Inventory and Classification of Information Assets
Under Article 5 of the law on information security, a critical information system subject must inventory its information systems to record every information asset. Each asset is assigned a criticality class — confidential or internal-use — while all other assets are open information. The inventory describes each asset’s significance, value and existing protection level; at creation, the class is set by the author or responsible person. Asset management rules for first- and second-category subjects are set by order of the head of the Operative-Technical Agency, for the third category — by the Digital Governance Agency, in defense — by the Minister of Defense; for commercial banks, additional standards come from the National Bank.
Information Security Audit and Penetration Testing
Under Article 6, the subject must conduct an initial and a periodic information security audit — an assessment of compliance with the minimum standards — ending with a conclusion whose requirements are mandatory. The initial audit of a first-category subject is carried out free of charge by the Operative-Technical Agency; the periodic audit — by the Agency or an organization authorized by the Digital Governance Agency. For second-category subjects the same bodies apply, for the third — the Digital Governance Agency or an authorized organization, in defense — the Cybersecurity Bureau. Audit requirements do not apply to payment, securities settlement and reserve management systems, nor to systems used for monetary and currency operations. Under the same rules a penetration test is carried out — per a pre-planned, documented task — ending with a mandatory conclusion. Where weaknesses are found, the subject draws up an action plan with a schedule and submits it for approval within 1 month to the relevant authority; for commercial banks — the National Bank. The audit proceeds in cooperation with the information security manager and the computer security specialist.
Authorization of Auditors
Article 6-1 defines who may conduct audits and penetration tests: an organization that has passed authorization at the Digital Governance Agency. The person carrying out the audit must have passed a security check under a procedure set by a normative act of the head of the State Security Service. In commercial banks, organizations from an additional list of authorized organizations may also be engaged, submitted by the National Bank to the Digital Governance Agency.
The Information Security Manager and the Computer Security Specialist
Under Article 7, the subject designates an information security manager responsible for fulfilling security requirements. The duties include daily monitoring of policy compliance, description of assets, internal documentation, incident information collection, reporting and training. The manager draws up an action plan and reports annually — first- and second-category subjects also to the Operative-Technical Agency, the third — to the Digital Governance Agency. Under Article 9, a computer security specialist is designated for the practical protection of computer systems. The specialist identifies incidents and immediately informs the relevant response team — of the Operative-Technical Agency for the first two categories, of the Digital Governance Agency for the third, and of the Cybersecurity Bureau in defense — and must be available at any time, ensuring coordination during the elimination of a cyberattack.
State Inspection and Additional Requirements
Article 9-1 entitles the Operative-Technical Agency to inspect the information technology infrastructure of a first-category subject for security purposes, covering the internal and external network, its configuration, hardware and software used for data, and connection rules. The inspection proceeds jointly with the manager and specialist and ends with a conclusion signed by the inspector and the subject’s representative — or, on refusal, by at least 2 attending persons. Where signs of a crime appear, the materials go immediately to the investigative body. The subject must fulfill binding instructions and agree planned infrastructure changes with the Agency in advance. Article 8-2 adds requirements: those related to countries of manufacture of hardware and software are set by the government, and for classified information exchange the Agency creates a special system on a special optical-fiber network; an electronic document created there has the force of a physical one.
Frequently Asked Questions
Who conducts the audit?
The initial audit of a first-category subject is conducted free of charge by the Operative-Technical Agency; the periodic audit — by the Agency or an organization authorized by the Digital Governance Agency, and in the defense sector — by the Cybersecurity Bureau.
What happens with defects found in an audit?
The subject analyzes the defects and draws up an action plan with a schedule, which it submits for approval to the relevant authority within 1 month of completion.
Who is the information security manager?
A person designated by the subject, responsible for fulfilling security requirements, who draws up the action plan and submits an annual report.
Do these requirements apply to payment systems?
No — the requirements of the audit, of the penetration test and of the inspection of the information technology infrastructure do not apply to payment systems, to securities settlement and reserve management systems, nor to critical systems used for monetary and currency operations.
How We Help on Legal.ge
On Legal.ge we help subjects plan their statutory obligations — from inventory to audit and approval of action plans. Contact our team on any compliance issue.
