Explore European Union Legislation by Asking a Legal Question
assisted-checkbox
filter-instruction-1
positive-filters
negative-filters
act-filter tabs-all
parameters-title
query
assisted-checkbox: ✅
result-title
total 2
Regulation (EU, Euratom) 2023/2841 of the European Parliament and of the Council of 13 December 2023 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union article 14 CELEX: 32023R2841 Guidelines, recommendations and calls for action
1. CERT-EU shall support the implementation of this Regulation by issuing: (a) calls for action describing urgent security measures that Union entities are urged to take within a set timeframe; (b) proposals to the IICB for guidelines addressed to all or a subset of the Union entities; (c) proposals to the IICB for recommendations addressed to individual Union entities. With regard to the first subparagraph, point (a), the Union entity concerned shall, without undue delay after receiving the call for action, inform CERT-EU of how the urgent security measures were applied. |
Regulation (EU, Euratom) 2023/2841 of the European Parliament and of the Council of 13 December 2023 laying down measures for a high common level of cybersecurity at the institutions, bodies, offices and agencies of the Union article 14 CELEX: 32023R2841 2. Guidelines and recommendations may include: (a) common methodologies and a model for assessing the cybersecurity maturity of the Union entities, including the corresponding scales or KPIs, serving as reference in support of continuous cybersecurity improvement across the Union entities and facilitating the prioritisation of cybersecurity domains and measures taking into account entities’ cybersecurity posture; (b) arrangements for or improvements to cybersecurity risk management and the cybersecurity risk-management measures; (c) arrangements for cybersecurity maturity assessments and cybersecurity plans; (d) where appropriate, the use of common technology, architecture, open source and associated best practices with the aim of achieving interoperability and common standards, including a coordinated approach to supply chain security; (e) where appropriate, information to facilitate the use of common procurement instruments for the purchasing of relevant cybersecurity services and products from third-party suppliers; (f) information-sharing arrangements pursuant to Article 20. |