BAKU, Azerbaijan, August 10. New obligations in
the field of cybersecurity have been established for owners of
internet information resources in Azerbaijan.


This is reflected in the amendments to the law "On information,
informatization and information protection" signed by President of
the Republic of Azerbaijan Ilham Aliyev.


According to the document, the law adds new concepts to the law:
information infrastructure, information infrastructure subject,
cybersecurity, cyberspace, cyber hygiene, digital evidence, digital
research, computer incident response center (CERT), Security
Operations Center (SOC), National CERT, State CERT and others.


The law defines the rights and obligations of state bodies,
information infrastructure subjects, CERTs and SOCs in the field of
cybersecurity, and establishes mechanisms for detecting,
preventing, investigating and eliminating cyber threats, cyber
attacks and cyber incidents.


The document also establishes provisions on ensuring the
cybersecurity of information infrastructure, conducting
cybersecurity monitoring and audits, exchanging information on
cyber incidents, conducting digital research, financing digital
development projects, and implementing a regulatory test
environment for testing digital solutions.


At the same time, new obligations in the field of cybersecurity
are established for information infrastructure entities, internet
providers, host providers, and owners of internet information
resources, and the directions and powers of the National CERT are
expanded.


According to the relevant decree signed by President Ilham
Aliyev in connection with the implementation of the law, the
Cabinet of Ministers must prepare and submit to the President
proposals on the rules for implementing the regulatory test
environment, including monitoring the activities of persons
participating in it, the maximum duration of the regulatory test
environment, and the procedure for applying exceptions to the
requirements of regulatory legal acts within one month.


Besides, proposals on the rules for ensuring information
security and cybersecurity of the information infrastructure of
state bodies (organizations) (except for intelligence and
counterintelligence entities), as well as protected persons,
protected and strategic objects, must be prepared and submitted to
the President within three months.


According to the decree, the State Security Service, the State
Service for Special Communications and Information Security were
instructed and the Central Bank was recommended to take measures
within one year to include computer incident response centers and
security operations centers in the register of CERTs and SOCs and
inform the President.