COUNCIL DECISION
of 23 September 2013
on the security rules for protecting EU classified information
(2013/488/EU)
Article 1
Purpose, scope and definitions
Article 2
Definition of EUCI, security classifications and markings
Article 3
Classification management
Article 4
Protection of classified information
Article 5
Security risk management
Article 6
Implementation of this Decision
Article 7
Personnel security
Article 8
Physical security
Article 9
Management of classified information
Article 10
Protection of EUCI handled in communication and information systems
Article 11
Industrial security
Article 12
Sharing EUCI
Article 13
Exchange of classified information with third States and international organisations
Article 14
Breaches of security and compromise of EUCI
Article 15
Responsibility for implementation
Article 16
The organisation of security in the Council
Article 17
Security Committee
Article 18
Replacement of previous decision
Article 19
Entry into force
ANNEXES
ANNEX I
ANNEX II
ANNEX III
ANNEX IV
ANNEX V
ANNEX VI
ANNEX I
PERSONNEL SECURITY
I. INTRODUCTION
II. GRANTING ACCESS TO EUCI
III. PERSONNEL SECURITY CLEARANCE REQUIREMENTS
Security investigation criteria
Investigative requirements for access to EUCI
Initial granting of a security clearance
Renewal of a security clearance
Authorisation procedures in the GSC
Records of security clearances and authorisations
Exemptions from the PSC requirement
IV. SECURITY EDUCATION AND AWARENESS
V. EXCEPTIONAL CIRCUMSTANCES
VI. ATTENDANCE AT MEETINGS IN THE COUNCIL
VII. POTENTIAL ACCESS TO EUCI
ANNEX II
PHYSICAL SECURITY
I. INTRODUCTION
II. PHYSICAL SECURITY REQUIREMENTS AND MEASURES
III. EQUIPMENT FOR THE PHYSICAL PROTECTION OF EUCI
IV. PHYSICALLY PROTECTED AREAS
V. PHYSICAL PROTECTIVE MEASURES FOR HANDLING AND STORING EUCI
VI. CONTROL OF KEYS AND COMBINATIONS USED FOR PROTECTING EUCI
ANNEX III
MANAGEMENT OF CLASSIFIED INFORMATION
I. INTRODUCTION
II. CLASSIFICATION MANAGEMENT
Classifications and markings
Markings
Abbreviated classification markings
TRÈS SECRET UE/EU TOP SECRET |
TS-UE/EU-TS |
SECRET UE/EU SECRET |
S-UE/EU-S |
CONFIDENTIEL UE/EU CONFIDENTIAL |
C-UE/EU-C |
RESTREINT UE/EU RESTRICTED |
R-UE/EU-R |
Creation of EUCI
Downgrading and declassification of EUCI
III. REGISTRATION OF EUCI FOR SECURITY PURPOSES
TRÈS SECRET UE/EU TOP SECRET registries
IV. COPYING AND TRANSLATING EU CLASSIFIED DOCUMENTS
V. CARRIAGE OF EUCI
Within a building or self-contained group of buildings
Within the Union
From within the Union to the territory of a third State
VI. DESTRUCTION OF EUCI
VII. ASSESSMENT VISITS
Conduct of assessment visits
Reports
Checklist
ANNEX IV
PROTECTION OF EUCI HANDLED IN CIS
I. INTRODUCTION
II. INFORMATION ASSURANCE PRINCIPLES
Security risk management
Security throughout the CIS life-cycle
Best practice
Defence in depth
Principle of minimality and least privilege
Information Assurance awareness
Evaluation and approval of IT-security products
Transmission within Secured and Administrative Areas
Secure interconnection of CIS
Computer storage media
Emergency circumstances
III. INFORMATION ASSURANCE FUNCTIONS AND AUTHORITIES
Information Assurance Authority
TEMPEST Authority
Crypto Approval Authority
Crypto Distribution Authority
Security Accreditation Authority
Information Assurance Operational Authority
ANNEX V
INDUSTRIAL SECURITY
I. INTRODUCTION
II. SECURITY ELEMENTS IN A CLASSIFIED CONTRACT
Security classification guide (SCG)
Security aspects letter (SAL)
Programme/Project Security Instructions (PSI)
III. FACILITY SECURITY CLEARANCE (FSC)
IV. CLASSIFIED CONTRACTS AND SUB-CONTRACTS
V. VISITS IN CONNECTION WITH CLASSIFIED CONTRACTS
VI. TRANSMISSION AND CARRIAGE OF EUCI
VII. TRANSFER OF EUCI TO CONTRACTORS LOCATED IN THIRD STATES
VIII INFORMATION CLASSIFIED RESTREINT UE/EU RESTRICTED
ANNEX VI
EXCHANGE OF CLASSIFIED INFORMATION WITH THIRD STATES AND INTERNATIONAL ORGANISATIONS
I. INTRODUCTION
II. FRAMEWORKS GOVERNING THE EXCHANGE OF CLASSIFIED INFORMATION
III. SECURITY OF INFORMATION AGREEMENTS
IV. ADMINISTRATIVE ARRANGEMENTS
V. EXCHANGE OF CLASSIFIED INFORMATION IN THE CONTEXT OF CSDP OPERATIONS
VI. EXCEPTIONAL AD HOC RELEASE OF EUCI
VII. AUTHORITY TO RELEASE EUCI TO THIRD STATES OR INTERNATIONAL ORGANISATIONS
Appendices
Appendix A
Appendix B
Appendix C
Appendix D
Appendix A
DEFINITIONS
Appendix B
EQUIVALENCE OF SECURITY CLASSIFICATIONS
EU |
TRÈS SECRET UE/EU TOP SECRET |
SECRET UE/EU SECRET |
CONFIDENTIEL UE/EU CONFIDENTIAL |
RESTREINT UE/EU RESTRICTED |
Belgium |
Très Secret (Loi 11.12.1998) Zeer Geheim (Wet 11.12.1998) |
Secret (Loi 11.12.1998) Geheim (Wet 11.12.1998) |
Confidentiel (Loi 11.12.1998) Vertrouwelijk (Wet 11.12.1998) |
nota(1) below |
Bulgaria |
Cтpoгo ceкретно |
Ceкретно |
Поверително |
За служебно ползване |
Czech Republic |
Přísně tajné |
Tajné |
Důvěrné |
Vyhrazené |
Denmark |
YDERST HEMMELIGT |
HEMMELIGT |
FORTROLIGT |
TIL TJENESTEBRUG |
Germany |
STRENG GEHEIM |
GEHEIM |
VS(2)— VERTRAULICH |
VS — NUR FÜR DEN DIENSTGEBRAUCH |
Estonia |
Täiesti salajane |
Salajane |
Konfidentsiaalne |
Piiratud |
Ireland |
Top Secret |
Secret |
Confidential |
Restricted |
Greece |
Άκρως Απόρρητο Abr: ΑΑΠ |
Απόρρητο Abr: (ΑΠ) |
Εμπιστευτικό Αbr: (ΕΜ) |
Περιορισμένης Χρήσης Abr: (ΠΧ) |
Spain |
SECRETO |
RESERVADO |
CONFIDENCIAL |
DIFUSIÓN LIMITADA |
France |
Très Secret Défense |
Secret Défense |
Confidentiel Défense |
nota(3) below |
Croatia |
VRLO TAJNO |
TAJNO |
POVJERLJIVO |
OGRANIČENO |
Italy |
Segretissimo |
Segreto |
Riservatissimo |
Riservato |
Cyprus |
Άκρως Απόρρητο Αbr: (ΑΑΠ) |
Απόρρητο Αbr: (ΑΠ) |
Εμπιστευτικό Αbr: (ΕΜ) |
Περιορισμένης Χρήσης Αbr: (ΠΧ) |
Latvia |
Sevišķi slepeni |
Slepeni |
Konfidenciāli |
Dienesta vajadzībām |
Lithuania |
Visiškai slaptai |
Slaptai |
Konfidencialiai |
Riboto naudojimo |
Luxembourg |
Très Secret Lux |
Secret Lux |
Confidentiel Lux |
Restreint Lux |
Hungary |
Szigorúan titkos! |
Titkos! |
Bizalmas! |
Korlátozott terjesztésű! |
Malta |
L-Ogħla Segretezza Top Secret |
Sigriet Secret |
Kunfidenzjali Confidential |
Ristrett Restricted(4) |
Netherlands |
Stg. ZEER GEHEIM |
Stg. GEHEIM |
Stg. CONFIDENTIEEL |
Dep. VERTROUWELIJK |
Austria |
Streng Geheim |
Geheim |
Vertraulich |
Eingeschränkt |
Poland |
Ściśle Tajne |
Tajne |
Poufne |
Zastrzeżone |
Portugal |
Muito Secreto |
Secreto |
Confidencial |
Reservado |
Romania |
Strict secret de importanță deosebită |
Strict secret |
Secret |
Secret de serviciu |
Slovenia |
STROGO TAJNO |
TAJNO |
ZAUPNO |
INTERNO |
Slovakia |
Prísne tajné |
Tajné |
Dôverné |
Vyhradené |
Finland |
ERITTÄIN SALAINEN YTTERST HEMLIG |
SALAINEN HEMLIG |
LUOTTAMUKSELLINEN KONFIDENTIELL |
KÄYTTÖ RAJOITETTU BEGRÄNSAD TILLGÅNG |
Sweden(5) |
HEMLIG/TOP SECRET HEMLIG AV SYNNERLIG BETYDELSE FÖR RIKETS SÄKERHET |
HEMLIG/SECRET HEMLIG |
HEMLIG/CONFIDENTIAL HEMLIG |
HEMLIG/RESTRICTED HEMLIG |
United Kingdom |
UK TOP SECRET |
UK SECRET |
UK CONFIDENTIAL |
UK RESTRICTED |
Appendix C
LIST OF NATIONAL SECURITY AUTHORITIES (NSAs)
BELGIUM
|
ESTONIA
|
||||||||||||||||||||||||
BULGARIA
|
IRELAND
|
||||||||||||||||||||||||
CZECH REPUBLIC
|
GREECE
|
||||||||||||||||||||||||
DENMARK
|
SPAIN
|
||||||||||||||||||||||||
GERMANY
|
FRANCE
|
||||||||||||||||||||||||
CROATIA
|
LUXEMBOURG
|
||||||||||||||||||||||||
ITALY
|
HUNGARY
|
||||||||||||||||||||||||
CYPRUS
|
MALTA
|
||||||||||||||||||||||||
LATVIA
|
NETHERLANDS
|
||||||||||||||||||||||||
LITHUANIA
|
AUSTRIA
|
||||||||||||||||||||||||
POLAND
|
SLOVAKIA
|
||||||||||||||||||||||||
PORTUGAL
|
FINLAND
|
||||||||||||||||||||||||
ROMANIA
|
SWEDEN
|
||||||||||||||||||||||||
SLOVENIA
|
UNITED KINGDOM
|
Appendix D
Acronym |
Meaning |
AQUA |
Appropriately Qualified Authority |
BPS |
Boundary Protection Services |
CAA |
Crypto Approval Authority |
CCTV |
Closed Circuit Television |
CDA |
Crypto Distribution Authority |
CFSP |
Common Foreign and Security Policy |
CIS |
Communication and Information Systems handling EUCI |
Coreper |
Committee of Permanent Representatives |
CSDP |
Common Security and Defence Policy |
DSA |
Designated Security Authority |
ECSD |
European Commission Security Directorate |
EUCI |
EU Classified Information |
EUSR |
EU Special Representative |
FSC |
Facility Security Clearance |
GSC |
General Secretariat of the Council |
IA |
Information Assurance |
IAA |
Information Assurance Authority |
IDS |
Intrusion Detection System |
IT |
Information Technology |
NSA |
National Security Authority |
PSC |
Personnel Security Clearance |
PSCC |
Personnel Security Clearance Certificate |
PSI |
Programme/Project Security Instructions |
SAA |
Security Accreditation Authority |
SAB |
Security Accreditation Board |
SAL |
Security Aspects Letter |
SecOPs |
Security Operating Procedures |
SCG |
Security Classification Guide |
SSRS |
System-Specific Security Requirement Statement |
TA |
TEMPEST Authority |