Archived data from 2016-2023

50. Azerbaijan 63.64

50th National Cyber Security Index
40th Global Cybersecurity Index
65th ICT Development Index
76th Networked Readiness Index
Population 9.7million
Area (km2) 86.6thousand
GDP per capita ($) 17.9thousand
NCSI FULFILMENT PERCENTAGE
NCSI DEVELOPMENT TIMELINE 3 years All data
RANKING TIMELINE
NCSI Update Data source
31 Aug 2023 Government officials
4 Jun 2023 Cooperation partner
24 Jan 2023 Cooperation partner

Version 31 Aug 2023

GENERAL CYBER SECURITY INDICATORS
BASELINE CYBER SECURITY INDICATORS
  • 5. Protection of digital services 1/5 20%
    1
    5 20%
    • 5.1. Cyber security responsibility for digital service providers 0
      0
      1
      Requirements
      Criteria

      According to legislation, digital service providers (except micro and small enterprises): (1) must manage cyber/ICT risks or (2) must implement established cyber/information security requirements.

      Accepted references

      Legal act

      Evidence
    • 5.2. Cyber security standard for the public sector 1
      1
      1
      Requirements
      Criteria

      Public sector digital service providers must implement (1) cyber/ICT security requirements (defined by legislation) or (2) a widely recognised security standard.

      Accepted references

      Legal act

      Evidence

      The scope of critical information infrastructure extends to include public sector digital service providers as well.
      According to 20-5.2, the entity responsible for critical information infrastructure is obligated to ensure the security of the infrastructure in accordance with both general and special security requirements that apply to the infrastructure. It is important to note that the Law includes new definitions relevant to these provisions, as detailed in Article 2.

      Article 20-4.1 states that the general requirements for the security of critical information infrastructure are determined by the designated body or institution as specified by the relevant executive authority.

      20-4.2 indicates that the subject of critical information infrastructure is responsible for determining the special requirements for the security of critical information infrastructure based on the purpose and operational characteristics of the infrastructure. These requirements are then registered in the list of critical information infrastructure objects.


      The primary objective of the Rules issued by the State Agency for Public Service and Social Innovations under the President of the Republic of Azerbaijan on 17.11.2020, titled "On the amendment of the Decision dated 04.11.2016 for the Evaluation of electronic services, information resources, and systems in State institutions," is to ensure the provision of electronic services, information resources, and systems in full compliance with the applicable normative legal acts of the Republic of Azerbaijan. These Rules also emphasize the importance of monitoring the implementation of approved projects, technical regulations, and requirements to guarantee their adherence to legal norms.

      According to these Rules, digital service providers are required to implement security measures, including network and primary security measures. These measures encompass various aspects such as physical security, the influence of equipment installation on virtual security, security equipment with features to repel DDOS attacks, malware, and other threats, continuous operation between security equipment (failover), DNS and DHCP security, internal network security, prevention of information leakage both internally and externally, and ensuring the security of communication lines with other institutions.

      To meet the evaluation criteria and sub-criteria for organizing and providing electronic services, detailed in Appendices No. 1 and No. 2 of the "Rules for Evaluating Electronic Services, Information Resources and Systems in State Institutions," digital service providers must effectively manage cyber/ICT risks and adhere to established cyber/information security requirements.

    • 5.3. Competent supervisory authority 0
      0
      3
      Requirements
      Criteria

      The government has a competent authority in the field of cyber/information security that has the power to supervise public and private digital service providers regarding the implementation of cyber/information security requirements.

      Accepted references

      Official website or legal act

      Evidence
  • 6. Protection of essential services 6/6 100%
    6
    6 100%
    • 6.1. Operators of essential services are identified 1
      1
      1
      Requirements
      Criteria

      There is a legal act that allows to identify operators of essential services.

      Accepted references

      Legal act

      Evidence

      The subjects of critical information infrastructure  also includes operators of essential services.

      See, the new chapter (Chapter V-I. Security of critical information infrastructure) added to the law on May 27, 2022.

      According to the Law critical information infrastructure is defined as a set of information systems, automated management systems and information-communication networks that provide activity in the field of public administration, defense, health care, financial markets, energy, transport, information technology, telecommunications, water supply or ecology, and whose functionality can cause significant damage to the interests of the state, society and citizens.

      According to the Article 20-1.1, the security of the critical information infrastructure is ensured by determining the requirements for the security of that infrastructure (which is further elaborated by Article 20-4), assessing compliance with these requirements and eliminating identified inconsistencies, applying the information security management system corresponding to those requirements, as well as monitoring the state of ensuring the security of the critical information infrastructure.

      20-5.2. The subject of critical information infrastructure ensures the security of the critical information infrastructure belonging to it in accordance with the general and special requirements for the security of the infrastructure.
      Note, there are also new relevant definitions added to the Law (See, Article 2).

    • 6.2. Cyber security requirements for operators of essential services 1
      1
      1
      Requirements
      Criteria

      According to the legislation, operators of essential services must manage cyber/ICT risks.

      Accepted references

      Legal act

      Evidence

      See, the new chapter (Chapter V-I. Security of critical information infrastructure) added to the law on May 27, 2022.

      According to the Article 20-5.2. The subject of critical information infrastructure must ensure the security of the critical information infrastructure belonging to it in accordance with the general and special requirements for the security of the infrastructure.

      Also, see

      20-4.1. General requirements for the security of critical information infrastructure are determined by the body (institution) determined by the relevant executive authority.

      20-4.2. Special requirements for the security of critical information infrastructure are determined by the subject of critical information infrastructure in accordance with the purpose of critical information infrastructure and its operational characteristics and are placed in the register of critical information infrastructure objects.

    • 6.3. Competent supervisory authority 3
      3
      3
      Requirements
      Criteria

      The government has a competent authority in the field of cyber/information security that has the power to supervise operators of essential services, regarding cyber/information security requirements.

      Accepted references

      Official website or legal act

      Evidence

      The State Security Service of the Republic of Azerbaijan performs the functions of the competent authority in the field of ensuring the security of critical information infrastructure and the fight against cyber threats. 

      In relation to state bodies, public legal entities created on behalf of the state, legal entities owned by the state, the State Security Service of the Republic of Azerbaijan performs those functions jointly with the State Service of Special Communication and Information Security of the Republic of Azerbaijan.

    • 6.4. Regular monitoring of security measures 1
      1
      1
      Requirements
      Criteria

      Operators of essential services must regularly (at least once every 3 years) provide evidence of the effective implementation of cyber/information security policies (e.g. audit result, documentation, specific report).

      Accepted references

      Legal act

      Evidence

      20-6.8. In order to ensure compliance with the requirements for the security of critical information infrastructure, as well as to organize the operation of the information security management system in accordance with the requirements, the subjects of the critical information infrastructure must conduct external audits by the cyber security service provider no less than once a year, and its results must be submitted to the [superviosory authority].

  • 7. E-identification and trust services 7/9 78%
    7
    9 78%
  • 8. Protection of personal data 1/4 25%
    1
    4 25%
INCIDENT AND CRISIS MANAGEMENT INDICATORS
Information Disclaimer

The information provided on the NCSI website is based on publicly available evidence materials. The appearance in the index and subsequent ranking is commensurate to the existence and public availability of such information. The NCSI links to third party websites and information. The NCSI and eGA are not responsible for the accuracy or completeness of third party website information.

What can I do to improve my country's data in NCSI?

Become a data contributor Update a specific indicator with evidence data

CONTRIBUTORS

Elvin Balajanov
Azerbaijan Cybersecurity Organizations Association
Samir Rasulov
Electronic Security Service under the Ministry of Digital Development and Transport / CERT.AZ
Bahar Asgarova
Intern at e-Governance Academy