BAKU, Azerbaijan, July 20. The general requirements for a provider of cybersecurity services to a subject of critical information infrastructure have been published in Azerbaijan, Trend reports.
This is reflected in the "Rules for ensuring the security of critical information infrastructure in the Republic of Azerbaijan" approved by the Cabinet of Ministers of the Republic of Azerbaijan.
The general requirements for a provider of cybersecurity services to a subject of critical information infrastructure are:
- the founder of the provider and his authorized representative must be citizens of the Republic of Azerbaijan;
- the provider must have a physical space allocated for the maintenance of critical information infrastructure facilities;
- the provider must ensure that information about personnel, supporting critical information infrastructure, is entered into the Register;
- the provider must comply with the general requirements for the security of critical information infrastructure.
The requirements for the personnel of the provider of cybersecurity services to the subject of critical information infrastructure are:
- the person in charge of the provider's activities to ensure the security of critical information infrastructure must be a citizen of the Republic of Azerbaijan, have the necessary knowledge and skills in the field of cybersecurity or information security, work experience in the field of cybersecurity or information security for at least 3 years, including at least 1 year of managerial experience.
Other employees of the provider involved in activities to ensure the security of critical information infrastructure must meet the following requirements:
- must be citizens of the Republic of Azerbaijan;
- must have the necessary knowledge and skills in the field of information technology or information security, be involved in training and educational activities on cybersecurity at least once a year;
- employees who carry out the activities of the operational security center and conduct testing must have at least 1 year of experience in the field of information technology, cybersecurity or information security;
- the person certifying the audit results with a signature must have at least 1 year of experience in auditing activities in the field of information security.