Про основні засади заб... | on October 5, 2017 № 2163-VIII (Print version)
24/09/2022, 01:03
auditors, determines the procedure for their attestation (recertification); co-ordinates, organises and
conducts an audit of the security of communications and technological systems of critical
infrastructure facilities; ensures the functioning of the State Centre for Cyber Defence, the
government's computer emergency response team of Ukraine CERT-UA;
2) The National Police of Ukraine ensures the protection of human and civil rights and freedoms
and the interests of society and the state from criminal encroachments in cyberspace; takes measures to
prevent, detect, suppress and disclose cybercrimes and raise citizen awareness of security in
cyberspace;
{Clause 2, part two of Article 8 as amended by Law No. 720-IX of 17 June 2020}
3) The Security Service of Ukraine prevents, detects, suppresses and solves criminal offences
against peace and security of humanity that are committed in cyberspace; carries out
counterintelligence and operational-search activities aimed at combating cyberterrorism and cyber
espionage, and covertly checks the readiness of critical infrastructure facilities for possible
cyberattacks and cyber incidents; counteracts cybercrime, the consequences of which may threaten the
vital interests of the state; investigates cyber incidents and cyberattacks against state electronic
information resources and information, the requirement for protection of which is established by law,
and critical information infrastructure; provides a response to cyber incidents in the field of national
security;
{Clause 3, part two of Article 8 as amended by Law No. 720-IX of 17 June 2020}
4) The Ministry of Defence of Ukraine and the General Staff of the Armed Forces of Ukraine
shall, with the respective competence, carry out measures to prepare the state to repulse military
aggression in cyberspace (cyber defence); carry out military co-operation with NATO and other
defence subjects to ensure the security of cyberspace and joint protection against cyber threats;
implement measures to ensure cyber protection of critical information infrastructure in conditions of
emergency and martial law;
5) intelligence agencies of Ukraine carry out intelligence activities on threats to the national
security of Ukraine in cyberspace, other events and circumstances related to the field of cybersecurity;
6) The National Bank of Ukraine determines the procedure, requirements and measures to ensure
cyber defence and information security in the banking system of Ukraine and for the subjects of funds
transfer, monitors their implementation; establishes a cyber defence centre of the National Bank of
Ukraine and ensures the functioning of the cyber defence system in the banking system of Ukraine;
provides an assessment of the state of cybersecurity and audit of information security at critical
infrastructure facilities in the banking system of Ukraine.
3. The functioning of the national cybersecurity system is ensured by:
1) development and operational adaptation of the public policy in the field of cybersecurity, aimed
at the development of cyberspace, achieving compatibility with the relevant standards of the European
Union and NATO;
2) creation of a legal and terminological base in the field of cybersecurity, harmonisation of
normative documents in the field of electronic communications, information protection, information
security and cybersecurity in line with international standards, in particular, those of the European
Union and NATO;
3) establishment of mandatory information security requirements for critical information
infrastructure facilities, including during their creation, commissioning, operation and upgrading,
taking into account international standards and the specifics of the industry to which the relevant
critical information infrastructure facilities belong;
4) formation of a competitive environment in the field of electronic communications, provision of
information protection and cyber defence services;
5) involving the expertise of scientific institutions, professional and public associations in the
preparation of draft conceptual documents in the field of cybersecurity;
6) conducting exercises on actions in case of emergencies and incidents in cyberspace;
7) functioning of the information security audit system, implementation of global best practices
and international standards on cybersecurity and cyber defence;
8) development of a network of computer emergency response teams;
9) development and improvement of the system of technical and cryptographic protection of
information;
10) ensuring compliance with the requirements of the legislation on the protection of state
information resources and information;
11) creation and ensuring the functioning of the National Telecommunication Network;
12) exchange of information on cybersecurity incidents between cybersecurity subjects in the
manner prescribed by law;
13) implementation of a unified (universal) system of cyber threat indicators, taking into account
international standards on cybersecurity and cyber defence;
https://zakon.rada.gov.ua/laws/show/en/2163-19/print
Page 6 of 12