Presentation is loading. Please wait.

Presentation is loading. Please wait.

Information Security Systems Cost Effective Authenticity & Integrity in CEN/FISCALIS eInvoicing Good Practice Guidelines Nick Pope – Principal Consultant,

Similar presentations


Presentation on theme: "Information Security Systems Cost Effective Authenticity & Integrity in CEN/FISCALIS eInvoicing Good Practice Guidelines Nick Pope – Principal Consultant,"— Presentation transcript:

1 Information Security Systems Cost Effective Authenticity & Integrity in CEN/FISCALIS eInvoicing Good Practice Guidelines Nick Pope – Principal Consultant, Thales e-Security Ltd OASIS Electronic Invoicing Panel: Confidentiality, Authentication, Reputation >

2 1 < eInvoicing: Cost effective authenticity & Integrity COUNCIL DIRECTIVE 2006/112/EC on VAT Harmonisation Article 233.1 “Invoices sent or made available by electronic means shall be accepted by Member States provided that the authenticity of the origin and the integrity of their content are guaranteed by one of the following methods: (a) by means of an advanced electronic signature…, …(b) by means of electronic data interchange (EDI)… Invoices may, however, be sent or made available by other electronic means, subject to acceptance by the Member States concerned.”

3 2 < eInvoicing: Cost effective authenticity & Integrity Divergence in Application of EU VAT Directive Advanced Electronic Signatures or “Any other means” Advanced Electronic Signatures ‘policy-based PKI’= standardized rules and contracts Qualified Electronic Signatures Advanced Electronic Signatures based on EU hardware and certificate standards LowMediumHigh Estonia Finland Netherlands Romania Sweden United Kingdom Austria Belgium Bulgaria Denmark France Greece (?) Hungary Ireland Luxembourg Portugal Cyprus Czech Republic Germany Italy Latvia Lithuania Poland Romania Slovakia Slovenia Spain (Illustrative only – refer to national legislation)

4 3 < eInvoicing: Cost effective authenticity & Integrity Authenticity & Integrity Basic Approach Authenticity & Integrity Controls  Process based: Emphasis on general procedural and technical controls to protect data at each stage of process (cf. EDI / Other), or  Technology based: Emphasis on protecting data using Advanced electronic signatures from creation through whole storage lifetime

5 4 < eInvoicing: Cost effective authenticity & Integrity Authenticity & Integrity in CEN/FISCALIS eInvoicing Good Practice Guidelines CEN WG3: Cost-effective authenticity and integrity of electronic invoices RisksControlsImplement’n Examples General Invoice Process risks Process controls Procedures & system audits Risks to Invoice Authenticity & Integrity Process based controls Procedures, secure comms, secure storage system Audits Technical based controls Procedures, Digital Signatures

6 5 < eInvoicing: Cost effective authenticity & Integrity Proposed Direction for eInvoicing Harmonisation  Aim towards “technology neutral” approach to VAT legislation (Recommendation of European Electronic Invoicing Expert Group)  Good practice standard  Common technology based solutions within good practice framework  Interoperable signatures alongside interchange formats  Common Trust Architecture (certification authorities)  Acceptance by businesses (cost & reputation)  Acceptance by tax authorities (minimise tax fraud)

7 6 < eInvoicing: Cost effective authenticity & Integrity Thank you CEN / FISCALIS e-Invoicing Good Practice Guidelines http://www.e-invoice-gateway.net/knowledgebase/eInvoiceBestPractice/ Nick Pope – nick.pope@thales-esecurity.com Technical editor Authenticity & Integrity – CEN eInvoicing Workshop Questions & Discussion


Download ppt "Information Security Systems Cost Effective Authenticity & Integrity in CEN/FISCALIS eInvoicing Good Practice Guidelines Nick Pope – Principal Consultant,"

Similar presentations


Ads by Google