Cybersecurity Law Proposal passed in the Grand National Assembly of Turkey
The Cybersecurity Law Proposal has been passed in the General Assembly of the Grand National Assembly of Turkey (TBMM).
The proposal establishes the principles for identifying and eliminating existing and potential threats directed from within and outside against all elements that constitute the Republic of Turkey's national power in cyberspace, determining the principles for reducing the potential impacts of cyber incidents, making necessary regulations for the protection of public institutions and organizations, professional organizations with public institution status, natural and legal persons, and organizations without legal personality against cyberattacks, determining strategies and policies to strengthen the country's cybersecurity, and establishing the Cybersecurity Board, while setting the general framework for the scope of the law.
Accordingly, the regulation will cover public institutions and organizations, professional organizations with public institution status, natural and legal persons, and organizations without legal personality that exist, operate, or provide services in cyberspace.
Intelligence activities carried out in accordance with the Law on Police Duties and Powers, the Law on the Organization, Duties and Powers of the Gendarmerie, as well as activities carried out in accordance with the State Intelligence Services and National Intelligence Organization Law, are kept outside the scope of the law.
In line with the motion accepted in the commission, activities carried out in accordance with the Turkish Armed Forces Internal Service Law and the Coast Guard Command Law will also be kept outside the scope.
The proposal defines terms such as "Hosting," "President," "Presidency," "Information systems," "Critical infrastructure," "Critical public service," "Cybersecurity," "Cyber incident," "Cyberattack," "Cyber threat," "Cyber threat intelligence," "Cyberspace," "SOME (Cyber Incident Response Team)," "Asset," and "Vulnerability," and also determines the fundamental principles for ensuring cybersecurity.
Accordingly, cybersecurity will be an integral part of national security. The protection of critical infrastructure and information systems and the creation of a secure cyberspace will be the primary goal.
Work related to cybersecurity will be carried out based on institutionalization, continuity, and sustainability. It will be essential to apply cybersecurity measures throughout the entire life cycle of services and products.
ACCOUNTABILITY WILL BE ESSENTIAL IN THE EXECUTION OF CYBERSECURITY PROCESSES
In efforts to ensure cybersecurity, domestic and national products will be prioritized. All public institutions and organizations, as well as natural and legal persons, will be held responsible for the execution of cybersecurity policies and strategies and for taking necessary measures to prevent cyberattacks or reduce their impact. Accountability will be essential in the execution of cybersecurity processes.
Cybersecurity policy and strategy development efforts will be carried out with a continuous improvement approach. Efforts to increase the capability and capacity of qualified human resources in the field of cybersecurity will be encouraged.
The dissemination of a cybersecurity culture throughout society will be targeted.
The principles of the rule of law, fundamental human rights and freedoms, and the protection of privacy will be accepted as the basic foundation.
PROTECTION AGAINST CYBERATTACKS
The proposal also defines the duties of the Cybersecurity Presidency. Accordingly, in addition to the duties included in the relevant legislation, the Cybersecurity Presidency will carry out activities aimed at increasing the cyber resilience of critical infrastructures and information systems, protecting them against cyberattacks, detecting cyberattacks that have been carried out, and preventing or reducing/eliminating the effects of potential attacks.
In this context, the Presidency will carry out or have carried out vulnerability and penetration tests and risk analyses for assets, combat cyber threats, obtain, create, and share cyber threat intelligence, and conduct malware analysis activities.
The Cybersecurity Presidency, which will determine critical infrastructures and the institutions and locations they belong to, will also be responsible for ensuring that public institutions and organizations and critical infrastructures keep an inventory of all their assets, including data inventories, and that risk analyses for these assets are performed, as well as taking or having security measures taken according to the criticality of the assets owned by public institutions and organizations and critical infrastructures.
Establishing, having established, and auditing Cyber Incident Response Teams (SOME), conducting studies to determine and increase the maturity levels of SOME units, measuring the cyber incident response capabilities of SOME units by conducting cybersecurity exercises, establishing coordination with the cyber incident response teams of other countries, and conducting, having conducted, and encouraging studies for the production and development of all kinds of cyber intervention tools and national solutions are also among the duties of the Presidency.
CYBERSECURITY OF CRITICAL PUBLIC SERVICES WILL BE ENSURED
The Cybersecurity Presidency will also regulate the procedures and principles that those operating in the field of cybersecurity must comply with.
The Cybersecurity Presidency will determine the application procedures and principles for establishing, having established, operating, and having operated the necessary infrastructure to ensure the cybersecurity of public institutions and organizations and critical public services, and for providing or ensuring the provision of hosting services to public institutions and organizations through secure systems and infrastructure.
Preparing standards related to the field of cybersecurity, examining standards prepared by other persons or organizations, providing opinions on them, accepting them as standards when deemed appropriate, publishing them, and monitoring their implementation are also among the duties of the Cybersecurity Presidency.
The Cybersecurity Presidency will carry out testing and certification processes for software, hardware, products, systems, and services related to the field of cybersecurity, establish, have established, and operate testing infrastructure for this purpose, and carry out certification, authorization, and accreditation processes for cybersecurity experts and companies in coordination with relevant institutions.
The Cybersecurity Presidency, which will carry out cybersecurity audits and impose sanctions based on the results, will be tasked with determining technical criteria and making legislative regulations regarding the qualifications that cybersecurity products and services to be used in public institutions and organizations and critical infrastructures, as well as the businesses that will provide them, must possess, conducting or having these audits performed, determining the qualifications that the organizations that will perform the audits must possess, assigning these organizations, and temporarily suspending or canceling the assignment when necessary.
News Source: 12punto
Most Read
Striking picture for Özgür Özel's 'New Party'
The PKK opening and Özgür Özel’s path!..
How did the newspapers view Özgür Özel's farewell to the CHP?
He killed his wife by slitting her throat: Their children witnessed the moments
What did the CHP do?
Özel’s new party move in the world press
Fire at TUSAŞ engine factory in Eskişehir under control
The New CHP, against CEHAPE
From self-efficacy to despair
Kılıçdaroğlu's first message on Özgür Özel's new party announcement