47
In 2013, the Ministry of Defence issued the Cyber Defence Concept of the Hungarian Defence Forces. This
concept outlines the main directions for the HDF and defines general requirements of the cyber security task
required of the HDF and their organisations. In order to create and develop the cyber defence capabilities of
the HDF the document assigns a three-level development plan, which includes initial cyber defence capabilities
(2013-2014), basic cyber defence capabilities (2013-2016), and full cyber defence capabilities. These
capabilities will build on full network security perspective, which will include network monitoring, military
CSIRT capabilities, and cyber security of tactical and operational networks.
Besides the core cyber defence capabilities, the document emphasises the needs for development of the legal
and regulatory environment, raising the level of security of electronic data management networks, application
of certified products, increasing security awareness and knowledge, cyber security research and development,
and cooperation between stakeholders.
In late 2014, the Minister of Defence ordered the Military National Security Service to set up and continue to
develop the Computer Incident Response Capability (MilCIRC) and afterwards to establish a Military Computer
48
Emergency Response Team (MilCERT).
The MilCIRC cooperates with GovCERT-Hungary in incident handling, and is authorised to perform vulnerability
49
tests in the military defence sector. MilCIRC is going to be an umbrella organisation incorporating the main
stakeholders of defence sector.
In accordance with the Constitution, the MoD has responsibility only for security of military communications in
peacetime. The Communications, Information Systems and Information Security Directory of the Hungarian
Defence Forces General Staff has basic management functions for operating and security issues of military
networks and a coordination role with governmental organisations, authorities and other partners including
NATO and EU cooperation.
The HDF has its own military communication and information system (CIS), the HDF Network (HDFN) for
supporting the activities of all military organisations from strategic to tactical levels, including cooperation with
partners and NATO organisations. Under the control of the CIS and CIS Security Directorates, the IT Centre of
the Budapest Garrison Brigade has basic network management functions of HDFN including security
mechanisms and elements. HDFN security incident handling capability (HDF CIRC) will be improved according to
the requirements of the mentioned Concept in line with government and NATO requirements.
Hungary joined to the NATO CCD COE as a Sponsoring Nation in June 2010. The country contributes to the main
aims of the Centre of Excellence and participates to enhance the cyber defence capability, cooperation and
information sharing within NATO. Hungary places great emphasis on education, research and development,
and consultation within the CCD COE.
On 1 January 2012, a new disaster management law was adopted by Act CXXVIII of 2011 in Hungary. This law
set three main pillars for disaster management: fire protection, civil protection, and industrial safety. The
National Directorate General for Disaster Management (NDGDM), supervised by the Ministry of Interior, is the
key player in these fields. Its main mission is preventing disasters as an authority, organising and controlling
47
60/2013 (30 September) Minister of Defence decree on Cyber Defence Concept of Hungarian Defence Forces.
<http://www.kozlonyok.hu/kozlonyok/Kozlonyok/13/PDF/2013/10.pdf>.
48
85/2014 (23 December) Minister of Defence decree on the main objectives and key tasks of national defence
organisations for 2015, and determining the main directions of activity of the years 2016-2017.
<http://www.kozlonyok.hu/kozlonyok/Kozlonyok/12/PDF/2014/64.pdf>.
49
185/2015. (VII. 13.) Gov. decree about scope of the governmental incident handling centre and incident handling centre’s
duties and their sphere of action, and about the rules of handling of security incidents, technical investigation of security
incidents and penetration testing.
<http://njt.hu/cgi_bin/njt_doc.cgi?docid=176703.296223 >
11