LAWON INFORMATION SECURITY("Off. Herald of the RS", No. 91/2025) |
Article 1
This Law shall regulate the measures of protection against security risks in information and communication systems, liability of entities while managing and using the information and communication systems, procedures and measures for achievement of high general level of information security and it shall designate the competent authorities for the implementation of protection measures, coordination between protection factors, monitoring of proper application of the prescribed protection measures, as well as competences of entities for supervising the implementation of this Law.
Article 2
Individual terms within the meaning of this Law shall have the following meanings:
1) Information and communication system (ICT system) shall mean a technological and organisational unit that includes:
(1) Electronic communications networks and services within the meaning of the law regulating electronic communications;
(2) Devices or groups of interconnected devices, such that automated data processing is carried out within the devices i.e. within at least one device in a group of devices, using a computer program;
(3) Data that is maintained, kept, processed, searched or transmitted by means referred to in sub-items (1) and (2) of this item for the purpose of their operation, use, protection or maintenance;
(4) Organisational structure through which the ICT system is managed;
(5) All types of system and application software and software development tools;
2) ICT system operator shall mean a natural person in the capacity of a registered entity, a legal person, authority or an organisational unit of the authority that uses the ICT system in performing its activity, i.e. duties falling within the scope of its competence;
3) Information security shall mean the ability of information and communication systems and networks to resist and/or mitigate, at a given level of reliability, any event that might compromise the availability, integrity, authenticity, non-repudiation or confidentiality of stored, transmitted or processed data as well as of the services provided, or accessible via those ICT systems;
4) Integrity shall mean a feature that ensures that data or information is not modified or destroyed in unauthorised manner since the moment of their creation, transmitting or storing;
5) Availability shall mean a feature that ensures the availability and usability of an ICT system upon demand by an authorized entity or process when needed;
6) Authenticity shall mean a feature that ensures the possibility to verify and confirm that the information was created or sent by the one claiming to have performed the operation concerned;
7) Confidentiality shall mean a feature that ensures that information and functions of an ICT system are available to the authorized persons only;
8) Non-repudiation shall represent the ability to prove the happening of a specific action or occurrence of a specific event, so that it cannot be subsequently denied;
9) Risk shall represent the possibility of a loss or disruption caused by an incident and is expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident;
10) Vulnerability shall mean weakness or flaw of ICT products or services that can be exploited for realisation of one or multiple threats;
11) Risk management shall mean the set of systematic activities of identification, assessment and establishing of a risk control system that enables planning, organisation and directing the protection measures in order to ensure that risks remain within prescribed and acceptable frameworks;
12) Near miss shall mean the identified event in an ICT system that could have led to a significant compromising of availability, authenticity, integrity, non-repudiation or confidentiality of data, services or systems, but the realization of harmful consequences was prevented by a timely intervention or protection measures;
13) Threat shall mean any circumstance, event or action that can jeopardize, disrupt or otherwise cause a disruptive effect on an ICT system, the users of such system and other persons with clear likelihood of occurrence of damage in case of a lack of response;
14) Significant threat shall mean a threat to information security which, bearing in mind its technical characteristics, can be assumed to have the potential to cause significant negative consequences on an ICT system, its operator or the users of the operator’s services by causing considerable loss or injury;
15) Incident shall mean any event that is compromising the availability, integrity, authenticity, non-repudiation or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, the ICT system;
16) Malicious software shall mean the software intentionally created with the aim of damaging, disrupting, preventing or gaining unauthorized access to the information and communication systems, which includes various types of harmful programs, including viruses, Trojan horses, worms, ransomware and spyware;
17) Single system for receipt of notifications of incidents shall mean the information system into which data is entered on incidents and near misses in ICT systems of special importance, which can have a significant role in disruption of information security;
18) Incident handling shall mean taking of any actions and procedures aiming to prevent, detect, analyse and contain the incident, as well as taking other measures to respond to the incident and to remove its consequences;
19) Cyber security crisis shall mean an event or conditions that jeopardize, interfere with the operation or prevent the operation of an ICT system of special importance while at the same time cause risks, threats or consequences for population, material resources or the environment in a volume that is exceptionally large and in intensity that cannot be prevented or removed through the regular action of competent authorities and services, and where the response to such an event or condition requires involvement of multiple competent authorities, as well as application of adequate measures;
20) ICT system protection measures shall mean the technical, organizational, administrative and physical measures for managing security risks in an ICT system;
21) Classified data shall mean any peace of data that is determined and classified with a certain degree of secrecy in accordance with the regulations on classified data;
22) ICT system for work with classified information shall mean the ICT system designated for work involving classified information in accordance with the law;
23) Authority shall mean a state authority, an authority of an autonomous province, a local self-government unit, organization and other legal or natural person entrusted with the discharge of public powers;
24) Security service shall mean the security service within the meaning of the law regulating the foundations of the security and intelligence system of the Republic of Serbia;
25) Autonomous ICT system operators shall mean the ministry in charge of defence affairs, the ministry in charge of internal affairs, the ministry in charge of foreign affairs, the security services and the National Bank of Serbia;
26) Centre for ICT Systems’ Security Risks Prevention (hereinafter referred to as: CERT) shall mean the functional unit within an authority or a legal person which includes the set of tasks relating to incident prevention and protection;
27) Compromising electromagnetic radiation (CE) shall mean unintentional electromagnetic emissions when transmitting, processing or storing data, the receipt and analysis of which can disclose the contents of such data;
28) Crypto security shall be a component of information security that encompasses crypto protection, management of crypto materials and development of crypto protection methods;
29) Crypto protection shall mean the application of methods, measures and procedures for the purpose of transforming data into a form that makes them inaccessible to unauthorized persons for a certain period of time or permanently;
30) Cryptographic product shall mean the software or device by which crypto protection is carried out;
31) Crypto materials shall be cryptographic products, data, technical documentation of cryptographic products, as well as the relevant cryptographic keys;
32) Security zone shall mean the space or room where classified data are processed and stored in accordance with the regulations on classified data, as well as the space or room which is of key importance for preservation of information security of an ICT system;
33) Information assets shall include information that is processed in accordance with the function and intended purpose of the ICT systems; electronic records on configuration of devices and electronic communications network; electronic records of interactions in ICT systems, access to and use of the ICT systems (the so-called log records); program code; technical and user documentation; electronic records of interactions in electronic communications network (the so-called network traffic); information regulating the intended purpose and use of an ICT system, processes, protection measures, etc.;
34) Information society service shall mean the service within the meaning of the law regulating electronic commerce;
35) Information society service provider shall mean the legal person that is the service provider within the meaning of the law regulating electronic commerce;
36) Content Delivery Network - CDN shall mean a network of geographically distributed servers designed to ensure high availability, accessibility and fast delivery of digital content and services to internet users, on behalf of content and service providers;
37) Internet exchange point shall mean a network structure which enables the interconnection of two or more than two independent networks (autonomous systems), primarily for the purpose of facilitating the exchange of internet traffic, and which provides interconnection of autonomous systems, in which case it is not needed that the internet traffic between autonomous systems passes through a third autonomous system, and which does not alter or otherwise influence such traffic;
38) Domain name system (DNS) shall mean a distributed, hierarchically organized system which connects domain names with the relevant IP addresses which are used for routing and connecting of user devices with internet services and resources;
39) DNS service provider shall mean an entity that provides resolution services for DNS inquiries to internet users or provides the service of authoritative servers for domain names used by third parties, with the exception of root name servers;
40) Trust service shall mean the service within the meaning of the law regulating electronic document, electronic identification and trust services in electronic business;
41) Trust service provider shall mean the provider within the meaning of the law regulating electronic document, electronic identification and trust services in electronic business;
42) Qualified trust service shall mean the service within the meaning of the law regulating electronic document, electronic identification and trust services in electronic business;
43) Qualified trust service provider shall mean the provider within the meaning of the law regulating electronic document, electronic identification and trust services in electronic business;
44) Cloud computing services shall mean the digital services that enable on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources, including situations where such resources are distributed across several locations;
45) Data management and storage centre service shall mean the service provided by using structures or groups of structures dedicated to the centralised accommodation, interconnection and operation of computer and network equipment for the purpose of storage, processing and transmission of data, including all facilities and infrastructure for electrical power distribution and environmental control;
46) Scientific research organization shall mean the organization within the meaning of the law regulating science and research;
47) Public electronic communications network shall mean the electronic communications network within the meaning of the law regulating electronic communications;
48) Electronic communications service shall mean the service within the meaning of the law regulating electronic communications;
49) Managed service provider shall mean an entity that provides services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or any other network and information system, through provision of support or active administration carried out either on service user’s premises or remotely;
50) Managed security service provider shall be a provider of managed services which carries out or provides assistance in implementation of activities relating to risk management in the field of security;
51) Top-level domain (TLD) name registry shall mean an entity to which a certain top-level domain is assigned and which is responsible for management of the top-level domain, including domain registration under the top-level domain and technical operation of the top-level domain, which includes the operation of its server names, maintenance of databases and distribution of top-level domain zones through name servers, irrespective of whether these activities are carried out by the entity itself or entrusted to third parties, except where the top-level domain names are used by the register solely for its own needs;
52) Domain name registration service provider shall mean the domain name registrar or another entity acting for or on behalf of the registrar;
53) ICT product shall mean an element or a group of elements within an information and communications system;
54) ICT service shall mean the service consisting fully or mainly in transmission, storing, retrieving or processing of data by using the ICT systems;
55) ICT process shall mean a set of activities performed to produce, develop, use and maintain an ICT product or an ICT service;
56) TLP (Traffic Light Protocol) shall represent a standard for sharing information in the field of information security, which is established with the aim of ensuring effective cooperation and sharing of information from the information source to one or more recipients. The protocol shall provide a simple and intuitive scheme of four designations for indicating with whom the potentially sensitive information can be shared;
57) Personal data shall mean any data relating to a natural person whose identity is determined or is determinable, either directly or indirectly, in particular on the basis of a label of identity, such as a name and identification number, location data, an identifier in electronic communications networks or one or a number of features of his physical, physiological, genetic, mental, economic, cultural or social identity;
58) Administrator shall mean a person who is authorized and responsible for maintenance, management and ensuring the functionality and security of an ICT system of special importance, in accordance with the provisions of this Law and other applicable regulations.
59) Technical specification shall mean the document laying down the technical requirements that a product, process or a service should fulfil, in accordance with the law regulating standardization.
The terms used in this Law and regulations that are to be passed based on this Law, which have gender meanings, when expressed in grammatical male gender shall imply the natural female and male sex of the person to which they pertain.
Principles of Information Security
Article 3
When planning and implementing the ICT system protection measures, the following principles should be observed:
1) The principle of risk management - selection of measures and level of their implementation shall be based on risk assessment, need for risk prevention and elimination of the consequences of the risk that materialised, including all types of extraordinary circumstances;
2) The principle of comprehensive protection - measures shall be implemented at all organisational, physical, technical and technological levels, as well as during the ICT system’s entire life cycle;
3) The principle of expertise and good practice - measures shall be implemented in accordance with expert and scientific knowledge and experience in the field of information security;
4) The principle of awareness and competence - all the persons who effectively or potentially affect information security by their actions should be aware of the risk and possess the appropriate knowledge and skills;
5) The principle of continuous improvement - the information security protection and management measures should be regularly assessed and improved in order to ensure their efficiency and adaptability to new threats and technological changes;
6) The principle of equality and non-discrimination - the ICT system protection measures must be implemented in such a manner as to ensure equal treatment of all the users, without discrimination on any grounds, in accordance with law.
Article 4
Provisions of this Law, provisions of special laws regulating specific fields, as well as provisions of the law regulating protection of personal data shall apply to processing of personal data necessary for discharging competencies and obligations arising from this Law.
II SECURITY IN ICT SYSTEMS OF SPECIAL IMPORTANCE
ICT Systems of Special Importance
Article 5
ICT systems of special importance shall be the ICT systems of key importance for maintenance of critical societal and economic activities the suspension or disruption in service provision of which would or could have significant impact on public security, public health, functioning of other sectors or would i.e. could create a significant systemic risk.
The ICT systems of special importance shall be:
1) The priority ICT systems;
2) The essential ICT systems.
The operators of the priority ICT systems shall be:
1) The legal and natural persons having the capacity of a registered entity, which perform the tasks and pursue the activities in the following sectors:
(1) Energy and mining
- Generation of electric power, with the exception of power generation by the end buyers within the meaning of the law regulating use of renewable energy sources and the law regulating energy production;
- Combined heat and electric power generation;
- Supply of electricity;
- Transmission of electricity and management of transmission system;
- Electricity distribution and distribution system management, as well as electricity distribution and management of the closed distribution system;
- Electricity storage, with the exception of storage by the end buyers within the meaning of the law regulating the use of renewable energy sources and the law regulating energy production;
- Management of organized electricity market;
- Generation, distribution and supply of heat;
- Oil transport by pipelines, oil derivatives’ transport by product pipelines and oil and oil derivatives’ transport by other forms of transport;
- Exploration and production of oil and natural gas;
- Production of oil derivatives;
- Storage of oil and oil derivatives;
- Transport of natural gas and natural gas transport system management;
- Natural gas storage and management of natural gas storage facility;
- Natural gas distribution and management of natural gas distribution system;
- Supply and public supply of natural gas;
- Production and processing of coal;
- Production and processing of copper, gold, led, zinc, lithium and boron;
- Production, storage and transport of hydrogen;
(2) Transport
- Carrying out of public air transport with a valid operation licence;
- Airport management;
- Air traffic control services;
- Management of public railway infrastructure;
- Operation of railway companies;
- Transportation of passengers and freight in inland waters;
- Port management;
- Vessel traffic service (VTS);
- River information services (RIS);
- Road infrastructure management;
- Intelligent transport systems’ (ITS) management;
(3) Banking and financial markets
- Operations of the financial institutions and capital market institutions, which are subject to supervision of the National Bank of Serbia i.e. Securities Commission;
- Tasks of managing the data registers on liabilities of natural and legal persons towards financial institutions;
- Tasks of managing i.e. performing activities in relation to the functioning of a regulated market;
- Financial instruments’ clearing i.e. settlement tasks, within the meaning of the law regulating capital market;
- Tasks of the providers of services related to digital assets, within the meaning of the law regulating digital assets;
(4) Health
- Provision of healthcare;
- Operation of national reference laboratories;
- Research and development of medicines;
- Manufacturing of pharmaceutical products and preparations intended for health use;
- Manufacturing of medicines and other products intended for use in the health sector, including products of vital importance during a public health emergency;
- Processing of genetic, biomedical data and other data of significance for research and development in the field of biotechnology, bioinformatics, bio economy, genetics, and medicine;
(5) Drinking water
- Supply and distribution of water intended for human consumption, with the exception of distributors for whom the mentioned operations are not the predominant part of their activity;
(6) Waste water
- Collecting, disposing of, or treating urban waste water, domestic waste water and industrial waste water, excluding companies for which the mentioned operations are not the predominant part of their activity;
(7) Digital infrastructure
- Provision of cloud computing services;
- Provision of service of a centre for keeping and storing of data;
(8) Management of ICT services provided to operators of priority ICT systems
- Provision of managed services;
- Provision of managed security services;
(9) Other fields
- Management of nuclear facilities;
- Provision of trust services, including qualified trust services, provision of domain system (DNS) services, management of top-level-domain registry and provision of domain registration services with the exception of root name server operators;
- Provision of content delivery network services;
- Pursuit of electronic communications activity;
- Internet traffic exchange point;
- Issuing of the "Official Herald of the Republic of Serbia" and keeping of the Legal Information System of the Republic of Serbia;
- Field in which there is only one service provider in the Republic of Serbia and which is necessary for performance of critical societal and economic activities;
2) Authorities;
3) Entities designated as critical infrastructure operators in accordance with regulations governing critical infrastructure.
In addition to the entities referred to in paragraph 3 of this Article, as operators of priority ICT systems can also be designated the entities whose ICT system interruption or disruption of operation:
1) Can lead to significant impact on public security, national security or public health;
2) Can cause a significant systemic risk, in particular in the sectors where the disruption can have a cross-border impact.
The entities referred to in paragraph 4 of this Article shall be designated by the ministry in charge of information security-related tasks, upon having acquired the opinion of the authority competent for the field in which the entity pursuits its activities.
The operators of priority ICT systems of special importance which are carrying out their activity in the banking and financial markets’ sector referred to in paragraph 3, item 1), sub-item (3), the first, second and the fifth indent of this Article shall be subject to special, sectorial regulations whereby individual issues from this Law are regulated in more detail, i.e. in a different manner, and which provide for at least the same level of efficiency of the measures of security risks’ management of these operators mutatis mutandis with the measures referred to in Article 10 of this Law, while at the same time providing for the reporting on incidents that present the information security crisis in accordance with this Law.
The National Bank of Serbia, as the authority competent for supervising the operation of priority ICT system operators of special importance which are carrying out their activity in the sector of banking and financial markets referred to in paragraph 3, item 1), sub-item (3), the first, second and the fifth indent of this Article (the subjects of supervision by the National Bank of Serbia), in accordance with this Law and provisions of special laws regulating the operation of these entities, shall pass the regulations that govern the issues of information security for these entities, and specifically the ICT systems’ protection measures, adoption of the risk assessment acts and act on ICT system security, incident classification, provision of notifications on incidents, handling of incidents, reporting in the course and following an incident, provision of statistical data on incidents and other issues of relevance for the security of an information system in these entities, as well as the supervision it conducts over them.
Operators of Essential ICT Systems
Article 6
The operators of essential ICT system shall be:
1) Legal and natural persons having the capacity of registered entities, which are carrying out the jobs and pursuing activities in the following fields:
- Postal services within the meaning of the law regulating the field of postal services;
- Waste management, within the meaning of the law regulating waste management, except for the companies whose core business does not include the stated activity;
- Managing the packaging waste, within the meaning of the law regulating packaging waste management;
- Production and supply of chemicals, in accordance with the law regulating chemicals;
- Production, processing and distribution of food in the wholesale and industrial production and processing segments;
- Manufacturing of computers, electronic and optical products;
- Production of electrical equipment;
- Production of machines and devices;
- Production of motor vehicles, trailers and semi-trailers and production of other transport equipment;
- Production of medical devices and production of in vitro diagnostic medical devices;
- Information society services within the meaning of the law regulating electronic commerce;
- Production, circulation, and transport of armaments and military equipment;
- Space services relying on ground infrastructure, especially the management activities in control centres, structures for monitoring and communication and provision of launching services;
2) Scientific and research institutions;
3) Legal and natural persons having the capacity of a registered entity and the authorities referred to in Article 5 of this Law, which are not categorized as the operators of priority ICT systems according to the operator designation criteria.
In addition to the entities referred to in paragraph 1 of this Article, as operators of essential ICT systems the following entities can be designated, for which an interruption or a disruption of operation of the ICT system:
1) Can have a significant effect on public safety, national security or public health;
2) Can cause a significant systemic risk, in particular in the sectors where a disruption can have a cross-border impact.
The entities referred to in paragraph 2 of this Article shall be designated by the ministry in charge of cyber security-related tasks, upon having obtained the opinion of the authority competent for the field in which the entity concerned pursues its activities.
A by-law regulating in more detail the conditions, general and sectorial criteria including the criteria relating to the size of economic entities, for designating the operators of priority and of essential ICT systems shall be passed by the Government, at the request of the ministry in charge of cyber security-related tasks.
The ministries whose scope of competences covers the fields in which the operators of priority and essential ICT systems pursue their activities and the National Bank of Serbia shall provide, in the procedure of drawing up of the by-law referred to in paragraph 4 of this Article, the proposals of sectorial criteria to the ministry in charge of the cyber security-related tasks for the purpose of designating the operators of the ICT systems of special importance.
Obligations of the Operator of ICT Systems of Special Importance
Article 7
An operator of an ICT system of special importance, in accordance with this Law, shall:
1) Submit the application for entry in the records of ICT systems of special importance;
2) Take adequate technical, operational, organizational and physical protection measures for the ICT systems of special importance, risk management and prevention and reduction of harmful consequences of incidents;
3) Carry out risk assessment and pass the risk assessment act;
4) Adopt an act on security of the ICT system of special importance;
5) Carry out the checks of conformity of the applied ICT system protection measures with the act on security of the ICT system, at least once a year;
6) Regulate the relations with third parties in such a manner as to ensure taking of protection measures for that ICT system in accordance with law, where the activities relating to the ICT system of special importance are entrusted to third parties;
7) Provide notifications, without delay, of each incident which is significantly jeopardizing the security of the ICT system of special importance;
8) Report near misses that present a significant threat in accordance with this Law;
9) Provide statistical data on incidents and near misses in ICT systems.
Obligations of Autonomous Operators
Article 8
An autonomous operator shall:
1) Submit an application for registration in the records of ICT systems of special importance;
2) Take adequate technical, operational, organizational and physical protection measures for the ICT systems of special importance, risk management and prevention and reduction of harmful consequences of incidents;
3) Adopt an act on security of the ICT system;
4) Carry out the checks of conformity of the applied ICT system protection measures with the act on security of the ICT system in accordance with his own rules for checking of protection measures conformity, at least once a year;
5) Regulate the relations with third parties in such a manner as to ensure taking of protection measures for that ICT system in accordance with the law, where the activities relating to the ICT system of special importance are entrusted to third parties;
6) Establish his own CERT in order to manage the incidents in his own systems.
The autonomous operators may exchange information on incidents with the Information Security Office, and where necessary with other organisations as well.
Provisions of this Law on reporting of incidents which are significantly jeopardizing information security, provisions on delivery of statistical data about incidents and provisions on proactive scanning of the network of the operator of the ICT system of special importance shall not apply to autonomous operators.
In order to detect vulnerabilities, the independent operators may autonomously and in coordination with the Information Security Office carry out proactive scanning of their own ICT systems which are connected to the Single Information and Communication e-Government Network.
The autonomous ICT system operators shall designate special persons, i.e. organisational unit for internal control of their own ICT systems.
The persons tasked with internal control with the autonomous ICT system operators shall submit the reports on performed internal control to the manager of the autonomous ICT system operator.
Records of Operators of ICT Systems of Special Importance
Article 9
The Ministry in charge of information security-related tasks (hereinafter: the Ministry) shall establish and keep records of priority and essential ICT systems (hereinafter: Register) which shall include:
1) The name, registration number and seat of the special importance ICT system operator;
2) The name and surname, official electronic mail address and official contact phone number of the administrator in charge of maintenance and management of the special importance ICT system;
3) The name and surname, official electronic mail address and official contact phone number of the responsible person of the special importance ICT system;
4) Information on the type of special importance ICT system, i.e. whether the special importance ICT system is categorized as priority or essential;
5) Data on the activity pursued by the operator of the special importance ICT system;
6) Internet protocol address range (IP address range) belonging to the special importance ICT system, which includes data on public static IP addresses;
7) Website of the operator of the special importance ICT system;
8) The number of locations in which the special importance ICT system is found.
In addition to data referred to in paragraph 1 of this Article, the Register may include other supplemental data on the special importance ICT system.
The autonomous ICT system operators shall be exempt from the obligation to provide data referred to in paragraph 1, items 4), 5), 6) and 8) of this Article.
The by-law regulating in more detail the contents and structure of the Register, as well as the method of submission of applications for entering and modifying information included in the Register shall be passed by the Ministry.
The operators of the special importance ICT systems shall deliver to the Ministry the data referred to in paragraphs 1 and 2 of this Article no later than 90 days from the date of adoption of the regulation referred to in paragraph 4 of this Article, i.e. 90 days from the date of establishing of the special importance ICT system.
In case of any change of data referred to in paragraph 1 of this Article, the operator of the special importance ICT system shall notify the Ministry thereof within 15 days from the date of occurrence of any such change.
Data referred to in paragraph 1, items 2) and 3) of this Article shall be processed for the purpose of executing the provisions of this Law in respect of provision of notifications and warnings of relevance for the security of special importance ICT systems, as well as for the purpose of establishing communication and realizing cooperation aimed at eliminating adverse consequences of incidents and preventive action.
Data referred to in paragraph 1, items 2) and 3) of this Article shall be processed in accordance with the law regulating protection of personal data and stored until the moment of termination of the purpose of processing or until the completion of change of data in accordance with paragraph 6 of this Article.
The Ministry shall provide the updated Register at the disposal of the Information Security Office for the purpose of executing the provisions of this Law in respect to collection and exchange of information on threats, vulnerabilities and incidents, and provision of support, warnings and counselling of the persons who manage the ICT systems.
The Register shall be deemed as classified data within the meaning of the law regulating classified data.
Measures to Protect the ICT System of Special Importance
Article 10
An operator of a special importance ICT system shall be responsible for the security of the ICT systems and for taking the measures to protect the ICT system.
The ICT system protection measures shall ensure incident prevention, i.e. prevention and reduction of damage from incidents that jeopardize the exercise of competences and pursuit of activities, in particular while providing services to other persons.
The protection measures shall be applied in all the ICT systems of the operators referred to in paragraph 1 of this Article.
The ICT system protection measures shall relate to:
1) Establishing of the organisational structure with determined jobs, knowledge, competences, experience and responsibilities of the employees, whereby information security management within the ICT system operator is achieved;
2) Collecting of data on threats to information security of the ICT system;
3) Achieving security of distance work and of the use of mobile devices;
4) Ensuring that the persons using the ICT system i.e. managing the ICT system are trained for the job they are performing and that they understand their responsibility, i.e. ensuring the organisation of the basic and, where necessary, of the advanced information trainings for all the employees and hired persons having access to the ICT systems, training for the managers i.e. for the management bodies of the operator of the special importance ICT system, as well as the specialized professional trainings for the employees responsible for managing the information security, in order to ensure provision of continuous education;
5) Ensuring sufficient resources for adequate management of information security;
6) Protection from the risks occurring in cases of any changes of jobs or termination of employment of the persons employed with the ICT system operator;
7) Identification of information resources and determining responsibilities for their protection;
8) Classification of data so that the level of their protection is matched to the significance of data in accordance with the risk management principle referred to in Article 3 of this Law;
9) Protection of data carrier;
10) Restriction of access to data and means for data processing;
11) Approval of authorised access and prevention of unauthorised access to the ICT system and services provided by the ICT system;
12) Determining user’s responsibilities for protection of own authentication means;
13) Envisaging the use of cryptographic controls and other techniques for data hiding to protect confidentiality, authenticity, and integrity of data;
14) Application of protection measures to prevent leaking of data;
15) Physical protection of facilities, spaces, premises, i.e. zones where the means and documents of the ICT system are located and where data is processed in the ICT system;
16) Protection from loss, damage, theft or other forms of jeopardizing security of the means comprising the ICT system;
17) Ensuring correct and safe functioning of the data processing means;
18) Application of adequate procedures and protection measures when using the cloud computing service;
19) Monitoring of the ICT system with the aim of detecting vulnerabilities and threats;
20) Restricting access to websites that can potentially harm the safety of the ICT system;
21) Protection of data and means for data processing from malware;
22) Protection from data loss through regular making of backup copies of data, software and the system, by using relevant means for data exchange;
23) Storing of data on events that can be of relevance for the security of the ICT system;
24) Securing integrity of software and of operation systems;
25) Protection from the abuse of technical and security vulnerabilities of the ICT system;
26) Providing protection for the ICT system when conducting the check testing;
27) Data protection in communication networks, including devices and lines;
28) Security of data transmitted within the ICT system operator, as well as between the ICT system operator and persons that are external to the ICT system operator;
29) Compliance with the requests for information security within management of all the stages of the lifecycle of the ICT system i.e. of the parts of the system;
30) Protection of data used for the needs of testing of the ICT system i.e. of the parts of the system;
31) Procedures for information storing and deleting in ICT systems, in accordance with regulations;
32) Protection of means of the ICT system operator that are available to service providers;
33) Maintenance of the agreed level of information security and services provided in accordance with the terms and conditions agreed with the service provider;
34) Prevention and response to security incidents, which implies adequate exchange of information on security vulnerabilities of the ICT system, incidents and threats, as well as application of remedial measures for any consequences of an incident;
35) Measures that ensure continuity of operation under extraordinary circumstances which are defined by the Operation Continuity Plan;
36) Adoption of documents defining procedures for adequacy checks of the protection measures;
37) Use of multifactor authentication or solutions for continuous authenticity check, protected voice, video and text communication, as well as secure communication systems in emergencies within the ICT system operator.
The by-law regulating in more detail the protection measures of the priority and essential ICT systems by taking into account the principles referred to in Article 3 of this Law, the national and international standards, as well as the standards applicable in relevant fields of work and the relevant technical specifications shall be passed by the Government, at the proposal of the Ministry.
Risk Assessment Act for the ICT System of Special Importance
Article 11
The operator of the ICT systems of special importance shall adopt a risk assessment act for the ICT systems (hereinafter: risk assessment act) managed by him.
The risk assessment act shall assess the risks for the ICT system of special importance bearing in mind the level of exposure to a given risk, the size of the operator and the certainty of incident occurrence and its severity, as well as its potential societal and economic impact.
The risk assessment act shall be revised at least once a year.
The risk assessment act shall be drawn up in accordance with the general methodology for risk assessment in priority and essential ICT systems of special importance passed by the authority, i.e. organisation within which the National CERT tasks are performed.
The operator of ICT system of special importance shall not be obliged to pass the act referred to in paragraph 1 of this Article if he has a defined risk assessment in other existing internal acts, which is covering the requests from the general methodology referred to in paragraph 4 of this Article.
Act on Security of the ICT Systems of Special Importance
Article 12
The operator of the ICT system of special importance shall pass the act on security of the ICT system (hereinafter: the security act).
The security act shall lay down the protection measures, and in particular the principles, method and procedures for achieving and maintaining an adequate level of system security, as well as the authorisations and responsibilities relating to security and resources of the ICT system of special importance.
The security act of the ICT system of special importance shall be based on the Risk Assessment Act referred to in Article 11 of this Law. Application of ICT system protection measures must be in accordance with the assessed risks in order to ensure adequate protection of the system and minimise the impact of potential incidents.
The security act must be aligned with the changes in the environment and within the ICT system itself.
The operator of the ICT system of special importance shall, either independently or by outsourcing relevant experts, carry out the check referred to in previous paragraph at least once a year and draw up a report thereof.
The by-law regulating in more detail the contents of the security act, the checking method of the ICT systems of special importance and the contents of the report on check, as well as the provision of the report to the competent authority shall be passed by the Government at the proposal of the Ministry.
Notification Obligation on Incidents that Significantly Distort the Information Security
Article 13
The operators of ICT systems of special importance shall provide notification of an incident that can have a significant impact in distortion of information security, without any delay, and no later than within 24 hours from learning of any such incident.
The incidents that can have a significant impact on distortion of information security shall be:
1) The incidents resulting in disruption of continuity of performance of jobs and provision of services, i.e. in significant difficulties in performance of jobs and provision of services;
2) The incident impacting a large number of service users, or lasting for a longer period of time;
3) The incidents resulting in disruption of continuity, i.e. difficulties in performance of jobs and provision of services, which are impacting performance of jobs and provision of services of other operators of ICT systems of special importance or affecting public safety;
4) The incidents resulting in disruption of continuity, i.e. in difficulties in performance of jobs and provision of services and affecting a larger part of the territory of the Republic of Serbia;
5) The incidents resulting in unauthorized access to data the disclosure of which may jeopardize the rights and interests of those to who the data pertain;
6) The incidents occurring as a consequence of an incident within the ICT system of the operator of the priority ICT systems which pursue the activities in the field of digital infrastructure, referred to in Article 5, paragraph 3, item 1), sub-item (7) of this Law, where the special importance ICT system in its operation uses the information services in the field of digital infrastructure;
7) The incidents that are causing or that can cause significant loss or injury to the operator of the ICT system of special importance and to other natural and legal persons.
The operators of ICT systems of special importance shall also report the near misses that are presenting a significant threat and that could result in the circumstances similar to those described in paragraph 2 of this Article. In case of incidents occurring in ICT systems for work with classified data, the operators of these ICT systems shall act in accordance with the regulations governing the field of protection of classified data.
Provision of Incident Notifications
Article 14
The operators of ICT systems of special importance shall provide notifications of incidents to the single system for receipt of incidents’ notifications through the website of the Ministry or the Information Security Office.
The operators of the priority ICT systems of special importance pursuing the activities in the fields of banking and financial markets referred to in Article 5, paragraph 3, item 1), sub-item (3) of this Law shall provide the notifications of incidents to the National Bank of Serbia, and if the operators of the priority ICT systems in the field of financial markets are subject to supervision by the Securities Commission, they shall additionally provide the notification to the Securities Commission.
The operators of priority ICT systems pursuing the electronic communications’ activities referred to in Article 5, paragraph 3, item 1), sub-item (9), fourth indent of this Law and the operators of essential ICT systems of special importance engaging in the postal services’ activity referred to in Article 6, paragraph 1, item 1), first indent of this Law shall provide the notification of an incident to Regulatory Authority for Electronic Communications and Postal Services.
The National Bank of Serbia, the Regulatory Authority for Electronic Communications and Postal Services and the Securities Commission shall forward the received notifications referred to in paragraphs 2 and 3 of this Article to the single system for receipt of incident notifications.
The operators of ICT systems of special importance, other than the ICT system operators referred to in paragraphs 2 and 3 of this Article, shall notify the users to which they provide services of the incident by using the appropriate communication channels, without any delay, in case of an incident that can cause or is causing harmful effect on provision and use of services, as well as of the measures that the users can take and use with the aim of reducing or eliminating the harmful consequences of the incident.
The operators of ICT systems of special importance referred to in paragraphs 2 and 3 of this Article shall notify the users of the incidents in accordance with special regulations.
The authority to which an incident notification is addressed in accordance with this Law, where it is a case of an ICT system of special importance which is identified as critical infrastructure in accordance with the law regulating critical infrastructure, shall forward the information thereof to the ministries in charge of the critical infrastructure sectors.
The authorities referred to in paragraphs 1 through 3 of this Article, to which the incident notification is addressed, shall, in case of an incident that has occurred in the ICT system of a critical infrastructure operator identified in accordance with the law regulating critical infrastructure, forward the information received without any delay to the ministries competent for the critical infrastructure sectors, in accordance with the regulations governing protection of classified information.
Contents of Incident Notification
Article 15
An incident notification must comprise the following data:
1) Data on the person filing the report;
2) Type and description of the incident and assessment whether the incident has resulted from a criminal offence;
3) Date and time of the start of the incident, i.e. of learning of the incident and the duration of the incident;
4) The consequences caused by the incident;
5) The activities taken to mitigate the consequences of the incident;
6) The initial assessment of the level of danger and effect of the incident on the ICT system of special importance, as well as the indicators of compromise;
7) Information on potential cross-border effect of the incident;
8) Data on similar previously reported incidents, if any, including the time and nature of these incidents, as well as the measures taken on any such occasion;
9) Other pieces of information of relevance, where necessary.
Importance of Incidents According to Danger Levels
Article 16
The incidents in ICT systems of special importance that can have a significant effect on distortion of information security shall be categorised according to the level of danger, bearing in mind the consequences of the incident, to the following levels of danger:
1) Low;
2) Medium;
3) High;
4) Very high.
A by-law regulating the incident notification procedure, the forms for notifications, the list of incidents according to types and the classification of incidents according to the level of danger shall be passed by the Government, at the proposal of the Ministry.
Operational Team for Incident Response
Article 17
With the aim of coordinated reaction to incidents of high and very high level, the Information Security Office shall form a standing operational team.
The Information Security Office shall regulate in more detail the criteria for appointment of members, as well as carrying out of the jobs and tasks of the standing operational team.
Depending on the nature and consequences of the incident, the Information Security Office may request inclusion of other authorities in the work of the operational team within their respective competences.
Where necessary, representatives of independent operators, the persons included in the work of the Coordination Body for Information Security Affairs, as well as the representatives of special CERTs may attend the meetings of the operational team.
The persons taking part in the work of the standing operational team shall get certifications for work with classified data.
Reaction Plan in Cases of High Level Incidents and Crises of Information Security
Article 18
The Government shall pass the Reaction Plan in cases of high level information security incidents and crises, at the proposal of the Information Security Office.
The Plan referred to in paragraph 1 of this Article shall include:
1) The objectives of reaction measures and activities in cases of high level information security incidents and crises;
2) The actions of the competent authorities aimed at implementing the plan;
3) A description of procedures in cases of high level information security incidents and crises;
4) The activities aimed at improving the incident response capacity, primarily the plans of relevant drills and trainings;
5) The cooperation models with private, non-governmental and academic sectors;
6) Mutual cooperation of competent authorities.
When drafting the plan referred to in paragraph 1 of this Article, cooperation shall be established with the authorities and legal persons whose competences, i.e. jobs and activities are linked to the planned activities.
The Plan referred to in paragraph 1 of this Article shall be periodically amended and supplemented in accordance with the needs and emerging circumstances, and it shall be redrawn up and readopted in its entirety every third year, or sooner in case of any significant change of circumstances.
Actions Following the Receipt of Incident Notification
Article 19
Following the receipt of a notification of incident in an ICT system of special importance, the Information Security Office shall act in accordance with the competences laid down by law, i.e. it shall collect, analyse and exchange information on risks to security of the ICT system, as well as on the incident, and shall notify, provide support, warn and advise the operator of the ICT system of special importance in relation to that and carry out other jobs within its scope of competence.
Following a completed analysis, the Information Security Office shall determine the danger level of the incident.
Where it is necessary to inform the public of the incident or where type of the incident is such that it is of interest for the general public, the Information Security Office shall publish the information about the incident, after consulting with the operator of the ICT system of special importance where the incident has happened.
Notwithstanding paragraph 3 of this Article, the Information Security Office can publish the information about the incident that occurred in the operator of a priority ICT system of special importance which pursues an activity in the field of banking and financial markets referred to in Article 5, paragraph 3, item 1), sub-item (3) of this Law, upon obtaining prior consent from the National Bank of Serbia i.e. the Securities Commission.
The Information Security Office, the National Bank of Serbia, the Securities Commission and the Regulatory Authority for Electronic Communications and Postal Services shall forward the notifications of incidents to:
1) The competent public prosecutor’s office, i.e. to the ministry in charge of internal affairs, in case that the incident is tied to perpetration of criminal offences that are prosecuted ex officio,
2) The authority in charge of security and counterintelligence tasks of relevance for the defence of the Republic of Serbia or to the authority in charge of national security-related tasks, in case that the incident is tied to a significant distortion of information security that has or can have as a consequence an endangerment of defence or national security of the Republic of Serbia.
When handling the incident, the Information Security Office, the National Bank of Serbia, the Securities Commission and the Regulatory Authority for Electronic Communications and Postal Services shall the mark the incident notification, i.e. information on incident in accordance with the regulations and the TLP ("traffic light protocol") protocol.
Actions to be taken in case of "Low" Threat Level Incident
Article 20
In case of incidents which are according to the classification determined to present the "low" threat level, the Information Security Office shall, where necessary, provide recommendations for conduct of the operator of the ICT system of special importance.
Actions to be taken in case of "Medium" Threat Level Incident
Article 21
In case of incidents which are according to the classification determined to present the "medium" threat level, the Information Security Office shall provide recommendations for conduct of the operator of the ICT system of special importance.
Actions to be taken in case of "High" Threat Level Incident
Article 22
In case of incidents which are according to the classification determined to present the "high" threat level, the Information Security Office shall notify the Ministry thereof.
The Information Security Office shall prepare, in cooperation with the operational team, recommendations and measures for incident resolving.
Following the receipt of the notification referred to in paragraph 1 of this Article, the Ministry shall convene the meeting of the Coordination Body for Information Security Affairs.
Following the end of the incident, the Information Security Office shall, in cooperation with the operational team, draw up the final report which shall be delivered to the Ministry within 30 days following the end of the incident.
Actions to be taken in case of "Very High" Threat Level Incident
Article 23
In the case of an incidents which is according to the classification determined to present the "very high" threat level and which presents an information security crisis, the Government shall undertake the management and coordination of implementation of measures and tasks.
The Information Security Office shall prepare, in cooperation with the operational team, a proposal for announcement of an information security crisis, in accordance with the Reaction plan in cases of high level incidents and information security crisis, which shall include:
1) Incident data;
2) Information on actions taken;
3) Reasons for the announcement of information security crisis;
4) Order to authorities to take actions in accordance with their respective competences;
5) Measures for crisis resolution.
A suggestion to announce the information security crisis shall be forwarded to the Ministry, which shall, following the receipt of any such suggestion, without any delay convene the meeting of the Coordination Body for Information Security Affairs.
At the proposal of the Ministry, the Government shall pass a decision to announce the information security crisis and order the authorities to act according to the suggested measures in accordance with their respective competences.
The Information Security Office shall coordinate, in cooperation with the operational team, the resolving of the information security crisis and report at least once a week to the Ministry and the Government on all the activities.
The proposal to announce the end of an information security crisis shall be addressed to the Ministry.
The decision to announce the end of an information security crisis shall be passed by the Government at the proposal of the Ministry.
Following the end of an information security crisis, the Information Security Office shall prepare the final report which shall be delivered to the Ministry and to the Government within 30 days from the end of the crisis.
Reporting During and Following an Incident
Article 24
The operators of ICT systems of special importance shall:
1) Provide incident report, during the incident, inclusive of a description of measures taken to resolve the incident, to the single system for receipt of incident notifications, in following intervals:
(1) Every third day in cases of medium level incidents;
(2) Once in 24 hours in cases of high and very high level incidents;
2) Provide notifications and additional reports on relevant events related to the incident and on undertaken activities, at the request of the Office;
3) Provide the final report on the incident within 15 days from the termination date of the incident, which shall include the following data:
(1) The type and a detailed description of the incident;
(2) The type of threat and the leading cause that led to the incident;
(3) The time and duration of the incident;
(4) The scope and the level of impact of the incident (realized risk), i.e. the consequences the incident has caused;
(5) Information on any cross-border effects of the incident;
(6) The activities taken in order to eliminate the consequences of the incident and, where necessary, other information of relevance for incident recording and statistical processing.
Following the end of the incident, the Information Security Office shall prepare recommendations and advice on protection from potential risks, based on the completed analysis of the occurred incident.
Provision of Statistical Data on Incidents
Article 25
An operator of ICT systems of special importance shall provide, in addition to the incident notifications referred to in Article 13 of this Law, the authority i.e. the organisation in charge of the tasks of the National CERT with statistical data on all the incidents in the ICT system, inclusive of the near misses, in the previous year, no later than by 28 February of the current year.
The authority, i.e. organisation referred to in paragraph 1 of this Article shall provide the reports on statistical data to the Ministry and publish them on its website.
The type, form and method of provision of the statistical data referred to in paragraph 1 of this Article shall be laid down by the authority, i.e. organisation referred to in paragraph 1 of this Article.
III AUTHORITIES IN CHARGE OF PREVENTION OF AND PROTECTION FROM SECURITY RISKS IN ICT SYSTEMS IN THE REPUBLIC OF SERBIA
Article 26
A public administration authority in charge of information security shall be the ministry in charge of information security-related affairs.
Within its scope of competence, the Ministry shall:
1) Prepare and propose regulations and planning documents within the field of information security in accordance with this Law;
2) Keep the records of operators of ICT systems of special importance;
3) Supervise the operations of the Information Security Office relating to exercise of tasks within its scope of competence in accordance with this Law;
4) Perform inspection supervision over the application of this Law and over the work the operators of ICT systems of special importance, other than the autonomous ICT systems operators and operators of the ICT systems for work with classified information;
5) Engage in international cooperation within the scope of its competences.
Coordination Body for Information Security Affairs
Article 27
With a view to establishing cooperation and harmonized work performance for the purpose of improving information security, as well as to initiate and monitor the preventive and other activities in the field of information security, the Government shall establish the Coordination Body for Information Security Affairs (hereinafter: the Coordination Body), as a Government’s coordination body, whose members shall be the representatives of the ministries in charge of information security, defence, interior affairs, foreign affairs, judiciary-related affairs, the representatives of the security services, Information Security Office, Information Technologies and e-Government Office, Office of the Council for National Security and Protection of Classified Data, General Secretariat of the Government, the National Bank of Serbia and the Regulatory Authority for Electronic Communications and Postal Services.
For the purpose of improving individual areas of information security, expert working groups shall be formed in the Coordination Body which shall include the representatives of other authorities, economic and academic community, as well as the non-governmental sector.
By means of the decision whereby it has established the Coordination Body, the Government shall additionally determine its composition, tasks, the period in which it files reports to the Government and other issues concerning its operation.
Article 28
The Information Security Office (hereinafter: the Office) shall be established as a separate organisation within the meaning of the law governing the status of state administration, in order to carry out the tasks of prevention and protection from security risks and incidents in the ICT systems in the Republic of Serbia.
The Office shall have the capacity of a legal person.
The operations of the Office shall be managed by the director, who must be a person with adequate qualifications and a minimum of five years of work experience in the field of information security and who shall be appointed by the Government, in accordance with the law governing the status of civil servants.
The Office shall have a deputy director, who must be a person with adequate qualifications and a minimum of five years of work experience in the field of information security, who shall be appointed in accordance with the regulations governing the status of civil servants and who shall have the authority in accordance with the regulations governing state administration.
Supervising the Office’s Operation
Article 29
The Ministry shall supervise the operation of the Office in carrying out of its tasks, in accordance with the law governing state administration.
Article 30
Within the scope of its competences, the Office shall carry out the following tasks, namely:
1) Provide prevention and protection from security risks on the national level in accordance with this Law (the tasks of the National CERT);
2) Take the preventive and reactive measures with the aim of protecting the Single e-Government Information and Communication Network in accordance with this Law (the governmental authority’s CERT tasks);
3) Carry out the cooperation at the national level in the field of information security;
4) Perform the tasks of the single contact point;
5) Carry out the certification tasks for the ICT systems, ICT products, ICT processes and ICT services, other than the systems, products, processes and services for the needs of defence and security and the ICT systems for work with classified information;
6) Prescribe the minimum protection measures for the ICT systems of authorities, by taking into account the principles referred to in Article 3 of this Law, the protection measures referred to in Article 10 of this Law, the national and international standards and the standards applicable in relevant fields of work;
7) In cooperation with competent authorities and other entities from the public, academic, economic and non-governmental sectors, participate in the development and implementation of training programs and professional advanced trainings for the persons working on information security jobs;
8) Engage in cooperation and exchange of information on international level in the field of information security with the aim of monitoring and harmonization with international regulations and standards;
9) Carry out expert supervision over the work of operators of ICT systems of special importance;
10) Keep the vulnerability database of ICT products and ICT services;
11) Provide quarterly reports to the Ministry on the activities taken;
12) Perform other tasks in accordance with this Law.
The by-law regulating in more detail the certification method of ICT systems, ICT products, ICT processes and ICT services referred to in paragraph 1, item 5) of this Article shall be passed by the Government, at the proposal of the Ministry.
The National Level Security Risks Prevention and Protection Tasks (National CERT)
Article 31
Within the security risks’ and incidents’ prevention and protection tasks, the Office shall carry out the tasks of the National CERT, namely:
1) Collect and exchange information on threats, vulnerabilities, near misses and incidents and provide support, warn and advice the persons managing the ICT systems in the Republic of Serbia, as well as the public;
2) Monitor the state of incidents in the Republic of Serbia;
3) Provide early warnings, alarms and announcements and inform the relevant persons on the threats, vulnerabilities and incidents;
4) Respond without any delays to the reported or otherwise detected incidents in the ICT systems of special importance, as well as to the reports of natural and legal persons, by providing advice and recommendations based on available information on the incidents and take other necessary measures within the scope of its competence based on received findings;
5) At the request of an operator of ICT system of special importance, provide assistance in monitoring the real-time or near real-time state of security of the ICT system;
6) At the request of an operator of ICT system of special importance, perform proactive scanning of the ICT system with the aim of determining the vulnerabilities that can potentially significantly distort the security of the ICT system, provided that such scanning must not have any detrimental effects on the operator’s work and his activities;
7) Act as the coordinator for the needs of coordinated detection of vulnerability, in accordance with this Law;
8) Take part in the development and use of technological tools for exchange of information with the operators of ICT systems of special importance and other entities with which it cooperates;
9) Continuously produce analyses of risks and incidents, based on collected information;
10) Raise awareness among citizens, business entities and authorities on the importance of information security, on the risks and protection measures, including the implementation of campaigns aimed at raising such awareness;
11) Keep the Records of special CERTs;
12) Prepare the quarterly-level reports on the undertaken activities;
13) Provide support in collection and analysis of forensic data and provide dynamic analyses of the risks and incidents in accordance with regulations;
14) Cooperate with the CERTs of foreign states and provide, at their request, mutual assistance in accordance with its capacities and competences.
The Office shall promote application and use of prescribed and standardized procedures for:
1) Incident management;
2) Classification of information on incidents, i.e. classification according to the danger level of an incident;
3) Management of crisis situations;
4) Coordinated detection of vulnerability.
The Office shall be authorized to perform processing of data on the person who reports the incident, where any such processing of personal data shall cover the name, surname and telephone number and/or the email address and shall be performed for the purpose of recording the submitted reports, informing the person submitting the report on the status of the case and, where necessary, forwarding the report to the competent authorities for further actions, in accordance with law.
The Office shall ensure continuous availability of its services through different means of communication.
The following requirements shall be ensured within the performance of tasks of the National CERT:
1) A high level of availability of communication channels by avoiding the single points of disruption and the use of multiple means for two-way contacting;
2) The premises of the National CERT and the information systems for support should be located in safe locations;
3) The use of an adequate system for managing the requests and their forwarding, in particular in order to facilitate efficient and effective exchange of information;
4) Ensuring confidentiality and reliability of own activities;
5) Existence of adequate staff capacities;
6) Equipping with redundant systems and backup work space in order to ensure continuity of services.
The by-law regulating in more detail the procedure of proactive scanning of the ICT systems referred to in paragraph 1, item 6) of this Article, the protective, technical and security conditions and the measures that the entity performing continuous scanning must fulfil, as well as the procedure laying down the conditions aimed at protecting the security of the system, network and data being accessed to, as well as the method of reporting to the competent authority shall be passed by the Government at the proposal of the Ministry.
Preventive and Reactive Measures aimed at protecting the Single e-Government Information and Communication Network (governmental authority CERT)
Article 32
Within the taking preventive and reactive measures aimed at protecting the Single e-Government Information and Communication Network (hereinafter: the e-Government network), the Office shall perform the following tasks:
1) Carry out the protection of the e-Government network;
2) Carry out coordination and cooperation with the operators of ICT systems connected by the e-Government network in incident prevention;
3) Actively participate in incident detection, collection of information on incidents and elimination of consequences of incidents;
4) Perform proactive scanning of the network of operators of ICT systems of special importance that are the network users, provided that no such scanning can have harmful influence on the operators’ tasks or activities;
5) In cases of detected vulnerability:
(1) Notify thereof the ICT system operators which are the e-Government network users;
(2) Order the operators of ICT systems of special importance which are network users to take adequate protection measures with the aim of preventing, reducing and eliminating the consequences of the incident;
6) Issue expert recommendations for protection of ICT systems of the authorities, other than the ICT systems for work with classified information;
7) Pass the act whereby it shall regulate the actions of the operators of ICT systems of special importance which are using the network in cases of incidents;
8) In cooperation with competent authorities, perform assessment of the need for further professional training of employees of operators of ICT systems of special importance which are using the network;
9) Plan and organise procedural and practical exercises in the field of information security for the employees of operators of ICT systems of special importance which are using the network;
10) Draw up proposals for improving the security features of the e-Government network;
11) Prepare analyses of the risks and incidents within the e-Government network;
12) Perform other tasks in accordance with law with the aim of improving the information security of the e-Government network.
The by-law regulating in more detail the procedure of proactive scanning of the ICT systems referred to in paragraph 1, item 4) of this Article, the protective, technical and security conditions and the measures that the entity performing continuous scanning must fulfil, as well as the procedure laying down the conditions aimed at protecting the security of the system, networks and data being accessed to, and the reporting method to the competent authority shall be passed by the Government at the proposal of the Ministry.
Article 33
The Office shall directly cooperate with the Ministry, Regulatory Authority for Electronic Communications and Postal Services, Special CERTs in the Republic of Serbia, with public and business entities and with the CERTs of ICT systems autonomous operators.
In accordance with their competences and security protocols, the CERTs can autonomously establish cooperation with relevant public and private sector actors, with an obligation to provide notifications to the Office for the purpose of coordination and exchange of information of relevance for the national system of information security.
The Office and the CERTs of the autonomous ICT systems’ operators shall hold their meetings, organized by the Office, at least three times a year, as well as when necessary in cases of incidents that are seriously jeopardizing information security in the Republic of Serbia.
Representatives of the Ministry shall also attend the meetings referred to in paragraph 3 of this Article, while representatives of special CERTs, as well as other persons, can also attend upon invitation.
When cooperating with the entities referred to in paragraph 1 of this Article, the Office shall ensure effective, efficient and safe exchange of information with application of adequate procedures, including the “traffic light protocol” (TLP), and complying with the regulations governing protection of personal data.
International Cooperation and Tasks of the Single Point of Contact
Article 34
The Office shall establish international cooperation in the field of ICT systems’ security, and it shall in particular provide warnings of risks and incidents fulfilling at least one of the following conditions:
1) They grow fast or have the tendency to become high-risk;
2) They exceed or can exceed the national capacities;
3) They can have a negative influence on more than one state.
When exchanging data referred to in paragraph 1 of this Article, the Office shall act in such a manner as not to jeopardize the confidentiality of data, as well as that such exchange of data does not influence the potential disruption of security of the ICT system.
The exchange of data referred to in paragraph 1 of this Article shall involve transmission or processing of data which is necessary for assessment and responding to security risks and incidents in accordance with this Law. In case that an exchange pertains to personal data, the Office shall ensure that any such transmission or processing is in line with the regulations governing protection of personal data, including the rules relating to data transmission to other states or international organizations.
If the incident is related to perpetration of a criminal offence that is to be prosecuted ex officio, the Office shall notify the competent public prosecutor’s office thereof, which shall autonomously or through the ministry in charge of interior affairs forward the report through official procedure in accordance with the ratified international treaties.
The Office shall perform the tasks of the single contact point for information security in case of cross-border security threats and incidents and it shall cooperate with the single contact points of other states.
Special Centres for prevention of ICT Systems’ Security Risks
Article 35
A special centre for prevention of security risks in ICT systems (hereinafter: Special CERT) shall perform the tasks related to prevention and protection from the security risks in ICT systems within an individual legal person, a group of legal persons, a field of operation, and similar.
A special CERT shall be a legal person or an organisational unit within a legal person with the seat in the territory of the Republic of Serbia, which is entered in the records of special CERTs kept by the authority i.e. organisation in charge of tasks of the National CERT, and such records are subject to public disclosure.
The entry in the records of special CERTs, kept by the Office, shall be performed based on an application of the legal person within which the special CERT is located.
Among the pieces of personal data, the records of special CERTs shall comprise data on responsible persons, namely: the name, surname, position and contact details such as the address, telephone number and email address, for the purpose of hiring special CERTs in cases of security risks and incidents in ICT systems.
The authority, i.e. the organisation referred to in paragraph 2 of this Article shall prescribe the contents, the entry method and the method of keeping of the records referred to in paragraph 3 of this Article.
Article 36
The authority, i.e. the organisation in charge of the National CERT tasks shall establish and maintain the vulnerability database of ICT products and ICT services in the Republic of Serbia and it shall enable the reporting, on a voluntary basis, by natural and legal persons, as well as producers, suppliers and service providers in an ICT system, of vulnerabilities in ICT products or ICT services, which can be reported anonymously.
The vulnerability database for ICT products and ICT services shall comprise:
1) Data on vulnerability;
2) Data on vulnerabilities of ICT products or ICT services.
At the proposal of the Ministry, the Government shall prescribe the contents, the vulnerability verification procedures, the procedures for managing the technical vulnerabilities of ICT products and ICT services, the entry method and the method of records keeping.
Article 37
The organisation authorised to manage the top-level domain registry shall keep the list of authorised registries for registration of domains in the Republic of Serbia.
The list referred to in paragraph 1 of this Article shall comprise the following data:
1) The name of the authorised registry;
2) The seat and updated contact details of the authorised registry (email address, official phone number);
3) The internet protocol address range ("IP address range") belonging to the authorised registry, which includes data on public static IP addresses.
The authorised registry shall, in case of any change to data referred to in paragraph 2 of this Article, notify thereof the organisation authorised to manage the top-level domain registry, within 15 days from the day of occurrence of the change.
The organisations authorised to manage the top-level domain registry and to provide the DNS services shall collect, store and maintain accurate and complete data on domain registration in a special database, by applying due diligence and the technical, organisational and security measures for data protection, in accordance with the regulations governing protection of personal data.
The database referred to in paragraph 4 of this Article must comprise at least the following information:
1) Domain name;
2) Domain registration date;
3) Details on the registrant, namely: name and surname of the natural person, i.e. name of the legal person, contact email address and telephone number;
4) Contact email address and telephone number of the person tasked with domain administration, if different from details of the registrant.
The organisations referred to in paragraph 4 of this Article shall adopt and apply the acts and procedures for verification of accuracy and completeness of data in the database. These procedures must be publicly available.
The organisations referred to in paragraph 4 of this Article shall ensure public availability of data other than personal data, immediately upon domain registration, all in accordance of the rules and conditions of registration of national internet domain names.
The organisations referred to in paragraph 4 of this Article shall enable access to data on domain registration which is not publicly available, on the basis of lawful and duly reasoned requests by authorised persons or authorities, in accordance with the powers granted by the regulations governing the scope of their work and in accordance with the regulations governing protection of personal data.
The reply to the request referred to in paragraph 7 of this Article must be provided without any delay, no later than 72 hours from the receipt of the request.
The organisations referred to in paragraph 4 of this Article shall pass and publish policies and procedures for acting upon the requests for disclosure of data on domain registration, in accordance with this Law and the regulations governing protection of personal data. In accordance with this Article, collection of data on domain registration must not result in data duplication. The organisations referred to in paragraph 4 of this Article shall cooperate to avoid duplication and to ensure compliance with law.
The minister in charge of information security shall prescribe the more detailed conditions for collection, storing, verification and publication of data referred to in this Article, all in accordance with the best practice of the registries of national internet domains from the European Union, as well as of the Internet Corporation for Assigned Names and Numbers (ICANN).
Child Protection in Use of Information and Communication Technologies
Article 38
The Ministry shall take preventive measures for safety and protection of children on the internet, as the activities of public interest, through educating and informing the children, parents and teachers of the advantages, risks and methods of safe internet use, as well as through the single point for provision of advice and receipt of reports relating to safety of children on the internet, and shall forward the reports to the competent authorities for further actions.
An operator of electronic communications which provides publicly available telephone services shall enable for all the subscribers a toll-free call service to the single point for provision of advice and receipt of reports relating to safety of children on the internet.
In case that the statements made in the report are indicative of a criminal offence, breach of a right, health status, wellbeing and/or general integrity of a child, of a risk of creation of addition to internet use, the report shall be forwarded to the competent authority so that they can act in accordance with the determined competences.
The Ministry shall be authorised to carry out data processing on the person who addressed the Ministry in accordance with the law regulating protection of personal data and other regulations.
Processing of personal data on the person referred to in paragraph 4 of this Article shall include the name, surname and telephone number and/or email address and shall be done for the purpose of recording the submitted reports, informing the person submitting the report of the status of the case and, where necessary, forwarding the report to the competent authorities for further actions, in accordance with law.
The personal data referred to in paragraph 5 of this Article shall be stored within the time limits envisaged by the regulations governing office operations.
The by-law regulating in more detail the method of implementation of measures for safety and protection of children on the internet referred to in paragraphs 1 and 3 of this Article shall be passed by the Government at the proposal of the Ministry.
IV CRYPTOSECURITY AND PROTECTION FROM COMPROMISING ELECTROMAGNETIC RADIATION
Article 39
The ministry in charge of defence related affairs shall be competent for the information security tasks related to approval of cryptographic products that are used for protection of transmission and storing of data classified as confidential, distribution of crypto materials and protection from compromising electromagnetic radiation and the jobs and tasks in accordance with law and regulations passed based on law.
Article 40
In accordance with this Law, the ministry in charge of defence related affairs shall:
1) Organise and realise the scientific and research work in the field of cryptographic security and protection from CE;
2) Develop, implement, verify and classify cryptographic algorithms;
3) Research, develop, verify and classify own cryptographic products and solutions for protection from CE;
4) Verify and classify the domestic and foreign cryptographic products and solutions for protection from CE;
5) Define the procedures and criteria for evaluation of cryptographic security solutions;
6) Perform the function of the national authority for approvals of cryptographic products and ensure that these products are approved in accordance with the relevant regulations;
7) Perform the function of the national authority for protection from CE;
8) Perform the check of an ICT system from the aspect of crypto security and protection from CE;
9) Perform the function of the national authority for distribution of crypto materials and define the management, handling, storing, distributing and recording of crypto materials in accordance with regulations;
10) Plan and coordinate production of crypto parameters (parameters of cryptographic algorithm), distribution of crypto materials and protection from compromising electromagnetic radiation in cooperation with the independent operators of ICT systems;
11) Establish and keep the central register of verified and distributed crypto materials;
12) Establish and keep the register of issued approvals for cryptographic products;
13) Produce electronic certificates for cryptographic systems based on Public Key Infrastructure (PKI);
14) Propose passing of the regulations in the field of crypto security and protection from CE based on this Law;
15) Perform the tasks of expert supervision in relation to crypto security and protection from CE;
16) Provide expert assistance to the person in charge of inspection supervision of information security in the field of crypto security and protection from CE;
17) Provide paid services to legal and natural persons, outside of the government system, in the field of crypto security and protection from CE in accordance with the Government regulation at the proposal of the minister of defence;
18) Cooperate with domestic and international authorities and organisations within the competencies regulated by this Law.
The funds earned from the fee for provision of services referred to in paragraph 1, item 17) of this Article shall be the revenue of the budget of the Republic of Serbia.
Compromising electromagnetic emanation
Article 41
The CE protection measures in ICT systems that handle classified information shall be applied in accordance with the regulations governing protection of classified information.
The CE protection measures can also be applied by the operators of ICT systems on their own initiative where there is no legal obligation for them to do so.
Checks of protection from CE and assessment of risk of unauthorised access to classified information through CE shall be performed in all the technical components of a system (devices, communication channels and spaces) where there is any risk of CE, which could result in disruption of information security referred to in paragraph 1 of this Article.
The check for protection from CE shall be performed by the ministry in charge of defence related affairs.
The autonomous operators of ICT systems can perform the check of CE for their own needs.
The by-law regulating in more detail the conditions for CE check and the method of risk assessment for CE data leakage shall be passed by the Government, at the proposal of the ministry in charge of defence related affairs.
Article 42
The crypto protection measures for classified information handing in ICT systems shall be applied in accordance with regulations governing protection of classified information.
The crypto protection measures can also be applied when transmitting and storing the data not marked as classified in accordance with the law governing classification of information, where it is necessary, based on a law or another legal act, to apply the technical measures to restrict access to data and to protect the integrity, authenticity and non-repudiation of data.
The by-law regulating the technical conditions for cryptographic algorithms, parameters, protocols and information resources in the field of crypto protection which are used in the Republic of Serbia in cryptographic products to protect the secrecy, integrity, authenticity, i.e. non-repudiation of data shall be passed by the Government, at the proposal of the ministry in charge of defence related affairs.
Approval for Cryptographic Product
Article 43
The cryptographic products used for protection of transmission and storing of data categorized as confidential, in accordance with law, must be verified and approved for use.
The by-law regulating in more detail the conditions that the cryptographic products referred to in paragraph 1 of this Article must comply with shall be passed by the Government, at the proposal of the ministry in charge of defence-related affairs.
Issuing Approval for Cryptographic Product
Article 44
An approval for a cryptographic product shall be issued by the ministry in charge of defence-related tasks, at the request of an ICT system operator, a producer of a cryptographic product or another interested person.
The approval for a cryptographic product can relate to an individual copy of a cryptographic product or to a specific model of a cryptographic product that is produced in series.
The approval for a cryptographic product can have a validity time limit.
The ministry in charge of defence-related affairs shall decide on the application for issuing the approval for a cryptographic products within 45 days from the date of submission of a complete application, which can be extended in case of special complexity of the check by additional 60 days at the maximum.
No appeal shall be permitted against the decision referred to in paragraph 4 of this Article, but an administrative dispute can be initiated.
The ministry in charge of defence-related tasks shall keep the register of issued cryptographic product approvals.
Among the personal data, the register referred to in paragraph 6 of this Article shall contain the following data on responsible persons, specifically: name, surname, position and contact details such as the address, telephone number and email address. The ministry in charge of defence-related tasks shall publish the public list of approved models of cryptographic products for all the models of cryptographic products for which it has been underlined in the application for approval issuing that the cryptographic product model should be included in the public list and where the application is submitted by the producer or a person authorised by the producer of the cryptographic product concerned.
The ministry in charge of defence-related tasks may revoke a previously issued approval for a cryptographic product or modify the conditions referred to in paragraphs 2 and 3 of this Article due to the reasons of new knowledge relating to the technical solutions applied in the product, which are impacting the assessment of the protection level provided by the product.
The by-law regulating in more detail the contents of the application for issuing approval for a cryptographic product, the conditions for issuing an approval for a cryptographic product, the method of approval issuing and keeping of the register of issued approvals for a cryptographic product shall be passed by the Government, at the proposal of the ministry in charge of defence-related tasks.
General Approval for Use of Cryptographic Products
Article 45
The autonomous ICT system operators shall have a general approval to use the cryptographic products.
The ICT system operator referred to in paragraph 1 of this Article shall autonomously assess the level of protection provided by each individual cryptographic product used by him, in accordance with the prescribed conditions.
Article 46
The autonomous ICT system operators holding the general approval to use the cryptographic products shall establish and keep registries of cryptographic products, crypto materials, rules and regulations and persons performing the crypto protection tasks.
Among the personal data, the registry of persons performing the crypto protection tasks shall contain the following data on persons who perform the crypto protection tasks: surname, father's name and name, date and place of birth, registration number, telephone number, email address, educational qualifications, information on completed professional training for crypto protection tasks, name of the work position, date of beginning and end of work on the crypto protection tasks.
The registry of crypto materials for handling foreign classified data shall be kept by the Office of the Council of National Security and Classified Data Protection, in accordance with the ratified international treaties.
The by-law regulating in more detail the keeping of the registries referred to in paragraph 1 of this Article shall be passed by the Government, at the proposal of the ministry in charge of defence-related tasks.
V COMPETENCES AND RESPONSIBILITIES OF SUPERVISORY ENTITIES IN IMPLEMENTATION OF THIS LAW
Information Security Inspection
Article 47
The information security inspection shall perform inspection supervision of the application of this Law and of the work of operators of ICT systems of special importance, other than the autonomous operators of ICT systems and ICT systems for work with classified data, in accordance with the law regulating the inspection supervision.
The information security inspection tasks shall be performed by the Ministry through information security inspectors.
Within the inspection supervision of the work of ICT system operators, the information security inspector shall establish whether the conditions prescribed by this Law and regulations passed based on this Law are fulfilled.
Powers of Information Security Inspector
Article 48
In a supervision procedure, in addition to measures that an inspector is authorized to order while carrying out the inspection supervision laid by law, an information security inspector shall be authorised to:
1) Order the removal of established irregularities, and set a reasonable time limit for that;
2) Prohibit the use of procedures and technical means which are jeopardizing or breaching information security, and set a time limit for that;
3) Request from the operator of ICT system of special importance to perform scanning, configuration and penetration testing of the ICT system with the aim of determining any security vulnerabilities, in accordance with risk assessment;
4) Order that the entity that is subject to supervision make publicly available information concerning non-compliance with the provisions of this Law, for which the legitimate public interest exists in the determined manner;
5) Order that the entity that is subject to supervision designate a person with precisely determined authorisations who shall supervise and monitor compliance with the provisions of this Law and imposed measures during a specified period of time;
6) Propose to the competent authority, compliance assessment body or another competent body to temporarily suspend or revoke an issued certificate, license or another act confirming compliance with the conditions, if the entity that is subject to supervision has not removed the irregularities within the set time limit;
7) Initiate procedure before the court of relevant jurisdiction or another competent authority with a view to impose a temporary measure prohibiting performance of managerial functions to the person that is performing managerial jobs in the entity that is subject to supervision, if his actions have prevented conformance with this Law and measures imposed.
The by-law regulating in more detail the procedure of scanning, configuration and penetration testing of the ICT systems with a view to determining any security vulnerabilities referred to in paragraph 1, item 3) of this Article, the protective, technical and security conditions and measures that an entity that is directly performing the activities referred to in paragraph 1, item 3) of this Article must fulfil, as well as the procedure for determining conditions for protection of the security of the systems, networks, and data being accessed to, and the reporting method to the competent authority, shall be passed by the Government at the proposal of the Ministry.
Article 49
The Office shall perform expert supervision over application of this Law and work of operators of ICT systems of special importance, other than the autonomous operators of ICT systems and ICT systems for work with classified information, in accordance with the law regulating inspection supervision.
The tasks of expert supervision shall be performed by the authorised person employed by the Office (hereinafter: the authorised person).
In the course of expert supervision, the authorised person shall have the right and obligation to control:
1) Adequacy of assessed risks bearing in mind the risk exposure level, the size of the operator and the certainty of incident occurrence and its seriousness, as well as its potential societal and economic impact;
2) Security level in technological procedures and technical equipment used by the operator of ICT system of special importance in order to apply protection measures;
3) Adequate implementation of the procedure of compliance check of the applied measures in ICT system with the security act;
4) Application of recommendations and measures in case of incidents which are significantly jeopardizing information security.
Where the Office, in the course of expert supervision, determines the existence of irregularities, deficiencies or omissions in application of this Law and regulations passed based on this Law, it shall notify thereof the entity that is subject to supervision, and set a time limit in which such entity must eliminate them.
The time limit referred to in paragraph 4 of this Article may not be shorter than eight days from the date of receipt of the notification, except in the cases requiring urgent action.
Where the Office establishes that the supervised entity has not eliminated the established irregularities, deficiencies or omissions in application of this Law and regulations passed based on this Law within the set time limit, it shall file a report to the inspection.
At the request of the information security inspector, the Office shall perform expert supervision and provide information on the determined state of facts.
The official ID card form and the method of ID card issuing to the authorised persons shall be laid down by the Office.
The official ID card of the authorised person shall comprise: coat of arms of the Republic of Serbia and the name of the Office, name and surname of the authorised person, photograph of the authorised person, official number of the ID card, date of issue of the ID card, Office stamp, signature of the Office director, as well as the printed text of the following contents: "The holder of this ID card holds the authorisations in accordance with the provisions of Article 49, paragraphs 3 and 4 of the Law on Information Security."
Article 50
The legal person that is the operator of a priority ICT system shall be sanctioned for a misdemeanour with a fine ranging from RSD 50,000.00 to RSD 2,000,000.00 for:
1) A failure to comply with the provisions on entry in the records referred to in Article 9 of this Law;
2) A failure to pass the Risk Assessment Act referred to in Article 11, paragraph 1 of this Law;
3) A failure to pass the ICT System Security Act referred to in Article 12, paragraph 1 of this Law;
4) A failure to apply the protection measures laid down by the ICT System Security Act referred to in Article 12, paragraph 2 of this Law;
5) A failure to perform a conformity check of the applied measures referred to in Article 12, paragraph 5 of this Law;
6) A failure to provide the statistical data referred to in Article 25, paragraph 1 of this Law;
7) A failure to comply with the order of an information security inspector within the set time limit referred to in Article 48, paragraph 1, item 1) of this Law.
The natural person having the capacity of a registered entity that is the operator of a priority ICT system shall be sanctioned for the misdemeanour referred to in paragraph 1 of this Article with a fine ranging from RSD 10,000.00 to RSD 500,000.00.
The responsible person with the legal person or an authority that is the operator of a priority ICT system shall also be sanctioned for the misdemeanour referred to in paragraph 1 of this Article with a fine ranging from RSD 5,000.00 to RSD 50,000.00.
Article 51
The legal person that is the operator of an essential ICT system shall be sanctioned for the misdemeanour with a fine ranging from RSD 50,000.00 to RSD 1,000,000.00 for:
1) A failure to comply with the provisions on entry in the records referred to in Article 9 of this Law;
2) A failure to pass the Risk Assessment Act referred to in Article 11, paragraph 1 of this Law;
3) A failure to pass the ICT System Security Act referred to in Article 12, paragraph 1 of this Law;
4) A failure to apply the protection measures laid down by the ICT System Security Act referred to in Article 12, paragraph 2 of this Law;
5) A failure to perform a conformity check of the applied measures referred to in Article 12, paragraph 5 of this Law;
6) A failure to provide the statistical data referred to in Article 25, paragraph 1 of this Law;
7) A failure to comply with the order of an information security inspector within the set time limit referred to in Article 48, paragraph 1, item 1) of this Law.
The natural person having the capacity of a registered entity that is the operator of an essential ICT system shall be sanctioned for the misdemeanour referred to in paragraph 1 of this Article with a fine ranging from RSD 10,000.00 to RSD 250,000.00.
The responsible person with the legal person or an authority that is the operator of an essential ICT system shall also be sanctioned for the misdemeanour referred to in paragraph 1 of this Article with a fine ranging from RSD 5,000.00 to RSD 50,000.00.
Article 52
The legal person that is the operator of a priority ICT system shall be sanctioned for a misdemeanour with a fine ranging from RSD 50,000.00 to RSD 500,000.00 for:
1) A failure to notify the authorities referred to in Article 14, paragraphs 1 through 3 of this Law, of the incidents in the ICT system referred to in Article 13, paragraph 2 of this Law;
2) A failure to notify the users to which they provide services in case of an incident that can potentially or actually causes an adverse effect on provision and use of services in accordance with Article 14, paragraph 5 of this Law;
3) A failure to provide notifications and reports during the course of, and following the end of the incident referred to in Article 24 of this Law.
The natural person having the capacity of a registered entity that is an operator of a priority ICT system shall be sanctioned for the misdemeanour referred to in paragraph 1 of this Article with a fine ranging from RSD 10,000.00 to RSD 500,000.00.
The responsible person with the legal person or authority which is the operator of a priority ICT system shall also be sanctioned for the misdemeanours referred to in paragraph 1 of this Article with a fine ranging from RSD 5,000.00 to RSD 50,000.00.
Notwithstanding paragraphs 1 through 3 of this Article, if an operator of priority ICT systems of special importance referred to in Article 14, paragraph 2 of this Law fails to notify the National Bank of Serbia of the incidents in the ICT system of special importance or fails to notify the users of the incidents in accordance with Article 14, paragraph 6 of this Law, the National Bank of Serbia shall impose measures and sanctions on such entity in accordance with the law regulating such entity’s operations.
Article 53
The fine ranging from RSD 50,000.00 to RSD 500,000.00 shall be imposed for a misdemeanour on the legal person that is the operator of an essential ICT system for:
1) A failure to notify the authorities referred to in Article 14, paragraphs 1 through 3 of this Law of the incidents in the ICT system referred to in Article 13, paragraph 2 of this Law;
2) A failure to notify the users to which they provide services in case of an incident that can cause or is causing a harmful effect on provision and use of services in accordance with Article 14, paragraph 5 of this Law;
3) A failure to provide notifications and reports during the course of and following the end of the incident referred to in Article 24 of this Law.
The natural person having the capacity of a registered entity which is the operator of a priority ICT system shall be sanctioned for the misdemeanour referred to in paragraph 1 of this Article with a fine ranging from RSD 10,000.00 to RSD 250,000.00.
The responsible person with the legal person or authority which is the operator of an essential ICT system shall also be sanctioned for the misdemeanour referred to in paragraph 1 of this Article with a fine ranging from RSD 5,000.00 to RSD 50,000.00.
VII TRANSITIONAL AND FINAL PROVISIONS
Time Limits for Passing of By-Laws
Article 54
The by-laws envisaged by this Law shall be passed within 12 months from the date of entry into force of this Law.
The reaction plan in case of high level incidents and information security crisis referred to in Article 18 of this Law shall be passed within 18 months from the date of entry into force of this Law.
Article 55
The operators of the ICT systems of special importance designated by the Law on Information Security ("Official Herald of the RS", Nos. 6/16, 94/17 and 77/19) shall continue to act in accordance with the obligations laid down by Articles 6a through 11b of that law by 31 December 2025.
The penal provisions referred to in Articles 30 and 31 of that law shall apply to the operators of the ICT systems of special importance designated by the Law on Information Security ("Official Herald of the RS", Nos. 6/16, 94/17 and 77/19) by the date referred to in paragraph 1 of this Article.
The operators of the ICT systems of special importance shall pass the act referred to in Article 11, paragraph 1 of this Law within 18 months from the date of entry into force of this Law.
The authority, i.e. the organisation in which the tasks of the National CERT are performed shall, within nine months from the date of entry into force of this Law, pass the general methodology for risk assessment in the ICT systems of special importance referred to in Article 11, paragraph 4 of this Law.
The operator of an ICT system of special importance shall pass the act referred to in Article 12 of this Law within 18 months from the date of entry into force of this Law.
Article 56
The Information Security Office shall be established and it shall commence to perform the tasks within the scope of its competence prescribed by this Law starting from 1 January 2027.
The tasks of the Information Security Office prescribed by this Law, except for the tasks of the National CERT, shall be performed by the Office for Information Technologies and e-Government in the period which starts at the date of expiry of six months from the date of entry into force of this Law and runs until 1 January 2027.
The Regulatory Authority for Electronic Communications and Postal Services shall perform the tasks of the National CERT laid down by this Law until the establishment of the Information Security Office, i.e. by 1 January 2027.
The Information Security Office shall take over the rights, obligations, employees, objects, equipment, means for work and the archive from the Regulatory Authority for Electronic Communications and Postal Services that originated in the performance of tasks of the National CERT, which are required for performance of expert tasks laid down by this Law.
Starting from the date referred to in paragraph 1 of this Article, the Information Security Office shall take over the rights, obligations, employees, objects, equipment, means for work and the archive from the Office for Information Technologies and e-Government originated in the performance of tasks prescribed by this Law within the scope of competence of the Information Security Office.
Repealing of Law on Information Security
Article 57
On the date of entry into force of this Law, the Law on Information Security ("Official Herald of the RS", Nos. 6/16, 94/17 and 77/19) shall cease to be valid, with the exception of the provisions of Articles 6a through 11b and Articles 30 and 31, which shall apply until 31 December 2025.
The by-laws adopted on the basis of the Law on Information Security ("Official Herald of the RS", Nos. 6/16, 94/17 and 77/19) shall apply until the entry into force of the by-laws that are to be passed in accordance with this Law.
Article 58
This Law shall enter into force on the eighth day from the day of publication in the "Official Herald of the Republic of Serbia", with the exception of Article 29 of this Law which shall become applicable from 1 January 2027.