Про основні засади заб... | on October 5, 2017 № 2163-VIII (Print version) 24/09/2022, 01:03 4) communication systems that do not interact with public electronic communication networks (electronic public networks), are not connected to the internet and/or other global data transmission networks (other than technological systems). 2. The application of cybersecurity legislation and decision-making by authorities pursuant to the norms of the Law shall be carried out in compliance with the principles of: 1) minimum necessary regulation, according to which the decisions (measures) of the subjects of power must be necessary and minimally sufficient to achieve the purpose and objectives defined in this Law; 2) objectivity and legal certainty, applying national and international law as much as possible to the powers and responsibilities of state bodies, enterprises, institutions, organisations and citizens in the field of cybersecurity; 3) ensuring protection of the rights of users of communications systems and/or consumers of electronic communications services and/or information protection services, cyber defence, including rights of non-interference in private life and protection of personal data; 4) transparency, according to which decisions (measures) of the subjects of power must be duly justified and notified to the subjects concerned before they come into force (their application); 5) balancing requirements and liability, according to which there should be a balance between imposing liability for failure to meet cybersecurity and cyber defence requirements and imposing excessive requirements and restrictions; 6) non-discrimination, according to which the decisions, actions and omissions of subjects of power cannot result in the legal or factual scope of the rights and obligations of the person who is: different from the scope of the rights and obligations of others in similar situations, unless such a difference is necessary and minimally sufficient to satisfy the general public interest; as well as the scope of rights and obligations of others in dissimilar situations, unless such equality is necessary and minimally sufficient to satisfy the general public interest; 7) equivalence of cybersecurity requirements for critical infrastructure facilities, according to which the application of legal provisions should be as equivalent as possible concerning the cyber defence of communications and technology systems of critical infrastructure facilities belonging to the same economic sector and/or performing similar functions. The above principles shall apply without prejudice to any of them, taking into account the purpose and objectives of this Law. Article 3. Legal basis for cybersecurity of Ukraine 1. The legal basis for cybersecurity of Ukraine is constituted by the Constitution of Ukraine, laws of Ukraine regarding the foundations of national security, the foundations of domestic and foreign policy, electronic communications, protection of state information resources and information whose protection is required by law, this and other laws of Ukraine, the Convention on Cybercrime, other international treaties ratified by the Verkhovna Rada of Ukraine, decrees of the President of Ukraine, acts of the Cabinet of Ministers of Ukraine, as well as other legal acts adopted according to the laws of Ukraine. 2. If an international treaty of Ukraine ratified by the Verkhovna Rada of Ukraine, provides for rules other than those established by this Law, the provisions of the international treaty of Ukraine shall apply. Article 4. Objects of cybersecurity and cyber defence 1. The objects of cybersecurity are: 1) constitutional human and citizen rights and freedoms; 2) society, the sustainable development of the information society and the digital communication environment; 3) the state, its constitutional order, sovereignty, territorial integrity and inviolability; 4) national interests in all spheres of life of the individual, society and state; 5) critical infrastructure facilities. 2. The objects of cyber defence are: 1) communication systems of all forms of ownership that process national information resources and/or are used in the interests of government authorities, local governments, law enforcement agencies and military formations formed under the law; 2) critical information infrastructure facilities; 3) communication systems that are used to meet public needs and/or implement legal relations in the areas of e-government, e-government services, e-commerce, e-document management. 3. The procedure for forming the list of facilities of critical information infrastructure, the list of such facilities and the procedure for including them in the state register of critical information https://zakon.rada.gov.ua/laws/show/en/2163-19/print Page 3 of 12

Select target paragraph3