of personal data and privacy is necessary and proportionate, in accordance with Article 52(1) of the Charter of Fundamental Rights of the European Union.

Amendment 8

Proposal for a regulation

Recital 5 b (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(5b) All information security measures involving processing of personal data should be compliant with the relevant Union data protection and privacy law. Union entities should provide relevant technical and organisational safeguards to ensure compliance in an accountable and transparent manner.

Amendment 9

Proposal for a regulation

Recital 5 c (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(5c) When implementing this Regulation, Union entities should strive to enhance transparency, minimise and limit in time the use of confidential documents, provide safeguards against use of classification that would prevent Union entities to fulfil their mission and ensure that whistle-blowers are adequately protected, while ensuring a high level of protection of information in line with Union law and best practices.

Amendment 10

Proposal for a regulation

Recital 6

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817 , Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18 , Regulation (EC) 1049/2001 of the European Parliament and of the Council19 , Regulation (EU) 2018/1725 of the European Parliament and of the Council20 , Council Regulation (EEC, EURATOM) No 354/8321 , Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union.(6) This Regulation is without prejudice to Regulation (Euratom) No 3/195817, Regulation No 31 (EEC), 11 (EAEC), laying down the Staff Regulations of Officials and the Conditions of Employment of other servants of the European Economic Community and the European Atomic Energy Community18, Regulation (EC) No 1049/2001 of the European Parliament and of the Council19, Regulation (EU) 2018/1725 of the European Parliament and of the Council20, including the rules on international transfers of personal data, Council Regulation (EEC, EURATOM) No 354/8321, Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council22 , Regulation (EU) 2021/697 of the European Parliament and of the Council23 , Regulation (EU) [...] of the European Parliament and of the Council24 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union.
17 Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406).17 Regulation (Euratom) No 3/1958 implementing Article 24 of the Treaty establishing the European Atomic Energy Community (OJ 17, 6.10.1958, p. 406).
18 OJ 45, 14.6.1962, p. 1385.18 OJ 45, 14.6.1962, p. 1385.
19 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).19 Regulation (EC) No 1049/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).
20 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).20 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).
21 Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1).21 Council Regulation (EEC, EURATOM) No 354/83 of 1 February 1983 concerning the opening to the public of the historical archives of the European Economic Community and the European Atomic Energy Community (OJ L 43, 15.2.1983, p. 1).
22 Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1).22 Regulation (EU, Euratom) 2018/1046 of the European Parliament and of the Council of 18 July 2018 on the financial rules applicable to the general budget of the Union, amending Regulations (EU) No 1296/2013, (EU) No 1301/2013, (EU) No 1303/2013, (EU) No 1304/2013, (EU) No 1309/2013, (EU) No 1316/2013, (EU) No 223/2014, (EU) No 283/2014, and Decision No 541/2014/EU and repealing Regulation (EU, Euratom) No 966/2012 (OJ L 193, 30.7.2018, p. 1).
23 Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149).23 Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund and repealing Regulation (EU) 2018/1092 (OJ L 170, 12.5.2021, p. 149).
24 Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted24 Regulation […] of the European Parliament and of the Council laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, to be adopted

Amendment 11

Proposal for a regulation

Recital 8

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(8) With a view to establishing a formal structure for cooperation between Union institutions and bodies in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union institutions and bodies.(8) With a view to establishing a formal common structure for cooperation between Union entities in the field of information security, it is necessary to set up an Interinstitutional Coordination Group (the ‘Coordination Group’) in which all Union institutions’ and bodies’ Security Authorities are represented. Without having decision-making powers, the Cordination Group should enhance the coherence of policies in the field of information security and should contribute to the harmonisation of the information security procedures and tools across the Union entities.

Amendment 12

Proposal for a regulation

Recital 12

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union institution and body. While the minimum requirements laid down in this Regulation must be met, each Union institution and body should adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each institution and body.(12) The principle of information security risk management should be at the core of the policy to be developed in the field by each Union entity. While the common minimum requirements laid down in this Regulation must be met, each Union entityshould adopt specific security measures for protecting information in accordance with the results of an internal risk assessment. In the same way, the technical means to protect the information should be adapted to the specific situation of each Union entity. However, the specific security measures should not constitute an impediment for the activity of other institutions and legal access to information, such as for example unduly limiting the access of the Members of the European Parliament to the information produced or held by the Commission.

Amendment 13

Proposal for a regulation

Recital 14

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(14) With the purpose of adjusting to the new teleworking practices, the networks used for connecting to the Union institution’s or body’s remote access services should be protected by adequate security measures.(14) With the purpose of adjusting to the new teleworking practices, the network information systems, digital infrastructure and terminal devices used for connecting to the Union entity’s remote access services should be protected by adequate security measures.

Amendment 14

Proposal for a regulation

Recital 15

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(15) Since Union institutions and bodies frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security.(15) Since Union entities frequently make use of contractors and outsourcing, it is important to establish common provisions relating to contractors’ personnel carrying out tasks related to information security. Such provisions should include a requirement to undergo a vetting procedure as part of the tender procedure. That procedure should take into account the full supply chain and the operational environment of the third party contractors.

Amendment 15

Proposal for a regulation

Recital 17 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(17a) The Union entities should apply Regulation (EU) 2018/1725 of the European Parliament and of the Council1a (EUDPR) when dealing with personal data breaches in their procedures for information security incident management. Therefore, the Union entities should adopt a personal data breach handling procedure.
1a Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018)

Amendment 16

Proposal for a regulation

Recital 18

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union institutions and bodies where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union institutions and bodies to select the appropriate security measures for their sites.(18) The protection of EUCI is also ensured by technical and organisational measures which apply to the premises, buildings, rooms, offices or facilities of the Union entities where EUCI is discussed, handled or stored. This Regulation provides for the implementation of an information security management process in the area of physical security which would allow Union entities to select the appropriate security measures for their sites. A thorough evaluation of security infrastructure, including services, should be carried out. That evaluation should take into account the full supply chain and the operative environment.

Amendment 17

Proposal for a regulation

Recital 21

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(21) Union institutions and bodies have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union institutions and bodies. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling and storing both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders.(21) Union entities have been traditionally developed their communication and information systems autonomously, with insufficient attention to their interoperability across all Union entities. It is therefore necessary to establish minimum security requirements concerning the Communication and Information Systems (CISs) handling, storing and transmitting both EUCI and non-classified information with the aim to guarantee a seamless exchange of information with the relevant stakeholders.

Amendment 18

Proposal for a regulation

Recital 21 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(21a) The information held by the Union entities is also exchanged through the ICT environment, on-premises or through virtual assets, ICT products, ICT services and ICT processes as well as any network and information system whether owned and operated by a Union entity, or hosted or operated by a third party, including mobile devices, corporate networks, and business networks not connected to the internet and any devices connected to the ICT environment.

Amendment 19

Proposal for a regulation

Recital 24

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(24) The close cooperation between Union institutions and bodies as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the trustworthiness of a Union institution or body should be assessed before they handle and store a specified level of EUCI.(24) The close cooperation between Union entities as well as the multitude of synergies developed among them involve the sharing of a large amount of information. For the sake of the classified information security, the capabilities of the Union entities to handle, store and transmit EUCI should be assessed before they handle and store a specified level of EUCI.

Amendment 20

Proposal for a regulation

Recital 29

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(29) The European Data Protection Supervisor was consulted in accordance with Article 42 of Regulation (EU) 2018/1725 of the European Parliament and of the Council27 and delivered an opinion on ...(29) The European Data Protection Supervisor was consulted in accordance with Article 42 of Regulation (EU) 2018/1725 and delivered an opinion on ...
27 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018).

Amendment 21

Proposal for a regulation

Article 1 – paragraph 1

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
1. This Regulation lays down information security rules for all Union institutions and bodies.1. This Regulation lays down common information security rules for all Union entities.

Amendment 22

Proposal for a regulation

Article 3 – paragraph 1 – point e

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(e) ‘Union institutions and bodies’ means the Union institutions, bodies, offices and agencies set up by, or on the basis of, the Treaty on European Union, the Treaty on the functioning of European Union, the Treaty establishing the European Atomic Energy Community or a legislative act;(e) ‘Union entities’ means the Union institutions, bodies, offices and agencies set up by, or on the basis of, the Treaty on European Union, the Treaty on the functioning of European Union, the Treaty establishing the European Atomic Energy Community or a legislative act;

Amendment 23

Proposal for a regulation

Article 3 – paragraph 1 – point s

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(s) ‘zero trust’ means a security model, a set of system design principles, and a coordinated cybersecurity and system management strategy based on an acknowledgement of the existence of threats inside and outside traditional network boundaries;(s) ‘zero trust’ means a security model, a set of system design principles, and a coordinated cybersecurity and system management strategy based on an acknowledgement of the existence of threats inside and outside traditional network boundaries and 'never trust, always verify' concept;

Amendment 24

Proposal for a regulation

Article 3 – paragraph 1 – point ae a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(aea) ‘standard’ means a standard as defined in Article 2, point (1), of Regulation (EU) No 1025/2012;

Amendment 25

Proposal for a regulation

Article 4 – paragraph 1 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
1a. The Members of the Union institutions shall have access to all necessary information on the basis of the need-to- know principle for the effective exercise of their mandate in accordance with the Treaties.

Amendment 26

Proposal for a regulation

Article 4 – paragraph 6 – subparagraph 2

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
Union institutions and bodies handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union institutions and bodies concerned shall organise specific training for the specific functions entrusted with information security tasks.Union entities handling and storing EUCI shall organise mandatory training at least once every 5 years for all individuals authorised to access EUCI. The Union entities concerned shall organise specific training for the specific functions entrusted with information security tasks. Union entities shall design and implement effective and appropriate trainings commensurate to the risks identified in accordance with Article 5 for all individuals authorised to access EUCI not later than ...[six months after the date of entry into force of this Regulation].

Amendment 27

Proposal for a regulation

Article 5 – paragraph 2 – point e a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(ea) integrity, availability and resilience of processing systems and services.

Amendment 28

Proposal for a regulation

Article 5 – paragraph 3 – point -a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(-a) the risks for the rights and freedoms of natural persons;

Amendment 29

Proposal for a regulation

Article 5 – paragraph 3 – point f

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(f) business continuity and disaster recovery;(f) business continuity, such as back up management, disaster recovery and crisis management;

Amendment 30

Proposal for a regulation

Article 6 – paragraph 2 – introductory part

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
2. Acting by consent and in the common interest of all Union institutions and bodies, the Coordination Group shall:2. Acting by simple majority and in the common interest of all Union entities, the Coordination Group shall:

Amendment 31

Proposal for a regulation

Article 6 – paragraph 2 – point c

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(c) establish guidance documents on the implementation of this Regulation, in cooperation with the Interinstitutional Cybersecurity Board referred to in Article 9 of the Regulation EU [...] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union, where appropriate;(c) establish guidance documents on the implementation of this Regulation, in cooperation with the Interinstitutional Cybersecurity Board referred to in Article 9 of the Regulation EU [...] laying down measures for a high common level of cybersecurity at the Union entities, where appropriate;

Amendment 32

Proposal for a regulation

Article 10 – paragraph 1 – point c a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(ca) strengthening cooperation and coordination with CERT-EU.

Amendment 33

Proposal for a regulation

Article 11 – paragraph 4 – point d a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(da) end-to-end encryption, in particular when exchanging sensitive non-classified information;

Amendment 34

Proposal for a regulation

Article 11 – paragraph 5 – point d

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(d) information security incidents shall be formally recorded and followed up, in accordance with Regulation EU [XXX] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union.(d) information security incidents shall be formally recorded and handled, in accordance with Regulation EU [XXX] laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union.

Amendment 35

Proposal for a regulation

Article 18 – paragraph 2

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
2. The Coordination Group shall adopt guidance documents on EUCI creation and classification.2. The Coordination Group shall adopt guidance documents on EUCI creation and classification, implementing the principle of minimisation of the use of classification and limiting in time the duration of such a classification.
Those guidance documents shall include rules on assessment of and justification for information and material classification, aimed at increasing transparency and avoiding unjustified lock-in effects.

Amendment 36

Proposal for a regulation

Article 20 – paragraph 3 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
3a. This Article is without prejudice to Regulation (EC) No 1049/2001.

Amendment 37

Proposal for a regulation

Article 22 – paragraph 3 – point a

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(a) inform the originator;(a) inform the originator without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach;

Amendment 38

Proposal for a regulation

Article 22 – paragraph 3 – point e

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(e) notify the competent authorities about the actual or potential compromise and the action taken.(e) notify the competent authorities about the actual or potential compromise and the action taken without undue delay, and in any event not later than one week after the Security Authority has been informed of the breach.

Amendment 39

Proposal for a regulation

Article 41 – paragraph 1 – point f a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(fa) the system owner or the Information Assurance Operational Authority shall ensure that a process of identifying and reporting vulnerabilities is in place, including internal and external rewards, as appropriate; that process shall be complemented by regular audits and penetration tests where appropriate.

Amendment 40

Proposal for a regulation

Article 42 – paragraph 1

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
1. Approved cryptographic products shall be used for transmission and storage of EUCI by electronic means. The list of approved cryptographic products shall be maintained by the Council, on the basis of input from the National Security Authorities.1. Approved cryptographic products shall be used for transmission and storage of EUCI by electronic means.

Amendment 41

Proposal for a regulation

Article 42 – paragraph 1 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
1a. For all information and material classified as EUCI, a list of approved cryptographic products shall be maintained by the Council, on the basis of input from the National Security Authorities.

Amendment 42

Proposal for a regulation

Article 42 – paragraph 4 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
4a. For information and material classified as RESTREINT UE/EU RESTRICTED, a list of additional approved cryptographic products shall be established, maintained and updated on a yearly basis by the European Union Agency for Cybersecurity (‘ENISA’). When establishing and updating that list ENISA shall take into account the latest technological and market developments as well as the specific needs of Union entities. By ...[18 months after the date of entry into force of this Regulation] ENISA shall establish the list.

Amendment 43

Proposal for a regulation

Article 42 – paragraph 5

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
5. The Coordination Group shall inform the Council on a yearly basis of any cryptographic products that it recommends for evaluation by a Crypto Authority Approval of a Member State on the basis of a survey carried out in the Union institutions and bodies.5. The Coordination Group shall inform the Council on a yearly basis of any cryptographic products that it recommends for evaluation by a Crypto Authority Approval of a Member State, or by ENISA, on the basis of a survey carried out in the Union entities.

Amendment 44

Proposal for a regulation

Article 52 – paragraph 2

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the Commission, the Council and the European External Action Service and shall work by consensus.2. The sub-group on EUCI sharing and exchange of classified information shall be composed of representatives from the European Parliament, the Commission, the Council and the European External Action Service and shall work by consensus. That sub-group shall ensure synergy with Regulation (EC) No 1049/2001 and shall ensure that the classification does not in itself prevent disclosure.

Amendment 45

Proposal for a regulation

Article 54 – paragraph 1 – point -a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
(-a) there is a legal obligation under Union law or an Interinstitutional agreement concluded between Union institutions; or

Amendment 46

Proposal for a regulation

Article 54 – paragraph 1 a (new)

Amendment: Text proposed by the Commission and Amendment
Text proposed by the CommissionAmendment
1a. The conditions referred to in paragraph 1, point (a) are considered to be fulfilled when access to EUCI is required to fulfil the Union entity mandate or mission, as entrusted by the Union law, or would otherwise encroach on their institutional autonomy.

Procedure pages and committee votes

How the committees handled the text and how their members voted on it. Collapsed.

Procedure – committee asked for opinion 1 block
Table from the text: Title
TitleInformation security in the institutions, bodies, offices and agencies of the Union
ReferencesCOM(2022)0119 – C9-0121/2022 – 2022/0084(COD)
Committee responsible Date announced in plenaryLIBE 4.4.2022
Opinion by Date announced in plenaryITRE 4.4.2022
Associated committees - date announced in plenary15.9.2022
Rapporteur for the opinion Date appointedHenna Virkkunen 13.7.2022
Discussed in committee29.11.2022
Date adopted9.2.2023
Result of final vote+: –: 0:68 0 4
Members present for the final voteNicola Beer, François-Xavier Bellamy, Hildegard Bentele, Tom Berendsen, Michael Bloss, Paolo Borchia, Marc Botenga, Markus Buchheit, Martin Buschmann, Cristian-Silviu Buşoi, Jerzy Buzek, Maria da Graça Carvalho, Ignazio Corrao, Beatrice Covassi, Ciarán Cuffe, Josianne Cutajar, Nicola Danti, Marie Dauchy, Pilar del Castillo Vera, Christian Ehler, Valter Flego, Lina Gálvez Muñoz, Jens Geier, Nicolás González Casares, Bart Groothuis, Christophe Grudler, András Gyürk, Henrike Hahn, Robert Hajšel, Ivo Hristov, Ivars Ijabs, Romana Jerković, Seán Kelly, Łukasz Kohut, Miapetra Kumpula-Natri, Marisa Matias, Eva Maydell, Iskra Mihaylova, Johan Nissinen, Mauri Pekkarinen, Mikuláš Peksa, Tsvetelina Penkova, Morten Petersen, Markus Pieper, Clara Ponsatí Obiols, Robert Roos, Sara Skyttedal, Maria Spyraki, Beata Szydło, Grzegorz Tobiszowski, Patrizia Toia, Henna Virkkunen, Pernille Weiss, Carlos Zorrinho
Substitutes present for the final voteDamian Boeselager, Jakop G. Dalunde, Matthias Ecke, Cornelia Ernst, Klemen Grošelj, Elena Kountoura, Dace Melbārde, Alin Mituța, Jutta Paulus, Massimiliano Salini
Substitutes under Rule 209(7) present for the final voteMarco Campomenosi, Rosanna Conte, Jarosław Duda, France Jamet, Aušra Maldeikienė, Tilly Metz, Alessandro Panza, Rovana Plumb
Final vote by roll call in committee asked for opinion 3 blocks

68 · For

ID
Paolo Borchia, Markus Buchheit, Marco Campomenosi, Rosanna Conte, Marie Dauchy, France Jamet, Alessandro Panza
No group
Martin Buschmann, András Gyürk, Clara Ponsatí Obiols
EPP
François-Xavier Bellamy, Hildegard Bentele, Tom Berendsen, Cristian-Silviu Buşoi, Jerzy Buzek, Maria da Graça Carvalho, Pilar del Castillo Vera, Jarosław Duda, Christian Ehler, Seán Kelly, Aušra Maldeikienė, Eva Maydell, Dace Melbārde, Markus Pieper, Massimiliano Salini, Sara Skyttedal, Maria Spyraki, Henna Virkkunen, Pernille Weiss
Renew
Nicola Beer, Nicola Danti, Valter Flego, Bart Groothuis, Klemen Grošelj, Christophe Grudler, Ivars Ijabs, Iskra Mihaylova, Alin Mituța, Mauri Pekkarinen, Morten Petersen
S&D
Beatrice Covassi, Josianne Cutajar, Matthias Ecke, Lina Gálvez Muñoz, Jens Geier, Nicolás González Casares, Robert Hajšel, Ivo Hristov, Romana Jerković, Łukasz Kohut, Miapetra Kumpula-Natri, Tsvetelina Penkova, Rovana Plumb, Patrizia Toia, Carlos Zorrinho
The Left
Marc Botenga, Cornelia Ernst, Elena Kountoura, Marisa Matias
Greens
Michael Bloss, Damian Boeselager, Ignazio Corrao, Ciarán Cuffe, Jakop G. Dalunde, Henrike Hahn, Tilly Metz, Jutta Paulus, Mikuláš Peksa

0 · Against

4 · Abstained

ECR
Johan Nissinen, Robert Roos, Beata Szydło, Grzegorz Tobiszowski

Connections

The dossier, the decisions on this text and its other versions.

No connections found for this item.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
25 September 2026

Cite as

European Parliament (2023). “OPINION on the proposal for a regulation of the European Parliament and of the Council Proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union”. Text, 14 February 2023. docId ITRE-AD-738558. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ITRE-AD-738558 (retrieved 25 September 2026). Data: EP Open Data API: document record, https://data.europarl.europa.eu/api/v2/documents/ITRE-AD-738558 (CC BY 4.0).
BibTeX
@misc{epw-text-itre-ad-738558,
  author = {{European Parliament}},
  title = {{OPINION on the proposal for a regulation of the European Parliament and of the Council Proposal for a regulation of the European Parliament and of the Council on information security in the institutions, bodies, offices and agencies of the Union}},
  year = {2023},
  date = {2023-02-14},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ITRE-AD-738558}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ITRE-AD-738558},
  urldate = {2026-09-25},
  publisher = {EU Parl Watch Research},
  note = {Text. docId ITRE-AD-738558. Data: EP Open Data API: document record (CC BY 4.0)}
}