Cyber risk management in Georgia is no longer purely a private-sector discretion: the Law of Georgia on Information Security imposes mandatory organisational measures on defined subjects — from policy and asset classification to audit, penetration testing and incident response. The first and most consequential question every company must ask is a verification question: does it fall within the scope of this law at all? This page is built around that logic: first the scope, then the obligations, and finally the architecture of responsibility.
Who the Law Covers — the Verification Question
Under Article 3, the law applies to a subject of a critical information system, and to any organisation or agency subordinate or connected to such a subject through employment, internship, contractual or other relations, where within those relations it ensures the availability of an information asset.
The list of critical information system subjects and their criticality classification are approved by government decree, guided by criteria including the severity and scale of the consequences of the system’s disruption or failure, the expected economic loss, the necessity of the services the system provides for the normal functioning of society, and the number of users. The law does not extend to mass media, editorial offices of publishing houses, scientific, educational, religious and public organisations or political parties. At the same time, any legal entity or state authority that is not a subject may voluntarily assume the obligations arising from the law — for many companies this is precisely the route by which best practice becomes a competitive standard.
Policy and Minimum Requirements
Article 4 obliges the subject to adopt internal rules for the use of information security, which define the organisation’s information security policy. The policy must satisfy minimum requirements established with regard to internationally recognised standards, by orders of the competent authorities according to categories. The adopted rules are submitted for review to the competent authority, which analyses the documents and issues binding instructions or recommendations to remedy the defects identified; any change to the rules is likewise notified.
Asset Inventory and Classification
Article 5 governs the first step of risk-based management: the subject inventories its information systems to record every information asset, assigning each a criticality class — confidential or for internal use — while the rest counts as open information. The record describes each asset’s significance, value and existing level of protection, and when an asset is created its class is determined by the author or the responsible person.
Audit and Penetration Testing
Article 6 obliges the subject to conduct an initial and periodic information security audit — an assessment of the management system’s compliance with the minimum standards. The audit concludes with findings whose requirements are mandatory. The same article requires the subject to ensure penetration testing of the information system according to a pre-planned, documented task; the conclusions of that test are equally binding.
Where the audit or the test reveals non-compliance or weaknesses, the subject analyses them and draws up an action plan with a schedule, submitted to the competent authority for agreement within one month of completion. The audit and the test are carried out in cooperation and coordination with the information security manager and the computer security specialist.
People and Incidents
Article 7 requires the subject to designate an information security manager — the person responsible for daily monitoring of the policy, describing assets and access, preparing internal documentation, collecting incident information and organising training. The manager is accountable to the head of the subject or an authorised collegiate body and reports annually.
Article 9 establishes the computer security specialist, who monitors computer systems daily, is available at any time including outside working hours, and immediately passes incident information to the computer incident response team. Article 10 governs the identification of incidents themselves: the subject studies, describes and responds to the incident, while the configuration of the network sensor must exclude any possibility of access to the content data of communications. The subject must respond to the response team’s binding instructions within a reasonable period. Data-protection incident duties form a separate regime on their own page.
Frequently Asked Questions
Below are the questions companies ask most often when planning cybersecurity, answered from the norms of the Law of Georgia on Information Security.
How do I check whether my company is covered?
Decisive under Article 3 are the government-approved list of critical information system subjects and the circle of connected organisations. Checking that list and your relations is the first step.
Can the obligations be assumed voluntarily?
Yes — an entity that is not a subject may voluntarily take on the obligations, which signals seriousness to customers and partners.
What is a penetration test and why is it mandatory?
A test of the system’s penetrability, run to a pre-planned, documented task; the conclusions’ requirements are mandatory for the subject.
Who is responsible for cybersecurity inside the organisation?
Two figures: the information security manager at policy level and the computer security specialist at the daily technical level, who must be reachable at any time.
How We Help on Legal.ge
The lawyers of Legal.ge guide cyber risk management through the full cycle: determining whether your company falls within the law’s scope, building the policy and asset classification system, preparing for audit and penetration testing, and drafting the incident response procedure. Contact us — and your cybersecurity will become part of the routine instead of a leap of faith.
