Document from CIS Legislation database © 2012-2026 CIS Legislation Company

ORDER OF THE MINISTER OF ENERGY OF THE REPUBLIC OF KAZAKHSTAN

of April 13, 2026 No. 148-n/k

About introduction of amendments to the order of the Minister of Energy of the Republic of Kazakhstan of September 15, 2025 No. 349-n/k "About approval of Rules of ensuring information security in the field of fuel and energy complex"

I ORDER:

1. Bring in the order of the Minister of Energy of the Republic of Kazakhstan of September 15, 2025 No. 349-n/k "About approval of Rules of ensuring information security in the field of fuel and energy complex" (it is registered in the Register of state registration of regulatory legal acts at No. 36852) the following changes:

to be reworded as follows heading of the order:

"About approval of Rules of ensuring cyber security in the field of fuel and energy complex";

to be reworded as follows Item 1 of the order:

"1. Approve the enclosed Rules of ensuring cyber security in the field of fuel and energy complex.";

The rules of ensuring information security in the field of fuel and energy complex approved by the specified order to be reworded as follows according to appendix to this order.

2. To provide to department of digitalization of the Department of Energy of the Republic of Kazakhstan in the procedure established by the legislation of the Republic of Kazakhstan:

1) state registration of this order in the Ministry of Justice of the Republic of Kazakhstan;

2) placement of this order on Internet resource of the Department of Energy of the Republic of Kazakhstan after its official publication;

3) within ten working days after state registration of this order in the Ministry of Justice of the Republic of Kazakhstan submission to Department of legal service of the Department of Energy of the Republic of Kazakhstan of data on execution of the actions provided by subitems 1) and 2) of this Item.

3. To impose control of execution of this order on the supervising vice-Minister of Energy of the Republic of Kazakhstan.

4. This order becomes effective since July 11, 2026 and is subject to official publication.

Minister of Energy of the Republic of Kazakhstan

E.Akkenzhenov

It is approved

Ministry of artificial intelligence and digital development of the Republic of Kazakhstan

 

It is approved

Ministry of Finance of the Republic of Kazakhstan

 

It is approved

Ministry of national economy of the Republic of Kazakhstan

 

Appendix

to the Order of the Minister of Energy of the Republic of Kazakhstan of April 13, 2026 No. 148-n/k

Approved by the order of the Minister of Energy of the Republic of Kazakhstan of September 15, 2025 No. 349-n/k

Rules of ensuring cyber security in the field of fuel and energy complex

Chapter 1. General provisions

1. These rules of ensuring cyber security in the field of fuel and energy complex (further - Rules) are developed according to subitem 6-3) of article 5 of the Law of the Republic of Kazakhstan "About power industry" (further - the Law) and determine procedure for ensuring cyber security in the field of fuel and energy complex, cyberstability of crucial digital objects of fuel and energy complex.

2. Industrial management systems of fuel and energy complex belong to objects of cyber security of the industry center of cyber security in the field of fuel and energy complex.

Chapter 2. Procedure for ensuring cyber security in the field of fuel and energy complex and functioning of the industry center of cyber security in the field of fuel and energy complex

3. The industry center of cyber security in the field of fuel and energy complex (further - the Industry center) functions on permanent basis, being guided by the principles of legality, centralization of management, efficiency of response to incidents of cyber security and confidentiality of information.

4. Main objective of functioning of the Industry center is creation of the single protected digital space for subjects of the fuel and energy complex providing stability of crucial digital objects of fuel and energy complex in the conditions of modern cyberthreats.

5. The industry center is the legal entity determined according to subitem 6-4) of article 5 of the Law, performing the organization and coordination of actions for forming of the protected digital space of fuel and energy complex.

6. The industry center requests and receives from subjects of fuel and energy complex and the operational centers of cyber security information necessary for the analysis of threats of cyber security, including data on cyberincidents, parameters of work of protective systems and results of audits of cyber security.

7. The industry center develops methodical recommendations, standards and regulations about protection of digital systems of subjects of fuel and energy complex which are considered by subjects of fuel and energy complex under the organization of measures of cyber security. The industry center submits methodical recommendations, standards and regulations about protection of digital systems of subjects of fuel and energy complex to subjects of fuel and energy complex for application in work, and also in authorized body in the field of power industry for data.

8. The industry center conducts examination of condition of security of digital systems of subjects of fuel and energy complex, except for the objects relating to the state secrets.

9. The industry center for results of inspection of cyber security of subjects of fuel and energy complex, submits recommendations about elimination of the revealed violations with the term of their execution within one month. In case of identification of the critical violations creating threat to steady work of objects of fuel and energy complex, the Industry center notifies authorized body in the field of ensuring cyber security according to the Rules of carrying out monitoring of events of cyber security of digital objects of state bodies approved by authorized body in the field of ensuring cyber security according to the subitem 6) of article 7-1 of the Law of the Republic of Kazakhstan "About cyber security".

10. The industry center performs monitoring of cyberthreats by means of data analysis about the events of cyber security arriving from the operational centers of cyber security.

All arriving data are analyzed using methods of machine training and the behavioural analysis for detection of abnormal activity. Special attention is paid to detection of the target attacks to industrial management systems of fuel and energy complex.

11. For rapid response to cyber security incidents in the Industry center is effective the three-level classification system of threats from which:

1) the critical incidents creating direct threat to steady work of objects of fuel and energy complex, requiring immediate reaction - within 1 (one) hour from the moment of detection;

The term of reaction constitutes 2) for incidents of high risk till 4 (four) o'clock;

The term of reaction constitutes 3) for incidents of low level till 24 (twenty four) o'clock.

12. In each case the group of reaction of the Industry center develops the individual actions plan on localization and elimination of effects of the attack.

13. Subjects of fuel and energy complex provide transfer to the operational centers of cyber security of the data necessary for cyber security monitoring implementation, in the formats, amounts and procedure established by regulations of the Industry center.

14. Subjects of fuel and energy complex, in case of independent detection of incident of cyber security, notify the Industry center within 30 (thirty) minutes from the moment of detection.

15. Interaction of the Industry center with authorized body in the field of power industry is performed through regular exchange of information in the following formats and terms:

1) the notification on all incidents of cyber security is provided within 1 (one) hour from the moment of their detection for acceptance of urgent measures of reaction;

2) operational reports about current status of cyber security of industry, including the status (processings) of earlier revealed incidents, go daily till 10:00 o'clock on time of the city of Astana;

3) the weekly analytical reports about condition of cyber security of industry directed every Friday till 18:00 o'clock on time of the city of Astana with the subsequent feedback within 3 (three) working days;

4) monthly reports with efficiency evaluation of the taken measures of cyber security are provided to 5 (fifth) days of the next month with receipt of summary response within 10 (ten) working days.

16. The industry center participates in development and implementation of state programs on protection of critical digital infrastructure, makes suggestions for improvement of the legislation of the Republic of Kazakhstan in the field of cyber security of fuel and energy complex.

17. The industry center performs permanent and system interaction with the National coordination center of cyber security according to article 9 of the Law of the Republic of Kazakhstan "About cyber security". Technical interaction with the National coordination center of cyber security is performed through secure channels of communication with use of the certified means of cryptographic information security.

Chapter 3. Procedure for ensuring confidentiality and information security

18. All data arriving in the Industry center from subjects of fuel and energy complex are subject to protection in compliance the Single requirements in spheres of digitalization and ensuring cyber security approved by the Government of the Republic of Kazakhstan according to the subitem 3) of article 6 of the Law of the Republic of Kazakhstan "About cyber security" (further - Single requirements).

19. The industry center uses the certified means of cryptographic information security, the control system of access and technical means of safety.

20. Information security about crucial digital objects of fuel and energy complex and vulnerabilities of their digital systems, is based on accomplishment of the following requirements:

1) reference of data to office information of limited distribution according to the procedure, established by the Rules of reference of data to office information of limited distribution and work with it approved by the order of the Government of the Republic of Kazakhstan of June 24, 2022 No. 429;

2) processing and storage of information in the Industry center are performed in specially allocated protected segments of digital system of the Industry center.

21. Requirements to safety of segments are determined on the basis of integrated approach to risk management, according to ST of PK IEC 62443-3-3 "Networks communication industrial. Safety of network and system - Part 3-3. Requirements to system safety and safety level" and Single requirements.

 

Disclaimer! This text was translated by AI translator and is not a valid juridical document. No warranty. No claim. More info

Search in text CTRL-F

Demo Access

If you are guest on our site, you will work in Demo mode. In Demo mode you can see only first page of each document.


Full Access

With full access you can

  • see full text
  • see original text of document in Russian
  • download attachment (if exist)
  • see History and statistics

Get Full Access Now

Effectively work with search system

Database include more 65000 documents. You can find needed documents using search system.
For effective work you can mix any on documents parameters: country, documents type, date range, teams or tags.
More about search system

Get help

If you cannot find the required document, or you do not know where to begin, go to Help section.

In this section, we’ve tried to describe in detail the features and capabilities of the system, as well as the most effective techniques for working with the database.

You also may open the section Frequently asked questions.
This section provides answers to questions set by users.

Search engine created by CIS Legislation Company