Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Cybersecurity Law
  4. Cybersecurity Compliance
  5. Cybersecurity Policy Development

Loading...

Cybersecurity Compliance

Cybersecurity Policy Development

Who is obliged to adopt an information security policy?

A subject of a critical information system. It must have adopted internal-use rules defining the organisation's policy and satisfying the minimum requirements of information security established under the law.

Where does the content of the minimum requirements come from?

They are established taking into account the standards of ISO, NIST and ISACA: for first- and second-category subjects by order of the head of the Operational-Technical Agency, and for third-category subjects by order of the chairperson of the Digital Governance Agency. For commercial banks the National Bank establishes additional standards.

To whom are the adopted rules submitted?

By category: first and second categories — to the Operational-Technical Agency; third category — to the Digital Governance Agency; the defence sphere — to the Cyber Security Bureau. Changes are notified as well, and binding instructions or recommendations are issued on defects found.

Can the manager and specialist roles be merged in one person?

The law defines two distinct roles: the manager monitors compliance with the requirements and reports to the leadership, while the specialist is responsible for the practical security of systems and incident response. The organisational decision is yours, but both functions must be designated.

5 min·...

An information security policy: what the law requires

Developing a cybersecurity policy in Georgia is not merely a private corporate matter. The Law of Georgia on Information Security obliges subjects of critical information systems to adopt internal-use rules that define the organisation's information security policy. That policy must satisfy the minimum requirements established under the law, and its constituent elements — asset management, responsible officers and their functions — are themselves regulated by statute. On this page we explain what a lawful policy must contain, who is called the information security manager and the computer security specialist, and how the document connects with the oversight of state agencies.

The essential content of the policy and the minimum requirements

Under the law, a subject of a critical information system must adopt internal-use rules for information security that serve the implementation of the law's provisions and define the organisation's information security policy. The policy, in turn, must satisfy the minimum requirements of information security. Those requirements are established by taking into account the standards and requirements set by the International Organization for Standardization (ISO), the United States National Institute of Standards and Technology (NIST) and the Information Systems Audit and Control Association (ISACA) — for subjects of the first and second categories by order of the head of the Operational-Technical Agency, and for subjects of the third category by order of the chairperson of the Digital Governance Agency. Policy drafting therefore begins with studying those orders: a document that does not reflect them will be treated as deficient when it is submitted to the supervisory agency.

The adopted rules must be submitted for review to the relevant agency: subjects of the first and second categories — to the Operational-Technical Agency; subjects of the third category — to the Digital Governance Agency; and subjects within the defence sphere — to the Cyber Security Bureau. The agencies are also notified of any change made to the rules. They carry out a general analysis of the submitted documents and, to cure the defects found, submit binding instructions or recommendations for execution. In addition, the agencies are empowered to demand from the subject other information connected with the development, deployment, monitoring and improvement of the policy. A separate regime applies to commercial banks: the National Bank of Georgia is authorised to demand the submission of their internal-use rules and to issue binding instructions or recommendations with respect to the additional standards and requirements it establishes for them.

Information asset management — the foundation of the policy

A policy must be built on a real register of assets. The law obliges the subject to carry out an inventory of information systems for the purpose of recording all information assets, as a result of which every asset is assigned a class corresponding to its criticality — confidential or internal-use; every other asset whose classification is not needed is considered open information. The record describes each asset's significance, value and existing level of security and protection. At the time an asset is created, its criticality class is determined by the asset's author or the person responsible for the asset. The rules for describing, classifying, making available, releasing, altering and destroying assets are established, by category, through orders of the respective agencies — and the internal policy must replicate those rules at the organisational level. Skipping the inventory step produces a policy detached from what the organisation actually holds.

The information security manager

The policy needs an owner. The subject is obliged to designate a specific person or employee responsible for the fulfilment of the information security requirements — the information security manager. His or her principal duties are set out in the law itself: daily monitoring of compliance with the policy's requirements; description of the assets and of access to them; preparation of internal documentation; collection of information on information security incidents and monitoring of the response; reporting and other administrative activity; and the organisation and delivery of general and sectoral training. The manager is accountable to the head of the subject or an employee duly authorised by him or her, or to a group of persons (collegial body) empowered to implement the policy; every material decision concerning the implementation of the policy is taken by that person or with his or her prior agreement. The manager establishes an action plan and reports annually on its implementation to the leadership; depending on the category, the plan and the annual report are additionally submitted to the Operational-Technical Agency, the Digital Governance Agency or the Cyber Security Bureau.

The computer security specialist

The second pillar operates at the operational level: the subject is obliged to designate a person responsible for the practical assurance of the security of computer systems — the computer security specialist. His or her duties include daily monitoring and assessment of the computer systems; identification of a computer incident, response to it and immediate supply of information about it to the computer incident assistance team of the relevant agency depending on the subject's category; analysis of incidents and security measures and reporting; and coordination with the assistance team. The specialist is accountable before the head of the information technology service, must be available at any time, including after working hours, and during the elimination of an ongoing or suspected cyberattack ensures permanent coordination with the relevant assistance team. Where an attack poses a special threat to the state's defence capability, economic security or the normal functioning of state power or society, the Operational-Technical Agency is empowered to effect temporary coordination of the specialists and of the assistance teams.

How we can help

We assist subjects of critical information systems in drafting the policy and the internal-use rules: we prepare a document that satisfies the minimum requirements and reflects the statutory framework for asset management and the functions of the manager and the specialist; we explain to which agency and within which term the document must be submitted; and we prepare the organisation to respond to the supervisory agency's instructions. Contact us — we will assess your subject's category and propose a practical solution.

Updated: ...

Legal basis:

  • საქართველოს შრომის კოდექსი

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer