Cabinet Resolution No. 1799: Who Must Assess Cybersecurity and How to Prepare
Cabinet Resolution No. 1799 introduces a single approach to assessing the cybersecurity posture of specified information systems and facilities. The State Service of Special Communications and Information Protection of Ukraine has clarified who is covered, what should be assessed and which documents organisations should prepare.
Who is covered by Resolution No. 1799
The Procedure applies to owners or administrators of specified systems and facilities. They may include public authorities, other state bodies, local government bodies, critical infrastructure operators and other legal entities regardless of their legal form.
- systems processing state information resources;
- systems processing official or restricted information;
- systems processing information that constitutes a state secret;
- critical infrastructure facilities;
- critical information infrastructure facilities.
The decisive factor is therefore not only the organisation’s status, but also whether it owns or administers the relevant systems or facilities.
Who is outside the scope of the Procedure
The Procedure does not apply to the National Bank of Ukraine, banks, institutions and persons operating in financial markets regulated by the National Bank, or payment system operators, participants and payment service technology operators.
What is assessed
The assessment should show the actual cybersecurity posture of the relevant facility, rather than merely the existence of individual documents or software tools. Its scope may include information, electronic communications and technology systems, services, databases, networks, infrastructure, accounts, roles and access rights.
- backup and recovery processes;
- cyber incident response;
- policies, plans, orders and instructions;
- responsible officers;
- contractors and suppliers whose services affect cybersecurity.
Where an organisation has several interconnected systems, they should be considered together, taking into account shared network infrastructure, administration, backup, monitoring and incident response processes.
Self-assessment and external assessment
Planned self-assessment of the current cybersecurity posture is organised by the owner or administrator of the facility every year. If necessary, the organisation may involve another eligible assessment subject.
External assessment is carried out by a subject that meets the established requirements and is included in the relevant list. For critical infrastructure operators and owners or administrators of critical information infrastructure facilities, planned external assessment is carried out at least once every two years, subject to the special rules for facilities in criticality categories III and IV.
An unscheduled external assessment may take place after a critical or emergency cyber incident, at the decision of the owner or administrator, or by court order. Where the response process identifies protection deficiencies or signs of a breach of cybersecurity or information protection requirements, the assessment is carried out within three months of the end of the response service or recommendations.
Who may conduct the assessment
Assessment subjects may include legal entities, individual entrepreneurs, individuals and military formations carrying out assessments for their own needs. They must meet the established requirements and be included in the relevant list.
An assessment may not be conducted by a subject that participated in creating the relevant facility. The same subject may not assess a facility for more than three consecutive years. These restrictions are intended to support an objective process.
The report and supporting documents
The result of the assessment is a report describing the facility and assessment scope, the type and grounds for the assessment, the period, the assessment subject, the results, conclusions and recommendations.
A copy of the report must be sent to the Administration of the State Service of Special Communications and Information Protection of Ukraine within 30 calendar days of the assessment’s completion. Copies are retained by the owner or administrator and the assessment subject for three years.
Before the assessment, it is useful to prepare information about the systems and facilities, the types of information processed, orders appointing responsible officers, access-control documents, cybersecurity policies and instructions, backup and recovery materials, incident-response records, and information about relevant contractors and suppliers.
How IQusion IT can help
IQusion IT can support an organisation at different stages of preparation, from explaining the resolution’s requirements to implementing technical and organisational cybersecurity measures.
- Lectures and seminars: training for management, responsible officers and IT specialists on assessment scope, access, backups and incident response.
- Readiness review: inventory of systems, data, services, networks and dependencies, with gap identification and a practical roadmap.
- Policies and documentation: development of information security policies, access models, backup and response procedures, and supplier requirements.
- Technical implementation: configuration of role-based access, SSO, multi-factor authentication, logging, redundancy, network segmentation and monitoring.
- Information system protection and integration: preparation for security authorisation, technical information protection expertise or another relevant conformity route.
- Ongoing support: maintenance of policies, updates, role changes, repeat reviews and corrective actions.
The official report must be prepared by a subject that meets the Procedure’s requirements and is included in the relevant list. IQusion IT can help organisations prepare for assessment, remediate identified gaps and implement the necessary protection measures.
Frequently asked questions
Does Resolution No. 1799 apply to every organisation?
No. It applies to owners or administrators of specified information systems, critical infrastructure facilities and critical information infrastructure facilities.
How often is self-assessment required?
Planned self-assessment of the current cybersecurity posture is carried out every year.
When must a report be sent to the Administration?
A copy of the report must be sent within 30 calendar days of the assessment’s completion.
Can the system developer conduct its assessment?
No. A subject that participated in creating the facility may not assess it. The same subject also may not assess a facility for more than three consecutive years.