Official Journal In the transport sector, which is composed of three pillars, the situation is as follows: Critical information infrastructure related to air transport meets minimum security rules obligations and sector CSIRT has been established in the relevant sector. Critical information infrastructure in road transport does not meet any minimum-security rules obligations, including the establishment of the relevant CSIRT. Information infrastructure in maritime transport, which is considered critical infrastructure in the meaning of the legal framework adopted by the European Commission on networks and infrastructure is yet to be identified. Besides, critical information infrastructure in the water supply sector, which is managed by local governance, has yet to be identified as such in the meaning of the applicable legislation on cybersecurity and no security measures are applied in this regard. Considering that the majority of cyber threats and cyberattacks are perpetrated through electronic communication networks, cybersecurity issues in the digital infrastructure and electronic communication networks and/or services are covered and are under the responsibility of the Electronic and Post Communication Authority (AKEP). According to article 122 of Law No. 9918, dated 19.5.2008 “On Electronic Communication in the Republic of Albania” and Regulation No. 37 dated 29.10.2015 “On Technical and Organization Measures to guarantee Electronic Communication Network and/or Services Integrity”, AKEP requires adequate technical and organizational measures to be put in place by all electronic communication entities operating under the General Authorization Regime to guarantee electronic communication networks and/or services security and integrity for all services they provide to their subscribers, including DNS services. AKEP has conducted and continues to periodically conduct inspections and audits in entities, to verify the establishment and implementation of the relevant technical and organizational security measures, and in cooperation with NECCA it follows up on security incidents reported by electronic Page|1488 Year 2021 - Issue 7 communication businesses. AKEP is the “.al” domain administrator and has authorized 8 businesses as accredited registries to provide domain name registration services under the .al domain (TLD name registries). With the inclusion of this service in the critical and important information infrastructure list, the registries accredited by AKEP to provide .al domain name registration services will also be subject to the provisions of regulation No. 37 “On Technical and Organization Measures to guarantee Electronic Communication Network and/or Services Integrity”. Internet penetration in Albania is still ongoing and the country currently has midlevel internet use. Some 67% of the population and some 40% of households had internet access in 2019. 2.1.2 Cybercrime Similar to other countries, Albania is often a victim of malicious cyber activity perpetrated by criminal actors, including state and nonstate actors that can use network infrastructure in the country and abroad. Alongside the improvement of internet services, Albania has also experienced the rise of various forms of cybercrime. The most common forms of cybercrime dominating in Albania include fraud-related to internet banking such as phishing and spam. Even when those responsible for cybercrime against the Republic of Albania are identified, it is often difficult for law enforcement agencies in the Republic of Albania and international organizations to persecute when they are located in restricted jurisdictions. Currently, there is a lack of necessary tools to obtain general cyber intelligence, using human and logistical resources available for law enforcement activities. For this reason, it is fundamental to increase capacities to address cyber challenges, which in turn requires a change in structures, approach, technical and logistical capacities, etc. An important step forward in legislation development and measures were taken against cybercrime will also be the first national cybercrime strategy, which will be

Select target paragraph3