EDPS Guidelines on controllers, processors and joint controllers

On 7 November 2019 the European Data Protection Supervisor published their guidelines on the concepts of controller, processor and joint controllership. While the EDPS is the supervising authority for EUI (European Union Institutions), whose data protection activities fall under Regulation 2018/1725 and not the GDPR, the document is of importance… Continue reading

EU Strategy on Artificial Intelligence

The European Commission published on April 25 2018 a Communication outlining the strategy of the EU for Artificial Intelligence. This post looks at the document, its structure and main points. While the first two chapters deal with a general introduction an AI scenarios and Europe’s competitive posture in the international… Continue reading

The European Court Strikes One for Privacy

Early this year the European Court of Justice declared the 2006 EU Date Retention Directive invalid. This is a very important turning point in the ongoing tug-of-war between privacy rights and security concerns, possibly a reversal of the tide that has been mounting since the beginning of the century. The… Continue reading

The (cyber) cop mentality

Last week (14-15 October 2014) I was in Brussels taking part in the ISSE 2014 information security conference, where I had also the opportunity to present a paper on the European Court of Justice’s repealing of the Data Retention Directive. Among the keynote speakers was Troels Ørting, head of EC3,… Continue reading

ISACA Venice paper on Critical Infrastructures

ISACA Venice Chapter just published its 5th paper, “National Cybersecurity, Awareness in Critical Industries in North East Italy”. I am a co-author, with Luca Moroni (coordinator) and Giuseppe Esposito. The paper sketches the general scenario on Critical Infrastructure Protection, supplies examples and also a practical tool for self-evaluation that can be… Continue reading

Cyber Security 2014 at Chatham House

Last week at Chatham House, the Royal Institute of International Affairs hosted its annual conference on Cyber Security. The theme was “Building Resilience, Reducing Risks” and it brought together a diverse set of speakers in the various panels, ranging from diplomats to public servants, from former military persons to corporate… Continue reading

Critical Infrastructure Protection: a legislation review

In this post I try to trace the evolution of EU legislation regarding Critical Infrastructure Protection, with some special attention to the Italian implementations. In any case the bulk of the regulations and laws in this field finds its origin at the European level. The main motivation behind Critical Infrastructure… Continue reading

EU Directive on Cybercrime ready for Parliament’s first lecture

The directive proposal on cybercrime (attacks against informations systems), and the amendments intrduced by commitees (LIBE in particular), will have its first reading by the Plenary of the European Parliament next July 1st, according to latest forecasts. EDIT: Reading is now scheduled for July 3rd, and the vote for July 4th Continue reading

Activities of the CEN-CENELEC-ETSI cybersecurity coordination group

Origins, motivations The EN-CENELEC-ETSI Cybersecurity Coordination Group was born in the second half of 2011 on an impulse coming from DIN, the German Standardization National Body. A need was felt for better coordination in Information Security standardization and on Cybersecurity in particular. The initial spark was the diffusion of so-called… Continue reading