The role and legal basis of an incident response plan
An incident response plan is the document that gives an organization direction in its critical hours: who does what, whom to notify, which system is restored first. In Georgia such a plan is not merely good will — the Law on Critical Information Systems and Cybersecurity obliges subjects of critical information systems to adopt internal information-security documents, to designate responsible persons, and to have those persons draw up an action plan. This page examines what the plan must contain, who owns it inside the organization, and how the state verifies its operation — the response process and the notification duties are covered on a separate page.
Information security rules and minimum requirements
Under point 1 of Article 4 of the law, the subject must adopt internal rules on the use of information security that serve the implementation of the law and define the organization's information security policy — the response plan is part of precisely that policy. The policy must satisfy minimum requirements set with regard to the standards of the International Organization for Standardization (ISO), the United States National Institute of Standards and Technology (NIST) and the Information Systems Audit and Control Association (ISACA) — the plan must therefore rest on internationally recognized foundations. The adopted rules are submitted for review to the Operational-Technical Agency, the Digital Governance Agency or the Cybersecurity Bureau according to category; any change is notified, and the agencies analyze the documents and issue binding instructions or recommendations to remedy deficiencies. For commercial banks, additional standards are set by the National Bank — the plan's authors must take this layer into account as well.
The manager and the specialist — the human ring of the plan
Article 7 of the law designates the person who keeps the plan alive day to day: the subject must designate an information security manager — a specific person or employee responsible for fulfilling the security requirements. The manager's duties include daily monitoring of the policy's implementation; describing information assets and access to them; preparing internal documentation; collecting incident information and monitoring response; reporting; and organizing trainings. The manager is accountable to the head of the organization or an authorized person, and it is the manager who draws up the information security action plan, reporting annually on its execution to the leadership — and, for the relevant categories, also to the Operational-Technical Agency, the Digital Governance Agency or the Cybersecurity Bureau. The plan is thus not a shelf document: its execution is reviewed every year and reported upward.
Article 9 defines the second ring: the computer security specialist, responsible for the practical security of computer systems. The specialist's duties are daily monitoring and assessment of the systems; identification of and response to incidents and immediate delivery of information to the relevant response team; analysis of incidents and security measures and reporting; and coordination with the team. The specialist must be available at any time, including outside working hours, and during the elimination of a cyberattack maintains permanent coordination with the relevant team. Where an ongoing or anticipated attack poses a particular threat to the state's defense capability, economic security, or the normal functioning of state power and society, the Operational-Technical Agency may temporarily coordinate the actions of specialists and the Digital Governance Agency's team. In the plan, responsibility for each stage of an incident should be distributed precisely between these two roles — the manager and the specialist.
Infrastructure verification — the state's test of the plan
The law also verifies the plan's operation through state inspection. To check the security of a first-category subject's information-technology infrastructure, the Operational-Technical Agency may decide to conduct an inspection, indicating the identity of the authorized person and the scope of the inspection. The inspection may cover the internal network, the external access point, the network configuration, the security tools, the hardware and software connected to the network and the rules of their connection. The authorized person may use special technical means, examine documents at their location, take copies and demand written or oral explanations; information unrelated to the infrastructure's functioning is beyond reach. The inspection is conducted in cooperation with the manager, the specialist or other authorized representatives, and results in a conclusion — with recommendations or binding instructions and deadlines for their execution. If signs of a crime emerge in the violation, the materials are immediately submitted to the investigative body. The subject must carry out the instructions and pre-agree with the Operational-Technical Agency any planned changes in the infrastructure that may affect their execution.
Frequently Asked Questions
Who owns the plan?
The information security manager, accountable to the head or a collegiate organ; he also organises general and sectoral trainings.
Who identifies an incident?
The computer security specialist, who immediately passes information to the assistance group and ensures coordination with it.
What must the plan rest on?
Internal rules that satisfy the minimum requirements and are submitted to the competent agency for review.
What a good plan must contain
From the law's requirements it follows that a response plan must rest on the adopted internal rules and minimum requirements, define the roles of the manager and the specialist, describe information assets and access, include procedures for collecting and monitoring incident information, channels for notifying the relevant response teams, and a training schedule. The plan is tied annually to an action report, and changes are notified to the agencies — it is a living document whose quality directly determines the organization's readiness. The Legal.ge team assists in drafting a response plan and an information security policy aligned with internal rules and international standards.
How We Help on Legal.ge
The lawyers of Legal.ge align the response plan with the requirements of the law and help document it. Contact us.
