A/66/152
Georgia
[Original: English]
[1 June 2011]
In the context of Georgia, the information security issues were given particular
attention after August 2008, when the Russian Federation carried out a heavy
distributed denial-of-service attack against Georgia.
Given the assessment of these events and under the recent rapid and largescale development of e-governance projects and services, information security has
become one of the significant aspects of the national security concept. For the
improved regulation of information security, the Government of Georgia has been
carrying out a number of significant initiatives in recent years.
In 2010, a legal entity, the Data Exchange Agency, was established under the
Ministry of Justice of Georgia, which is directly responsible for the development
and implementation of information security policy in the Government sector. With
the establishment of the Data Exchange Agency, the Government of Georgia has
developed the institutional mechanism for coordinated realization of e-governance
and information security.
The Data Exchange Agency, within the framework of functions provided for
by the law and its own charter, cooperates with the Ministry of Justice of Georgia in
pursuing and introducing of an information security policy, which should conform
to International Organization for Standardization (ISO) 27000 standard. The Agency
also coordinates the enforcement and introduction of either mechanisms or
standards necessary for information security in the State and business sectors,
particularly by carrying out activities of various levels of significance. Out of these
events, one the most important is the annual Georgian information technology
innovations conference, the agenda of which always deals with information and
cybersecurity; the conference also has the mandate of the Agency to develop and
carry out the policy of public awareness enhancement regarding information and
cybersecurity issues.
In the context of everyday cybersecurity, the Data Exchange Agency is
responsible for the establishment and operation of the computer emergency response
team, which currently is functioning at the Agency with a view to managing the
information security incidents in Georgia’s cyberspace. The Agency also monitors
the functioning of the Georgian governmental network for the safeguarding of its
security.
The functions of the Agency, in the context of information and communication
technologies, also provide for raising the levels of professional education (in order
to train information security specialists), preparing proposals, monitoring security
and issuing digital signature certificates. Given the sphere of professional education,
the Agency plans to carry out a number of special projects with the help of
international donors (such as the European Union (EU) and the World Bank). These
projects will ensure the appropriate level of professional education; as for digital
signature security, the Agency will perform this function upon the beginning of
issuance of citizens electronic identity cards (bearing digital signatures) by the Civil
Registry Agency.
11-41691
7