{"id":4835,"date":"2019-05-15T19:08:47","date_gmt":"2019-05-15T19:08:47","guid":{"rendered":"https:\/\/laweuro.com\/?p=4835"},"modified":"2019-05-16T04:13:33","modified_gmt":"2019-05-16T04:13:33","slug":"regulation-eu-no-526-2013-of-the-european-parliament-and-of-the-council-of-21-may-2013-concerning-the-european-union-agency-for-network-and-information-security-enisa-and-repealing-regulation-ec","status":"publish","type":"post","link":"https:\/\/laweuro.com\/?p=4835","title":{"rendered":"Regulation (EU) No 526\/2013 of the European Parliament and of the Council of 21 May 2013 concerning the European Union Agency for Network and Information Security (ENISA) and repealing Regulation (EC) No 460\/2004 Text with EEA relevance"},"content":{"rendered":"<div id=\"docHtml\" class=\"col-md-9\">\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td>\n<p class=\"hd-date\">18.6.2013<\/p>\n<\/td>\n<td>\n<p class=\"hd-lg\">EN<\/p>\n<\/td>\n<td>\n<p class=\"hd-ti\">Official Journal of the European Union<\/p>\n<\/td>\n<td>\n<p class=\"hd-oj\">L 165\/41<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr class=\"separator\" \/>\n<p id=\"d1e40-41-1\" class=\"doc-ti\" style=\"text-align: center;\"><strong>REGULATION (EU) No 526\/2013 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL<\/strong><\/p>\n<p class=\"doc-ti\" style=\"text-align: center;\"><strong>of 21 May 2013<\/strong><\/p>\n<p class=\"doc-ti\" style=\"text-align: center;\"><strong>concerning the European Union Agency for Network and Information Security (ENISA) and repealing Regulation (EC) No 460\/2004<\/strong><\/p>\n<p class=\"doc-ti\" style=\"text-align: center;\"><strong>(Text with EEA relevance)<\/strong><\/p>\n<p class=\"normal\">THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,<\/p>\n<p class=\"normal\">Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,<\/p>\n<p class=\"normal\">Having regard to the proposal from the European Commission,<\/p>\n<p class=\"normal\">After transmission of the draft legislative act to the national parliaments,<\/p>\n<p class=\"normal\">Having regard to the opinion of the European Economic and Social Committee\u00a0(<span class=\"super\">1<\/span>),<\/p>\n<p class=\"normal\">Acting in accordance with the ordinary legislative procedure\u00a0(<span class=\"super\">2<\/span>),<\/p>\n<p class=\"normal\">Whereas:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(1)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Electronic communications, infrastructure and services are essential factors, both directly and indirectly, in economic and societal development. They play a vital role for society and have in themselves become ubiquitous utilities in the same way as electricity or water supplies, and also constitute vital factors in the delivery of electricity, water and other critical services. Communications networks function as social and innovation catalysts, multiplying the impact of technology and shaping consumer behaviours, business models, industries, as well as citizenship and political participation. Their disruption has the potential to cause considerable physical, social and economic damage, underlining the importance of measures to increase protection and resilience aimed at ensuring continuity of critical services. The security of electronic communications, infrastructure and services, in particular their integrity, availability and confidentiality, faces continuously expanding challenges which relate, inter alia, to the individual components of the communications infrastructure and the software controlling those components, the infrastructure overall and the services provided through that infrastructure. This is of increasing concern to society not least because of the possibility of problems due to system complexity, malfunctions, systemic failures, accidents, mistakes and attacks that may have consequences for the electronic and physical infrastructure which delivers services critical to the well-being of European citizens.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(2)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The threat landscape is continuously changing and security incidents can undermine the trust that users have in technology, networks and services, thereby affecting their ability to exploit the full potential of the internal market and widespread use of information and communications technologies (ICT).<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(3)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Regular assessment of the state of network and information security in the Union, based on reliable Union data, as well as systematic forecast of future developments, challenges and threats, both at Union and global level, is therefore important for policy makers, industry and users.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(4)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">By Decision 2004\/97\/EC, Euratom\u00a0(<span class=\"super\">3<\/span>), adopted at the meeting of the European Council on 13 December 2003, the representatives of the Member States decided that the European Network and Information Security Agency (ENISA), that was to be established on the basis of the proposal submitted by the Commission, would have its seat in a town in Greece to be determined by the Greek Government. Following that Decision, the Greek Government determined that ENISA should have its seat in Heraklion, Crete.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(5)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">On 1 April 2005, a Headquarters Agreement (\u2018Seat Agreement\u2019) was concluded between the Agency and the host Member State.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(6)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency\u2019s host Member State should ensure the best possible conditions for the smooth and efficient operation of the Agency. It is imperative for the proper and efficient performance of its tasks, for staff recruitment and retention and to enhance the efficiency of networking activities that the Agency be based in an appropriate location, among other things providing appropriate transport connections and facilities for spouses and children accompanying members of staff of the Agency. The necessary arrangements should be laid down in an agreement between the Agency and the host Member State concluded after obtaining the approval of the Management Board of the Agency.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(7)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In order to improve the operational efficiency of the Agency, the Agency has established a branch office in the metropolitan area of Athens, which should be maintained with the agreement and support of the host Member State, and where the operational staff of the Agency should be located. Staff primarily engaged in the administration of the Agency (including the Executive Director), finance, desk research and analysis, IT and facilities management, human resources, training, and communications and public affairs, should be based in Heraklion.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(8)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency has the right to determine its own organisation in order to ensure the proper and efficient performance of its tasks, while respecting the provisions on the seat and Athens branch office laid down in this Regulation. In particular, in order to carry out tasks involving interaction with key stakeholders such as the Union institutions, the Agency should make the necessary practical arrangements to enhance such operational efficiency.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(9)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In 2004 the European Parliament and the Council adopted Regulation (EC) No\u00a0460\/2004\u00a0(<span class=\"super\">4<\/span>) establishing ENISA with the purpose of contributing to the goals of ensuring a high level of network and information security within the Union and developing a culture of network and information security for the benefit of citizens, consumers, enterprises and public administrations. In 2008, the European Parliament and the Council adopted Regulation (EC) No\u00a01007\/2008\u00a0(<span class=\"super\">5<\/span>) extending the mandate of the Agency until March 2012. Regulation (EC) No\u00a0580\/2011\u00a0(<span class=\"super\">6<\/span>) extends the mandate of the Agency until 13 September 2013.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(10)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should succeed ENISA as established by Regulation (EC) No\u00a0460\/2004. Within the framework of the Decision of the Representatives of the Member States, meeting in the European Council of 13 December 2003, the host Member State should maintain and further develop the current practical arrangements in order to ensure the smooth and efficient operation of the Agency, including its Athens branch office, and facilitate the recruitment and retention of highly qualified staff.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(11)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Since ENISA was set up, the challenges of network and information security have changed with technology, market and socioeconomic developments and have been the subject of further reflection and debate. In response to the changing challenges, the Union has updated its priorities for network and information security policy. This Regulation aims to strengthen the Agency to successfully contribute to the efforts of the Union institutions and the Member States to develop a European capacity to cope with network and information security challenges.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(12)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Internal market measures in the field of security of electronic communications and, more generally, network and information security require different forms of technical and organisational applications by the Union institutions and the Member States. The heterogeneous application of those requirements can lead to inefficiencies and can create obstacles to the internal market. This makes a centre of expertise at Union level necessary, providing guidance, advice and assistance on issues related to network and information security, which may be relied upon by the Union institutions and the Member States. The Agency can respond to those needs by developing and maintaining a high level of expertise and assisting the Union institutions, the Member States, and the business community in order to help them meet the legal and regulatory requirements of network and information security and to determine and address network and information security issues, thereby contributing to the proper functioning of the internal market.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(13)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should carry out the tasks conferred on it by legal acts of the Union in the field of electronic communications and, in general, contribute to an enhanced level of security of electronic communications as well as of privacy and personal data protection by, among other things, providing expertise and advice, and promoting the exchange of best practices, and offering policy suggestions.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(14)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Directive 2002\/21\/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive)\u00a0(<span class=\"super\">7<\/span>) requires that providers of public electronic communications networks or publicly available electronic communications services take appropriate measures to safeguard the integrity and security thereof, and introduces an obligation for the national regulatory authorities, where appropriate, to inform, inter alia, the Agency about any security breach or integrity loss that has had a significant impact on the operation of networks or services and to submit to the Commission and to the Agency an annual summary report on the notifications received and the action taken. Directive 2002\/21\/EC further calls on the Agency, by providing opinions, to contribute to the harmonisation of appropriate technical and organisational security measures.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(15)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Directive 2002\/58\/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)\u00a0(<span class=\"super\">8<\/span>) requires a provider of a publicly available electronic communications service to take appropriate technical and organisational measures to safeguard the security of its services and also requires that the confidentiality of the communications and related traffic data be maintained. Directive 2002\/58\/EC introduces personal data breach information and notification requirements for electronic communication services providers. It also requires the Commission to consult the Agency on any technical implementing measures to be adopted concerning the circumstances or format of and procedures applicable to information and notification requirements. Directive 95\/46\/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data\u00a0(<span class=\"super\">9<\/span>) requires Member States to provide that the controller must implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, in particular where the processing involves the transmission of data over a network and against all other unlawful forms of processing.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(16)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should contribute to a high level of network and information security, to better protection of privacy and personal data, and to the development and promotion of a culture of network and information security for the benefit of citizens, consumers, businesses and public sector organisations in the Union, thus contributing to the proper functioning of the internal market. In order to achieve this, the necessary budgetary funds should be allocated to the Agency.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(17)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Given the increasing significance of electronic networks and communications, which now constitute the backbone of the European economy, and the actual size of the digital economy, the financial and human resources allocated to the Agency should be increased to reflect its enhanced role and tasks, and its critical position in defending the European digital ecosystem.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(18)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should operate as a point of reference establishing trust and confidence by virtue of its independence, the quality of the advice it delivers and the information it disseminates, the transparency of its procedures and methods of operation, and its diligence in carrying out its tasks. The Agency should build on national and Union efforts and therefore carry out its tasks in full cooperation with the Union institutions, bodies, offices and agencies and the Member States, and be open to contacts with industry and other relevant stakeholders. In addition, the Agency should build on input from and cooperation with the private sector, which plays an important role in securing electronic communications, infrastructures and services.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(19)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">A set of tasks should indicate how the Agency is to accomplish its objectives while allowing flexibility in its operations. The tasks carried out by the Agency should include the collection of appropriate information and data needed to carry out analyses of the risks to the security and resilience of electronic communications, infrastructure and services and to assess, in cooperation with Member States, the Commission and, where appropriate, with relevant stakeholders, the state of network and information security in the Union. The Agency should ensure coordination and collaboration with the Union institutions, bodies, offices and agencies and Member States, and enhance cooperation between stakeholders in Europe, in particular by involving in its activities competent national and Union bodies and high-level private sector experts in relevant areas, in particular providers of electronic communications networks and services, network equipment manufacturers and software vendors, taking into account that network and information systems comprise combinations of hardware, software and services. The Agency should provide assistance to the Union institutions and to the Member States in their dialogue with industry to address security-related problems in hardware and software products, thereby contributing to a collaborative approach to network and information security.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(20)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Network and information security strategies made public by a Union institution, body, office or agency or a Member State should be provided to the Agency for its information and to avoid duplication of effort. The Agency should analyse the strategies and promote their presentation in a format that facilitates comparability. It should make the strategies and its analyses available to the public through electronic means.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(21)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should assist the Commission by means of advice, opinions and analyses on all the Union matters related to policy development in the area of network and information security, including Critical Information Infrastructure Protection and resilience. The Agency should also assist the Union institutions, bodies, offices and agencies and where relevant, the Member States, at their request, in their efforts to develop network and information security policy and capability.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(22)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should take full account of the ongoing research, development, and technological assessment activities, in particular those carried out by the various Union research initiatives to advise the Union institutions, bodies, offices and agencies and where relevant, the Member States, at their request, on research needs in the area of network and information security.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(23)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should assist the Union institutions, bodies, offices and agencies as well as the Member States in their efforts to build and enhance cross-border capability and preparedness to prevent, detect and respond to network and information security problems and incidents. In this regard, the Agency should facilitate cooperation among the Member States and between the Commission and other Union institutions, bodies, offices and agencies and the Member States. To this end, the Agency should support the Member States in their continuous efforts to improve their response capability and to organise and run European exercises on security incidents and, at the request of a Member State, national exercises.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(24)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">To understand better the challenges in the network and information security field, the Agency needs to analyse current and emerging risks. For that purpose the Agency should, in cooperation with Member States and, as appropriate, with statistical bodies and others, collect relevant information. Furthermore, the Agency should assist the Union institutions, bodies, offices and agencies and the Member States and in their efforts to collect, analyse and disseminate network and information security data. The collection of appropriate statistical information and data needed to carry out analyses of the risks to the security and resilience of electronic communications, infrastructure and services should take place on the basis of the information provided by the Member States and the Agency\u2019s insight to the Union institutions\u2019 ICT infrastructures in accordance with Union provisions and national provisions in compliance with Union law. On the basis of that information, the Agency should maintain awareness of the latest state of network and information security and related trends in the Union for the benefit of Union institutions, bodies, offices and agencies and the Member States.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(25)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In performing its tasks, the Agency should facilitate cooperation between the Union and the Member States to improve awareness of the state of network and information security in the Union.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(26)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should facilitate cooperation among the Member States\u2019 competent independent regulatory authorities, in particular supporting the development, promotion and exchange of best practices and standards for education programmes and awareness-raising schemes. Increased information exchange between Member States will facilitate such action. The Agency should contribute towards raising the awareness of individual users of electronic communications, infrastructure and services, including by assisting Member States, where they have chosen to use the public interest information platform provided for in Directive 2002\/22\/EC of the European Parliament and of the Council of 7 March 2002 on universal service and users\u2019 rights relating to electronic communications networks and services (Universal Service Directive)\u00a0(<span class=\"super\">10<\/span>), to produce relevant public interest information regarding network and information security, and also by assisting in the development of such information to be included with the supply of new devices intended for use on public communications networks. The Agency should also support cooperation between stakeholders at Union level, partly by promoting information sharing, awareness-raising campaigns and education and training programmes.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(27)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should, inter alia, assist the relevant Union institutions, bodies, offices and agencies and the Member States in public education campaigns to end users, aiming at promoting safer individual online behaviour and raising awareness of potential threats in cyberspace, including cybercrimes such as phishing attacks, botnets, financial and banking fraud, as well as promoting basic authentication and data protection advice.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(28)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">To ensure that it fully achieves its objectives, the Agency should liaise with relevant bodies, including those dealing with cybercrime such as Europol, and privacy protection authorities to exchange know-how and best practices and provide advice on network and information security aspects that might have an impact on their work. The Agency should aim to achieve synergies between the efforts of those bodies and its own efforts to promote advanced network and information security. Representatives of national and Union law enforcement and privacy protection authorities should be eligible to be represented in the Agency\u2019s Permanent Stakeholders Group. In liaising with law enforcement bodies regarding network and information security aspects that might have an impact on their work, the Agency should respect existing channels of information and established networks.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(29)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Commission has launched a European Public-Private Partnership for Resilience as a flexible Union-wide cooperation platform for resilience of ICT infrastructure, in which the Agency should play a facilitating role, bringing together stakeholders to discuss public policy priorities, economic and market dimensions of challenges and measures for the resilience of ICT.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(30)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In order to promote network and information security and its visibility, the Agency should facilitate cooperation among the Member States\u2019 competent public bodies, in particular by supporting the development and exchange of best practices and awareness-raising schemes and by enhancing their outreach activities. The Agency should also support cooperation between stakeholders and the Union institutions, partly by promoting information sharing and awareness-raising activities.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(31)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In order to enhance an advanced level of network and information security in the Union, the Agency should promote cooperation and the exchange of information and best practices between relevant organisations, such as Computer Security Incident Response Teams (CSIRTs) and Computer Emergency Response Teams (CERTs).<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(32)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">A Union system of properly functioning CERTs should constitute a cornerstone of the Union\u2019s network and information security infrastructure. The Agency should support Member State CERTs and the Union CERT in the operation of a network of CERTs, including the members of the European Governmental CERTs Group. In order to assist in ensuring that each of the CERTs has sufficiently advanced capabilities and that those capabilities correspond as far as possible to the capabilities of the most developed CERTs, the Agency should promote the establishment and operation of a peer-review system. Furthermore, the Agency should promote and support cooperation between the relevant CERTs in the event of incidents, attacks on or disruptions of networks or infrastructure managed or protected by the CERTs and involving or potentially involving at least two CERTs.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(33)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Efficient network and information security policies should be based on well-developed risk assessment methods, both in the public and private sector. Risk assessment methods and procedures are used at different levels with no common practice regarding how to apply them efficiently. Promoting and developing best practices for risk assessment and for interoperable risk management solutions in public- and private-sector organisations will increase the security level of networks and information systems in the Union. To this end, the Agency should support cooperation between stakeholders at Union level, facilitating their efforts relating to the establishment and take-up of European and international standards for risk management and for measurable security of electronic products, systems, networks and services which, together with software, comprise the network and information systems.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(34)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Where appropriate and useful for fulfilling its objectives and tasks, the Agency should share experience and general information with Union institutions, bodies, offices and agencies dealing with network and information security. The Agency should contribute to identifying research priorities, at Union level, in the areas of network resilience and network and information security, and should convey knowledge of industry needs to relevant research institutions.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(35)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should encourage Member States and service providers to raise their general security standards so that all internet users take the necessary steps to ensure their own personal cyber security.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(36)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Network and information security problems are global issues. There is a need for closer international cooperation to improve security standards, including the definition of common norms of behaviour and codes of conduct, and information sharing, promoting swifter international collaboration in response to, as well as a common global approach to, network and information security issues. To that end, the Agency should support further Union involvement and cooperation with third countries and international organisations by providing, where appropriate, the necessary expertise and analysis to the relevant Union institutions, bodies, offices and agencies.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(37)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should operate in accordance with the principle of subsidiarity, ensuring an appropriate degree of coordination between the Member States on matters relating to network and information security and improving the effectiveness of national policies, thus adding value to them and in accordance with the principle of proportionality, not going beyond what is necessary in order to achieve the objectives set out by this Regulation. The exercise of the Agency\u2019s tasks should reinforce, but not interfere with, the competences, nor should it pre-empt, impede or overlap with the relevant powers and tasks, of the national regulatory authorities as set out in the Directives relating to electronic communications networks and services, as well as those of the Body of European Regulators for Electronic Communications (BEREC) established by Regulation (EC) No\u00a01211\/2009\u00a0(<span class=\"super\">11<\/span>) and the Communications Committee referred to in Directive 2002\/21\/EC, of the European standardisation bodies, the national standardisation bodies and the Standing Committee as set out in Directive 98\/34\/EC\u00a0(<span class=\"super\">12<\/span>) and the independent supervisory authorities of the Member States as set out in Directive 95\/46\/EC.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(38)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">It is necessary to implement certain principles regarding the governance of the Agency in order to comply with the Joint Statement and Common Approach agreed upon in July 2012 by the Inter-Institutional Working Group on EU decentralised agencies, the purpose of which statement and approach is to streamline the activities of agencies and improve their performance.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(39)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Joint Statement and Common Approach should also be reflected, as appropriate, in the Agency\u2019s Work Programmes, evaluations of the Agency, and the Agency\u2019s reporting and administrative practice.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(40)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In order for the Agency to function properly, the Commission and the Member States should ensure that persons to be appointed to the Management Board have appropriate professional expertise. The Commission and the Member States should also make efforts to limit the turnover of their respective Representatives on the Management Board, in order to ensure continuity in its work.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(41)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">It is essential that the Agency establish and maintain a reputation for impartiality, integrity and high professional standards. Accordingly, the Management Board should adopt comprehensive rules covering the entire Agency for the prevention and management of conflicts of interest.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(42)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Given the unique circumstances of the Agency and the difficult challenges facing it, the organisational structure of the Agency should be simplified and strengthened to ensure greater efficiency and effectiveness. Therefore, among other things, an Executive Board should be established in order to enable the Management Board to focus on issues of strategic importance.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(43)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Management Board should appoint an Accounting Officer in accordance with rules adopted under Regulation (EU, Euratom) No\u00a0966\/2012\u00a0(<span class=\"super\">13<\/span>) (the \u2018Financial Regulation\u2019).<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(44)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In order to ensure that the Agency is effective, the Member States and the Commission should be represented on the Management Board, which should define the general direction of the Agency\u2019s operations and ensure that it carries out its tasks in accordance with this Regulation. The Management Board should be entrusted with the powers necessary to establish the budget, verify its execution, adopt the appropriate financial rules, establish transparent working procedures for decision making by the Agency, adopt the Agency\u2019s work programme, adopt its own rules of procedure and the Agency\u2019s internal rules of operation, appoint the Executive Director, decide on the extension of the Executive Director\u2019s term of office after obtaining the views of the European Parliament, and decide on the termination thereof. The Management Board should set up an Executive Board to assist it with its administrative and budgetary tasks.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(45)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The smooth functioning of the Agency requires that its Executive Director be appointed on grounds of merit and documented administrative and managerial skills, as well as competence and experience relevant for network and information security, and that the duties of the Executive Director be carried out with complete independence as to the organisation of the internal functioning of the Agency. To this end, the Executive Director should prepare a proposal for the Agency\u2019s work programme, after prior consultation with the Commission, and take all necessary steps to ensure the proper execution of the work programme of the Agency. The Executive Director should prepare an annual report to be submitted to the Management Board, draw up a draft statement of estimates of revenue and expenditure for the Agency, and implement the budget.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(46)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Executive Director should have the option of setting up ad hoc Working Groups to address specific matters, in particular of a scientific, technical or legal or socioeconomic nature. In setting up ad hoc Working Groups the Executive Director should seek input from and draw on the relevant external expertise needed to enable the Agency to have access to the most up-to-date information available regarding security challenges posed by the developing information society. The Executive Director should ensure that the ad hoc Working Groups\u2019 members are selected according to the highest standards of expertise, taking due account of a representative balance, as appropriate according to the specific issues in question, between the public administrations of the Member States, the Union institutions and the private sector, including industry, users, and academic experts in network and information security. The Executive Director should be able, as appropriate, to invite individual experts recognised as competent in the relevant field to participate in the Working Groups\u2019 proceedings, on a case-by-case basis. Their expenses should be met by the Agency in accordance with its internal rules and in accordance with rules adopted under the Financial Regulation.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(47)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should have a Permanent Stakeholders\u2019 Group as an advisory body, to ensure regular dialogue with the private sector, consumers\u2019 organisations and other relevant stakeholders. The Permanent Stakeholders\u2019 Group, set up by the Management Board on a proposal by the Executive Director, should focus on issues relevant to stakeholders and bring them to the attention of the Agency. The Executive Director should, where appropriate and according to the agenda of the meetings, be able to invite representatives of the European Parliament and other relevant bodies to take part in meetings of the Group.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(48)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Since there is provision for ample representation of stakeholders in the Permanent Stakeholders Group, and that group is to be consulted in particular regarding the draft Work Programme, there is no longer any need to provide for representation of stakeholders in the Management Board.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(49)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should apply the relevant Union provisions concerning public access to documents as set out in Regulation (EC) No\u00a01049\/2001 of the European Parliament and of the Council\u00a0(<span class=\"super\">14<\/span>). The information processed by the Agency for purposes relating to its internal functioning as well as the information processed in carrying out its tasks should be subject to Regulation (EC) No\u00a045\/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data\u00a0(<span class=\"super\">15<\/span>).<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(50)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency should comply with the provisions applicable to the Union institutions, and with national legislation regarding the treatment of sensitive documents.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(51)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In order to guarantee the full autonomy and independence of the Agency and to enable it to perform additional and new tasks, including unforeseen emergency tasks, the Agency should be granted a sufficient and autonomous budget whose revenue comes primarily from a contribution from the Union and contributions from third countries participating in the Agency\u2019s work. The majority of the Agency staff should be directly engaged in the operational implementation of the Agency\u2019s mandate. The host Member State, or any other Member State, should be allowed to make voluntary contributions to the revenue of the Agency. The Union\u2019s budgetary procedure should remain applicable as far as any subsidies chargeable to the general budget of the European Union are concerned. Moreover, the Court of Auditors should audit the Agency\u2019s accounts to ensure transparency and accountability.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(52)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">In view of the continually changing threat landscape and the evolution of Union policy on network and information security, and in order to align to the multiannual financial framework, the duration of the mandate of the Agency should be set to a limited period of seven years with a possibility of extending the duration.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(53)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The Agency\u2019s operations should be evaluated independently. The evaluation should have regard to the Agency\u2019s effectiveness in achieving its objectives, its working practices and the relevance of its tasks, in order to determine the continuing validity, or otherwise, of the objectives of the Agency and, based thereon, whether and for what period the duration of its mandate should be further extended.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(54)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">If, towards the end of the duration of the mandate of the Agency, the Commission has not introduced a proposal for an extension of the mandate, the Agency and the Commission should take the relevant measures, addressing in particular issues relating to staff contracts and budget arrangements.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(55)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Since the objective of this Regulation, namely to establish a European Union Agency for Network and Information Security for the purpose of contributing to a high level of network and information security within the Union and in order to raise awareness and develop and promote a culture of network and information security in society for the benefit of citizens, consumers, enterprises and public sector organisations in the Union, thus contributing to the establishment and proper functioning of the internal market, cannot be sufficiently achieved by the Member States and can therefore be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality, as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(56)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">Regulation (EC) No\u00a0460\/2004 should be repealed.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(57)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">The European Data Protection Supervisor was consulted in accordance with Article 28(2) of Regulation (EC) No\u00a045\/2001 and adopted his opinion on 20 December 2010\u00a0(<span class=\"super\">16<\/span>),<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"normal\" style=\"text-align: center;\">HAVE ADOPTED THIS REGULATION:<\/p>\n<p id=\"d1e593-41-1\" class=\"ti-section-1\" style=\"text-align: center;\">SECTION 1<\/p>\n<p id=\"L_2013165EN.01004101-d-001\" class=\"ti-section-2\" style=\"text-align: center;\"><span class=\"bold\">SCOPE OBJECTIVES AND TASKS<\/span><\/p>\n<p id=\"d1e601-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 1<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Subject matter and Scope<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0This Regulation establishes a European Union Agency for Network and Information Security (ENISA, hereinafter \u2018the Agency\u2019) to undertake the tasks assigned to it for the purpose of contributing to a high level of network and information security within the Union and in order to raise awareness of network and information security and to develop and promote a culture, of network and information security in society for the benefit of citizens, consumers, enterprises and public sector organisations in the Union, thus contributing to the establishment and proper functioning of the internal market.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The objectives and the tasks of the Agency shall be without prejudice to the competences of the Member States regarding network and information security and in any case to activities concerning public security, defence, national security (including the economic well-being of the state when the issues relate to national security matters) and the activities of the state in areas of criminal law.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0For the purposes of this Regulation \u2018network and information security\u2019 means the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted data and the related services offered by or accessible via those networks and systems.<\/p>\n<p id=\"d1e629-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 2<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Objectives<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Agency shall develop and maintain a high level of expertise.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Agency shall assist the Union institutions, bodies, offices and agencies in developing policies in network and information security.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Agency shall assist the Union institutions, bodies, offices and agencies and the Member States in implementing the policies necessary to meet the legal and regulatory requirements of network and information security under existing and future legal acts of the Union, thus contributing to the proper functioning of the internal market.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The Agency shall assist the Union and the Member States in enhancing and strengthening their capability and preparedness to prevent, detect and respond to network and information security problems and incidents.<\/p>\n<p class=\"normal\">5.\u00a0\u00a0\u00a0The Agency shall use its expertise to stimulate broad cooperation between actors from the public and private sectors.<\/p>\n<p id=\"d1e659-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 3<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Tasks<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0Within the purpose set out in Article 1, and in order to attain the objectives set out in Article 2, whilst respecting Article 1(2), the Agency shall perform the following tasks:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(a)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">support the development of Union policy and law, by:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(i)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">assisting and advising on all matters relating to Union network and information security policy and law;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(ii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">providing preparatory work, advice and analyses relating to the development and update of Union network and information security policy and law;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(iii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">analysing publicly available network and information security strategies and promoting their publication;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(b)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">support capability building by:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(i)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">supporting Member States, at their request, in their efforts to develop and improve the prevention, detection and analysis of and the capability to respond to network and information security problems and incidents, and providing them with the necessary knowledge;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(ii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">promoting and facilitating voluntary cooperation among the Member States and between the Union institutions, bodies, offices and agencies and the Member States in their efforts to prevent, detect and respond to network and information security problems and incidents where these have an impact across borders;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(iii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">assisting the Union institutions, bodies, offices and agencies in their efforts to develop the prevention, detection and analysis of and the capability to respond to network and information security problems and incidents, in particular by supporting the operation of a Computer Emergency Response Team (CERT) for them;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(iv)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">supporting the raising of the level of capabilities of national\/governmental and Union CERTs, including by promoting dialogue and exchange of information, with a view to ensuring that, with regard to the state of the art, each CERT meets a common set of minimum capabilities and operates according to best practices;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(v)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">supporting the organisation and running of Union network and information security exercises, and, at their request, advising Member States on national exercises;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(vi)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">assisting the Union institutions, bodies, offices and agencies and the Member States in their efforts to collect, analyse and, in line with Member States\u2019 security requirements, disseminate relevant network and information security data; and on the basis of information provided by the Union institutions, bodies, offices and agencies and the Member States in accordance with provisions of Union law and national provisions in compliance with Union law, maintaining the awareness, on the part of the Union institutions, bodies, offices and agencies as well as the Member States of the latest state of network and information security in the Union for their benefit;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(vii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">supporting the development of a Union early warning mechanism that is complementary to Member States\u2019 mechanisms;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(viii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">offering network and information security training for relevant public bodies, where appropriate in cooperation with stakeholders;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(c)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">support voluntary cooperation among competent public bodies, and between stakeholders, including universities and research centres in the Union, and support awareness raising, inter alia, by:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(i)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">promoting cooperation between national and governmental CERTs or Computer Security Incident Response Teams (CSIRTs), including the CERT for the Union institutions, bodies, offices and agencies;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(ii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">promoting the development and sharing of best practices with the aim of attaining an advanced level of network and information security;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(iii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">facilitating dialogue and efforts to develop and exchange best practices;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(iv)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">promoting best practices in information sharing and awareness raising;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(v)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">supporting the Union institutions, bodies, offices and agencies and, at their request, the Member States and their relevant bodies in organising awareness raising, including at the level of individual users, and other outreach activities to increase network and information security and its visibility by providing best practices and guidelines;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(d)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">support research and development and standardisation, by:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(i)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">facilitating the establishment and take-up of European and international standards for risk management and for the security of electronic products, networks and services;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(ii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">advising the Union and the Member States on research needs in the area of network and information security with a view to enabling effective responses to current and emerging network and information security risks and threats, including with respect to new and emerging information and communications technologies, and to using risk-prevention technologies effectively;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(e)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">cooperate with Union institutions, bodies, offices and agencies, including those dealing with cybercrime and the protection of privacy and personal data, with a view to addressing issues of common concern, including by:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(i)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">exchanging know-how and best practices;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(ii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">providing advice on relevant network and information security aspects in order to develop synergies;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(f)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">contribute to the Union\u2019s efforts to cooperate with third countries and international organisations to promote international cooperation on network and information security issues, including by:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(i)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">being engaged, where appropriate, as an observer and in the organisation of international exercises, and analysing and reporting on the outcome of such exercises;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(ii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">facilitating exchange of best practices of relevant organisations;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(iii)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">providing the Union institutions with expertise.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0Union institutions, bodies, offices and agencies and Member State bodies may request advice from the Agency in the event of breach of security or loss of integrity with a significant impact on the operation of networks and services.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Agency shall carry out tasks conferred on it by legal acts of the Union.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The Agency shall express independently its own conclusions, guidance and advice on matters within the scope and objectives of this Regulation.<\/p>\n<p id=\"d1e873-41-1\" class=\"ti-section-1\" style=\"text-align: center;\">SECTION 2<\/p>\n<p id=\"L_2013165EN.01004101-d-002\" class=\"ti-section-2\" style=\"text-align: center;\"><span class=\"bold\">ORGANISATION<\/span><\/p>\n<p id=\"d1e881-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 4<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Composition of the Agency<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Agency shall comprise:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(a)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">a Management Board;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(b)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">an Executive Director and staff; and<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(c)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">a Permanent Stakeholders\u2019 Group.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0In order to contribute to enhancing effectiveness and efficiency of the operation of the Agency, the Management Board shall establish an Executive Board.<\/p>\n<p id=\"d1e916-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 5<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Management Board<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Management Board shall define the general direction of the operation of the Agency and ensure that the Agency works in accordance with the rules and principles laid down in this Regulation. It shall also ensure consistency of the Agency\u2019s work with activities conducted by the Member States as well as at Union level.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Management Board shall adopt the Agency\u2019s annual and multiannual work programme.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Management Board shall adopt an annual report on the Agency\u2019s activities and send it, by 1 July of the following year, to the European Parliament, the Council, the Commission and the Court of Auditors. The annual report shall include the accounts and describe how the Agency has met its performance indicators. The annual report shall be made public.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The Management Board shall adopt an anti-fraud strategy that is proportionate to the fraud risks having regard to a cost-benefit analysis of the measures to be implemented.<\/p>\n<p class=\"normal\">5.\u00a0\u00a0\u00a0The Management Board shall ensure adequate follow-up to the findings and recommendations resulting from investigations of the European Anti-fraud Office (OLAF) and the various internal or external audit reports and evaluations.<\/p>\n<p class=\"normal\">6.\u00a0\u00a0\u00a0The Management Board shall adopt rules for the prevention and management of conflicts of interest.<\/p>\n<p class=\"normal\">7.\u00a0\u00a0\u00a0The Management Board shall exercise, with respect to the staff of the Agency, the powers conferred by the Staff Regulations of Officials and the Conditions of Employment of Other Servants of the European Union (the \u2018Staff Regulations\u2019 and the \u2018Conditions of Employment of Other Servants\u2019), laid down in Regulation (EEC, Euratom, ECSC) No\u00a0259\/68\u00a0(<span class=\"super\">17<\/span>) on the Appointing Authority and on the Authority Empowered to Conclude Contract of Employment, respectively.<\/p>\n<p class=\"normal\">The Management Board shall adopt, in accordance with the procedure under Article 110 of the Staff Regulations, a decision based on Article 2(1) of the Staff Regulations and on Article 6 of the Conditions of Employment of Other Servants delegating the relevant Appointing Authority powers to the Executive Director. The Executive Director may sub-delegate those powers.<\/p>\n<p class=\"normal\">Where exceptional circumstances so require, the Management Board may revoke the delegation of the powers of the Appointing Authority to the Executive Director and those sub-delegated by the Executive Director. In such a case, the Management Board may delegate them, for a limited period to one of its members or to a staff member other than the Executive Director.<\/p>\n<p class=\"normal\">8.\u00a0\u00a0\u00a0The Management board shall adopt appropriate rules implementing the Staff Regulations and the Conditions of Employment of Other Servants in accordance with the procedure provided for in Article 110 of the Staff Regulations.<\/p>\n<p class=\"normal\">9.\u00a0\u00a0\u00a0The Management Board shall appoint the Executive Director and may extend his term of office or remove him from office in accordance with Article 24 of this Regulation.<\/p>\n<p class=\"normal\">10.\u00a0\u00a0\u00a0The Management Board shall adopt the rules of procedure for itself and for the Executive Board after consulting the Commission. The rules of procedure shall provide for expedited decisions through either written procedure or by remote conferencing.<\/p>\n<p class=\"normal\">11.\u00a0\u00a0\u00a0The Management Board shall adopt the Agency\u2019s internal rules of operation after consulting the Commission services. Those rules shall be made public.<\/p>\n<p class=\"normal\">12.\u00a0\u00a0\u00a0The Management Board shall adopt the financial rules applicable to the Agency. They may not depart from Commission Regulation (EC, Euratom) No\u00a02343\/2002 of 19 November 2002 on the framework Financial Regulation for the bodies referred to in Article 185 of Council Regulation (EC, Euratom) No\u00a01605\/2002 on the Financial Regulation applicable to the general budget of the European Communities\u00a0(<span class=\"super\">18<\/span>), unless such departure is specifically required for the Agency\u2019s operation and the Commission has given its prior consent.<\/p>\n<p class=\"normal\">13.\u00a0\u00a0\u00a0The Management Board shall adopt a Multiannual Staff Policy Plan, after consulting the Commission services and having duly informed the European Parliament and the Council.<\/p>\n<p id=\"d1e1014-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 6<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Composition of the Management Board<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Management Board shall be composed of one representative of each Member State, and two representatives appointed by the Commission. All representatives shall have voting rights.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0Each member of the Management Board shall have an alternate to represent the member in their absence.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0Members of the Management Board and their alternates shall be appointed in light of their knowledge of the Agency\u2019s tasks and objectives, taking into account the managerial, administrative and budgetary skills relevant to fulfil the tasks listed in Article 5. The Commission and the Member States should make efforts to limit turnover of their representatives in the Management Board, in order to ensure continuity of that board\u2019s work. The Commission and the Member States shall aim to achieve a balanced representation between men and women on the Management Board.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The term of office of members of the Management Board and of their alternates shall be four years. That term shall be renewable.<\/p>\n<p id=\"d1e1039-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 7<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Chairperson of the Management Board<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Management Board shall elect its Chairperson and a Deputy Chairperson from among its members for a period of three years, which shall be renewable. The Deputy Chairperson shall <span class=\"italic\">ex officio<\/span> replace the Chairperson if the latter is unable to attend to his or her duties.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Chairperson may be invited to make a statement before the relevant committee(s) of the European Parliament and answer Members\u2019 questions.<\/p>\n<p id=\"d1e1057-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 8<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Meetings<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0Meetings of the Management Board shall be convened by its Chairperson.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Management Board shall hold an ordinary meeting at least once a year. It shall also hold extraordinary meetings at the request of the Chairperson or of at least a third of its members.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Executive Director shall take part, without voting rights, in the meetings of the Management Board.<\/p>\n<p id=\"d1e1077-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 9<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Voting<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Management Board shall take its decisions by an absolute majority of its members.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0A two-thirds majority of all Management Board members shall be required for the adoption of the Management Board\u2019s rules of procedure, the Agency\u2019s internal rules of operation, the budget, the annual and multiannual work programme, the appointment, extension of the term of office or removal of the Executive Director, and the designation of the Chairperson of the Management Board.<\/p>\n<p id=\"d1e1092-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 10<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Executive Board<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Management Board shall be assisted by an Executive Board.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Executive Board shall prepare decisions to be adopted by the Management Board on administrative and budgetary matters only.<\/p>\n<p class=\"normal\">Together with the Management Board, it shall ensure adequate follow-up to the findings and recommendations stemming from investigations of OLAF and the various internal or external audit reports and evaluations.<\/p>\n<p class=\"normal\">Without prejudice to the responsibilities of the Executive Director, as set out in Article 11, the Executive Board shall assist and advise the Executive Director in implementing the decisions of the Management Board on administrative and budgetary matters.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Executive Board shall be made up of five members appointed from among the members of the Management Board amongst whom the Chairperson of the Management Board, who may also chair the Executive Board, and one of the representatives of the Commission.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The term of office of members of the Executive Board shall be the same as that of members of the Management Board set out in Article 6(4).<\/p>\n<p class=\"normal\">5.\u00a0\u00a0\u00a0The Executive Board shall meet at least once every three months. The chairperson of the Executive Board shall convene additional meetings at the request of its members.<\/p>\n<p id=\"d1e1126-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 11<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Duties of the Executive Director<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Agency shall be managed by its Executive Director, who shall be independent in the performance of his\/her duties.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Executive Director shall be responsible for:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(a)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">the day-to-day administration of the Agency;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(b)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">implementing the decisions adopted by the Management Board;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(c)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">after consultation with the Management Board, preparing the annual work programme and the multiannual work programme and submitting them to the Management Board after consulting the Commission;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(d)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">implementing the annual work programme and the multiannual work programme and reporting to the Management Board thereon;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(e)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">preparing the annual report on the Agency\u2019s activities and presenting it to the Management Board for approval;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(f)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">preparing an action plan following-up on the conclusions of the retrospective evaluations and reporting on progress every two years to the Commission;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(g)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">protecting the financial interests of the Union by the application of preventive measures against fraud, corruption and any other illegal activities, by effective checks and, if irregularities are detected, by the recovery of the amounts wrongly paid and, where appropriate, by effective, proportionate and dissuasive administrative and financial penalties;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(h)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">preparing an anti-fraud strategy for the Agency and presenting it to the Management Board for approval;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(i)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">ensuring that the Agency performs its activities in accordance with the requirements of those using its services, in particular with regard to the adequacy of the services provided;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(j)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">developing and maintaining contact with the Union institutions, bodies, offices and agencies;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(k)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">developing and maintaining contact with the business community and consumers\u2019 organisations to ensure regular dialogue with relevant stakeholders;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(l)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">other tasks assigned to the Executive Director by this Regulation.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0Where necessary and within the Agency\u2019s objectives and tasks, the Executive Director may set up ad hoc Working Groups composed of experts, including from the Member States\u2019 competent authorities. The Management Board shall be informed in advance. The procedures regarding in particular the composition, the appointment of the experts by the Executive Director and the operation of the ad hoc Working Groups shall be specified in the Agency\u2019s internal rules of operation.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The Executive Director shall make administrative support staff and other resources available to the Management Board and the Executive Board whenever necessary.<\/p>\n<p id=\"d1e1226-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 12<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Permanent Stakeholders\u2019 Group<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Management Board, acting on a proposal by the Executive Director, shall set up a Permanent Stakeholders\u2019 Group composed of recognised experts representing the relevant stakeholders, such as the ICT industry, providers of electronic communications networks or services available to the public, consumer groups, academic experts in network and information security, and representatives of national regulatory authorities notified under Directive 2002\/21\/EC as well as of law enforcement and privacy protection authorities.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0Procedures for, in particular, the number, composition, and the appointment of the members of the Permanent Stakeholders\u2019 Group by the Management Board, the proposal by the Executive Director and the operation of the Group shall be specified in the Agency\u2019s internal rules of operation and shall be made public.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Permanent Stakeholders\u2019 Group shall be chaired by the Executive Director or by any person the Executive Director appoints on a case-by-case basis.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The term of office of the Permanent Stakeholders\u2019 Group\u2019s members shall be two-and-a-half years. Members of the Management Board may not be members of the Permanent Stakeholders\u2019 Group. Experts from the Commission and the Member States shall be entitled to be present at the meetings of the Permanent Stakeholders\u2019 Group and to participate in its work. Representatives of other bodies deemed relevant by the Executive Director, who are not members of the Permanent Stakeholders\u2019 Group, may be invited to be present at the meetings of the Permanent Stakeholders\u2019 Group and to participate in its work.<\/p>\n<p class=\"normal\">5.\u00a0\u00a0\u00a0The Permanent Stakeholders\u2019 Group shall advise the Agency in respect of the performance of its activities. It shall in particular advise the Executive Director on drawing up a proposal for the Agency\u2019s work programme, and on ensuring communication with the relevant stakeholders on all issues related to the work programme.<\/p>\n<p id=\"d1e1257-41-1\" class=\"ti-section-1\" style=\"text-align: center;\">SECTION 3<\/p>\n<p id=\"L_2013165EN.01004101-d-003\" class=\"ti-section-2\" style=\"text-align: center;\"><span class=\"bold\">OPERATION<\/span><\/p>\n<p id=\"d1e1265-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 13<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Work Programme<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Agency shall carry out its operations in accordance with its annual and multiannual work programme, which shall contain all of its planned activities.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The work programme shall include tailored performance indicators allowing for effective assessment of the results achieved in terms of objectives.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Executive Director shall be responsible for drawing up the Agency\u2019s draft work programme after prior consultation with the Commission services. By 15 March each year the Executive Director shall submit the draft work programme for the following year to the Management Board.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0By 30 November each year, the Management Board shall adopt the Agency\u2019s work programme for the following year, after having received the opinion of the Commission. The work programme shall include a multiannual outlook. The Management Board shall ensure that the work programme is consistent with the Agency\u2019s objectives and with the Union\u2019s legislative and policy priorities in the area of network and information security.<\/p>\n<p class=\"normal\">5.\u00a0\u00a0\u00a0The work programme shall be organised in accordance with the activity-based management principle. The work programme shall be in line with the statement of estimates of the Agency\u2019s revenue and expenditure and the Agency\u2019s budget for the same financial year.<\/p>\n<p class=\"normal\">6.\u00a0\u00a0\u00a0The Executive Director shall, following adoption by the Management Board, forward the work programme to the European Parliament, the Council, the Commission and the Member States and shall publish it. At the invitation of the relevant committee of the European Parliament, the Executive Director shall present and hold an exchange of views on the adopted annual work programme.<\/p>\n<p id=\"d1e1300-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 14<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Requests to the Agency<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0Requests for advice and assistance falling within the Agency\u2019s objectives and tasks shall be addressed to the Executive Director and accompanied by background information explaining the issue to be addressed. The Executive Director shall inform the Management Board and Executive Board of the requests received, the potential resource implications, and, in due course, of the follow-up to the requests. If the Agency refuses a request, it shall give a justification.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0Requests referred to in paragraph 1 may be made by:<\/p>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(a)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">the European Parliament;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(b)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">the Council;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(c)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">the Commission;<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\">\n<colgroup>\n<col width=\"4%\" \/>\n<col width=\"96%\" \/> <\/colgroup>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p class=\"normal\">(d)<\/p>\n<\/td>\n<td valign=\"top\">\n<p class=\"normal\">any competent body appointed by a Member State, such as a national regulatory authority defined in Article 2 of Directive 2002\/21\/EC.<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The practical arrangements for applying paragraphs 1 and 2, regarding in particular submission, prioritisation, follow-up and information to the Management and Executive Board on the requests to the Agency, shall be laid down by the Management Board in the Agency\u2019s internal rules of operation.<\/p>\n<p id=\"d1e1346-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 15<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Declaration of interest<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0Members of the Management Board, the Executive Director and officials seconded by Member States on a temporary basis shall each make a declaration of commitments and a declaration indicating the absence or presence of any direct or indirect interest which might be considered prejudicial to their independence. The declarations shall be accurate and complete, made annually in writing and updated whenever necessary.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0Members of the Management Board, the Executive Director, and external experts participating in ad hoc Working Groups shall each accurately and completely declare, at the latest at the start of each meeting, any interest which might be considered prejudicial to their independence in relation to the items on the agenda, and shall abstain from participating in the discussion of and voting upon such points.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Agency shall lay down, in its internal rules of operation, the practical arrangements for the rules on declarations of interest referred to in paragraphs 1 and 2.<\/p>\n<p id=\"d1e1366-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 16<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Transparency<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Agency shall ensure that it carries out its activities with a high level of transparency and in accordance with Articles 17 and 18.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Agency shall ensure that the public and any interested parties are given appropriate, objective, reliable and easily accessible information, in particular with regard to the results of its work. It shall also make public the declarations of interest made in accordance with Article 15.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Management Board, acting on a proposal from the Executive Director, may authorise interested parties to observe the proceedings of some of the Agency\u2019s activities.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The Agency shall lay down, in its internal rules of operation, the practical arrangements for implementing the transparency rules referred to in paragraphs 1 and 2.<\/p>\n<p id=\"d1e1391-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 17<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Confidentiality<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0Without prejudice to Article 18, the Agency shall not divulge to third parties information that it processes or receives in relation to which a reasoned request for confidential treatment, in whole or in part, has been made.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0Members of the Management Board, the Executive Director, the members of the Permanent Stakeholders Group, external experts participating in ad hoc Working Groups, and members of the staff of the Agency including officials seconded by Member States on a temporary basis shall comply with the confidentiality requirements under Article 339 of the Treaty on the Functioning of the European Union (TFEU), even after their duties have ceased.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Agency shall lay down, in its internal rules of operation, the practical arrangements for implementing the confidentiality rules referred to in paragraphs 1 and 2.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0If required for the performance of the Agency\u2019s tasks, the Management Board shall decide to allow the Agency to handle classified information. In that case the Management Board shall, in agreement with the Commission services, adopt internal rules of operation applying the security principles set out in Commission Decision 2001\/844\/EC, ECSC, Euratom of 29 November 2001 amending its internal rules of procedure\u00a0(<span class=\"super\">19<\/span>). Those rules shall cover, inter alia, provisions for the exchange, processing and storage of classified information.<\/p>\n<p id=\"d1e1425-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 18<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Access to documents<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0Regulation (EC) No\u00a01049\/2001 shall apply to documents held by the Agency.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Management Board shall adopt arrangements for implementing Regulation (EC) No\u00a01049\/2001 within six months of the establishment of the Agency.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0Decisions taken by the Agency pursuant to Article 8 of Regulation (EC) No\u00a01049\/2001 may be the subject of a complaint to the Ombudsman under Article 228 TFEU or of an action before the Court of Justice of the European Union under Article 263 TFEU.<\/p>\n<p id=\"d1e1446-41-1\" class=\"ti-section-1\" style=\"text-align: center;\">SECTION 4<\/p>\n<p id=\"L_2013165EN.01004101-d-004\" class=\"ti-section-2\" style=\"text-align: center;\"><span class=\"bold\">FINANCIAL PROVISIONS<\/span><\/p>\n<p id=\"d1e1454-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 19<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Adoption of the budget<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The revenues of the Agency shall consist of a contribution from the Union budget, contributions from third countries participating in the work of the Agency as provided for in Article 30, and voluntary contributions from Member States in money or in kind. Member States that provide voluntary contributions may not claim any specific right or service as a result thereof.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The expenditure of the Agency shall include staff, administrative and technical support, infrastructure and operational expenses, and expenses resulting from contracts entered into with third parties.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0By 1 March each year, the Executive Director shall draw up a draft statement of estimates of the Agency\u2019s revenue and expenditure for the following financial year, and shall forward it to the Management Board, together with a draft establishment plan.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0Revenue and expenditure shall be in balance.<\/p>\n<p class=\"normal\">5.\u00a0\u00a0\u00a0Each year, the Management Board shall, on the basis of a draft statement of estimates of revenue and expenditure drawn up by the Executive Director, produce a statement of estimates of revenue and expenditure for the Agency for the following financial year.<\/p>\n<p class=\"normal\">6.\u00a0\u00a0\u00a0The Management Board shall, by 31 March each year, send that statement of estimates, which shall include a draft establishment plan together with the draft work programme, to the Commission and the third countries with which the Union has concluded agreements in accordance with Article 30.<\/p>\n<p class=\"normal\">7.\u00a0\u00a0\u00a0The Commission shall forward that statement of estimates to the European Parliament and the Council together with the draft general budget of the Union.<\/p>\n<p class=\"normal\">8.\u00a0\u00a0\u00a0On the basis of that statement of estimates, the Commission shall enter in the draft budget of the Union the estimates it deems necessary for the establishment plan and the amount of the subsidy to be charged to the general budget, which it shall submit to the European Parliament and the Council in accordance with Article 314 TFEU.<\/p>\n<p class=\"normal\">9.\u00a0\u00a0\u00a0The European Parliament and the Council shall authorise the appropriations for the subsidy to the Agency.<\/p>\n<p class=\"normal\">10.\u00a0\u00a0\u00a0The European Parliament and the Council shall adopt the establishment plan for the Agency.<\/p>\n<p class=\"normal\">11.\u00a0\u00a0\u00a0Together with the work programme, the Management Board shall adopt the Agency\u2019s budget. It shall become final following definitive adoption of the general budget of the Union. Where appropriate, the Management Board shall adjust the Agency\u2019s budget and work programme in accordance with the general budget of the Union. The Management Board shall forward the budget without delay to the European Parliament, the Council and the Commission.<\/p>\n<p id=\"d1e1515-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 20<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Combating fraud<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0In order to facilitate the combating of fraud, corruption and other unlawful activities under Regulation (EC) No\u00a01073\/1999\u00a0(<span class=\"super\">20<\/span>), the Agency shall, within six months from the day it becomes operational, accede to the Interinstitutional Agreement of 25 May 1999 concerning internal investigations by the European Anti-fraud Office (OLAF)\u00a0(<span class=\"super\">21<\/span>) and shall adopt the appropriate provisions applicable to all the employees of the Agency, using the template set out in the Annex to that Agreement.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Court of Auditors shall have the power of audit, on the basis of documents and on the spot, over all grant beneficiaries, contractors and subcontractors who have received Union funds from the Agency.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0OLAF may carry out investigations, including on-the-spot checks and inspections, in accordance with the provisions and procedures laid down in Regulation (EC) No\u00a01073\/1999 and Council Regulation (Euratom, EC) No\u00a02185\/96 of 11 November 1996 concerning on-the-spot checks and inspections carried out by the Commission in order to protect the European Communities\u2019 financial interests against fraud and other irregularities\u00a0(<span class=\"super\">22<\/span>) with a view to establishing whether there has been fraud, corruption or any other illegal activity affecting the financial interests of the Union in connection with a grant or a contract funded by the Agency.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0Without prejudice to paragraphs 1, 2 and 3, cooperation agreements with third countries and international organisations, contracts, grant agreements and grant decisions of the Agency shall contain provisions expressly empowering the Court of Auditors and OLAF to conduct such audits and investigations, according to their respective competences.<\/p>\n<p id=\"d1e1572-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 21<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Implementation of the budget<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Executive Director shall be responsible for the implementation of the Agency\u2019s budget.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Commission\u2019s internal auditor shall exercise the same powers over the Agency as over Commission departments.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0By 1 March following each financial year (1 March of year N +\u00a01), the Agency\u2019s accounting officer shall send the provisional accounts to the Commission\u2019s accounting officer together with a report on the budgetary and financial management for that financial year. The Commission\u2019s accounting officer shall consolidate the provisional accounts of the institutions and decentralised bodies in accordance with Article 147 of the Financial Regulation.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0By 31 March of year N +\u00a01, the Commission\u2019s accounting officer shall send the Agency\u2019s provisional accounts to the Court of Auditors, together with a report on the budgetary and financial management for that financial year. The report on the budgetary and financial management for the financial year shall also be sent to the European Parliament and the Council.<\/p>\n<p class=\"normal\">5.\u00a0\u00a0\u00a0On receipt of the Court of Auditor\u2019s observations on the Agency\u2019s provisional accounts, pursuant to Article 148 of the Financial Regulation, the Executive Director shall draw up the Agency\u2019s final accounts under his\/her own responsibility and send them to the Management Board for an opinion.<\/p>\n<p class=\"normal\">6.\u00a0\u00a0\u00a0The Management Board shall deliver an opinion on the Agency\u2019s final accounts.<\/p>\n<p class=\"normal\">7.\u00a0\u00a0\u00a0The Executive Director shall, by 1 July of year N +\u00a01, transmit the final accounts, including the report on the budgetary and financial management for that financial year and the Court of Auditor\u2019s observations, to the European Parliament, the Council, the Commission and the Court of Auditors, together with the Management Board\u2019s opinion.<\/p>\n<p class=\"normal\">8.\u00a0\u00a0\u00a0The Executive Director shall publish the final accounts.<\/p>\n<p class=\"normal\">9.\u00a0\u00a0\u00a0The Executive Director shall send the Court of Auditors a reply to its observations by 30 September of year N +\u00a01 and shall also send to the Management Board a copy of that reply.<\/p>\n<p class=\"normal\">10.\u00a0\u00a0\u00a0The Executive Director shall submit to the European Parliament, at the latter\u2019s request, all the information necessary for the smooth application of the discharge procedure for the financial year in question, as laid down in Article 165(3) of the Financial Regulation.<\/p>\n<p class=\"normal\">11.\u00a0\u00a0\u00a0The European Parliament, acting on a recommendation from the Council, shall, before 15 May of year N +\u00a02, give a discharge to the Executive Director in respect of the implementation of the budget for the year N.<\/p>\n<p id=\"d1e1634-41-1\" class=\"ti-section-1\" style=\"text-align: center;\">SECTION 5<\/p>\n<p id=\"L_2013165EN.01004101-d-005\" class=\"ti-section-2\" style=\"text-align: center;\"><span class=\"bold\">STAFF<\/span><\/p>\n<p id=\"d1e1642-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 22<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">General provisions<\/p>\n<p class=\"normal\">The Staff Regulations and the Conditions of Employment of Other Servants and the rules adopted by agreement between the Union institutions for giving effect to those Staff Regulations shall apply to the staff of the Agency.<\/p>\n<p id=\"d1e1649-41-1\" class=\"ti-art\">Article 23<\/p>\n<p class=\"sti-art\">Privileges and immunity<\/p>\n<p class=\"normal\">Protocol No\u00a07 on the Privileges and Immunities of the European Union annexed to the Treaty on European Union and to the TFEU shall apply to the Agency and its staff.<\/p>\n<p id=\"d1e1656-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 24<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Executive Director<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Executive Director shall be engaged as a temporary agent of the Agency under Article 2(a) of the Conditions of Employment of Other Servants.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Executive Director shall be appointed by the Management Board from a list of candidates proposed by the Commission, following an open and transparent selection procedure.<\/p>\n<p class=\"normal\">For the purpose of concluding the contract of the Executive Director, the Agency shall be represented by the Chairperson of the Management Board.<\/p>\n<p class=\"normal\">Before appointment, the candidate selected by the Management Board shall be invited to make a statement before the relevant committee of the European Parliament and to answer Members\u2019 questions.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The term of office of the Executive Director shall be five years. By the end of that period, the Commission shall undertake an assessment which takes into account the evaluation of the performance of the Executive Director and the Agency\u2019s future tasks and challenges.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0The Management Board may, acting on a proposal from the Commission which takes into account the assessment referred to in paragraph 3 and after obtaining the views of the European Parliament, extend once the term of office of the Executive Director for no more than five years.<\/p>\n<p class=\"normal\">5.\u00a0\u00a0\u00a0The Management Board shall inform the European Parliament about its intention to extend the Executive Director\u2019s term of office. Within three months before any such extension, the Executive Director shall, if invited, make a statement before the relevant committee of the European Parliament and answer Members\u2019 questions.<\/p>\n<p class=\"normal\">6.\u00a0\u00a0\u00a0An Executive Director whose term of office has been extended may not participate in another selection procedure for the same post.<\/p>\n<p class=\"normal\">7.\u00a0\u00a0\u00a0The Executive Director may be removed from office only by decision of the Management Board.<\/p>\n<p id=\"d1e1700-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 25<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Seconded national experts and other staff<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Agency may make use of seconded national experts or other staff not employed by the Agency. The Staff Regulations and the Conditions of Employment of Other Servants shall not apply to such staff.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Management Board shall adopt a decision laying down rules on the secondment to the agency of national experts.<\/p>\n<p id=\"d1e1716-41-1\" class=\"ti-section-1\" style=\"text-align: center;\">SECTION 6<\/p>\n<p id=\"L_2013165EN.01004101-d-006\" class=\"ti-section-2\" style=\"text-align: center;\"><span class=\"bold\">GENERAL PROVISIONS<\/span><\/p>\n<p id=\"d1e1724-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 26<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Legal status<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Agency shall be a body of the Union. It shall have legal personality.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0In each of the Member States the Agency shall enjoy the most extensive legal capacity accorded to legal persons under their laws. It may, in particular, acquire and dispose of movable and immovable property and be a party to legal proceedings.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Agency shall be represented by its Executive Director.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0A branch office established in the metropolitan area of Athens shall be maintained in order to improve the operational efficiency of the Agency.<\/p>\n<p id=\"d1e1749-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 27<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Liability<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The contractual liability of the Agency shall be governed by the law applicable to the contract in question.<\/p>\n<p class=\"normal\">The Court of Justice of the European Union shall have jurisdiction to give judgment pursuant to any arbitration clause contained in a contract concluded by the Agency.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0In the case of non-contractual liability, the Agency shall, in accordance with the general principles common to the laws of the Member States, make good any damage caused by it or its servants in the performance of their duties.<\/p>\n<p class=\"normal\">The Court of Justice of the European Union shall have jurisdiction in any dispute relating to compensation for such damage.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The personal liability of its servants towards the Agency shall be governed by the relevant conditions applying to the staff of the Agency.<\/p>\n<p id=\"d1e1773-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 28<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Languages<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0Regulation No\u00a01 of 15 April 1958 determining the languages to be used in the European Economic Community\u00a0(<span class=\"super\">23<\/span>) shall apply to the Agency. The Member States and the other bodies appointed by them may address the Agency and receive a reply in the official language of the institutions of the Union of their choice.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The translation services required for the functioning of the Agency shall be provided by the Translation Centre for the Bodies of the European Union.<\/p>\n<p id=\"d1e1797-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 29<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Protection of personal data<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0When processing data relating to individuals, in particular while performing its tasks, the Agency shall observe the principles of personal data protection in, and be subject to, the provisions of Regulation (EC) No\u00a045\/2001.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Management Board shall adopt implementing measures referred to in Article 24(8) of Regulation (EC) No\u00a045\/2001. The Management Board may adopt additional measures necessary for the application of Regulation (EC) No\u00a045\/2001 by the Agency.<\/p>\n<p id=\"d1e1812-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 30<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Participation of third countries<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0The Agency shall be open to the participation of third countries which have concluded agreements with the European Union by virtue of which they have adopted and applied Union legal acts in the field covered by this Regulation.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0Arrangements shall be made under the relevant provisions of those agreements, specifying in particular the nature, extent and manner in which those countries will participate in the Agency\u2019s work, including provisions relating to participation in the initiatives undertaken by the Agency, financial contributions and staff.<\/p>\n<p id=\"d1e1827-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 31<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Security Rules on the protection of classified information<\/p>\n<p class=\"normal\">The Agency shall apply the security principles contained in the Commission\u2019s security rules for protecting European Union Classified Information (EUCI) and sensitive non-classified information, as set out in the Annex to Decision 2001\/844\/EC, ECSC, Euratom. This shall cover, inter alia, provisions for the exchange, processing and storage of such information.<\/p>\n<p id=\"d1e1835-41-1\" class=\"ti-section-1\" style=\"text-align: center;\">SECTION 7<\/p>\n<p id=\"L_2013165EN.01004101-d-007\" class=\"ti-section-2\" style=\"text-align: center;\"><span class=\"bold\">FINAL PROVISIONS<\/span><\/p>\n<p id=\"d1e1843-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 32<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Evaluation and review<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0By 20 June 2018 the Commission shall commission an evaluation to assess, in particular, the impact, effectiveness and efficiency of the Agency and its working practices. The evaluation shall also address the possible need to modify the mandate of the Agency and the financial implications of any such modification.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The evaluation referred to in paragraph 1 shall take into account any feedback made to the Agency in response to its activities.<\/p>\n<p class=\"normal\">3.\u00a0\u00a0\u00a0The Commission shall forward the evaluation report together with its conclusions to the European Parliament, the Council and the Management Board. The findings of the evaluation shall be made public.<\/p>\n<p class=\"normal\">4.\u00a0\u00a0\u00a0As part of the evaluation, there shall also be an assessment of the results achieved by the Agency, having regard to its objectives, mandate and tasks. If the Commission considers that the continuation of the Agency is justified with regard to its assigned objectives, mandate and tasks, it may propose that the duration of the mandate of the Agency set out in Article 36 be extended.<\/p>\n<p id=\"d1e1871-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 33<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Cooperation of the host Member State<\/p>\n<p class=\"normal\">The Agency\u2019s host Member State shall provide the best possible conditions to ensure the proper functioning of the Agency, including the accessibility of the location, the existence of adequate education facilities for the children of staff members, appropriate access to the labour market, social security and medical care for both children and spouses.<\/p>\n<p id=\"d1e1878-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 34<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Administrative control<\/p>\n<p class=\"normal\">The operations of the Agency shall be supervised by the Ombudsman in accordance with Article 228 TFEU.<\/p>\n<p id=\"d1e1885-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 35<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Repeal and succession<\/p>\n<p class=\"normal\">1.\u00a0\u00a0\u00a0Regulation (EC) No\u00a0460\/2004 is repealed.<\/p>\n<p class=\"normal\">References to Regulation (EC) No\u00a0460\/2004 and to ENISA shall be construed as references to this Regulation and to the Agency.<\/p>\n<p class=\"normal\">2.\u00a0\u00a0\u00a0The Agency succeeds the Agency that was established by Regulation (EC) No\u00a0460\/2004 as regards all ownership, agreements, legal obligations, employment contracts, financial commitments and liabilities.<\/p>\n<p id=\"d1e1902-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 36<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Duration<\/p>\n<p class=\"normal\">The Agency shall be established for a period of seven years from 19 June 2013.<\/p>\n<p id=\"d1e1912-41-1\" class=\"ti-art\" style=\"text-align: center;\">Article 37<\/p>\n<p class=\"sti-art\" style=\"text-align: center;\">Entry into force<\/p>\n<p class=\"normal\">This Regulation shall enter into force on the day following that of its publication in the <span class=\"italic\">Official Journal of the European Union<\/span>.<\/p>\n<div class=\"final\">\n<p class=\"normal\">This Regulation shall be binding in its entirety and directly applicable in all Member States.<\/p>\n<p class=\"normal\">Done at Strasbourg, 21 May 2013.<\/p>\n<div class=\"signatory\">\n<p class=\"signatory\"><span class=\"italic\">For the European Parliament<\/span><\/p>\n<p class=\"signatory\"><span class=\"italic\">The President<\/span><\/p>\n<p class=\"signatory\">M. SCHULZ<\/p>\n<\/div>\n<div class=\"signatory\">\n<p class=\"signatory\"><span class=\"italic\">For the Council<\/span><\/p>\n<p class=\"signatory\"><span class=\"italic\">The President<\/span><\/p>\n<p class=\"signatory\">L. CREIGHTON<\/p>\n<\/div>\n<\/div>\n<hr class=\"note\" \/>\n<p class=\"note\">(<span class=\"super\">1<\/span>)\u00a0\u00a0OJ C 107, 6.4.2011, p. 58.<\/p>\n<p class=\"note\">(<span class=\"super\">2<\/span>)\u00a0\u00a0Position of the European Parliament of 16 April 2013 (not yet published in the Official Journal) and decision of the Council of 13 May 2013.<\/p>\n<p class=\"note\">(<span class=\"super\">3<\/span>)\u00a0\u00a0Decision 2004\/97\/EC, Euratom taken by common agreement between the Representatives of the Member States, meeting at Head of State or Government level, of 13 December 2003 on the location of the seats of certain offices and agencies of the European Union (OJ L 29, 3.2.2004, p. 15).<\/p>\n<p class=\"note\">(<span class=\"super\">4<\/span>)\u00a0\u00a0Regulation (EC) No\u00a0460\/2004 of the European Parliament and of the Council of 10 March 2004 establishing the European Network and Information Security Agency (OJ L 77, 13.3.2004, p. 1).<\/p>\n<p class=\"note\">(<span class=\"super\">5<\/span>)\u00a0\u00a0Regulation (EC) No\u00a01007\/2008 of the European Parliament and of the Council of 24 September 2008 amending Regulation (EC) No\u00a0460\/2004 establishing the European Network and Information Security Agency as regards its duration (OJ L 293, 31.10.2008, p. 1).<\/p>\n<p class=\"note\">(<span class=\"super\">6<\/span>)\u00a0\u00a0Regulation (EU) No\u00a0580\/2011 of the European Parliament and of the Council of 8 June 2011 amending Regulation (EC) No\u00a0460\/2004 establishing the European Network and Information Security Agency as regards its duration (OJ L 165, 24.6.2011, p. 3).<\/p>\n<p class=\"note\">(<span class=\"super\">7<\/span>)\u00a0\u00a0OJ L 108, 24.4.2002, p. 33.<\/p>\n<p class=\"note\">(<span class=\"super\">8<\/span>)\u00a0\u00a0OJ L 201, 31.7.2002, p. 37.<\/p>\n<p class=\"note\">(<span class=\"super\">9<\/span>)\u00a0\u00a0OJ L 281, 23.11.1995, p. 31.<\/p>\n<p class=\"note\">(<span class=\"super\">10<\/span>)\u00a0\u00a0OJ L 108, 24.4.2002, p. 51.<\/p>\n<p class=\"note\">(<span class=\"super\">11<\/span>)\u00a0\u00a0Regulation (EC) No\u00a01211\/2009 of the European Parliament and of the Council of 25 November 2009 establishing the Body of European Regulators for Electronic Communications (BEREC) and the Office (OJ L 337, 18.12.2009, p. 1).<\/p>\n<p class=\"note\">(<span class=\"super\">12<\/span>)\u00a0\u00a0Directive 98\/34\/EC of the European Parliament and of the Council of 22 June 1998 laying down a procedure for the provision of information in the field of technical standards and regulations and of rules on Information Society services (OJ L 204, 21.7.1998, p. 37).<\/p>\n<p class=\"note\">(<span class=\"super\">13<\/span>)\u00a0\u00a0Regulation (EU, Euratom) No\u00a0966\/2012 of the European Parliament and of the Council of 25 October 2012 on the financial rules applicable to the general budget of the Union and repealing Council Regulation (EC, Euratom) No\u00a01605\/2002 (OJ L 298, 26.10.2012, p. 1).<\/p>\n<p class=\"note\">(<span class=\"super\">14<\/span>)\u00a0\u00a0Regulation (EC) No\u00a01049\/2001 of the European Parliament and of the Council of 30 May 2001 regarding public access to European Parliament, Council and Commission documents (OJ L 145, 31.5.2001, p. 43).<\/p>\n<p class=\"note\">(<span class=\"super\">15<\/span>)\u00a0\u00a0OJ L 8, 12.1.2001, p. 1.<\/p>\n<p class=\"note\">(<span class=\"super\">16<\/span>)\u00a0\u00a0OJ C 101, 1.4.2011, p. 20.<\/p>\n<p class=\"note\">(<span class=\"super\">17<\/span>)\u00a0\u00a0OJ L 56, 4.3.1968, p. 1.<\/p>\n<p class=\"note\">(<span class=\"super\">18<\/span>)\u00a0\u00a0OJ L 357, 31.12.2002, p. 72.<\/p>\n<p class=\"note\">(<span class=\"super\">19<\/span>)\u00a0\u00a0OJ L 317, 3.12.2001, p. 1.<\/p>\n<p class=\"note\">(<span class=\"super\">20<\/span>)\u00a0\u00a0Regulation (EC) No\u00a01073\/1999 of the European Parliament and of the Council of 25 May 1999 concerning investigations conducted by the European Anti-Fraud Office (OLAF) (OJ L 136, 31.5.1999, p. 1).<\/p>\n<p class=\"note\">(<span class=\"super\">21<\/span>)\u00a0\u00a0Interinstitutional Agreement of 25 May 1999 between the European Parliament, the Council of the European Union and the Commission of the European Communities concerning internal investigations by the European Anti-fraud Office (OLAF) (OJ L 136, 31.5.1999, p. 15).<\/p>\n<p class=\"note\">(<span class=\"super\">22<\/span>)\u00a0\u00a0OJ L 292, 15.11.1996, p. 2.<\/p>\n<p class=\"note\">(<span class=\"super\">23<\/span>)\u00a0\u00a0OJ 17, 6.10.1958, p. 385\/58.<\/p>\n<hr class=\"doc-end\" \/>\n<\/div>\n<div class=\"social-share-buttons\"><a href=\"https:\/\/www.facebook.com\/sharer\/sharer.php?u=https:\/\/laweuro.com\/?p=4835\" target=\"_blank\" rel=\"noopener\">Facebook<\/a><a href=\"https:\/\/twitter.com\/intent\/tweet?url=https:\/\/laweuro.com\/?p=4835&text=Regulation+%28EU%29+No+526%2F2013+of+the+European+Parliament+and+of+the+Council+of+21+May+2013+concerning+the+European+Union+Agency+for+Network+and+Information+Security+%28ENISA%29+and+repealing+Regulation+%28EC%29+No+460%2F2004+Text+with+EEA+relevance\" target=\"_blank\" rel=\"noopener\">Twitter<\/a><a href=\"https:\/\/www.linkedin.com\/shareArticle?url=https:\/\/laweuro.com\/?p=4835&title=Regulation+%28EU%29+No+526%2F2013+of+the+European+Parliament+and+of+the+Council+of+21+May+2013+concerning+the+European+Union+Agency+for+Network+and+Information+Security+%28ENISA%29+and+repealing+Regulation+%28EC%29+No+460%2F2004+Text+with+EEA+relevance\" target=\"_blank\" rel=\"noopener\">LinkedIn<\/a><a href=\"https:\/\/pinterest.com\/pin\/create\/button\/?url=https:\/\/laweuro.com\/?p=4835&description=Regulation+%28EU%29+No+526%2F2013+of+the+European+Parliament+and+of+the+Council+of+21+May+2013+concerning+the+European+Union+Agency+for+Network+and+Information+Security+%28ENISA%29+and+repealing+Regulation+%28EC%29+No+460%2F2004+Text+with+EEA+relevance\" target=\"_blank\" rel=\"noopener\">Pinterest<\/a><\/div>","protected":false},"excerpt":{"rendered":"<p>18.6.2013 EN Official Journal of the European Union L 165\/41 REGULATION (EU) No 526\/2013 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 21 May 2013 concerning the European Union Agency for Network and Information Security (ENISA) and repealing Regulation&hellip;<\/p>\n<p class=\"more-link-p\"><a class=\"more-link\" href=\"https:\/\/laweuro.com\/?p=4835\">Read more &rarr;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-4835","post","type-post","status-publish","format-standard","hentry","category-eu-law"],"_links":{"self":[{"href":"https:\/\/laweuro.com\/index.php?rest_route=\/wp\/v2\/posts\/4835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/laweuro.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/laweuro.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/laweuro.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/laweuro.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4835"}],"version-history":[{"count":2,"href":"https:\/\/laweuro.com\/index.php?rest_route=\/wp\/v2\/posts\/4835\/revisions"}],"predecessor-version":[{"id":4844,"href":"https:\/\/laweuro.com\/index.php?rest_route=\/wp\/v2\/posts\/4835\/revisions\/4844"}],"wp:attachment":[{"href":"https:\/\/laweuro.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/laweuro.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/laweuro.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}