4.1.7."information system" shall have the meaning as stipulated in article 4.1.1 of the
Law on Transparency of Public Information;
4.1.8."information network" shall have the meaning as stipulated in article 4.1.2 of the
Law on Transparency of Public Information;
4.1.9."cyber security risk assessment" shall have the meaning professional activities that
define the probability of failure of, threats and risks to, the cyber security of electronic information,
information systems, and information networks, the level of vulnerability, and measures to reduce its
consequences and risks, and of prevention;
4.1.10."information security audit" shall mean unbiased, independent professional
activities that review the compliance with cyber security laws and relevant procedures and standards and
issue recommendations;
4.1.11."log of information system actions" shall mean the registration that defines the
action and time of access, login, processing, collecting, and use to a specific information system;
4.1.12."Organization with critical information infrastructure" shall mean an organization
that has an information system or information network, of which the failure of the cyber security could
potentially cause failure of such organization's operations, and cause harm to the security, society, and
economy of Mongolia;
4.1.13."Cyber security violation" shall mean any act or omission thereof that threatens
the safety, confidentiality, or accessibility of an information system;
4.1.14."cyber-attack" shall mean an action that aims to disrupt the cyber security of
information systems or information networks;
4.1.15."cyber-attack at national level" shall mean a cyber-attack that attacks the
information system and information network of an organization with critical information infrastructure
thereby disrupting the operations of such organization potentially causes harm to the national security,
society, and economy of Mongolia;
4.1.16."Center against cyber-attacks and violations" shall mean person charged with the
function to facilitate activities to prevent, detect, terminate, and respond to cyber-attacks and violations,
and restore information systems, and provide professional guidance thereto;
4.1.17."State information consolidated network" shall mean the comprehensive system
of state internet usage and official and special use networks, with a consolidated infrastructure aimed at
ensuring information-exchange and cyber security between state organizations;
4.1.18."state-owned legal person" shall have the meaning stipulated in article 13 of the
Law on State and Local Properties.
Article 5.Principles of ensuring cyber security
5.1.In addition to that stipulated in article 4.1 of the Law on National Security, the following
principles shall be adhered to in ensuring cyber security:
5.1.1.maintain unified supervision;
5.1.2.to be grounded on science, progressive technology and innovation;
5.1.3.support national products, services, and human resources capabilities;
5.1.4.to base on risk assessment;
5.1.5.to base on public-private partnership;
5.1.6.develop international cooperation.