19.2.15. notify the relevant center against cyber-attacks and violations, and the users
immediately of failure of normal, uninterrupted operations infrastructure due to planned inspections and
audits, damages and events and circumstances of force majeure to networks and systems outside of their
own infrastructure.
19.3. If information security audits have been conducted in the time period stipulated in this law
and in accordance with international standards, the report of such audit shall be based on to deem the
obligation stipulated in article 19.2.6 of this law as fulfilled.
CHAPTER FOUR
COMBATING CYBER ATTACKS AND VIOLATIONS
Article 20.Center against attacks and violations
20.1.The following centers with the human resources, technical and technological capacity, and
information databases shall operate with the key functions to provide professional and methodology
support and assistance for the detection, termination of, and responses to. cyber-attacks and violations,
and for the restoration of targeted infrastructures and information systems:
20.1.1.National center against cyber-attacks and violations (hereinafter referred to as
"National center");
20.1.2.Public center against cyber-attacks and violations (hereinafter referred to as
"Public center");
20.1.3.Armed forces center against cyber-attacks and violations (hereinafter referred to
as "Armed forces center").
20.2.Legal persons other than the above shall have fulfilled the relevant requirements stipulated
in article 10.1.4 of this law in conducting activities to detect and terminate cyber-attacks.
20.3.The centers stipulated in article 20.12 and 20.1.3 of this law, and the legal person stipulated
in article 20.2 of this law shall cooperate with the National center and exchange information regarding
cyber-attacks and violations.
Article 21.National Center
21.1.The National center shall fall under the structure of the intelligence agency.
21.2.The National center shall exercise the following functions:
21.2.1.coordinate and facilitate the activities and operation of the centers against
cyber-attacks and violations nationwide, and provide professional and methodology assistance thereto;
21.2.2.detect, terminate, and respond to cyber-attacks and violations directed at the
information systems of state-owned legal persons with critical information infrastructure and organizations
connected to the state information consolidated network, and provide support in the restoration of the
targeted information systems;
21.2.3.conduct analysis, accumulate databases, develop statistical information and
surveys, and distribute recommendations and information pertaining to information on cyber-attacks and
violations nationwide;
21.2.4.represent Mongolia in collaborations and exchange of information with
international organizations and organizations of foreign countries in areas that fall under the scope of
authority;
21.2.5.receive information pertaining to cyber-attacks and violations, transfer such
information to the relevant authorities;
21.2.6.issue and submit recommendations and requirements regarding cyber-attacks