CHAPTER 4 MANAGEMENT OF EU CLASSIFIED INFORMATION

Article 21Basic principles

1.All EUCI documents should be managed in compliance with the Commission's policy on document management and consequently should be registered, filed, preserved and finally eliminated, sampled or transferred to the Historical Archives in accordance with the common Commission-level retention list for European Commission files.

2.Information classified CONFIDENTIEL UE/EU CONFIDENTIAL or above shall be registered for security purposes prior to distribution and on receipt. Information classified TRES SECRET UE/EU TOP SECRET shall be registered in designated registries.

3.Within the Commission, a EUCI registry system shall be set up in accordance with the provisions of Article 27.

4.Commission departments and premises where EUCI is handled or stored shall be subject to regular inspection by the Commission Security Authority.

5.EUCI shall be conveyed between services and premises outside physically protected areas as follows:

(a)as a general rule, EUCI shall be transmitted by electronic means protected by cryptographic products approved in accordance with Chapter 5;

(b)when the means referred to in point (a) are not used, EUCI shall be carried either:

(i)

on electronic media (e.g. USB sticks, CDs, hard drives) protected by cryptographic products approved in accordance with Chapter 5; or

(ii)

in all other cases, as prescribed in implementing rules.