lexiara

Recital 71

AMLA

(71) As stated in the Communication of the Commission of 7 February 2013 entitled ‘Cybersecurity Strategy of the European Union: An Open, Safe and Secure Cyberspace’, it is essential to ensure a high level of cyber resilience in all Union institutions, bodies, offices and agencies due to the increasingly hostile threat environment. The Executive Director should thus ensure appropriate IT risk management, a strong internal IT governance and sufficient IT security funding. As a rule, at least 10 % of the Authority’s IT expenditure should be transparently allocated to direct IT security. The contribution to the Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU) could be counted in that minimum expenditure requirement. The Authority should work closely with CERT-EU and report major incidents within 24 hours to CERT-EU as well as to the Commission.

· All articles ·

Source: EUR-Lex CELLAR · retrieved 2026-09-04 · Text as adopted (Official Journal); later amendments are not incorporated in this text.