CADA tracker · source extraction
(50)
To protect public order, it is therefore necessary to specify the conditions that Union
and Member States’ contracting authorities should use in public procurement
procedures of cloud computing services. The consideration of possible exposure to
risk is fundamental when selecting appropriate mitigation measures to preserve the
public order of the Union and Member States. The Union and Member States being
critically dependent on a limited number of cloud computing service providers subject
to the control of a third country or a legal entity established in a third-country may
lead to risks such as misuse (i.e. manipulation, remote access and control, sabotage,
weaponisation), access to information (i.e. access to sensitive information,
unauthorised communication, technology leakage, data manipulation or exfiltration,
espionage) and dependency vulnerabilities (i.e. political and/or economic coercion, for
example by using vendor or technology lock-ins, embargos or sanctions, monopoly
pricing damaging the financial interest of the Union and Member States).