CYBERSECURITY OF CRITICAL INFRASTRUCTURE UNDER MARTIAL LAW CONDITIONS
DOI:
https://doi.org/10.66556/2522-4549.3540.koshovyi-bKeywords:
cybersecurity, critical infrastructure, martial law, cyberattack, cyber defense, CERT-UA, national securityAbstract
The article examines the legal and organizational foundations for ensuring cybersecurity of critical infrastructure objects under martial law conditions in Ukraine. The provisions of the Law of Ukraine "On the Basic Principles of Ensuring Cybersecurity of Ukraine" of October 5, 2017, in particular the norms of Articles 6 and 8 regarding cyber defense of critical infrastructure and the structure of the national cybersecurity system, are analyzed in their interrelation with the Law of Ukraine "On Critical Infrastructure" of November 16, 2021, and the martial law regime introduced by the Decree of the President of Ukraine of February 24, 2022. The practice of cyberattacks on critical infrastructure objects of Ukraine during the full-scale armed aggression of the Russian Federation is examined and the main threat vectors in cyberspace are identified, including coordinated cyberattacks on energy and communications infrastructure. The powers of the national cybersecurity system subjects are considered, in particular the State Service of Special Communications and Information Protection of Ukraine and the governmental computer emergency response team CERT-UA, and their activities during wartime are analyzed. The Cybersecurity Strategy of Ukraine for 2021–2025 is analyzed and the degree of its adaptability to armed conflict conditions is determined. The necessity of improving sectoral cybersecurity requirements for critical infrastructure objects taking into account the experience of countering cyber threats during martial law and relevant European Union standards, in particular Directive NIS 2, is substantiated. Proposals for strengthening the liability of critical infrastructure operators and developing public-private partnerships in the field of cyber defense are formulated.References
1. Pro osnovni zasady zabezpechennya kiberbezpeky Ukrayiny : Zakon Ukrayiny vid 5 zhovtnya 2017 roku № 2163-VIII. Vidomosti Verkhovnoyi Rady Ukrayiny. 2017. № 45. St. 403. [in Ukrainian].
2. Telenyk S.S. Derzhavna systema zakhystu krytychnoyi infrastruktury Ukrayiny: kontseptualni zasady administratyvno-pravovoho rehulyuvannya : monohrafiya. Odesa : Vydavnychyi dim «Helvetyka», 2020. 602 s. [in Ukrainian].
3. Pro krytychnu infrastrukturu : Zakon Ukrayiny vid 16 lystopada 2021 roku № 1882-IX. Vidomosti Verkhovnoyi Rady Ukrayiny. 2022. № 9. St. 60. [in Ukrainian].
4. Pro rishennya Rady natsionalnoyi bezpeky i oborony Ukrayiny vid 14 travnya 2021 roku «Pro Stratehiyu kiberbezpeky Ukrayiny» : Ukaz Prezydenta Ukrayiny vid 26 serpnya 2021 roku № 447/2021. Ofitsiinyi visnyk Prezydenta Ukrayiny. 2021. № 20. St. 871. [in Ukrainian].
5. Omelchenko A.V. Orhanizatsiino-pravovi zasady zabezpechennya kiberbezpeky Ukrayiny. Kyyivskyi chasopys prava. 2022. № 2. S. 38–46. [in Ukrainian].
6. Lipkan V.A. Kiberbezpeka: pravovyi vymir : monohrafiya. Kyyiv : Lipkan O.S., 2018. 380 s. [in Ukrainian].
7. Tsyapa S.M. Pravove ta orhanizatsiine zabezpechennya zakhystu obyektiv krytychnoyi informatsiinoyi infrastruktury vid kiberatak. Informatsiya i pravo. 2020. № 4. S. 28–38. [in Ukrainian].
8. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. Official Journal of the European Union. L 333/80. 27.12.2022.
9. Butuzov V.M. Kiberbezpeka v umovakh suchasnykh zahroz: orhanizatsiino-pravovi aspekty. Pravo i bezpeka. 2021. № 3. S. 48–60. [in Ukrainian].
10. Konventsiya pro kiberzlochynnist vid 23 lystopada 2001 roku (Budapeshtska konventsiya). URL: https://zakon.rada.gov.ua/laws/show/994_575 (data zvernennya: 01.11.2022). [in Ukrainian].