Fines have been established for the violation of requirements of normative legal acts in the field of ensuring cybersecurity.
“Elchi” reports that this is reflected in the new Article 371-2 added to the Code of Administrative Offenses, approved by President Ilham Aliyev.
According to the Code, for the failure of computer incident response centers, security operations centers, as well as subjects of information infrastructure, including owners of internet information resources, internet service providers, and host providers to take measures related to ensuring the cybersecurity of information infrastructure, namely:
– failure to comply with the instructions of the body (institution) determined by the relevant executive authority regarding the provision of cybersecurity of information infrastructure (prevention of cyber threats, cyberattacks, and cyber incidents, as well as elimination of their consequences), as well as conducting digital research and providing information about the results;
– failure to immediately provide the body (institution) determined by the relevant executive authority with information about cyber threats, cyberattacks, and cyber incidents directed at information infrastructure, as well as information obtained as a result of continuous real-time monitoring of cyber incidents and cyberattacks and initial technical response measures against them;
– failure to respond within 24 hours to requests sent by the body (institution) determined by the relevant executive authority for the purpose of studying the state of cybersecurity of information infrastructure and conducting proactive cybersecurity research, and within 5 business days for requests related to conducting digital research;
– failure to carry out continuous real-time monitoring of cyber incidents and cyberattacks and initial technical response measures against them;
– violation of general and specific requirements for the cybersecurity of information infrastructure performing socially significant functions by subjects of information infrastructure, including internet service providers, host providers, and owners of internet information resources;
– failure to create conditions for digital research and proactive cybersecurity research, as well as allowing the integrity of information obtained during digital research to be compromised, or allowing its alteration, deletion, or falsification –
officials will be fined in the amount of five hundred to one thousand manats, and legal entities in the amount of one thousand to two thousand manats.
For operating as a computer incident response center or a security operations center without being included in the “Register of computer incident response centers and security operations centers,” officials will be fined in the amount of one thousand to one thousand five hundred manats, and legal entities in the amount of one thousand five hundred to two thousand five hundred manats.
These provisions will not apply to the information infrastructure belonging to critical information infrastructure, state bodies (institutions), including the Central Bank of the Republic of Azerbaijan, subjects of intelligence and counter-intelligence activities, subjects supervised in financial markets (banks, insurers, reinsurers, persons licensed in the securities market, joint-stock investment funds and investment fund managers, payment service providers, etc.), as well as the information infrastructure of protected persons, protected and strategic facilities, and computer incident response centers and security operations centers created by the body (institution) determined by the relevant executive authority and the Central Bank of the Republic of Azerbaijan.