A/66/152 Georgia [Original: English] [1 June 2011] In the context of Georgia, the information security issues were given particular attention after August 2008, when the Russian Federation carried out a heavy distributed denial-of-service attack against Georgia. Given the assessment of these events and under the recent rapid and largescale development of e-governance projects and services, information security has become one of the significant aspects of the national security concept. For the improved regulation of information security, the Government of Georgia has been carrying out a number of significant initiatives in recent years. In 2010, a legal entity, the Data Exchange Agency, was established under the Ministry of Justice of Georgia, which is directly responsible for the development and implementation of information security policy in the Government sector. With the establishment of the Data Exchange Agency, the Government of Georgia has developed the institutional mechanism for coordinated realization of e-governance and information security. The Data Exchange Agency, within the framework of functions provided for by the law and its own charter, cooperates with the Ministry of Justice of Georgia in pursuing and introducing of an information security policy, which should conform to International Organization for Standardization (ISO) 27000 standard. The Agency also coordinates the enforcement and introduction of either mechanisms or standards necessary for information security in the State and business sectors, particularly by carrying out activities of various levels of significance. Out of these events, one the most important is the annual Georgian information technology innovations conference, the agenda of which always deals with information and cybersecurity; the conference also has the mandate of the Agency to develop and carry out the policy of public awareness enhancement regarding information and cybersecurity issues. In the context of everyday cybersecurity, the Data Exchange Agency is responsible for the establishment and operation of the computer emergency response team, which currently is functioning at the Agency with a view to managing the information security incidents in Georgia’s cyberspace. The Agency also monitors the functioning of the Georgian governmental network for the safeguarding of its security. The functions of the Agency, in the context of information and communication technologies, also provide for raising the levels of professional education (in order to train information security specialists), preparing proposals, monitoring security and issuing digital signature certificates. Given the sphere of professional education, the Agency plans to carry out a number of special projects with the help of international donors (such as the European Union (EU) and the World Bank). These projects will ensure the appropriate level of professional education; as for digital signature security, the Agency will perform this function upon the beginning of issuance of citizens electronic identity cards (bearing digital signatures) by the Civil Registry Agency. 11-41691 7

Select target paragraph3