Annexes to COM(2006)251 - A strategy for a Secure Information Society - “Dialogue, partnership and empowerment”

Please note

This page contains a limited version of this dossier in the EU Monitor.

agreements with third countries including the issue of the fight against spam, spyware and malware;
4.Strengthen the involvement of ENISA in supporting the Strategy for a Secure Information Society in Europe, as set out in this Resolution, in line with the objectives and tasks set out in Regulation (EC) No 460/2004 as well as in closer cooperation and tighter working relations with Member States and stakeholders;

5.Develop, within the i2010 framework, in cooperation with Member States and all stakeholders, especially with statistical and Member States' information security experts, appropriate indicators for Community surveys on aspects related to security and trust;

6.Encourage the Member States to examine, via a multi-stakeholder dialogue, the economic, business and societal drivers with the aim of developing an ICT sector-specific policy to enhance the security and resilience of network and information systems, as a potential contribution to the planned European Programme on Critical Infrastructure Protection;

7.Continue its efforts, in coordination with Member States, to promote dialogue with relevant international partners and organisations to foster global cooperation on Network and Information Security, notably by implementing the WSIS Action lines and reporting to the Council on a regular basis;

AND CALLS UPON:

1.ENISA to continue working in close cooperation with the Member States, the Commission and other relevant stakeholders, in order to fulfil those tasks and objectives that are defined in Regulation (EC) No 460/2004 and to assist the Commission and the Member States in their efforts to meet the requirements of network and information security, thus contributing to the implementation and further development of the Strategy for a Secure Information Society in Europe, as set out in this Resolution;

2.All stakeholders to improve the security of software and the security and resilience of network and information systems in line with the Strategy for a Secure Information Society in Europe, as set out in this Resolution, as well as to engage in a structured multi-stakeholder debate on how best to utilise existing tools and regulatory instruments;

3.Enterprises to take a positive attitude towards information and network security in order to create more advanced and secure products and services, considering investments in such products and services as a competitive advantage;

4.Manufacturers and service providers to build, where appropriate, security, privacy and confidentiality requirements into their product- and service design and deployment of network infrastructure, applications and software, implement and monitor security solutions;

5.Stakeholders to cooperate and to launch experimental environments for testing and piloting new technologies and services in a secure manner; stakeholders to adopt in a timely manner the new secure technologies and services after they have been launched commercially;

6.All stakeholders to engage in further efforts to combat spam and other on-line malpractices and to actively cooperate with competent authorities at national and international level;

7.The service providers and the ICT industry to focus on enhancing security, privacy and usability in products, processes and services in order to have reliability, prevent and fight ID theft and other privacy-intrusive attacks;

8.Network operators, service providers and the private sector to share and implement good security practices and to foster a culture of risk analysis and management in organisations and business by supporting appropriate training programmes and developing contingency planning as well as make security solutions available to their customers as part of their services.



(1) OJ C 43, 16.2.2002, p. 2.

(2) OJ C 48, 28.2.2003, p. 1.

(3) Directives 2002/58/EC (Directive on privacy and electronic communications), 2002/20/EC (Authorisation Directive), 2002/22/EC (Universal Service Directive) (OJ L 201, 31.7.2002, p. 37, OJ L 108, 24.4.2002, p. 21 and OJ L 108, 24.4.2002, p. 51, respectively).

(4) OJ L 77, 13.3.2004, p. 1.