A/65/154
procedures for achieving information protection requirements for the individual
components of a comprehensive information protection system depending on the
variety of information and communication technology involved, the ultimate
purpose, the field of use and the type of information processed.
17. Ukraine has also created its own national system of criteria for assessing the
security of information technologies. The system is based on a set of regulatory
instruments on protecting information in information and telecommunications
systems from unauthorized access; these instruments have been harmonized with
similar instruments of European Union countries and with international standards, in
particular standard 15408 of the International Organization for Standardization/
International Electrotechnical Commission.
18. In addition, a national system of organizational and technical measures is
being established in Ukraine with a view to preventing unauthorized acts against the
information and telecommunications systems of the State authorities, law
enforcement, customs and tax authorities, credit and financial institutions and
others, in particular attempts to interfere with their work through the Internet.
19. As specified in article 16, paragraphs 10 and 11, of the Act on the State
Service for Special Communications and Information Protection, and in order to
improve coordination between State agencies for the detection of threats to
information in information and telecommunications systems, to deal with the
consequences of implementation of such threats and to organize international
cooperation in such matters, the appropriate Computer Emergency Response Team
(CERT-UA) has been created within the Service and is operational.
20. Reflecting the global trend towards networks of rapid reaction facilities, CERT
responds to computer emergencies. International coordination of the activities of
such facilities is provided by the international Forum for Incident Response Security
Teams (FIRST), a forum for teams responding to security incidents.
21. On 13 July 2009, CERT-UA (www.cert.gov.ua) became a full member of
FIRST.
22. Among its activities for 2009, CERT-UA processed 461 reports from CERTs in
30 countries (Australia, Austria, Belgium, Canada, China, Denmark, Finland,
France, Estonia, Germany, Hungary, India, Israel, Italy, Japan, Korea, Lithuania,
Malaysia, Netherlands, Norway, Pakistan, Poland, Portugal, Romania, Russian
Federation, Saudi Arabia, Spain, Taiwan, Turkey, United States of America) of
unauthorized acts in the Ukrainian segment of the Internet (distribution of harmful
software, distributed denial-of-service (DDoS) attacks and other attempts to commit
unauthorized acts).
23. It should be added that Ukraine has created a legal and regulatory framework
and made efforts to ensure cooperation between the State Service for Special
Communications and Information Protection and the law enforcement agencies with
a view to implementing measures to safeguard the security of State information
resources in information and telecommunications systems and improving the
effectiveness of the system for responding to unauthorized acts against those
information resources.
24. Thus, in Ukraine, information can now be protected at all stages of the
establishment of information and telecommunications systems and the
10-45842
13