Official Gazette, 79/2007 Security of Information Article 11 (1) Security of information is the information security area for which determined are implemented as general measures of protection for prevention, detection and removal of damage caused by loss or unauthorised disclosure of classified and unclassified data. (2) Bodies and legal persons referred to in Article 1, paragraph 2 of this Act, who use classified and unclassified data within their scope of work, shall implement the procedures on handling classified and unclassified data, on content and management of the records of classified data access and oversight of information security and stipulated information security measures and standards. INFOSEC Article 12 (1) INFOSEC is the information security area within which information security measures and standards are determined for classified and unclassified data that are processed, stored or transmitted within the information system and the protection of integrity and availability of the information system in the process of planning, designing, making, using and cease of work of the information system. (2) Security accreditation of the information system shall be performed for the information system where classified data of CONFIDENTIAL, SECRET and TOP SECRET degree of secrecy are used. (3) Persons who take part in the process referred to in paragraph 1 of this Article shall have the Certificate with the TOP SECRET degree of secrecy or one degree of secrecy higher than the highest degree of secrecy of classified data that are processed, stored or transmitted in the information systems under their competence. (4) Measures of physical protection of facilities where information systems are located shall be taken in accordance with the highest degree of secrecy of classified data that are processed, stored or transmitted in the said facilities. (5) NSA and NCSA shall form the registry of certified equipment and machines used in the information system of the CONFIDENTIAL, SECRET and TOP SECRET degree of secrecy. Registry of certified equipment and machines shall be formed on the basis of taking over the appropriate registers of international organizations or by own certifying process in accordance with relevant international norms. Industrial Security Article 13 (1) Industrial security is the information security area where stipulated information security measures and standards are applied for tenders or contracts with classified documentation which are binding for legal and natural persons referred to in Article 1, paragraph 3 of this Act. 4

Select target paragraph3