当前位置:首页 > 报告详情

CSA2.0提案:新的ECCF - 迈卡·福伦巴赫欧盟委员会.pdf

上传人: 自*** 编号:1265448 2026-06-06 8页 763.48KB

1、Cyber Security Act 2(CSA2)Proposal:the New ECCFCNECT 26 January 2026 AdobeStock,Looker_StudioCSA2:Creating European cyber services ecosystemBased on the following pillars:1.Develop a framework for addressing the ICT supply chain security challenges in critical infrastructure.2.Simplify and enhance t

2、he European cybersecurity certification framework.3.Introduce simplification measures to reduce unnecessary administrative burden related to the implementation of the NIS2 Directive.4.Strengthened European Union Agency for Cybersecurity(ENISA)to make it fit for purpose.European Cybersecurity Certifi

3、cation FrameworkEuropean Cybersecurity Certification Framework AdobeStock,loechai Cybersecurity certification increases trust and security in the internal market and facilitating compliance.Certification ICT product,services,processes and managed security services or cyber posture Addressing Technic

4、al risk factors High-risk suppliers and their key ICT assets excluded from certificationClarified and extended scope(1)Certification updated and fully synergised with existing Union law(alignment with the CRA)as a simplification tool to demonstrate compliance with CRA&NIS2 and potentially other lega

5、l acts(organisation cyber posture scheme to enable complified compliance)harmonised across schemes through model provisions(user-friendly reference provisions to harmonise templates across schemes)Certification as Compliance Tool(2)Efficient procedure and effective governance(3)The scheme owner Over

6、sight of the procedure and implementationStrategic planning and requesting of schemesAdoption and review of schemesThe scheme managerThe scheme implementorConsulted in every step of the way(ECCG,Comitology)Certification issuers through NCCAsAccreditations and

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
1. **CSA2核心目标**:建立欧洲网络安全服务生态系统,基于四大支柱:解决ICT供应链安全挑战、简化欧盟网络安全认证框架、减轻NIS2指令行政负担、强化ENISA机构能力。 2. **认证框架升级**:扩展认证范围(覆盖ICT产品、服务、流程),与现有法律(如CRA)协同,作为合规工具简化NIS2等法规遵从。 3. **治理结构优化**:明确“所有者”(欧盟委员会)、“管理者”(ENISA)、“实施者”(成员国)职责,通过高效程序(如90天评审、公共咨询)确保问责。 4. **透明度提升**:新增欧洲网络安全认证 assembly、COM认证网站,强化利益相关方参与及公众咨询机制。
**CSA2新框架?** **认证如何简化?** **ENISA如何强化?**
客服
商务合作
小程序
服务号
折叠