COMMISSION OF THE EUROPEAN COMMUNITIES DIRECTORATE GENERAL XIII: Telecommunications, Information Market and Exploitation of Research DIRECTORATE B: Advanced Communications Technologies and Services Brussels, 5 November, 1993 RPOH/d:sm/windows/RA934349 The Director Dear Contributor, Interested Party, Subj.: Green Book on the Security of Information Systems Conc.: Consultation The Council adopted in March 1992 a Decision in the field of the security of information systems and the setting up of a Senior Officials Group (SOG-IS) to advise the Commission on action to be undertaken. The Decision defines an action plan having as an objective the development of overall strategies aiming to provide users and providers of electronically stored, processed or transmitted information with appropriate protection of information systems against accidental or deliberate attacks. As a step towards the formulation of future activities, as identified in the Council Decision and in accordance with the opinion of SOG-IS, a "Green Book on the Security of Information Systems" is being prepared with the help of leading experts, which addresses an overall view of the issues, discussion on the status and trends, and the requirements and options for action. This document is now available in the form of Draft 4.0. You are invited to: a) comment on the conclusions and recommendations (section "Summary of Requirements for Action") b) identify existing work and activities that could contribute to the implementation of some or all of the recommendations c) formulate suggestions for the implementation of the recommendations d) signal interest to participate in the implementation of the recommendations e) register for the participation in a Workshop which will provide an opportunity for the exchange of views on the recommendations and the ideas put forward to implement them. The Green Book will be avaliable in electronic form (Word for Macintosh and Word for Windows) from o CompuServe in the ECTF forum (GO ECTF or GO RACE) in library INFO SECURITY[12], and from o anonymous FTP ftp.uni-stuttgart.de, login: ftp password: cd /pub/doc/security/green-book-4.0/ Dates: Workshop in Brussels December 15, 1993 Written comments with reference to "INFOSEC Green Book" November 26, 1993 Your registration for the Workshop November 26, 1993 Address for written comments and registration for the workshop: Commission of the European Communities DGXIII/B Office BU9, 5/46 Avenue de Beaulieu 9 B-1060 Brussels E-Mail: rh@postman.dg13.cec.be CompuServe: 100013,1437 Fax: +32 2 296 2980 With best regards, Roland Hüber Address: Rue de la Loi 200, B-1049 Brussels Office Av. de Beaulieu 95/46 B-1160 Brussels Telephone: direct line (+32 2) 296 34 56, central 299 11 11 - Facsimile: (+32 2) 295 06 54 or 296 29 80 Email: Internet address rh@postman.dg13.cec.be CompuServe 100013.1437