The legal framework of most of the Hungarian cyber security organisations was founded by the Act L of 2013 on
the Electronic Information Security of Central and Local Government Agencies, and it was the first legal act
31
based on the National Cyber Security Strategy. Beyond the National Cyber Security Strategy, Act L of 2013
32
became the second main pillar to deal with the cyber defence structure.
The provisions of the Act are quite wide and applicable to:
-
constitutional and central state administration bodies, except for the Government and Government
Committees;
-
the offices of the representative bodies of local and nationality governments and the administrative
associations of the authorities; and
-
the Hungarian Defence Forces.
In accordance with the law, these governmental organisations and bodies have to reach different security
institutional levels in information security. It means that these stakeholders should be categorised on a five
point scale from level 1 to level 5. These levels, depending on the tasks and importance of the organisation,
require different security personnel, measures and documents (e.g. IT security officers, log analysis, permanent
vulnerability testing). Level 5 organisations have the most strict criteria. The latest guide to declaring these
levels is the Executive Decree of the Minister of Interior 41/2015 (15 July).
Political coordination and management are key elements of a nation’s digital economy, developed information
infrastructures and of course, cyber security. In the age of global alliances, ‘digital power gives a clear
33
asymmetric advantage in national security to small states’, of which Hungary is an example. Besides national
coordination, international cooperation is the other main requirement of cyber security: ‘Cyber defence is a
cooperative effort, where no one, however powerful, can go it alone. You cannot build fences that are high
34
enough to keep cyber threats away’. Following this reasoning, the Hungarian Government has built up
a complex cyber security system in recent years, focusing on the national and international environment and
involving the private sector.
The National Cyber Security Coordination Council, created by the National Cyber Security Strategy, is the
highest political coordination body in Hungary in this regard. The members of the Council are the ministerial
leaders delegated by the ministers with responsibilities in the field of cyber security matters – including State
Secretaries of Defence, Interior, Foreign Affairs and Trade, Finance, National Development – together with the
heads of independent public entities, such as the Hungarian National Bank, and the National Media and
35
Telecommunications Authority. The Council operates under the supervision of the Ministry of Interior. The
daily operative work is executed by the national cyber coordinator, who is coordinating the connected Cyber
Security Working Groups (e.g. Homeland Security, Child protection, e-Government) as well, with the support of
31
The Act L of 2013 also referred as ’information security law’ or ’cyber law’.
Krasznay Csaba and Török Szilárd, ‘Hungary’s Cyber Defense Readiness from the Perspective of International
Recommendations,’ Hadmérnök 1 (2014): 210. <http://hadmernok.hu/141_20_krasznaycs.pdf>.
33
Liina Areng, ‘Liliputian States in Digital Affairs and Cyber Security,’ The Tallinn Papers 4 (2014): 11.
<https://ccdcoe.org/sites/default/files/multimedia/pdf/TP_04.pdf>.
34
Christian-Marc Liflander, ‘Defining Cyber-Security: The Role of NATO in Ensuring Common Defence,’ Magyar Rendészet
Special Issue (2013): 138. <http://www.bm-tt.hu/assets/letolt/t2konf/MR_2013_KSZ_beliv.pdf>.
35
Szemerkényi and Suba, ‘Public Private Partnership in Cybersecurity,’ 30.
32
8