An information security policy: what the law requires
Developing a cybersecurity policy in Georgia is not merely a private corporate matter. The Law of Georgia on Information Security obliges subjects of critical information systems to adopt internal-use rules that define the organisation's information security policy. That policy must satisfy the minimum requirements established under the law, and its constituent elements — asset management, responsible officers and their functions — are themselves regulated by statute. On this page we explain what a lawful policy must contain, who is called the information security manager and the computer security specialist, and how the document connects with the oversight of state agencies.
The essential content of the policy and the minimum requirements
Under the law, a subject of a critical information system must adopt internal-use rules for information security that serve the implementation of the law's provisions and define the organisation's information security policy. The policy, in turn, must satisfy the minimum requirements of information security. Those requirements are established by taking into account the standards and requirements set by the International Organization for Standardization (ISO), the United States National Institute of Standards and Technology (NIST) and the Information Systems Audit and Control Association (ISACA) — for subjects of the first and second categories by order of the head of the Operational-Technical Agency, and for subjects of the third category by order of the chairperson of the Digital Governance Agency. Policy drafting therefore begins with studying those orders: a document that does not reflect them will be treated as deficient when it is submitted to the supervisory agency.
The adopted rules must be submitted for review to the relevant agency: subjects of the first and second categories — to the Operational-Technical Agency; subjects of the third category — to the Digital Governance Agency; and subjects within the defence sphere — to the Cyber Security Bureau. The agencies are also notified of any change made to the rules. They carry out a general analysis of the submitted documents and, to cure the defects found, submit binding instructions or recommendations for execution. In addition, the agencies are empowered to demand from the subject other information connected with the development, deployment, monitoring and improvement of the policy. A separate regime applies to commercial banks: the National Bank of Georgia is authorised to demand the submission of their internal-use rules and to issue binding instructions or recommendations with respect to the additional standards and requirements it establishes for them.
Information asset management — the foundation of the policy
A policy must be built on a real register of assets. The law obliges the subject to carry out an inventory of information systems for the purpose of recording all information assets, as a result of which every asset is assigned a class corresponding to its criticality — confidential or internal-use; every other asset whose classification is not needed is considered open information. The record describes each asset's significance, value and existing level of security and protection. At the time an asset is created, its criticality class is determined by the asset's author or the person responsible for the asset. The rules for describing, classifying, making available, releasing, altering and destroying assets are established, by category, through orders of the respective agencies — and the internal policy must replicate those rules at the organisational level. Skipping the inventory step produces a policy detached from what the organisation actually holds.
The information security manager
The policy needs an owner. The subject is obliged to designate a specific person or employee responsible for the fulfilment of the information security requirements — the information security manager. His or her principal duties are set out in the law itself: daily monitoring of compliance with the policy's requirements; description of the assets and of access to them; preparation of internal documentation; collection of information on information security incidents and monitoring of the response; reporting and other administrative activity; and the organisation and delivery of general and sectoral training. The manager is accountable to the head of the subject or an employee duly authorised by him or her, or to a group of persons (collegial body) empowered to implement the policy; every material decision concerning the implementation of the policy is taken by that person or with his or her prior agreement. The manager establishes an action plan and reports annually on its implementation to the leadership; depending on the category, the plan and the annual report are additionally submitted to the Operational-Technical Agency, the Digital Governance Agency or the Cyber Security Bureau.
The computer security specialist
The second pillar operates at the operational level: the subject is obliged to designate a person responsible for the practical assurance of the security of computer systems — the computer security specialist. His or her duties include daily monitoring and assessment of the computer systems; identification of a computer incident, response to it and immediate supply of information about it to the computer incident assistance team of the relevant agency depending on the subject's category; analysis of incidents and security measures and reporting; and coordination with the assistance team. The specialist is accountable before the head of the information technology service, must be available at any time, including after working hours, and during the elimination of an ongoing or suspected cyberattack ensures permanent coordination with the relevant assistance team. Where an attack poses a special threat to the state's defence capability, economic security or the normal functioning of state power or society, the Operational-Technical Agency is empowered to effect temporary coordination of the specialists and of the assistance teams.
How we can help
We assist subjects of critical information systems in drafting the policy and the internal-use rules: we prepare a document that satisfies the minimum requirements and reflects the statutory framework for asset management and the functions of the manager and the specialist; we explain to which agency and within which term the document must be submitted; and we prepare the organisation to respond to the supervisory agency's instructions. Contact us — we will assess your subject's category and propose a practical solution.
