Про основні засади заб... | on October 5, 2017 № 2163-VIII (Print version) 24/09/2022, 01:03 auditors, determines the procedure for their attestation (recertification); co-ordinates, organises and conducts an audit of the security of communications and technological systems of critical infrastructure facilities; ensures the functioning of the State Centre for Cyber Defence, the government's computer emergency response team of Ukraine CERT-UA; 2) The National Police of Ukraine ensures the protection of human and civil rights and freedoms and the interests of society and the state from criminal encroachments in cyberspace; takes measures to prevent, detect, suppress and disclose cybercrimes and raise citizen awareness of security in cyberspace; {Clause 2, part two of Article 8 as amended by Law No. 720-IX of 17 June 2020} 3) The Security Service of Ukraine prevents, detects, suppresses and solves criminal offences against peace and security of humanity that are committed in cyberspace; carries out counterintelligence and operational-search activities aimed at combating cyberterrorism and cyber espionage, and covertly checks the readiness of critical infrastructure facilities for possible cyberattacks and cyber incidents; counteracts cybercrime, the consequences of which may threaten the vital interests of the state; investigates cyber incidents and cyberattacks against state electronic information resources and information, the requirement for protection of which is established by law, and critical information infrastructure; provides a response to cyber incidents in the field of national security; {Clause 3, part two of Article 8 as amended by Law No. 720-IX of 17 June 2020} 4) The Ministry of Defence of Ukraine and the General Staff of the Armed Forces of Ukraine shall, with the respective competence, carry out measures to prepare the state to repulse military aggression in cyberspace (cyber defence); carry out military co-operation with NATO and other defence subjects to ensure the security of cyberspace and joint protection against cyber threats; implement measures to ensure cyber protection of critical information infrastructure in conditions of emergency and martial law; 5) intelligence agencies of Ukraine carry out intelligence activities on threats to the national security of Ukraine in cyberspace, other events and circumstances related to the field of cybersecurity; 6) The National Bank of Ukraine determines the procedure, requirements and measures to ensure cyber defence and information security in the banking system of Ukraine and for the subjects of funds transfer, monitors their implementation; establishes a cyber defence centre of the National Bank of Ukraine and ensures the functioning of the cyber defence system in the banking system of Ukraine; provides an assessment of the state of cybersecurity and audit of information security at critical infrastructure facilities in the banking system of Ukraine. 3. The functioning of the national cybersecurity system is ensured by: 1) development and operational adaptation of the public policy in the field of cybersecurity, aimed at the development of cyberspace, achieving compatibility with the relevant standards of the European Union and NATO; 2) creation of a legal and terminological base in the field of cybersecurity, harmonisation of normative documents in the field of electronic communications, information protection, information security and cybersecurity in line with international standards, in particular, those of the European Union and NATO; 3) establishment of mandatory information security requirements for critical information infrastructure facilities, including during their creation, commissioning, operation and upgrading, taking into account international standards and the specifics of the industry to which the relevant critical information infrastructure facilities belong; 4) formation of a competitive environment in the field of electronic communications, provision of information protection and cyber defence services; 5) involving the expertise of scientific institutions, professional and public associations in the preparation of draft conceptual documents in the field of cybersecurity; 6) conducting exercises on actions in case of emergencies and incidents in cyberspace; 7) functioning of the information security audit system, implementation of global best practices and international standards on cybersecurity and cyber defence; 8) development of a network of computer emergency response teams; 9) development and improvement of the system of technical and cryptographic protection of information; 10) ensuring compliance with the requirements of the legislation on the protection of state information resources and information; 11) creation and ensuring the functioning of the National Telecommunication Network; 12) exchange of information on cybersecurity incidents between cybersecurity subjects in the manner prescribed by law; 13) implementation of a unified (universal) system of cyber threat indicators, taking into account international standards on cybersecurity and cyber defence; https://zakon.rada.gov.ua/laws/show/en/2163-19/print Page 6 of 12

Select target paragraph3