Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Military & National Security Law
  3. National Security
  4. Cybersecurity Defense
  5. Critical Infrastructure Protection

Loading...

Cybersecurity Defense

Critical Infrastructure Protection

What is the inventory of information assets?

The recording of every information asset with the assignment of a criticality class: confidential, internal-use or open information.

Within what period must an action plan be submitted?

Within 1 month of completion of the audit or penetration test, for approval by the relevant authority.

Whom does the specialist notify of an incident?

The computer security specialist immediately notifies the relevant authority’s computer incident response team.

Who inspects a first-category subject?

The Operative-Technical Agency may inspect its information technology infrastructure — covering networks, configurations and equipment.

4 min·...

Inventory and Classification of Information Assets

Under Article 5 of the law on information security, a critical information system subject must inventory its information systems to record every information asset. Each asset is assigned a criticality class — confidential or internal-use — while all other assets are open information. The inventory describes each asset’s significance, value and existing protection level; at creation, the class is set by the author or responsible person. Asset management rules for first- and second-category subjects are set by order of the head of the Operative-Technical Agency, for the third category — by the Digital Governance Agency, in defense — by the Minister of Defense; for commercial banks, additional standards come from the National Bank.

Information Security Audit and Penetration Testing

Under Article 6, the subject must conduct an initial and a periodic information security audit — an assessment of compliance with the minimum standards — ending with a conclusion whose requirements are mandatory. The initial audit of a first-category subject is carried out free of charge by the Operative-Technical Agency; the periodic audit — by the Agency or an organization authorized by the Digital Governance Agency. For second-category subjects the same bodies apply, for the third — the Digital Governance Agency or an authorized organization, in defense — the Cybersecurity Bureau. Audit requirements do not apply to payment, securities settlement and reserve management systems, nor to systems used for monetary and currency operations. Under the same rules a penetration test is carried out — per a pre-planned, documented task — ending with a mandatory conclusion. Where weaknesses are found, the subject draws up an action plan with a schedule and submits it for approval within 1 month to the relevant authority; for commercial banks — the National Bank. The audit proceeds in cooperation with the information security manager and the computer security specialist.

Authorization of Auditors

Article 6-1 defines who may conduct audits and penetration tests: an organization that has passed authorization at the Digital Governance Agency. The person carrying out the audit must have passed a security check under a procedure set by a normative act of the head of the State Security Service. In commercial banks, organizations from an additional list of authorized organizations may also be engaged, submitted by the National Bank to the Digital Governance Agency.

The Information Security Manager and the Computer Security Specialist

Under Article 7, the subject designates an information security manager responsible for fulfilling security requirements. The duties include daily monitoring of policy compliance, description of assets, internal documentation, incident information collection, reporting and training. The manager draws up an action plan and reports annually — first- and second-category subjects also to the Operative-Technical Agency, the third — to the Digital Governance Agency. Under Article 9, a computer security specialist is designated for the practical protection of computer systems. The specialist identifies incidents and immediately informs the relevant response team — of the Operative-Technical Agency for the first two categories, of the Digital Governance Agency for the third, and of the Cybersecurity Bureau in defense — and must be available at any time, ensuring coordination during the elimination of a cyberattack.

State Inspection and Additional Requirements

Article 9-1 entitles the Operative-Technical Agency to inspect the information technology infrastructure of a first-category subject for security purposes, covering the internal and external network, its configuration, hardware and software used for data, and connection rules. The inspection proceeds jointly with the manager and specialist and ends with a conclusion signed by the inspector and the subject’s representative — or, on refusal, by at least 2 attending persons. Where signs of a crime appear, the materials go immediately to the investigative body. The subject must fulfill binding instructions and agree planned infrastructure changes with the Agency in advance. Article 8-2 adds requirements: those related to countries of manufacture of hardware and software are set by the government, and for classified information exchange the Agency creates a special system on a special optical-fiber network; an electronic document created there has the force of a physical one.

Frequently Asked Questions

Who conducts the audit?

The initial audit of a first-category subject is conducted free of charge by the Operative-Technical Agency; the periodic audit — by the Agency or an organization authorized by the Digital Governance Agency, and in the defense sector — by the Cybersecurity Bureau.

What happens with defects found in an audit?

The subject analyzes the defects and draws up an action plan with a schedule, which it submits for approval to the relevant authority within 1 month of completion.

Who is the information security manager?

A person designated by the subject, responsible for fulfilling security requirements, who draws up the action plan and submits an annual report.

Do these requirements apply to payment systems?

No — the requirements of the audit, of the penetration test and of the inspection of the information technology infrastructure do not apply to payment systems, to securities settlement and reserve management systems, nor to critical systems used for monetary and currency operations.

How We Help on Legal.ge

On Legal.ge we help subjects plan their statutory obligations — from inventory to audit and approval of action plans. Contact our team on any compliance issue.

Updated: ...

Find a Specialist

Professionals working in this field

Military & National Security Law LawyerMilitary & National Security Law Attorney