information security audits on the same organization two years after such time that it has rendered
information technology and information security services to such organization.
9.4.Organizations with critical information infrastructure shall have its information security audits
conducted by the intelligence agency, or with the permission thereof, by legal person stipulated in article
9.1 of this law.
9.5.The state central administrative organization in charge of digital development and
communications shall adopt procedures on registering legal persons to conduct information security audits,
and on conducting audits.
9.6. The legal persons stipulated in article 9.1 of this law, and the relevant organization and
official who have received the information security audit report shall be obligated to maintain the
confidentiality and ensure non-disclosure thereof.
CHAPTER THREE
CYBER SECURITY SYSTEM
Article 10. Government
10.1.In accordance with the national security framework, the Government shall implement the
following authority regarding ensuring cyber security:
10.1.1.adopt the national strategy on cyber security;
10.1.2.incorporate cyber security within development policy and planning documents,
facilitate the implementation of legislation accordingly;
10.1.3.adopt a national level plan for protection from cyber-attacks;
10.1.4.adopt the rules, organizational structure, staff positions of the national center
against cyber-attacks and violations and the public center, the operational procedure of the centers, and
their operational requirements;
10.1.5.adopt the list of organizations with critical information infrastructure;
10.1.6.adopt the procedure for establishing and using the state information consolidated
network, and the list of organizations affiliated thereto;
10.1.7.incorporate funds necessary for implementing activities aimed at ensuring cyber
security, within the state budget;
10.1.8.adopt the organizational structure, staff positions, and operational procedure of
the cyber security council office.
Article 11.Cyber Security council
11.1.A non-staff Cyber security council (hereinafter referred to as "the Council") shall operate with
the key functions to provide cyber security activities with unified supervision, coordinated facilitation,
organize implementation, and ensure exchange of information.
11.2.The Council shall be led by the Prime Minister, and the vice-director shall be the Member of
Government in charge of digital development and communications as well as the Head of the General
Intelligence Agency, and the Council shall have an office.
11.3.The constitution and the rules of the Council shall be adopted by the Government.
11.4.The Council shall implement the following authority:
11.4.1.Exercise monitoring on the implementation of the cyber security legislation;
11.4.2.provide unified supervision and facilitation on ensuring cyber security at the