Про основні засади заб... | on October 5, 2017 № 2163-VIII (Print version)
24/09/2022, 01:03
such facilities and the procedure for including them in the state register of critical information
infrastructure facilities, as well as the procedure for forming and maintaining the state register of
critical information infrastructure facilities shall be approved by the Cabinet of Ministers of Ukraine.
The National Bank of Ukraine is responsible for the formation and operation of the register of
critical information infrastructure facilities in the banking system of Ukraine.
Article 5. Subjects of cybersecurity
1. Co-ordination of cybersecurity activities as part of Ukraine's national security is carried out by
the President of Ukraine through the National Security and Defense Council of Ukraine headed by
him.
2. The National Coordination Centre for Cybersecurity, as a working body of the National
Security and Defense Council of Ukraine, co-ordinates and monitors the activities of security and
defence sector subjects that provide cybersecurity, submits proposals to the President of Ukraine on
the formation and refinement of the Cybersecurity Strategy of Ukraine.
3. The Cabinet of Ministers of Ukraine ensures the formation and implementation of public policy
in the field of cybersecurity, the protection of human and civil rights and freedoms and national
interests of Ukraine in cyberspace, and the fight against cybercrime; organises and ensures the
necessary forces, means and resources for the functioning of the national cybersecurity system; forms
requirements and ensures the functioning of the information security audit system at critical
infrastructure facilities (except for critical infrastructure facilities in the banking system of Ukraine).
4. Subjects that directly implement cybersecurity measures within their competence are:
1) ministries and other central executive authorities;
2) local state administrations;
3) local governments;
4) law enforcement, intelligence and counter-intelligence agencies, subjects of operational and
investigative activities;
5) the Armed Forces of Ukraine and other military formations formed in accordance with the law;
6) the National Bank of Ukraine;
7) enterprises, institutions and organisations classified as critical infrastructure facilities;
8) business entities, citizens of Ukraine and associations of citizens, other persons carrying out
activities and/or providing services related to national information resources, electronic information
services, electronic transactions, electronic communications, information protection and cybersecurity.
5. Subjects of cybersecurity within their competence shall:
1) implement measures to prevent the use of cyberspace for military, intelligence-subversive,
terrorist and other illegal and criminal purposes;
2) detect and respond to cyber incidents and cyberattacks, eliminate their consequences;
3) carry out information exchange regarding actual and potential cyber threats;
4) develop and implement protective, organisational, educational and other measures in the field
of cybersecurity and cyber defence;
5) ensure the conduct of information security audits, including at subordinate facilities and
facilities belonging to the scope of their management;
6) carry out other activities to ensure the development and security of cyberspace.
Article 6. Critical infrastructure facilities
1. Critical infrastructure facilities may include enterprises, institutions and organisations,
irrespective of their form of ownership, which:
1) carry out actions and provide services in the fields of energy, chemical industry, transport,
information and communication technologies, electronic communications, in the banking and financial
sectors;
2) provide services in the areas of essential services of the population, in particular, in the areas of
centralised water supplies, water disposal, electricity and gas supplies, food production, agriculture
and health care;
3) are utility, emergency and rescue services and emergency services for the public;
4) are included in the list of enterprises of strategic importance for the economy and security of
the state;
5) are objects of potentially hazardous technologies and industries.
2. Criteria and procedure for classifying facilities as critical infrastructure facilities, a list of such
facilities, general requirements for their cyber defence, including the application of cyber threat
indicators, and requirements for independent audits of information security shall be approved by the
Cabinet of Ministers of Ukraine, and in the banking system of Ukraine – by the National Bank of
https://zakon.rada.gov.ua/laws/show/en/2163-19/print
Page 4 of 12