All official European Union website addresses are in the europa.eu domain.
This document is an excerpt from the EUR-Lex website
Document 32019R1583
Commission Implementing Regulation (EU) 2019/1583 of 25 September 2019 amending Implementing Regulation (EU) 2015/1998 laying down detailed measures for the implementation of the common basic standards on aviation security, as regards cybersecurity measures (Text with EEA relevance.)
Commission Implementing Regulation (EU) 2019/1583 of 25 September 2019 amending Implementing Regulation (EU) 2015/1998 laying down detailed measures for the implementation of the common basic standards on aviation security, as regards cybersecurity measures (Text with EEA relevance.)
Commission Implementing Regulation (EU) 2019/1583 of 25 September 2019 amending Implementing Regulation (EU) 2015/1998 laying down detailed measures for the implementation of the common basic standards on aviation security, as regards cybersecurity measures (Text with EEA relevance.)
C/2019/6825
OJ L 246, 26.9.2019, p. 15–18
(BG, ES, CS, DA, DE, ET, EL, EN, FR, HR, IT, LV, LT, HU, MT, NL, PL, PT, RO, SK, SL, FI, SV)
In force: This act has been changed. Current consolidated version: 02/07/2020
26.9.2019 |
EN |
Official Journal of the European Union |
L 246/15 |
COMMISSION IMPLEMENTING REGULATION (EU) 2019/1583
of 25 September 2019
amending Implementing Regulation (EU) 2015/1998 laying down detailed measures for the implementation of the common basic standards on aviation security, as regards cybersecurity measures
(Text with EEA relevance)
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EC) No 300/2008 of the European Parliament and of the Council of 11 March 2008 on common rules in the field of civil aviation security and repealing Regulation (EC) No 2320/2002 (1), and in particular Articles 1 and 4(3) thereof,
Whereas:
(1) |
One of the main objectives of Regulation (EC) No 300/2008 is to provide the basis for a common interpretation of Annex 17 (Security Annex) of the Convention on International Civil Aviation (2) of 7 December 1944, 10th edition, 2017 to which all the EU Member States are signatories. |
(2) |
The means of achieving the objectives are (a) the setting of common rules and common basic standards on aviation security and (b) mechanisms for monitoring compliance. |
(3) |
The purpose for amending the implementing legislation is to support Member States in ensuring full compliance with the most recent amendment (Amendment 16) to Annex 17 of the Convention on International Civil Aviation, which introduced new standards under chapters 3.1.4 related to national organisation and appropriate authority and 4.9.1 related to preventive cybersecurity measures. |
(4) |
By transposing these standards into the implementing EU wide aviation security legislation, it will be ensured that appropriate authorities establish and implement procedures to share, as appropriate and in a practical and timely manner, relevant information to assist other national authorities and agencies, airport operators, air carriers and other entities concerned, to conduct effective security risk assessments relating to their operations and in that way support these entities in conducting effective security risk assessments related to, among other areas, cybersecurity and implement measures addressing cyber threats. |
(5) |
Directive (EU) 2016/1148 of the European Parliament and of the Council concerning measures for a high common level of security of network and information systems across the Union (NIS Directive) lays down measures with a view to achieving a high common level of security of network and information systems within the Union (3) so as to improve the functioning of the internal market. Measures stemming from the NIS Directive and this Regulation should be coordinated at national levels to avoid gaps and duplications of obligations. |
(6) |
Commission Implementing Regulation (EU) 2015/1998 (4) should therefore be amended accordingly. |
(7) |
The measures provided for in this Regulation are in accordance with the opinion of the Committee on Civil Aviation Security set up pursuant to Article 19(1) of Regulation (EC) No 300/2008, |
HAS ADOPTED THIS REGULATION:
Article 1
The Annex to Implementing Regulation (EU) 2015/1998 is amended in accordance with the Annex to this Regulation.
Article 2
This Regulation shall enter into force on 31 December 2020.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 25 September 2019.
For the Commission
The President
Jean-Claude JUNCKER
(2) https://icao.int/publications/pages/doc7300.aspx
(3) Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union (OJ L 194, 19.7.2016, p. 1).
(4) Commission Implementing Regulation (EU) 2015/1998 of 5 November 2015 laying down detailed measures for the implementation of the common basic standards on aviation security (OJ L 299, 14.11.2015, p. 1).
ANNEX
The Annex to Implementing Regulation (EU) 2015/1998 is amended as follows:
(1) |
The following point 1.0.6 is added:
|
(2) |
The following point 1.7 is added: ‘1.7 IDENTIFICATION AND PROTECTION OF CIVIL AVIATION CRITICAL INFORMATION AND COMMUNICATION TECHNOLOGY SYSTEMS AND DATA FROM CYBER THREATS
|
(3) |
Point 11.1.2 is replaced by the following:
|
(4) |
The following point 11.2.8 is added: ‘11.2.8. Training of persons with roles and responsibility related to cyber threats
|