Official
Journal
In the transport sector, which is composed
of three pillars, the situation is as follows:
Critical information infrastructure related to
air transport meets minimum security rules
obligations and sector CSIRT has been
established in the relevant sector.
Critical information infrastructure in road
transport does not meet any minimum-security
rules obligations, including the establishment of
the relevant CSIRT.
Information infrastructure in maritime
transport, which is considered critical
infrastructure in the meaning of the legal
framework adopted by the European Commission
on networks and infrastructure is yet to be
identified.
Besides, critical information infrastructure in
the water supply sector, which is managed by
local governance, has yet to be identified as such
in the meaning of the applicable legislation on
cybersecurity and no security measures are
applied in this regard.
Considering that the majority of cyber threats
and cyberattacks are perpetrated through
electronic
communication
networks,
cybersecurity issues in the digital infrastructure
and electronic communication networks and/or
services are covered and are under the
responsibility of the Electronic and Post
Communication Authority (AKEP). According to
article 122 of Law No. 9918, dated 19.5.2008
“On Electronic Communication in the Republic
of Albania” and Regulation No. 37 dated
29.10.2015 “On Technical and Organization
Measures
to
guarantee
Electronic
Communication Network and/or Services
Integrity”, AKEP requires adequate technical and
organizational measures to be put in place by all
electronic communication entities operating
under the General Authorization Regime to
guarantee electronic communication networks
and/or services security and integrity for all
services they provide to their subscribers,
including DNS services. AKEP has conducted
and continues to periodically conduct inspections
and audits in entities, to verify the establishment
and implementation of the relevant technical and
organizational security measures, and in
cooperation with NECCA it follows up on
security incidents reported by electronic
Page|1488
Year 2021 - Issue 7
communication businesses. AKEP is the “.al”
domain administrator and has authorized 8
businesses as accredited registries to provide
domain name registration services under the .al
domain (TLD name registries).
With the inclusion of this service in the critical
and important information infrastructure list,
the registries accredited by AKEP to provide .al
domain name registration services will also be
subject to the provisions of regulation No. 37
“On Technical and Organization Measures to
guarantee Electronic Communication Network
and/or Services Integrity”.
Internet penetration in Albania is still
ongoing and the country currently has midlevel internet use. Some 67% of the population
and some 40% of households had internet
access in 2019.
2.1.2 Cybercrime
Similar to other countries, Albania is often a
victim of malicious cyber activity perpetrated
by criminal actors, including state and nonstate actors that can use network infrastructure
in the country and abroad. Alongside the
improvement of internet services, Albania has
also experienced the rise of various forms of
cybercrime. The most common forms of
cybercrime dominating in Albania include
fraud-related to internet banking such as
phishing and spam. Even when those
responsible for cybercrime against the Republic
of Albania are identified, it is often difficult for
law enforcement agencies in the Republic of
Albania and international organizations to
persecute when they are located in restricted
jurisdictions.
Currently, there is a lack of necessary tools
to obtain general cyber intelligence, using
human and logistical resources available for
law enforcement activities.
For this reason, it is fundamental to increase
capacities to address cyber challenges, which in
turn requires a change in structures, approach,
technical and logistical capacities, etc.
An important step forward in legislation
development and measures were taken against
cybercrime will also be the first national
cybercrime strategy, which will be