3. The price for the information security audit conducted by the Data Exchange Agency shall be fixed under a contract concluded with the critical information system subject. 4. The Data Exchange Agency shall lay down, by a normative act, the authorisation rules for the persons and agencies entitled to conduct information security audit, authorisation procedures, and cost. 5. The Data Exchange Agency, with the consent of the critical information system subject or an independent, competent person or agency selected by the critical information system subject with the prior permission of the Data Exchange Agency shall carry out penetration testing and vulnerability assessment of the information system according to the pre-scheduled and documented task. 6. If an audit or testing provided for by this article identifies non-compliance with the information security policy requirements, the critical information system subject shall analyse the cause for such non-compliance and, if necessary, shall determine and carry out relevant corrective measures, and shall submit their schedule to the Data Exchange Agency. Article 7 - Information security manager 1. The critical information system subject shall be obliged to determine the person(s) or the employee(s) (Information Security Manager) responsible for observing the information security requirements of the critical information system subject. 2. An Information Security Manager shall have the following basic duties: a) daily monitoring of the compliance with the information security policy requirements; b) providing assessment of information assets and their availability; c) drafting internal information security policy documentation; d) collecting information on information security incidents and monitoring responses to such incidents; e) reporting on information security issues and other administrative/organizational activities; f) organizing and conducting general and sectorial trainings on information security; g) other duties defined by the critical information system subject. 3. An Information Security Manager shall be accountable to the head of the critical information system subject or its duly authorised employee, or a group of persons (collegiate body) entitled to implement information security policy. All major decisions concerning the implementation of information security policy shall be made by the person(s) specified under this paragraph or by a prior consent of the same person(s). 4. An Information Security Manager shall draft an action plan for information security and present an annual progress report to the person(s) specified under the third paragraph of this article, and to the Data Exchange Agency. Chapter III - Ensuring Cyber Security Article 8 - Computer Emergency Response Team of the Data Exchange Agency 1. The Computer Emergency Response Team of the Data Exchange Agency – CERT.GOV.GE (‘CERT’) shall be responsible for the enforcement of the provisions of this Law, in particular, the management of the incidents against information security in the cyberspace of Georgia, as well as other related activities aimed to coordinate information security that serves to eliminate priority cyber security threats. 2. Priority cyber security threats shall include: a) a cyber-attack that threatens human life and health, state interests or defence capacity of the country; b) a cyber-attack against the information systems of the critical information system subject; c) a cyber-attack that threatens the financial resources and/or property rights of a state, an organisation or a private person; d) any other action that, based on its nature, purpose, source, scale or quantity, or the amount of resources required for its prevention, contains sufficient threat for proper functioning of the critical information system. 3. CERT duties shall include: a) giving recommendations on maintaining information security of the critical information system; b) detecting computer incidents in a timely manner; c) responding to computer incidents and coordinating the responses to such incidents; d) recording computer incidents, as well as establishing and categorizing their response priorities; http://www.matsne.gov.ge 14000000005001016807

Select target paragraph3