e) analysing computer incidents; f) providing assistance in the process of remedying the consequences of computer incidents and minimising the inflicted damage; g) coordinating the computer incident prevention measures and providing assistance in the implementation of such measures; h) raising awareness of information security issues, including providing information on existing threats and weak points within the critical information systems, unless the availability of such information poses a threat to the information security; i) warning a wide circle of users about potential threats and providing relevant information to them; j) providing educational and information support on information security issues; k) providing representation and coordination on information security issues at international level; l) performing other duties related to information security objectives that are defined by law or other normative act. 4. CERT may request access to the information asset, information system and/or to any object that is a part of the information infrastructure of the critical information system subject, if such access is necessary for proper response to any current or past computer incident. The Information Security Manager shall notify CERT about the possibility or impossibility of such access after reviewing the request within a reasonable period of time. 5. The Data Exchange Agency shall define CERT’s competence, working procedures, computer incident response mechanisms, and other rules of activity by a normative act. Article 9 - Cyber security specialist 1. The critical information system subject shall be obliged to determine the person(s) or the employee(s) responsible for the practical provision of security for the computer systems of the critical information system subject (Cyber Security Specialist). 2. A Cyber Security Specialist shall have the following basic duties: a) daily monitoring and assessing computer systems; b) identifying and responding to computer incidents; c) providing analysis and reporting of computer incidents and security measures; d) coordinating with CERT; e) performing other duties defined by the critical information system subject. 3. A Cyber Security Specialist shall be accountable to the head of information technology service of the critical information system subject, or to the employee duly authorised by the latter. 4. A Cyber Security Specialist shall be available at any time, including the time after working hours. He/she shall ensure regular coordination with the Data Exchange Agency during the ongoing or potential cyber-attacks against the critical information system subject, as well as in the process of eliminating the effects of such cyber-attacks. 5. If an ongoing or a potential cyber-attack poses an exceptional threat to the defence capacity or economic security of the country, as well as to the proper functioning of state authority and/or society, the Data Exchange Agency shall be authorised to temporarily coordinate cyber security specialists to prevent, repel the attack, and/or eliminate its consequences. Article 10 - Computer incident identification 1. The critical information system subject shall identify computer incidents that imply the study and description of each incident and the response thereto. 2. In agreement with the critical information system subject, the Data Exchange Agency and a Cyber Security Specialist shall configure and manage the network sensor (system of sensors) required for the identification and examination of computer incidents in the network of the critical information system subject. The Data Exchange Agency shall determine the configuration rules for network sensors by a normative act. 3. CERT shall be immediately notified of the identified computer incident and, if necessary, urgent measures shall be taken in order to preserve and protect incident-related information. 4. While performing the duties provided for by this Law, CERT shall study and describe computer incidents and adequately respond to them. Chapter III1 - Cyber Security Bureau Law of Georgia No 1829 of 24 December 2013 – website, 28.12.2013 http://www.matsne.gov.ge 14000000005001016807

Select target paragraph3