Official Gazette, 79/2007
Security of Information
Article 11
(1) Security of information is the information security area for which determined are
implemented as general measures of protection for prevention, detection and removal of
damage caused by loss or unauthorised disclosure of classified and unclassified data.
(2) Bodies and legal persons referred to in Article 1, paragraph 2 of this Act, who use
classified and unclassified data within their scope of work, shall implement the procedures on
handling classified and unclassified data, on content and management of the records of
classified data access and oversight of information security and stipulated information
security measures and standards.
INFOSEC
Article 12
(1) INFOSEC is the information security area within which information security measures
and standards are determined for classified and unclassified data that are processed, stored or
transmitted within the information system and the protection of integrity and availability of
the information system in the process of planning, designing, making, using and cease of
work of the information system.
(2) Security accreditation of the information system shall be performed for the information
system where classified data of CONFIDENTIAL, SECRET and TOP SECRET degree of
secrecy are used.
(3) Persons who take part in the process referred to in paragraph 1 of this Article shall have
the Certificate with the TOP SECRET degree of secrecy or one degree of secrecy higher than
the highest degree of secrecy of classified data that are processed, stored or transmitted in the
information systems under their competence.
(4) Measures of physical protection of facilities where information systems are located shall
be taken in accordance with the highest degree of secrecy of classified data that are
processed, stored or transmitted in the said facilities.
(5) NSA and NCSA shall form the registry of certified equipment and machines used in the
information system of the CONFIDENTIAL, SECRET and TOP SECRET degree of secrecy.
Registry of certified equipment and machines shall be formed on the basis of taking over the
appropriate registers of international organizations or by own certifying process in
accordance with relevant international norms.
Industrial Security
Article 13
(1) Industrial security is the information security area where stipulated information security
measures and standards are applied for tenders or contracts with classified documentation
which are binding for legal and natural persons referred to in Article 1, paragraph 3 of this
Act.
4