- Research Article
- 10.36030/2664-3618-2018-1-42-60
ПРАВОВІ МЕХАНІЗМИ УПРАВЛІННЯ КРИТИЧНОЮ ІНФОРМАЦІЙНОЮ ІНФРАСТРУКТУРОЮ УКРАЇНИ
- May 30, 2018
- Збірник наукових праць Національної академії державного управління при Президентові України
- O V Melnichuk
The article analyzes the existing legal mechanisms for managing critical information infrastructure in Ukraine. The instruments for their improvement are proposing in this article. An important component of critical infrastructure is its information component – a critical information infrastructure. The sphere of protection of critical information infrastructure in Ukraine is at the initial stage of formation. The current legislation defines only certain objects of socio-economic sphere, in which extraordinary events can lead to socially dangerous consequences. In view of the fact, that the term “critical information infrastructure” does not having a consistent interpretation in different countries, we propose our opinion. “Critical information infrastructure is a system of information management of critical facilities and information and communication networks that provide defense capabilities and security of public and private institutions, whose operation may flow to the national security of Ukraine” (KII). In the KII we can identified information and network components. Information environment of KII is a system for information management of critical objects, including computing and information resources that form automated control systems (ACS). The network component of KII consists of a set of telecommunication devices, communication lines and network equipment, systems of open protocols for the exchange of information between elecommunication devices, global system of digital addresses and digital identifiers, software. The Internet network can be considered as a technological add-on over a telecommunication network that provides the provision of data transmission and processing services (e-mail, teleconferencing, file transfer, access to computing and information systems in local area networks). The main threat to the safety of ACS of critical information infrastructure objects is targeted actions on information systems, information and telecommunication networks by software and hardware. KII legal security include two main components – national and international. The national component may be forming by a set of principles, legal institutions and norms, which are enshrined in the national legislation regulating public relations in Ukraine in the area of counteracting the security threats of the ACS of critical objects. In order to protect the most important objects of KII, it is necessary to identify these objects. The current legislation defines such categories of objects, for which special conditions for ensuring their protection and functioning are established. Some of them, in whole or in part, may be classifying as objects of critical infrastructure. The specificity of providing information security was reflecting in such Ukraine laws like “On the Fundamentals of National Security of Ukraine”, “On the Concept of the National Program of Informatization”, “On the National Program of Informatization”. As well as the Concept of Development of the Security and Defense Sector of Ukraine, the National Security Strategy of Ukraine, the Strategy of Cybersecurity Of Ukraine. The National Security Strategy identifies actual threats to national security and sets priorities for information security, cyber security and security of information resources and critical infrastructure. At the same time, the implementation of the state policy in the field of security of KII requires the further development of legal principles and norms governing the relevant social relations, that is, the national component of the legal security of KII. Ukraine should ensure the establishment of a nationwide system for assessing risks and threats to critical infrastructure, and after the legislative definition of the main terms, the implementation of the Identification of Critical Information Infrastructure objects. Identification of objects of critical information infrastructure can be accomplishing by introducing the certification of objects of critical information infrastructure. Such passports must contain general data about the facility, data on the main sources of danger, data on hazardous natural conditions, technological processes and response to threats. The international component of the legal security of KII provides for the regulation of a set of principles and norms defined by international treaties and recognized by the state, regulating issues of international cooperation in this area. Ukraine has signed the Convention on Cybercrime together with the member states of the Council of Europe and other States. It is aiming at stopping actions against the confidentiality, integrity and availability of computer systems, networks and computer data, as well as abusing such systems, networks and data by installing the criminal responsibility for such behavior, the provision of powers sufficient to combat criminal offenses, and the conclusion of agreements on rapid and reliable international cooperation. In addition, the plan of measures for 2017 on implementation of the Cybersecurity Strategy of Ukraine provides for the implementation of Directive 2008/114/EC on the protection of critical infrastructure, in particular on cybersecurity and cyber defense of critical infrastructure objects. Development of the system of international information security, the following main groups of international relations that requirenormative legal regulation within the framework of the legal security of KII: definition of the boundaries of the national KII in the global information and communication infrastructure and fixing signs of computer incidents in the control system of critical objects information infrastructure. The absence of generally recognized borders of state sovereignty of States in this space is a significant obstacle to the application of international law to the actions of other states. In particular, this impedes the establishment of limits of responsibility of states for violating the security of the KII and organizing international cooperation in the field of countering computer crime. The urgency of the legislative consolidation of signs of computer incidents in the automated control system of critical information infrastructure objects suggests the widespread use of the concept of “incident” in international law. An incident in cyberspace usually associated with a violation of the functioning of the components of cyberspace – an electronic collection environment and automated processing of information that determines the processes of the implementation of these operations, as well as information systems and automated control systems. The essence of the general definition of the “international incident” in the field of KII will be determining, firstly, by the nature of international relations between states that are violating by the “incident”. This event may be the result of unforeseen actions of the state, including actions that harm the interests of public bodies of one or more states, or, conversely, be one of many intentional but minor provocations carried out by agents of one state against another state. Given that international relations in the field of incidents in the field of KII are not regulating by international treaties, the main and, in fact, the only source of international law in this case serves as an international custom, however, its application to the sphere of KII is accompanying by considerable difficulties. For Ukraine, it is possible to introduce the positive experience of other states in the security of the KII. In particular, the problem of security of information technologies has been enshrined in the international standard ISO / IEC 15408 “General criteria for assessing the safety of information technology”.
Read more