The Council took note of the state of play regarding a draft directive aimed at ensuring a high common level of security of electronic communication networks and information systems across the EU.
Although all delegations fully acknowledge the need for action to combat cyber attacks, views differ on the best way to ensure network security throughout the EU:
As regards more detailed provisions, further discussion is needed on a number of questions, such as:
NIS strategy and NIS competent body: delegations acknowledge that a substantial disruption in one Member State can also affect other Member States and could support the principle of a coordinating entity at national level. However, in particular those Member States, which already adopted NIS strategies, designated competent bodies and set up a national computer emergency response teams (CERT), seem to critically look at chapter II of the proposal, which deals with the national framework on NIS: they wish to make sure that the requirements that will have to be met by Member States are consistent with and do not go beyond the current national practice.
Other delegations seek further clarification about the terminology used in this chapter, such as 'risks' and 'threats' and wonder what the exact requirements are and also question whether these requirements should only concern the private sector or also the public sector.
Competent authority and its task description: many issues require further clarification, such as whether the authority should assume operational tasks, which is something many Member States object to, and what should be the division of responsibilities with the national CERT.
Risk management and incident notification: many delegations:
There are also concerns with regard to the implications of notifications on matters of privacy and confidentiality of information.
Cooperation network: further discussion will be needed on the tasks of the cooperation network although many delegations are of the opinion that it should not assume any operational tasks; some argue in this respect that it would be better to refer to a mechanism rather than to a network.
A number of organisational issues also require further clarification, such as:
According to the Presidency, the main challenge will be to agree on an approach, which strikes the right balance between EU-wide binding rules and optional, voluntary measures, all of which should lead to similar levels of NIS preparedness among the Member States and allow the EU to respond effectively to NIS challenges.