LAW OF MONGOLIA ON CYBER SECURITY
17 December 2021
State Palace, City of Ulaanbaatar
CHAPTER ONE
GENERAL PROVISIONS
Article 1. Purpose of the law
1.1. The purpose of this law is to regulate relations pertaining to establishing the system,
principles, and legal framework in ensuring cyber security, and ensuring the safety, confidentiality, and
accessibility of information within cyberspace and cyber environments.
Article 2. Legislation on cyber security
2.1. Cyber security legislation shall consist of the Constitution of Mongolia, Law on National
Security, Law on Armed Forces, Law on State and Official Secrets, Law on Communications, Law on the
Intelligence Agency, Law on Organizational Secrets, Law on Transparency of Public Information, Law on
Personal Secrets, the Law on Electronic Signatures, this law, and other legislative acts enacted in
accordance thereto.
2.2. Where an international treaty to which Mongolia is party stipulates differently from this law,
the rules of such international treaty shall prevail.
Article 3. Scope of application of the law
3.1.This law applies to relations of coordinating, facilitating, and monitoring relations between the
State, inpiduals, and legal persons in ensuring cyber security.
3.2. Unless otherwise stipulated in the law, this law shall apply indiscriminately to foreign citizens,
stateless persons, and foreign or foreign-invested legal persons operating through the information systems
and information networks of Mongolia.
3.3.The auditing of information security regulated by this law shall not comprise auditing by state
audit organizations.
Article 4.Definition of terms in this law
4.1.The following terms used in this law shall have the following definitions, respectively:
4.1.1."cyber security" shall mean the fulfillment of safety, confidentiality, and accessibility
of information within cyber environments;
4.1.2."cyberspace" shall mean tangible and non-tangible platforms that consist of
internet and other information and communication networks, and inter-dependent systems that ensure their
operation;
4.1.3."cyber environment" shall mean the information systems, and information network
environments that allow accessing, login, collection, processing, storing, and use of information;
4.1.4."safety" shall mean protection from unauthorized deletion or modification;
4.1.5."confidentiality" shall mean the state of protection of information from unauthorized
access or login;
4.1.6."accessibility" shall mean the possibility of accessing, logging in, collecting, and
using of information within the allowed scope;