{"id":7945,"date":"2025-04-07T10:03:31","date_gmt":"2025-04-07T07:03:31","guid":{"rendered":"https:\/\/lexcovery.com\/2025\/04\/on-approval-of-requirements-for-risk-management-of-security-at-critical-infrastructure-facilities-of-category-i-criticality-2\/"},"modified":"2025-04-07T10:03:31","modified_gmt":"2025-04-07T07:03:31","slug":"on-approval-of-requirements-for-risk-management-of-security-at-critical-infrastructure-facilities-of-category-i-criticality-2","status":"publish","type":"post","link":"https:\/\/lexcovery.com\/en\/2025\/04\/on-approval-of-requirements-for-risk-management-of-security-at-critical-infrastructure-facilities-of-category-i-criticality-2\/","title":{"rendered":"On Approval of Requirements for Risk Management of Security at Critical Infrastructure Facilities of Category I Criticality"},"content":{"rendered":"<p>Resolution Essence:<br \/>\nThe document establishes detailed requirements for risk management of safety at critical infrastructure facilities of the first criticality category. It defines the procedure for creating a risk management system, main types of risks, and principles of their assessment. The resolution aims to prevent incidents and minimize their consequences at critically important facilities.<\/p>\n<p>Structure and Main Provisions:<br \/>\n1. Five main types of risks are identified: material, cybersecurity, human factor, interconnection disruption, and process risks.<br \/>\n2. Principles of the risk management system are established: integration, structuredness, individuality, dynamism, proper awareness, and minimization of the human factor.<br \/>\n3. The procedure for risk assessment through their identification, analysis, and processing is defined.<br \/>\n4. Reporting requirements are established &#8211; annual submission of reports by operators to sectoral bodies and by sectoral bodies to the State Special Communications Service.<\/p>\n<p>Key Provisions for Application:<br \/>\n&#8211; Critical infrastructure operators must create a separate unit or appoint a person responsible for risk management<br \/>\n&#8211; Internal documents on risk management and a facility-level security action plan must be developed<br \/>\n&#8211; Risk assessment must be conducted at least once a year<br \/>\n&#8211; The risk management system must comply with national and international standards, including DSTU IEC\/ISO 31010:2013 and NIST SP 800-53<\/p>\n<p><a href=\"https:\/\/zakon.rada.gov.ua\/go\/367-2025-%D0%BF\"><strong>Full text by link<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Resolution Essence: The document establishes detailed requirements for risk management of safety at critical infrastructure facilities of the first criticality category. It defines the procedure for creating a risk management system, main types of risks, and principles of their assessment. The resolution aims to prevent incidents and minimize their consequences at critically important facilities. Structure&hellip;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_bbp_topic_count":0,"_bbp_reply_count":0,"_bbp_total_topic_count":0,"_bbp_total_reply_count":0,"_bbp_voice_count":0,"_bbp_anonymous_reply_count":0,"_bbp_topic_count_hidden":0,"_bbp_reply_count_hidden":0,"_bbp_forum_subforum_count":0,"pmpro_default_level":"","footnotes":""},"categories":[15,45],"tags":[],"class_list":["post-7945","post","type-post","status-publish","format-standard","hentry","category-ukrainian-legislation-general-en","category-ukrainian-legislation-important","pmpro-has-access"],"acf":{"patreon-level":0},"_links":{"self":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts\/7945","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/comments?post=7945"}],"version-history":[{"count":0,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/posts\/7945\/revisions"}],"wp:attachment":[{"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/media?parent=7945"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/categories?post=7945"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lexcovery.com\/en\/wp-json\/wp\/v2\/tags?post=7945"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}