LEGAL FRAMEWORK

LIST OF LEGISLATION DOCUMENTS ABOUT CYBERSECURITY IN UKRAINE

Legislative and conceptual acts
  • Law of Ukraine "On the Basic Principles of Cyber Security of Ukraine".
https://zakon.rada.gov.ua/laws/show/2163-19#Text

  • Resolution of the Cabinet of Ministers of Ukraine "On approval of general requirements for cyber protection of critical infrastructure".
https://zakon.rada.gov.ua/laws/show/518-2019-%D0%BF#n8

  • Law of Ukraine "On Information".
https://zakon.rada.gov.ua/laws/show/2657-12#Text

  • Law of Ukraine "On protection of information in information and telecommunication systems".
https://zakon.rada.gov.ua/laws/show/80/94-%D0%B2%D1%80#Text

  • Law of Ukraine "On State Secrets".
https://zakon.rada.gov.ua/laws/show/3855-12#Text

  • Law of Ukraine "On electronic documents and electronic document management".
https://zakon.rada.gov.ua/laws/show/851-15#Text

  • The doctrine of information security.
https://zakon.rada.gov.ua/laws/show/47/2017#Text

  • Law of Ukraine "On National Security of Ukraine".
https://zakon.rada.gov.ua/laws/show/2469-19#Text

  • Article 15 of the Constitution of Ukraine. Control over the legality of cybersecurity measures in Ukraine.
https://protocol.ua/ua/pro_osnovni_zasadi_zabezpe_vid_05_10_2017_2163_viii_stattya_15/

  • The concept of development of the digital economy and society of Ukraine for 2018-2020.
https://zakon.rada.gov.ua/laws/show/67-2018-%D1%80.#n250
National Standards of Ukraine
  • State standard of symmetric information encryption «Калина» (ДСТУ 7624: 2015).

  • State hashing standard «Купина» (ДСТУ 7564: 2014).

Sectoral standardization of cybersecurity in Ukraine
  • Resolution of the Cabinet of Ministers of Ukraine "On approval of general requirements for cyber protection of critical infrastructure".
https://zakon.rada.gov.ua/laws/show/518-2019-%D0%BF#Text

  • Memorandum of Cooperation and Cooperation in the Field of Cyber ​​Security and Cyber ​​Defense, aimed at preventing, detecting, effectively responding to and counteracting current cyber threats, raising the level of information security and situational awareness in the field of cyber security and cyber security.
https://interacademy.info/ekspert-mizhnarodnoi-akademii-informatsii-vziav-uchast-u-pidpysanni-memorandumu-pro-vzaiemodiiu/

  • NERC Series of Critical Information Infrastructure Protection Standards.
https://www.nerc.com/pa/Stand/Pages/CIPStandards.aspx

  • Resolution №95 "On the organization of measures to ensure information security in the banking system of Ukraine."
https://bank.gov.ua/ua/legislation/Resolution_28092017_95

  • Resolution of the NBU Board "On approval of the Regulation on information protection and cyber protection in payment systems".
https://bank.gov.ua/admin_uploads/article/Project_of_resolution_11082020.pdf?v=4

  • Resolution of the NBU Board "On approval of regulations on information security".
https://bank.gov.ua/ua/legislation/Resolution_26112015_829

  • Resolution of the Board of the NBU "On approval of the Rules for the organization of protection of electronic banking documents using the means of information protection of the National Bank of Ukraine".
https://zakon.rada.gov.ua/laws/show/z0419-07
LIST OF INTERNATIONAL STANDARDS, DOCUMENTS AND LEGISLATIVE REGULATIONS ABOUT CYBERSECURITY ISSUES
ISO / IEC series of standards
  • ISO/IEC27000:2019 - Information technology — Security techniques — Information security management systems — Overview and vocabulary

  • ISO/IEC 27001:2013 - Informationtechnology - Security techniques - Information security management systems - Requirements

  • ISO/IEC 27002:2013/COR 2:2015 - Information technology — Security techniques — Code of practice for information security controls


  • ISO/IEC 27003:2017 - Information technology — Security techniques — Information security management systems — Guidance

  • ISO/IEC 27004:2016 - Information technology — Security techniques — Information security management ― Monitoring, measurement, analysis and evaluation

  • ISO/IEC 27005:2018 - Information technology — Security techniques — Information security risk management

  • ISO/IEC 27006:2015/AMD 1:2020 - Information technology — Security techniques — Requirements for bodie sproviding audit and certification of information security management systems

  • ISO/IEC 27007:2020 - Information security, cybersecurity and privacy protection — Guidelines for information security management systems auditing

  • ISO/IEC 15408-1:2009 - Common Criteria for Information Technology Security Evaluation

  • ISO/IEC TS 27008:2019 - Методи безпеки - Вказівки для оцінки засобів контролю інформаційної безпеки

  • ISO27032 – Information Technology. Methods of protection

  • ISO 27035 – Incident management

  • ISO 22301 – Business continuity management systems

  • ISO31000 – Risk management
Other international standards
  • Cybersecurity standard ANSI / ISA 62443

  • Payment Card Industry Data Security Standard (PCI DSS)

  • COBIT5 (Control Objectives for Information and Related Technologies) / Objectives of information and related technologies management

  • COSOERM2017 enterprise risk management system

  • TheCISCriticalSecurityControlsforEffectiveCyberDefensev7.1 / Important security measures Central Internet security to provide effective cybersecurity

  • Microsoft Operations Framework (MOF) 4.0
European Union. General provisions on cybersecurity
  • REGULATION (EU) 2019/881 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 17 April 2019 on ENISA (the European Union Agency for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU) No 526/2013 (Cybersecurity Act)
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32019R0881&from=EN


  • DIRECTIVE (EU) 2016/1148 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 6 July 2016 concerning measures for a high common level of security of network and information systems across the Union
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016L1148&from=EN


  • COMMISSION RECOMMENDATION (EU) 2017/1584 of 13 September 2017 on coordinated response to large-scale cybersecurity incidents and crises
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32017H1584&from=EN


  • COMMISSION RECOMMENDATION (EU) 2019/534 of 26 March 2019 Cybersecurity of 5G networks
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32019H0534&from=ES


  • Resilience, Deterrence and Defense: Building strong cyber security for the EU
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52017JC0450&from=EN


  • DIRECTIVE 2002/58/EC OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32002L0058&from=EN


  • REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCILof 27 April 2016on the protection of natural persons with regard to the processing of personal data and on the freemovement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN

  • COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL on Promoting Data Protection by Privacy Enhancing Technologies
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52007DC0228&from=EN


  • Cybersecurity Strategy of the European Union: An Open, Safe and Secure Cyberspace
https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52013JC0001&from=EN


  • Strengthening Europe’s Cyber Resilience System and Fostering a Competitive and Innovative Cybersecurity Industry
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52016DC0410


  • CONVENTION ON CYBERCRIME 23.XI.2001
https://www.europarl.europa.eu/meetdocs/2014_2019/documents/libe/dv/7_conv_budapest_/7_conv_budapest_en.pdf
Cybersecurity in the field of critical infrastructure protection
  • Communication from the Commission on a European Programme for Critical Infrastructure Protection
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52006DC0786

  • A Framework Strategy for a Resilient Energy Union with a Forward-Looking Climate Change Policy
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM:2015:80:FIN

  • Council Directive 2008/114/EC of 8 December 2008 on the identification and designation of European critical infrastructures and the assessment of the need to improve their protection
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv %3AOJ.L_.2008.345.01.0075.01.ENG

  • Commission Recommendation on cybersecurity in the energy sector
https://ec.europa.eu/energy/sites/ener/files/swd2019_1240_final.pdf

  • Recommendations to the European Commissionfor the Implementation of Sector-Specific Rules for Cybersecurity Aspects
https://ec.europa.eu/energy/sites/ener/files/sgtf_eg2_report_final_report_2019.pdf

  • Cybersecurity in the Energy Sector
https://ec.europa.eu/energy/sites/ener/files/documents/eecsp_report_final.pdf

  • Cybersecurity in Finance
https://www.ceps.eu/wp-content/uploads/2018/06/TFRCybersecurityFinance.pdf

  • Guidance on cyber resilience for financial market infrastructures
https://www.ecb.europa.eu/paym/pol/shared/pdf/CPMI_IOSCO_Guidance_on_cyber_resilience_for_FMIs.pdf

  • Cyber Information and Intelligence Sharing Initiative
https://www.ecb.europa.eu/paym/groups/euro-cyber-board/shared/pdf/ciisi-eu_practical_example.pdf

  • NERC CIP Standards
https://blog.rsisecurity.com/nerc-cip-standards-what-you-need-to-know/

  • CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY ACT 2018
https://www.congress.gov/115/plaws/publ278/PLAW-115publ278.pdf

  • NIPP 2013: Partnering for Critical Infrastructure Security and Resilience
https://www.dhs.gov/sites/default/files/publications/National-Infrastructure-Protection-Plan-2013-508.pdf

  • ExecutiveOrder 13636 — Improving Critical Infrastructure Cybersecurity
https://fas.org/irp/offdocs/eo/eo-13636.pdf

  • Framework for Improving Critical Infrastructure Cybersecurity
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
Regulating cybersecurity issues in the United States
  • Cybersecurity Information Sharing Act of 2015
https://www.congress.gov/114/bills/s754/BILLS-114s754es.pdf

  • Health Insurance, Portability and Accountability Act of 1996
https://www.govinfo.gov/content/pkg/CRPT-104hrpt736/pdf/CRPT-104hrpt736.pdf

  • Financial Modernization Act (Gramm-Leach-Bliley Act) of 1999
https://www.congress.gov/106/plaws/publ102/PLAW-106publ102.pdf

  • Internal Security Act of 2002
https://www.dhs.gov/xlibrary/assets/hr_5005_enr.pdf

  • NIST Special Publication 800-82 – Guide to Industrial Control Systems Security
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf

  • NIST Special Publication 800-50 - Building an Information Technology Security Awareness and Training Program
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-50.pdf

  • NIST Special Publication 800-40 - Guide to Enterprise Patch Management Technologies
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r3.pdf

  • NIST Special Publication 800-53 – Security and Privacy Controls for Federal Information Systems and Organizations
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf

  • NIST Special Publication 800-63-3 – Digital Identity Guidelines
https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63-3.pdf
ADDRESS:

03115, Ukraine,
Kyiv City, Peremogy Ave., 121-b,
office 224
CONTACTS:

+38(044)454-07-92
info@ligabezinfo.org