Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

EU progressing on information infrastructure policy

Guidelines would strengthen computer security response centers across Europe, increase Internet resiliency

The European Union is refining a set of guidelines that would strengthen its ability to respond to computer security crises as well as ensure Internet infrastructure in member countries is more resilient.

In late March, the European Commission adopted a set of recommendations called the Critical Information Infrastructure Protection (CIIP).

The proposals seek to improve Europe's ability to cope with large-scale cyberattacks or disruptions, said Andrea Glorioso, a policy officer in the Commission's Directorate-General for the Information Society and Media. Glorioso gave a presentation at the Conference on Cyber Warfare on Thursday in Tallinn, Estonia.

The proposals call for a range of measures, including agreeing on minimum standards for the capabilities of European Computer Emergency Response Teams (CERTs), government-run agencies dedicated to computer security.

Other suggestions include creating an agency that would foster closer cooperation between the private sector and government to increase the resilience of networks that could fall under attack as well as improve information sharing between E.U. countries.

By the end of 2010, Europe also hopes to have a roadmap for the European Information Sharing and Alert System (EISAS), which would distribute information on cyberthreats to businesses.

The CIIP plan also calls for E.U. members to run national cybersecurity exercises with a view to holding pan-European network security exercises.

"We want to know how good we are," Glorioso said.

Another focus is Internet stability. The Commission will work to define principles and guidelines for ensuring the robustness of networks along with identifying what is critical infrastructure.

One main motivation for the plan is the impact that cyberattacks can potentially have on economies. Glorioso cited a figure from the World Economic Forum from 2008 that there is a 10 percent to 20 percent possibility that a major critical information infrastructure breakdown could cost the world US$250 billion.

It is difficult to definitively estimate the economic impact, but "we could lose a lot of money," Glorioso said.

E.U member states are embracing the plan. In April, countries discussed and endorsed the CIIP at a meeting in Tallinn, Estonia. Last month, the E.U. Telecommunications Council also gave the plan full support.

Workshops to refine the plan are scheduled through the end of the year. The Council of the European Union could put the plan to a vote as soon as December.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: European Commission, SAS
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Critical Information Infrastructure Protection, EC, eu, security
Latest Blog Posts
Whitepapers
  • IBM zEnterprise System Brings Hybrid Computing Capabilities to Midsize Organisations
    This paper focuses on the IBM z114 cross-tier solution, which brings IBM AIX Unix and Linux workloads into the mix, with Microsoft Windows support to follow in the future. This blended approach to computing allows workloads running on any of those operating systems to communicate more quickly and effectively with the System z, producing business benefits from the orchestration, or coordination, of management for all of the workloads running across all of the linked platforms.
    Learn more »
  • The State of Data Security
    Recognize how your data can become vulnerable, including the latest issues stemming from unprotected data on mobile devices and social media sites. Understand the compliance issues involved, and identify data protection strategies you can use to keep your company’s information both safe and compliant.
    Learn more »
  • A buyer’s guide to application lifecycle management (ALM) solutions
    This buyer's guide describes the key criteria for application lifecycle management (ALM) solutions for today's high-performance teams. It includes key considerations for enhancing your single- or multi-vendor ALM environment.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments

HP and IDG news, product videos and resources