19.1.10.organizations that produce, store, and distribute strategic food stuff;
19.1.11.Information and operational management center;
19.1.12.National public radio and television;
19.1.13.organization in charge of main and supporting information systems and base
information databases;
19.1.14.organization in charge of data centers, their branches and resource center
operations;
19.1.15.organization in charge of border port control and administration systems;
19.1.16.organization mining minerals of strategic significance;
19.1.17.organization in charge of registration, monitoring, and consolidated information
systems relating to passengers and transportation vehicles that are crossing the national borders.
19.2.Organizations with critical information infrastructure shall have the following obligations:
19.2.1.adopt internal procedures for ensuring cyber security;
19.2.2.adopt and implement an action plan in case of cyber-attacks and violations;
19.2.3.introduce standards to ensure information security;
19.2.4. have an officer or unit on staff in charged with ensuring cyber security;
19.2.5. have cyber security risk assessments conducted every year, and where
modifications are made to the information systems and information networks have such assessments done
partially for each case, and fully if required by the relevant authorities, and take measures in accordance
with the conclusion, recommendations, and requirements issued in relation thereto;
19.2.6.have information security audits conducted every two years;
19.2.7.plan and implement management, organizational, and technical measures
necessary for ensuring the information system and information network security;
19.2.8.have an information system for the detection, registration, and termination of
cyber-attacks and violations;
19.2.9. store information system action log for the time period stipulated in the common
procedure for ensuring cyber security;
19.2.10.submit the cyber security risk assessment and information security audit reports
to the relevant center against cyber-attacks and violations within one month of receipt;
19.2.11.comply with the requirements issued by the relevant authorities, and take
measures to eliminate the violations and errors detected;
19.2.12.If cyber security risk assessments are to be conducted by foreign citizens and
foreign legal persons, the intelligence agency shall be consulted;
19.2.13.have an action plan in place for ensuring the normal, uninterrupted operation of
the information system and infrastructure, and for restoration thereof in case of damages and interruptions;
19.2.14. notify the relevant center against cyber-attacks and violations immediately of
failure of normal, uninterrupted operations of the information systems and infrastructure due to
cyber-attacks and violations;