Про основні засади заб... | on October 5, 2017 № 2163-VIII (Print version)
24/09/2022, 01:03
4) communication systems that do not interact with public electronic communication networks
(electronic public networks), are not connected to the internet and/or other global data transmission
networks (other than technological systems).
2. The application of cybersecurity legislation and decision-making by authorities pursuant to the
norms of the Law shall be carried out in compliance with the principles of:
1) minimum necessary regulation, according to which the decisions (measures) of the subjects of
power must be necessary and minimally sufficient to achieve the purpose and objectives defined in
this Law;
2) objectivity and legal certainty, applying national and international law as much as possible to
the powers and responsibilities of state bodies, enterprises, institutions, organisations and citizens in
the field of cybersecurity;
3) ensuring protection of the rights of users of communications systems and/or consumers of
electronic communications services and/or information protection services, cyber defence, including
rights of non-interference in private life and protection of personal data;
4) transparency, according to which decisions (measures) of the subjects of power must be duly
justified and notified to the subjects concerned before they come into force (their application);
5) balancing requirements and liability, according to which there should be a balance between
imposing liability for failure to meet cybersecurity and cyber defence requirements and imposing
excessive requirements and restrictions;
6) non-discrimination, according to which the decisions, actions and omissions of subjects of
power cannot result in the legal or factual scope of the rights and obligations of the person who is:
different from the scope of the rights and obligations of others in similar situations, unless such a
difference is necessary and minimally sufficient to satisfy the general public interest;
as well as the scope of rights and obligations of others in dissimilar situations, unless such
equality is necessary and minimally sufficient to satisfy the general public interest;
7) equivalence of cybersecurity requirements for critical infrastructure facilities, according to
which the application of legal provisions should be as equivalent as possible concerning the cyber
defence of communications and technology systems of critical infrastructure facilities belonging to the
same economic sector and/or performing similar functions.
The above principles shall apply without prejudice to any of them, taking into account the
purpose and objectives of this Law.
Article 3. Legal basis for cybersecurity of Ukraine
1. The legal basis for cybersecurity of Ukraine is constituted by the Constitution of Ukraine, laws
of Ukraine regarding the foundations of national security, the foundations of domestic and foreign
policy, electronic communications, protection of state information resources and information whose
protection is required by law, this and other laws of Ukraine, the Convention on Cybercrime, other
international treaties ratified by the Verkhovna Rada of Ukraine, decrees of the President of Ukraine,
acts of the Cabinet of Ministers of Ukraine, as well as other legal acts adopted according to the laws of
Ukraine.
2. If an international treaty of Ukraine ratified by the Verkhovna Rada of Ukraine, provides for
rules other than those established by this Law, the provisions of the international treaty of Ukraine
shall apply.
Article 4. Objects of cybersecurity and cyber defence
1. The objects of cybersecurity are:
1) constitutional human and citizen rights and freedoms;
2) society, the sustainable development of the information society and the digital communication
environment;
3) the state, its constitutional order, sovereignty, territorial integrity and inviolability;
4) national interests in all spheres of life of the individual, society and state;
5) critical infrastructure facilities.
2. The objects of cyber defence are:
1) communication systems of all forms of ownership that process national information resources
and/or are used in the interests of government authorities, local governments, law enforcement
agencies and military formations formed under the law;
2) critical information infrastructure facilities;
3) communication systems that are used to meet public needs and/or implement legal relations in
the areas of e-government, e-government services, e-commerce, e-document management.
3. The procedure for forming the list of facilities of critical information infrastructure, the list of
such facilities and the procedure for including them in the state register of critical information
https://zakon.rada.gov.ua/laws/show/en/2163-19/print
Page 3 of 12