Про основні засади заб... | on October 5, 2017 № 2163-VIII (Print version) 24/09/2022, 01:03 Cabinet of Ministers of Ukraine, and in the banking system of Ukraine – by the National Bank of Ukraine. 3. Requirements and procedures for independent audits of information security at critical infrastructure facilities are established by relevant regulations on information security audits approved by the Cabinet of Ministers of Ukraine. The development of regulations on independent audits of information security at critical infrastructure facilities is based on international, European Union and NATO standards with the mandatory involvement of representatives of the main subjects of the national cybersecurity system, scientific institutions, independent auditors and cybersecurity experts, public organisations. 4. Responsibility for ensuring the cyber defence of communication and technological systems of critical infrastructure facilities, protection of technological information under the requirements of the legislation, for the prompt reporting of cybersecurity incidents to the government's computer emergency response team of Ukraine CERT-UA, for arranging an independent information security audit at such facilities is entrusted to the owners and/or managers of enterprises, institutions and organisations classified as critical infrastructure. 5. The exchange of information on cybersecurity incidents containing personal data shall comply with the requirements of the Law of Ukraine “On Protection of Personal Data”. Article 7. Principles of ensuring cybersecurity 1. Ensuring cybersecurity in Ukraine is based on the principles of: 1) the rule of law, legality, respect for human rights and fundamental freedoms and their protection in the manner prescribed by law; 2) ensuring the national interests of Ukraine; 3) openness, accessibility, stability and security of cyberspace, development of the Internet and responsible action in cyberspace; 4) public-private co-operation, broad co-operation with civil society in the field of cybersecurity and cyber defence, in particular, through sharing information on cybersecurity incidents, implementing joint scientific and research projects, and training and professional development of personnel in this field; 5) proportionality and adequacy of cyber defence measures to actual and potential risks, realising the inherent right of a state to self-defence in accordance with international law in the event of aggressive actions in cyberspace; 6) priority of precautionary measures; 7) inevitability of punishment for committing cybercrimes; 8) priority development and support of domestic scientific, scientific-technical and production potential; 9) international co-operation in order to strengthen mutual trust in the field of cybersecurity and develop joint approaches to counter cyber threats, consolidate efforts to investigate and prevent cybercrime, and prevent the use of cyberspace for terrorist, military and other illegal purposes; 10) ensuring democratic civilian control over military formations and law enforcement agencies established under the laws of Ukraine, carrying out actions in the field of cybersecurity. Article 8. National cybersecurity system 1. The national cybersecurity system is a set of cybersecurity subjects and interrelated measures of a political, scientific and technical, informational, educational, organisational, legal, intelligence, counterintelligence, defence, engineering and technical nature, as well as measures for the cryptographic and technical protection of national information resources and the cyber defence of critical information infrastructure facilities. 2. The main entities of the national cybersecurity system are the State Service for Special Communication and Information Protection of Ukraine, the National Police of Ukraine, the Security Service of Ukraine, the Ministry of Defense of Ukraine and the General Staff of the Armed Forces of Ukraine, intelligence agencies and the National Bank of Ukraine, which, under the Constitution and the laws of Ukraine, perform the following main tasks in the prescribed manner: 1) The State Service for Special Communication and Information Protection of Ukraine ensures the formation and implementation of public policy on the protection in cyberspace of state information resources and information whose protection is required by law, cyber defence of critical information infrastructure facilities, and exercises state control in these fields; co-ordinates the activities of other cybersecurity subjects with regard to cyber defence; ensures the establishment and operation of the National Telecommunications Network and the implementation of an organisational and technical model for cyber defence; implements organisational and technical measures to prevent, detect and respond to cyber incidents and cyberattacks and eliminate their consequences; informs about cyber threats and appropriate methods of protection against them; ensures implementation of information security audits at critical infrastructure facilities, establishes requirements for information security auditors, determines the procedure for their attestation (recertification); co-ordinates, organises and https://zakon.rada.gov.ua/laws/show/en/2163-19/print Page 5 of 12

Select target paragraph3