A/69/112
Republic of Serbia until 2020, adopted by the Government of the Republic of Serbia
in 2010, information security is declared to be one of six priority areas. Serbia does
not have a national strategy solely dedicated to information security, but this topic is
dealt with in a number of other documents. In October 2013, a special working group
was formed and tasked to draft a law on information security. The law is harmonized
with the relevant international and European Union legal frameworks and determines
the following: information security institutional framework; measures needed to
provide enhanced security of ICT systems in the Republic of Serbia, including ICT
systems of public bodies and enterprises; norms for prevention coordination in respect
of security risks in ICT systems; establishment of the national computer emergency
response team; specific security measures and preconditions to be applied in
information systems of State bodies; security of classified data in ICT systems;
crypto-security and protection from compromising electromagnetic emanations.
The ICT Department of the Administration for Joint Services of the Republic
Bodies performs the activities related to the protection of information security, data
protection and the implementation of prescribed security standards for information
systems of State bodies. In the Administration’s annual report, it was stated that within
its mandate of protection of State ICT systems, the Department provides protection
from cyberattacks on a daily basis, as the network is attacked every day.
The Academic Network of the Republic of Serbia performs the computer
security incident response activities for the educational and scientific research
institutions in the Republic of Serbia. In the Academic Network ’s 2013 annual report,
it was declared that there has been an increasing number of incidents compared with
2012. The report identified old equipment as one of the reasons for the increasing
number of attacks.
Only a well-established national information security culture embraced at every
level of society can be effective to locally strengthen the security of national
information and telecommunications systems. Similarly, only such well-established
national information security systems can be a part of the application of the
international information security concepts to strengthen the security of global
information and telecommunications systems.
The Office of the National Security Council and Classified Information
Protection (hereinafter, the National Security Council Office) is the Serbian
Government service responsible for coordination of the implementation of national
and European Union security policies at the national level (National Security
Authority). A specific segment of its activities is reflected in the adoption of
information assurance measures and the coordination of the implementation of those
measures in Government bodies and other institutions for the purpose of the
protection of classified information. In this context, the Decree on special measures
for the protection of classified information in information telecommunications
systems was passed in 2011 (Official Gazette RS, No. 53/2011). At the international
level, since 2011, the National Security Council Office has been an active participant
in the Forum of the directors of the South-East European National Security
Authorities. One of the Forum’s primary aims is to enhance information assurance and
classified information protection in the regional countries, in line with international
standards. The National Security Council Office acts as a chief coordinator for
developing a regional cyberdefence concept within the framework of the South -East
European National Security Authorities.
14/18
14-56479