от 15.04.2022 г. № LRU-764
ONLINE TRANSLATE
Law of the Republic of Uzbekistan, от 15.04.2022 г. № LRU-764
Date of entry into force
17.07.2022
Unofficial translation
Suggestion to the documentListen to audioGet a link from a document element
Law of the Republic of Uzbekistan
Suggestion to the documentListen to audioGet a link from a document element
On cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
Adopted by the Legislative Chamber on February 25, 2022
Approved by the Senate on March 17, 2022
Suggestion to the documentListen to audioGet a link from a document element
Suggestion to the documentListen to audioGet a link from a document element
Chapter 1. General provisions
Suggestion to the documentListen to audioGet a link from a document element
Article 1. Purpose of this Law
Suggestion to the documentListen to audioGet a link from a document element
The purpose of this Law is the regulation of relations in the sphere of cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
Article 2. Legislation on cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
The legislation on cybersecurity consists of this Law and other acts of legislation.
Suggestion to the documentListen to audioGet a link from a document element
Ensuring the cybersecurity of the system for operational-search activities on telecommunication networks and communication channels is carried out in the manner established by separate acts of legislation.
Suggestion to the documentListen to audioGet a link from a document element
If an international treaty of the Republic of Uzbekistan establishes rules other than those stipulated by the legislation of the Republic of Uzbekistan on cybersecurity, the rules of the international treaty shall apply.
Suggestion to the documentListen to audioGet a link from a document element
Article 3. Basic concepts
Suggestion to the documentListen to audioGet a link from a document element
The following basic concepts are used in this Law:
Suggestion to the documentListen to audioGet a link from a document element
object of informatization — information systems of various levels and purposes, telecommunication networks, technical means of information processing, and premises where these means are installed and operated.
Suggestion to the documentListen to audioGet a link from a document element
cybercrime — a totality of crimes carried out in cyberspace using software and technical means, with the aim of seizing information, modifying it, destroying it, or hacking information systems and resources.
Suggestion to the documentListen to audioGet a link from a document element
cyberspace — a virtual environment created with the help of information technologies
Suggestion to the documentListen to audioGet a link from a document element
cyber threat — a complex of conditions and factors in cyberspace that pose a threat to the interests of the individual, society, and the state.
Suggestion to the documentListen to audioGet a link from a document element
cybersecurity — the state of protection of the interests of the individual, society, and the state from external and internal threats in cyberspace.
Suggestion to the documentListen to audioGet a link from a document element
cybersecurity incident — an event in cyberspace that resulted in failures in the operation of information systems and (or) violations of the accessibility of information in them, the integrity, and its free use.
Suggestion to the documentListen to audioGet a link from a document element
cybersecurity object — a complex of information systems used in the activity of ensuring cyber protection of information and cybersecurity of national information systems and resources, including critical information infrastructure objects.
Suggestion to the documentListen to audioGet a link from a document element
cybersecurity subject — a legal entity or individual entrepreneur having certain rights and duties related to the possession, use, and disposal of national information resources and the provision of informational electronic services for their use, information protection, and cybersecurity, including critical information infrastructure subjects.
Suggestion to the documentListen to audioGet a link from a document element
cyber protection — a complex of legal, organizational, financial-economic, engineering-technical measures, as well as measures for cryptographic and technical data protection, aimed at preventing cybersecurity incidents, detecting and protecting against cyberattacks, eliminating the consequences of cyberattacks, and restoring the stability and reliability of the operation of telecommunication networks, information systems, and resources.
Suggestion to the documentListen to audioGet a link from a document element
cyberattack — an action posing a threat to cybersecurity, deliberately carried out in cyberspace using hardware, hardware-software, and software tools.
Suggestion to the documentListen to audioGet a link from a document element
critical information infrastructure — a complex of automated control systems, information systems, and resources of networks and technological processes that have important strategic and socio-economic significance.
Suggestion to the documentListen to audioGet a link from a document element
critical information infrastructure objects — informatization systems applied in the sphere of state administration and the provision of state services, defense, ensuring state security, law and order, the fuel and energy complex (nuclear energy), the chemical, petrochemical industries, metallurgy, water use and protection, water supply, agriculture, healthcare, housing and communal services, the banking and financial system, transport, information and communication technologies, ecology and environmental protection, the extraction and processing of strategically important minerals, the production sphere, as well as in other sectors of the economy and the social sphere.
Suggestion to the documentListen to audioGet a link from a document element
critical information infrastructure subjects — state bodies and organizations, as well as legal entities that own critical information infrastructure objects on the rights of ownership, lease, or other legitimate grounds, including legal entities and (or) individual entrepreneurs ensuring the operation and interaction of critical information infrastructure objects.
Suggestion to the documentListen to audioGet a link from a document element
Article 4. Basic principles of ensuring cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
The basic principles of ensuring cybersecurity are:
Suggestion to the documentListen to audioGet a link from a document element
legality;
Suggestion to the documentListen to audioGet a link from a document element
the priority of protecting the interests of the individual, society, and the state in cyberspace;
Suggestion to the documentListen to audioGet a link from a document element
a unified approach to the regulation of the cybersecurity sphere;
Suggestion to the documentListen to audioGet a link from a document element
the priority of participation of domestic producers in the creation of the cybersecurity system;
Suggestion to the documentListen to audioGet a link from a document element
the openness of the Republic of Uzbekistan to international cooperation in ensuring cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
Article 5. Principle of legality
Suggestion to the documentListen to audioGet a link from a document element
In ensuring cybersecurity, the strict observance and fulfillment of the requirements of the Constitution of the Republic of Uzbekistan, this Law, and other acts of legislation is mandatory.
Suggestion to the documentListen to audioGet a link from a document element
Any deviation from the exact execution and observance of the requirements of legislation, regardless of the motives that caused it, is a violation of legality and entails established responsibility.
Suggestion to the documentListen to audioGet a link from a document element
Article 6. Principle of priority of protecting the interests of the individual, society, and the state in cyberspace
Suggestion to the documentListen to audioGet a link from a document element
The protection of the interests of the individual, society, and the state from external and internal threats in cyberspace is a priority in ensuring the state's cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
Article 7. Principle of a unified approach to the regulation of the cybersecurity sphere
Suggestion to the documentListen to audioGet a link from a document element
A unified approach to the regulation of the cybersecurity sphere is ensured by the introduction of a unified state system for cyber protection of information systems and resources, aimed at the organization, monitoring, and control of the process of developing and implementing software and technical means for data processing and protection.
Suggestion to the documentListen to audioGet a link from a document element
The assurance of cybersecurity must be carried out on the basis of unified approaches in forming the system of legal, administrative, and technical regulation of relations in this sphere.
Suggestion to the documentListen to audioGet a link from a document element
Article 8. Principle of priority of participation of domestic producers in the creation of the cybersecurity system
Suggestion to the documentListen to audioGet a link from a document element
When purchasing goods (works, services) necessary for ensuring the cybersecurity of state and economic management bodies, and local state authorities, goods (works, services) produced on the territory of the Republic of Uzbekistan enjoy priority over products manufactured abroad.
Suggestion to the documentListen to audioGet a link from a document element
Article 9. Principle of openness of the Republic of Uzbekistan to international cooperation in ensuring cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
The Republic of Uzbekistan carries out international cooperation in the field of ensuring cybersecurity within the framework of international treaties with international organizations, foreign states, and their competent departments.
Suggestion to the documentListen to audioGet a link from a document element
Chapter 2. State regulation of the cybersecurity sphere
Suggestion to the documentListen to audioGet a link from a document element
Article 10. Unified state policy in the sphere of cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
The unified state policy in the sphere of cybersecurity is determined by the President of the Republic of Uzbekistan.
Suggestion to the documentListen to audioGet a link from a document element
Article 11. Authorized state body in the sphere of cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
The state security service of the Republic of Uzbekistan is the authorized state body in the sphere of cybersecurity (hereinafter — the authorized state body).
Suggestion to the documentListen to audioGet a link from a document element
The powers of the authorized state body in the sphere of cybersecurity include:
Suggestion to the documentListen to audioGet a link from a document element
development of normative legal acts and state programs in the sphere of cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
exercising control over the execution of acts of legislation on cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
carrying out operational-search activities, preliminary inquiries, and investigative actions on cybersecurity incidents;
Suggestion to the documentListen to audioGet a link from a document element
prevention, detection, and preclusion of cybersecurity incidents and taking corresponding measures regarding them, including organizational and technical measures to eliminate their consequences;
Suggestion to the documentListen to audioGet a link from a document element
cyber protection of information systems and resources during emergency situations and the development of plans containing measures on other issues in the sphere of cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
organization of works to ensure cybersecurity, as well as works on the prevention, detection, and elimination of the consequences of cyberattacks on critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
organization of works on the certification of hardware, hardware-software, and software tools in information systems and resources in accordance with cybersecurity requirements;
Suggestion to the documentListen to audioGet a link from a document element
organization of conducting research and monitoring in the sphere of cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
formation of a unified register of critical information infrastructure objects, as well as the organization and assurance of its maintenance;
Suggestion to the documentListen to audioGet a link from a document element
adoption of a decision on the inclusion of objects in the unified register of critical information infrastructure objects based on information submitted by cybersecurity subjects;
Suggestion to the documentListen to audioGet a link from a document element
determination of requirements for ensuring the cybersecurity of critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
determination of the procedure for conducting the attestation of informatization objects and critical information infrastructure objects in accordance with cybersecurity requirements;
Suggestion to the documentListen to audioGet a link from a document element
licensing of activity for the development, production, and realization of means of cryptographic information protection;
Suggestion to the documentListen to audioGet a link from a document element
taking measures to protect the rights and legitimate interests of users of information systems and resources;
Suggestion to the documentListen to audioGet a link from a document element
conducting studies and inspections of information systems and resources of cybersecurity subjects, as well as at critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
development of plans for preventing attempts at cyberattacks on critical information infrastructure objects and their direct implementation;
Suggestion to the documentListen to audioGet a link from a document element
regulation of the activity of cybersecurity subdivisions, services, and groups of independent experts, interaction with law enforcement bodies in the sphere of counteracting cyber threats;
Suggestion to the documentListen to audioGet a link from a document element
informing state and economic management bodies, and local state authorities about vulnerabilities, cyber threats, cyberattacks, and other subversive actions detected in information systems and resources;
Suggestion to the documentListen to audioGet a link from a document element
involvement of law enforcement bodies and critical information infrastructure subjects in the joint investigation of cybersecurity incidents at critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
implementation of international cooperation in the sphere of cybersecurity and the development of common approaches for counteracting cyber threats, the unification of efforts in conducting investigative actions and preventing cybercrime, as well as taking measures to prevent the use of the cyberspace of the Republic of Uzbekistan for terrorist, extremist, and other illegal activity;
Suggestion to the documentListen to audioGet a link from a document element
organization of works on the introduction of means for detecting, preventing, and eliminating the consequences of cyberattacks, as well as taking measures regarding cybersecurity incidents at critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
organization of works on the detection, collection, and analysis of data on existing vulnerabilities and possible threats at critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
creation of a classifier for the level of cybersecurity assurance in information systems and resources;
Suggestion to the documentListen to audioGet a link from a document element
classification of cybersecurity objects by the level of cybersecurity assurance;
Suggestion to the documentListen to audioGet a link from a document element
implementation of activity for the training of personnel in the sphere of cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
determination of mechanisms for conducting expertise for compliance with cybersecurity requirements;
Suggestion to the documentListen to audioGet a link from a document element
determination of methods for assessing and the assessment of the implementation of cybersecurity of cybersecurity objects and critical information infrastructure;
Suggestion to the documentListen to audioGet a link from a document element
determination of criteria for categorization and the categorization of critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
conducting the attestation of employees involved in ensuring the cybersecurity of cybersecurity subjects, in the manner established by legislation.
Suggestion to the documentListen to audioGet a link from a document element
the fulfillment of the legitimate requirements (instructions) of the authorized state body is mandatory.
Suggestion to the documentListen to audioGet a link from a document element
Article 12. Rights of the authorized state body
Suggestion to the documentListen to audioGet a link from a document element
The authorized state body, when exercising powers in the sphere of cybersecurity, has the right to:
Suggestion to the documentListen to audioGet a link from a document element
lease technical, software, and hardware-software tools intended for the detection of cyberattacks, the prevention and elimination of their consequences, as well as taking measures regarding cybersecurity incidents;
Suggestion to the documentListen to audioGet a link from a document element
use technical installations and services free of charge for taking urgent measures to eliminate cyberattacks;
Suggestion to the documentListen to audioGet a link from a document element
visit state bodies and other organizations, get acquainted with necessary documents and materials, as well as request and receive from state bodies and other organizations, and citizens, information and other necessary documents and materials, conduct their identification, and use them in investigative actions on cybersecurity incidents;
Suggestion to the documentListen to audioGet a link from a document element
create a working body for ensuring cybersecurity, as well as transfer a part of its powers to it;
Suggestion to the documentListen to audioGet a link from a document element
issue prescriptions and instructions, mandatory for execution, to cybersecurity subjects regarding the elimination of causes and conditions that contributed to the commission of offenses posing a threat to cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
have unobstructed access and connection, in the established manner, to the information systems and resources of state bodies and organizations, and critical information infrastructure objects, for the purpose of exercising the function of state control and verification of the cybersecurity status, as well as studying data regarding the implementation and operation of means for ensuring the cybersecurity of the information systems and resources of these objects;
Suggestion to the documentListen to audioGet a link from a document element
have access to monitoring systems or critical information infrastructure objects for the implementation of organizational and technical measures when conducting monitoring works to ensure cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
enter residential premises and other objects of physical and legal entities without hindrance, with damage to locking devices and other items if necessary, and inspect them when pursuing persons suspected of committing crimes in the sphere of information technologies, or when there are sufficient grounds to believe that such a crime is being committed or has been committed there, or a person who has escaped from law enforcement bodies is located there, or if delay may threaten the life and health of citizens, with subsequent notification of the prosecutor about this within twenty-four hours, as well as with compensation for the caused harm in the manner established by legislation.
Suggestion to the documentListen to audioGet a link from a document element
Article 13. Duties of the authorized state body
Suggestion to the documentListen to audioGet a link from a document element
The authorized state body, when exercising the assigned powers in the sphere of cybersecurity, is obliged to:
Suggestion to the documentListen to audioGet a link from a document element
take all necessary measures for the prevention, detection, and preclusion of cybercrimes;
Suggestion to the documentListen to audioGet a link from a document element
participate in the preparation and implementation of state programs in the sphere of cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
carry out scientific-research and organizational-methodical activity on problems in the sphere of cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
register appeals and information about cybercrimes and offenses posing a threat to cybersecurity, and timely take measures regarding them in the manner established by legislation;
Suggestion to the documentListen to audioGet a link from a document element
take measures for the prevention of offenses posing a threat to cybersecurity, and the detection and elimination of causes and conditions that contributed to their commission;
Suggestion to the documentListen to audioGet a link from a document element
notify the prosecutor in written form within twenty-four hours about all cases of entry by employees of the authorized state body into the residential premises and other objects of physical and legal entities against the will of the owners and their representatives or in their absence.
Suggestion to the documentListen to audioGet a link from a document element
Other duties may be imposed on the authorized state body in accordance with legislation.
Suggestion to the documentListen to audioGet a link from a document element
Chapter 3. Rights and duties of state bodies and organizations in ensuring cybersecurity. Data backup
Suggestion to the documentListen to audioGet a link from a document element
Article 14. Rights and duties of state bodies and organizations in ensuring cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
State bodies and organizations have the right to:
Suggestion to the documentListen to audioGet a link from a document element
receive from the authorized state body information about cyber threats, vulnerabilities of software, equipment, and technologies for the purpose of ensuring cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
receive from the authorized state body information and consultations about the means and methods of protection against cyberattacks, and the ways of their detection and prevention;
Suggestion to the documentListen to audioGet a link from a document element
develop and implement measures to ensure cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
state bodies and organizations are obliged to:
Suggestion to the documentListen to audioGet a link from a document element
ensure cybersecurity in the information systems and resources under their jurisdiction, the stability of network operation, as well as fulfill their obligations on cybersecurity, and warn the authorized state body about cyberattacks;
Suggestion to the documentListen to audioGet a link from a document element
take measures to prevent cases of theft and falsification of data stored in their information systems and resources;
Suggestion to the documentListen to audioGet a link from a document element
use certified hardware, hardware-software, and software tools for the cyber protection of their information systems and resources;
Suggestion to the documentListen to audioGet a link from a document element
coordinate the normative legal acts in the sphere of cybersecurity and normative documents in the field of technical regulation that are being developed with the authorized state body.
Suggestion to the documentListen to audioGet a link from a document element
Article 15. Data backup
Suggestion to the documentListen to audioGet a link from a document element
Ensuring the storage of data of information systems and resources of state bodies and organizations, as well as critical information infrastructure objects, is carried out in accordance with the internal information security policy by creating a backup copy of data, the storage period of which must not be less than the last three months.
Suggestion to the documentListen to audioGet a link from a document element
Chapter 4. Ensuring cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
Article 16. Rights and duties of cybersecurity subjects
Suggestion to the documentListen to audioGet a link from a document element
Cybersecurity subjects have the right to:
Suggestion to the documentListen to audioGet a link from a document element
receive from the authorized state body information about cyber threats, vulnerabilities of software, equipment, and technologies for the purpose of ensuring their cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
receive information and consultations from the authorized state body about the means and methods of protection against cyberattacks, as well as methods for their detection and prevention;
Suggestion to the documentListen to audioGet a link from a document element
Develop and implement measures to ensure their cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
cybersecurity subjects are obliged to:
Suggestion to the documentListen to audioGet a link from a document element
prevent the illegal dissemination, theft, loss, violation of integrity, blocking, and falsification of data in information systems and resources, as well as other types of unauthorized access (entry) to information systems and resources, and take timely corresponding measures upon the detection of such cases;
Suggestion to the documentListen to audioGet a link from a document element
take measures for the operational restoration of data in information systems and resources in order to minimize negative consequences in case of violation of access procedure and in case of their modification or deletion as a result of unauthorized access to them;
Suggestion to the documentListen to audioGet a link from a document element
notify the authorized state body about occurred cybersecurity incidents and cybercrimes, take measures to prevent the loss of relevant digital traces for the full disclosure of these incidents, and also ensure the permanent storage of information necessary for the analysis of cybersecurity incidents and the investigation of cybercrimes;
Suggestion to the documentListen to audioGet a link from a document element
implement mutual exchange with the authorized state body of data in the sphere of protection and conducting monitoring of the safe operation of cybersecurity objects;
Suggestion to the documentListen to audioGet a link from a document element
observe the cybersecurity requirements determined by the authorized state body in ensuring the cyber protection of information systems and resources;
Suggestion to the documentListen to audioGet a link from a document element
ensure the functioning of mechanisms for taking measures regarding cybersecurity incidents and the operation of subdivisions for ensuring cybersecurity, and in case of their absence — use outsourcing services with the permission of the authorized state body in the established manner;
Suggestion to the documentListen to audioGet a link from a document element
grant the authorized state body the right of access to monitoring systems and (or) cybersecurity objects for the implementation of organizational and technical measures for monitoring the assurance of cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
Article 17. Classification of cybersecurity objects
Suggestion to the documentListen to audioGet a link from a document element
The classification of cybersecurity objects consists of a complex of organizational measures aimed at determining the level of organizational and technical complexity of the type of cybersecurity objects.
Suggestion to the documentListen to audioGet a link from a document element
The categories of cybersecurity objects subject to classification are determined in accordance with legislation.
Suggestion to the documentListen to audioGet a link from a document element
Chapter 4. Ensuring cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
Article 18. Expertise for compliance with cybersecurity requirements
Suggestion to the documentListen to audioGet a link from a document element
Expertise for compliance with cybersecurity requirements is carried out on a mandatory basis or at the initiative of cybersecurity subjects.
Suggestion to the documentListen to audioGet a link from a document element
The following are subject to mandatory expertise for compliance with cybersecurity requirements:
Suggestion to the documentListen to audioGet a link from a document element
information resources of state bodies;
Suggestion to the documentListen to audioGet a link from a document element
information systems of state bodies;
Suggestion to the documentListen to audioGet a link from a document element
information systems included in the category of critical information infrastructure objects.
Suggestion to the documentListen to audioGet a link from a document element
The procedure for conducting expertise for compliance with cybersecurity requirements is determined by the authorized state body.
Suggestion to the documentListen to audioGet a link from a document element
Article 19. Certification of hardware, hardware-software, and software tools used to ensure cybersecurity of information systems and resources
Suggestion to the documentListen to audioGet a link from a document element
Hardware, hardware-software, and software tools used to ensure the cybersecurity of information systems and resources of state bodies and organizations, as well as critical information infrastructure objects, are subject to mandatory certification.
Suggestion to the documentListen to audioGet a link from a document element
The procedure for the certification of hardware, hardware-software, and software tools used to ensure the cybersecurity of information systems and resources is established by the authorized state body.
Suggestion to the documentListen to audioGet a link from a document element
Article 20. Attestation of informatization objects and critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
Attestation of informatization objects and critical information infrastructure objects is a complex of organizational and technical measures aimed at determining the compliance of the actual state of protection of informatization objects with the requirements of state standards and normative legal acts in the sphere of cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
The categories of informatization objects and critical information infrastructure objects subject to attestation are determined in accordance with legislation.
Suggestion to the documentListen to audioGet a link from a document element
The procedure for conducting the attestation of informatization objects and critical information infrastructure objects for compliance with cybersecurity requirements is determined by the authorized state body.
Suggestion to the documentListen to audioGet a link from a document element
Article 21. Assessment of the level of cybersecurity assurance
Suggestion to the documentListen to audioGet a link from a document element
Assessment of the level of cybersecurity assurance is a complex of organizational and technical measures aimed at determining the state of protection of information systems and resources, as well as the effectiveness of the organizational measures being taken.
Suggestion to the documentListen to audioGet a link from a document element
The categories of informatization objects and critical information infrastructure objects subject to mandatory assessment are determined in accordance with legislation.
Suggestion to the documentListen to audioGet a link from a document element
The procedure for assessing the level of cybersecurity assurance is determined by the authorized state body.
Suggestion to the documentListen to audioGet a link from a document element
The authorized state body issues prescriptions, mandatory for execution, on the elimination of deficiencies identified as a result of the assessment.
Suggestion to the documentListen to audioGet a link from a document element
Chapter 5. Cybersecurity incidents
Suggestion to the documentListen to audioGet a link from a document element
Article 22. Investigation of cybersecurity incidents
Suggestion to the documentListen to audioGet a link from a document element
Cybersecurity incidents are investigated by the authorized state body or by officials of the working body for ensuring cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
The owner of an information resource or information system where a cybersecurity incident occurred may conduct an investigation of the cybersecurity incident if they possess the necessary resources and technical capabilities to conduct the investigation. In this case, the authorized state body must be notified of the investigation results.
Suggestion to the documentListen to audioGet a link from a document element
Article 23. Adoption of measures by cybersecurity subjects regarding cybersecurity incidents
Suggestion to the documentListen to audioGet a link from a document element
The adoption of measures by cybersecurity subjects regarding cybersecurity incidents may be carried out in the following forms:
Suggestion to the documentListen to audioGet a link from a document element
prevention of vulnerabilities and errors in software and devices;
Suggestion to the documentListen to audioGet a link from a document element
destruction of malicious programs, restriction of their dissemination, technical restriction of the source of cyberattacks;
Suggestion to the documentListen to audioGet a link from a document element
isolation of informatization objects from real cyber threats;
Suggestion to the documentListen to audioGet a link from a document element
provision of information about cybersecurity incidents to law enforcement bodies.
Suggestion to the documentListen to audioGet a link from a document element
Article 24. Disclosure of information about cybersecurity incidents
Suggestion to the documentListen to audioGet a link from a document element
Information about vulnerabilities, cyber threats, cyberattacks, and other subversive actions detected in information systems and resources, as well as about informatization objects, may be disclosed with the permission of the cybersecurity subject after the adoption of corresponding measures for their protection.
Suggestion to the documentListen to audioGet a link from a document element
Information about detected cyber threats and vulnerabilities must be used exclusively for their elimination and the prevention of illegal actions.
Suggestion to the documentListen to audioGet a link from a document element
Chapter 6. Critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
Article 25. Main directions for ensuring the cybersecurity of critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
The main directions for ensuring the cybersecurity of critical information infrastructure objects are:
Suggestion to the documentListen to audioGet a link from a document element
creation of a unified complex of measures for the regulation of the normative legal, organizational, and technical protection of critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
establishment of requirements for ensuring cybersecurity in the information systems and resources of state bodies and organizations, and at critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
promotion of the creation of conditions for the effective assurance of the cybersecurity of critical information infrastructure objects.
Suggestion to the documentListen to audioGet a link from a document element
Article 26. Categorization of critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
Categorization of critical information infrastructure objects is carried out for the purpose of determining the compliance of critical information infrastructure objects with the categories provided for by part two of this Article, as well as checking the information based on the results of categorization.
Suggestion to the documentListen to audioGet a link from a document element
Critical information infrastructure objects are subdivided into the following categories:
Suggestion to the documentListen to audioGet a link from a document element
critical information infrastructure objects of a high level;
Suggestion to the documentListen to audioGet a link from a document element
critical information infrastructure objects of a medium level;
Suggestion to the documentListen to audioGet a link from a document element
critical information infrastructure objects of a low level.
Suggestion to the documentListen to audioGet a link from a document element
The criteria for the categorization of critical information infrastructure objects are determined by the authorized state body.
Suggestion to the documentListen to audioGet a link from a document element
Article 27. Unified register of critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
The authorized state body maintains the unified register of critical information infrastructure objects.
Suggestion to the documentListen to audioGet a link from a document element
The categories of cybersecurity objects subject to mandatory inclusion in the unified register of critical information infrastructure objects are determined in accordance with legislation.
Suggestion to the documentListen to audioGet a link from a document element
The procedure for entering cybersecurity objects into the unified register of critical information infrastructure objects is determined by the authorized state body.
Suggestion to the documentListen to audioGet a link from a document element
Article 28. Rights and duties of critical information infrastructure subjects
Suggestion to the documentListen to audioGet a link from a document element
Critical information infrastructure subjects have the right to:
Suggestion to the documentListen to audioGet a link from a document element
receive from the authorized state body information about cyber threats, vulnerabilities of software, equipment, and technologies for the purpose of ensuring the cybersecurity of critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
receive information and consultations from the authorized state body about the means and methods of protection against cyberattacks, as well as methods for their detection and prevention;
Suggestion to the documentListen to audioGet a link from a document element
develop and implement measures to ensure the cybersecurity of critical information infrastructure objects.
Suggestion to the documentListen to audioGet a link from a document element
Critical information infrastructure subjects are obliged to:
Suggestion to the documentListen to audioGet a link from a document element
ensure the continuous functioning of the information systems of critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
bring to the attention of the authorized state body information about cybersecurity incidents;
Suggestion to the documentListen to audioGet a link from a document element
provide assistance to officials of the authorized state body or the working body for ensuring cybersecurity in the detection, prevention, and elimination of the consequences of cyberattacks, and the determination of the causes and conditions of the origin of cybersecurity incidents;
Suggestion to the documentListen to audioGet a link from a document element
install and operate monitoring systems while observing the technical requirements for the operation of hardware, software, and hardware-software tools for preventing cyberattacks, eliminating their consequences, as well as taking measures regarding cybersecurity incidents at critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
ensure the security of critical information infrastructure objects in accordance with cybersecurity requirements;
Suggestion to the documentListen to audioGet a link from a document element
fulfill the instructions of the authorized state body on the elimination of detected offenses regarding the assurance of cybersecurity at critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
take measures to eliminate the consequences of cybersecurity incidents and cyberattacks on critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
grant the authorized state body rights of access to monitoring systems or critical information infrastructure objects for the implementation of organizational and technical measures for monitoring the state of cybersecurity assurance;
Suggestion to the documentListen to audioGet a link from a document element
notify the authorized state body upon the change of information about an object included in the unified register of critical information infrastructure objects.
Suggestion to the documentListen to audioGet a link from a document element
Article 29. Requirements for ensuring the cybersecurity of critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
Critical information infrastructure subjects are obliged to fulfill the requirements established by the authorized state body for ensuring cybersecurity at the critical information infrastructure objects belonging to them.
Suggestion to the documentListen to audioGet a link from a document element
Critical information infrastructure subjects, in agreement with the authorized state body and proceeding from the specifics of the work of critical information infrastructure objects, may establish additional requirements for ensuring cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
Employees responsible for ensuring the cybersecurity of critical information infrastructure objects undergo attestation conducted by the authorized state body, in the manner established by legislation.
Suggestion to the documentListen to audioGet a link from a document element
The system for ensuring the cybersecurity of critical information infrastructure objects, created by the critical information infrastructure subject, is connected to the system for monitoring and managing cybersecurity incidents of critical information infrastructure objects of the authorized state body, based on the decision of the authorized state body.
Suggestion to the documentListen to audioGet a link from a document element
Article 30. System for ensuring the cybersecurity of critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
The system for ensuring the cybersecurity of critical information infrastructure objects consists of:
Suggestion to the documentListen to audioGet a link from a document element
The system for monitoring and managing cybersecurity incidents of critical information infrastructure objects of the authorized state body;
Suggestion to the documentListen to audioGet a link from a document element
Systems for ensuring the cybersecurity of critical information infrastructure objects.
Suggestion to the documentListen to audioGet a link from a document element
Information about cybersecurity incidents in the cybersecurity assurance system is restricted for dissemination. This information may be disclosed after the complete elimination of the incidents.
Suggestion to the documentListen to audioGet a link from a document element
Article 31. Assessment of the cybersecurity of critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
Assessment of the cybersecurity of critical information infrastructure objects is carried out for the purpose of determining the state (level) of protection of these objects from various cyber threats within the framework of state control in the sphere of cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
Assessment of the cybersecurity of critical information infrastructure objects is carried out with the permission of the authorized state body and with the involvement of specialized organizations.
Suggestion to the documentListen to audioGet a link from a document element
Chapter 7. Support and development in the sphere of cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
Article 32. State support for cybersecurity subjects
Suggestion to the documentListen to audioGet a link from a document element
State support for cybersecurity subjects includes:
Suggestion to the documentListen to audioGet a link from a document element
improvement of the normative legal base in the sphere of cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
provision of tax, customs benefits, and preferences to cybersecurity subjects;
Suggestion to the documentListen to audioGet a link from a document element
creation of conditions for attracting funds from economic entities for financing the sphere of cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
organization of state procurement in the sphere of cybersecurity, aimed at ensuring the guaranteed implementation of products and advanced technologies based on scientific and technical achievements;
Suggestion to the documentListen to audioGet a link from a document element
rendering assistance in the training and retraining of personnel in the sphere of cybersecurity, as well as enhancing their qualifications.
Suggestion to the documentListen to audioGet a link from a document element
Article 33. Support for scientific, technical, and innovation activity in the sphere of cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
Support for scientific, technical, and innovation activity in the sphere of cybersecurity is carried out by state administration bodies, local state authorities, and economic entities through:
Suggestion to the documentListen to audioGet a link from a document element
placing orders for the execution of scientific research, experimental design, and technological works within the framework of the state order;
Suggestion to the documentListen to audioGet a link from a document element
allocation of subsidies to cybersecurity subjects for financing scientific research, design, and technological works conducted in the process of implementing investment projects;
Suggestion to the documentListen to audioGet a link from a document element
stimulation of demand for innovation products, including the optimization of goods (works, services) purchased for state needs;
Suggestion to the documentListen to audioGet a link from a document element
rendering financial assistance to organizations implementing projects for improving the level of cybersecurity, including those engaged in innovation activity in the provision of services using existing advanced technologies;
Suggestion to the documentListen to audioGet a link from a document element
creation of conditions for the implementation of scientific, scientific-technical, and innovation activity in the sphere of cybersecurity and the assurance of the cybersecurity of critical information infrastructure objects;
Suggestion to the documentListen to audioGet a link from a document element
granting priority to domestically produced products when conducting state procurement related to ensuring cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
Article 34. Development and support of personnel potential in the sphere of ensuring cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
Support for the development of personnel potential of state administration bodies, local state authorities, and economic entities in the sphere of ensuring cybersecurity may be carried out through:
Suggestion to the documentListen to audioGet a link from a document element
provision of financial, informational, and consultative assistance to organizations carrying out activity on the retraining and professional development of personnel in the sphere of ensuring cybersecurity;
Suggestion to the documentListen to audioGet a link from a document element
rendering educational-methodological and scientific-pedagogical assistance in the sphere of ensuring cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
Employees responsible for ensuring the cybersecurity of critical information infrastructure subjects must constantly improve their qualifications in accordance with international and state standards and requirements.
Suggestion to the documentListen to audioGet a link from a document element
Article 35. Stimulation of employees responsible for ensuring the cybersecurity of critical information infrastructure objects
Suggestion to the documentListen to audioGet a link from a document element
Stimulation of employees responsible for ensuring the cybersecurity of critical information infrastructure objects is carried out in the manner established by legislation.
Suggestion to the documentListen to audioGet a link from a document element
Chapter 8. Final Provisions
Suggestion to the documentListen to audioGet a link from a document element
Article 36. International Cooperation in the Sphere of Cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
The authorized state body, within the limits of its powers, carries out international cooperation in the sphere of cybersecurity.
Suggestion to the documentListen to audioGet a link from a document element
The authorized state body, in accordance with the legislation and international treaties of the Republic of Uzbekistan, provides foreign states and international organizations, upon request, with information on issues of combating international cybercrime.
Suggestion to the documentListen to audioGet a link from a document element
Information on issues of combating international cybercrime may be provided to foreign states and international organizations in advance without a request, if such information does not impede investigative actions or court proceedings and serves to suspend cyberattacks, and the timely detection and elimination of criminal actions committed using cyberspace.
Suggestion to the documentListen to audioGet a link from a document element
Article 37. Responsibility for violation of legislation on cybersecurity
Suggestion to the documentListen to audioGet a link from a document element
Persons guilty of violating legislation on cybersecurity bear responsibility in the established manner.
Suggestion to the documentListen to audioGet a link from a document element
Article 38. Ensuring the execution, delivery, explanation of the essence and significance of this Law
Suggestion to the documentListen to audioGet a link from a document element
The state security service of the Republic of Uzbekistan and other interested organizations are to ensure the execution, delivery to executors, and explanation among the population of the essence and significance of this Law.
Suggestion to the documentListen to audioGet a link from a document element
Article 39. Bringing legislation into compliance with this Law
Suggestion to the documentListen to audioGet a link from a document element
The Cabinet of Ministers of the Republic of Uzbekistan is to:
Suggestion to the documentListen to audioGet a link from a document element
bring government decisions into compliance with this Law;
Suggestion to the documentListen to audioGet a link from a document element
ensure the review and cancellation by state administration bodies of their normative legal acts that contradict this Law.
Suggestion to the documentListen to audioGet a link from a document element
Article 40. Entry into force of this Law
Suggestion to the documentListen to audioGet a link from a document element
This Law enters into force upon the expiration of three months from the day of its official publication.
Suggestion to the documentListen to audioGet a link from a document element
President of the Republic of Uzbekistan SH. MIRZIYOYEV
Suggestion to the documentListen to audioGet a link from a document element
Tashkent,
Suggestion to the documentListen to audioGet a link from a document element
April 15, 2022,
Suggestion to the documentListen to audioGet a link from a document element
No. LRU-764