Israeli LegislationEnglish Edition

Translation Notice — This is an English translation of a Hebrew law and may contain inaccuracies. In any dispute or legal matter, the original Hebrew text as published in Reshumot (ספר החוקים) is the sole authoritative and legally binding version.

Secondary LegislationPublished: 2017-05-09Last amended: 2023-09-18

Privacy Protection Regulations (Data Security), 2017

תקנות הגנת הפרטיות (אבטחת מידע), תשע"ז-2017

General

Definitions

1.

In these Regulations —

"security event" — an event concerning the information security of a database;

"serious security event" — a security event giving rise to concern of a breach of privacy affecting a large number of persons, material damage to data subjects, a violation of confidentiality obligations binding the database owner, or impairment of the database owner's functioning, including loss of data, unauthorised modification of data, or exposure of information to unauthorised parties;

"authorised holder" — a person authorised to access a database who is not an employee of the database owner;

"database definition document" — a document prepared pursuant to Regulation 2;

"information security officer" — a person appointed pursuant to Regulation 3;

"outsourcing" — performance of services involving access to a database by a person who is not an employee of the database owner;

"manager" — a person who manages a database on behalf of the database owner;

"security procedure" — a written procedure established pursuant to Regulation 4;

"security survey" — an annual survey of compliance with these Regulations, as referred to in Regulation 16;

"risk survey" — a survey designed to identify threats and vulnerabilities to a database and to assess the risks arising therefrom;

"basic security level", "medium security level", "high security level" — a security level determined pursuant to Regulation 21 and the Schedules to these Regulations;

"mobile device" — any portable end-user device used to access a database, including a mobile phone, laptop computer, tablet or portable storage device;

"biometric information" — a unique biological characteristic of a person used to identify that person, including a fingerprint, iris pattern, or facial recognition data.

Database Definition Document

2.
(a)A database owner shall prepare a written definition document for each database held by the owner, setting out —
(1)the name of the database and the purposes for which the information in it is used;
(2)the types of information held in the database;
(3)the categories of persons about whom information is held;
(4)the names of persons authorised to access the database and the scope of their authorisation;
(5)how information is transferred to and from the database, including details of parties receiving information;
(6)the location of the database and the location of the systems through which it is managed.
(b)The database owner shall update the definition document whenever a material change occurs in any of the particulars referred to in subsection (a).

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Security Officers, Procedures and Risk Management

Information Security Officer

3.
(a)A database owner holding a database at the medium or high security level shall appoint an information security officer.
(b)The information security officer shall be responsible for —
(1)formulating security procedures and supervising their implementation;
(2)conducting periodic security surveys;
(3)managing security events;
(4)training employees in information security matters.
(c)A person who holds another role in the organisation that creates a conflict of interest shall not be appointed as information security officer.
(d)A database owner whose database contains no more than one thousand registered persons may appoint an external information security officer.
(e)The database owner shall provide the information security officer with the authority and resources required to perform the role.

Security Procedure

4.
(a)A database owner shall formulate and implement written security procedures for each database held by the owner.
(b)The security procedures shall address, at minimum —
(1)management and revocation of access authorisations;
(2)physical security of the database systems;
(3)handling of portable media;
(4)software updates and system maintenance;
(5)backup and recovery of the database;
(6)identification and documentation of security events;
(7)management of outsourcing provider access.
(c)Security procedures shall be updated at least once a year and whenever a material change occurs.

Database System Mapping and Risk Survey

5.
(a)A database owner of a database at the medium or high security level shall prepare a written mapping of the database systems, which shall include —
(1)an inventory of hardware components used to store or process the database;
(2)an inventory of software components used to manage or access the database;
(3)a description of the communication interfaces between the various components.
(b)A database owner of a database at the high security level shall, in addition, conduct a risk survey of the database at intervals of no less than once every three years.
(c)The risk survey shall identify threats to the confidentiality, integrity, and availability of the database, assess the associated risks, and evaluate the effectiveness of existing controls.
(d)The database owner shall act upon the findings of the risk survey.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Physical, Environmental and Personnel Security

Physical and Environmental Security

6.
(a)A database owner shall implement physical and environmental security measures proportionate to the security level of the database.
(b)Physical security measures shall include —
(1)restricting physical access to areas where the database systems are located to authorised persons only;
(2)maintaining records of physical access to protected areas;
(3)measures to protect database systems from environmental hazards such as fire, flooding, and extreme weather conditions.
(c)The database owner shall review physical security measures periodically.

Personnel Management Security

7.
(a)A database owner shall implement information security measures in the management of employees with access to the database.
(b)Such measures shall include —
(1)defining security requirements for roles that include access to the database;
(2)providing information security awareness training to employees with access;
(3)immediate revocation of access rights upon termination of employment or change of role;
(4)taking appropriate action where an employee is suspected of violating the security policy.
(c)Employees with access to a database at the high security level shall sign a confidentiality undertaking.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Access Control, Authentication and Logging

Access Authorisation Management

8.
(a)Access to a database shall be granted only to persons who require such access for the performance of their duties.
(b)The database owner shall —
(1)maintain a current register of all persons authorised to access each database and the scope of their authorisation;
(2)establish a defined procedure for granting and revoking access authorisations;
(3)review access authorisations at least once a year and revoke those no longer required;
(4)immediately revoke access authorisations upon termination of employment or change of role.
(c)Access to sensitive information shall be granted on a need-to-know basis only.

Identification and Authentication

9.
(a)Database systems shall require identification and authentication of all users prior to granting access.
(b)Authentication measures shall be proportionate to the security level of the database and the sensitivity of the information held.
(c)For databases at the medium and high security levels —
(1)a password policy shall be enforced, including minimum length and complexity requirements;
(2)periodic password changes shall be required;
(3)mechanisms shall be implemented to detect and respond to repeated failed authentication attempts.
(d)For databases at the high security level, the database owner shall enforce strong authentication, including two-factor authentication for remote access.

Access Control and Logging

10.
(a)The database owner shall implement controls to monitor and log access to the database.
(b)Access logs shall record, at minimum —
(1)the identity of the person who accessed the database;
(2)the date and time of access;
(3)the actions performed on the database.
(c)Access logs shall be retained for a period of no less than 24 months.
(d)The database owner shall review access logs periodically and investigate unusual access patterns.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Operational Security

Security Event Documentation

11.
(a)The database owner shall maintain documentation of security events affecting the database.
(b)Every security event shall be documented, including —
(1)a description of the event;
(2)the date and time of the event;
(3)the estimated scope of impact;
(4)the measures taken in response.
(c)Where a serious security event occurs, the database owner shall notify the Registrar of Databases within 72 hours of becoming aware of it and shall submit a full report within 30 days.
(d)The notification to the Registrar shall include all particulars referred to in subsection (b), as well as details of preventive measures adopted to prevent recurrence.

Mobile Devices

12.
(a)A database owner of a database at the medium or high security level shall formulate a written policy governing the use of mobile devices that have access to the database.
(b)The mobile device policy shall cover —
(1)the types of mobile devices authorised to access the database;
(2)requirements for securing mobile devices, including screen locking and encryption;
(3)procedures for handling lost or stolen mobile devices, including remote wipe capability;
(4)restrictions on downloading database information to the mobile device and storing it thereon.

Secure and Updated System Management

13.
(a)The database owner shall maintain the systems that hold and process the database in a secure and updated state.
(b)To this end —
(1)security patches and software updates shall be applied within a reasonable time of their release;
(2)an inventory of software versions in use shall be maintained;
(3)controls shall be implemented to prevent the installation of unauthorised software;
(4)software that is no longer required and is no longer supported by its vendor shall be removed.

Communications Security

14.
(a)The database owner shall implement measures to protect information transmitted over communications networks.
(b)Sensitive information and access credentials transmitted between systems shall be encrypted using industry-accepted protocols.
(c)A database owner of a database at the medium or high security level shall implement network security controls proportionate to the risk level, including restricting network interface access from unauthorised sources.

Outsourcing

15.
(a)A database owner who engages an outsourcing service provider to perform services involving access to the database shall —
(1)conduct due diligence to verify that the provider implements appropriate security measures;
(2)include contractual provisions requiring the provider to maintain the security of the database.
(b)The contract with the outsourcing service provider shall include —
(1)a description of the security measures the provider is required to implement;
(2)provisions obligating the provider to report security events;
(3)audit rights in favour of the database owner;
(4)provisions governing the handling of database information upon termination of the engagement.
(c)The database owner remains responsible for compliance with these Regulations notwithstanding the engagement of an outsourcing service provider.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Audits, Data Retention and Backup

Periodic Audits

16.
(a)A database owner of a database at the medium or high security level shall conduct an annual security survey to assess compliance with the provisions of these Regulations.
(b)A database owner of a database at the high security level shall, in addition, conduct penetration tests of the database systems at intervals of no less than once every three years.
(c)The database owner shall maintain records of all security surveys and penetration tests conducted.
(d)The database owner shall act upon all findings and recommendations arising from security surveys and penetration tests.

Security Data Retention

17.
(a)The database owner shall retain security documentation, access logs and incident records for a minimum period of 24 months.
(b)Documentation to be retained shall include —
(1)database access logs;
(2)records of security events;
(3)security survey and penetration test reports;
(4)records of changes to access authorisations.

Data Backup and Recovery

18.
(a)The database owner shall implement backup procedures to ensure the availability and integrity of the database.
(b)Backup procedures shall cover —
(1)the frequency of backups;
(2)the media on which backups are stored and the measures for their protection;
(3)testing of recovery procedures;
(4)storage of backup copies at a physical location separate from the primary systems.
(c)The database owner shall periodically test the ability to recover the database from backup.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Administrative Provisions

Obligations of Manager and Authorised Holder

19.
(a)A database owner who engages a manager or authorised holder shall ensure that the manager or authorised holder implements the provisions of these Regulations applicable to that database.
(b)The manager or authorised holder shall implement all security measures required under these Regulations in respect of the database held by them.
(c)The manager or authorised holder shall immediately notify the database owner of any security event affecting the database.

Registrar's Powers

20.
(a)The Registrar may, upon application, grant an exemption from a specific provision of these Regulations where satisfied that the database owner implements alternative measures providing equivalent or greater protection.
(b)The Registrar may publish guidelines and frameworks to assist database owners in complying with the provisions of these Regulations.
(c)The Registrar may publish, from time to time, lists of approved security standards and frameworks for purposes of demonstrating compliance.

Scope

21.
(a)The provisions of these Regulations shall apply to database owners in accordance with the security level of each database.
(b)The security level of a database shall be determined as follows —
(1)a database meeting one of the conditions listed in the First Schedule shall be classified at the medium security level;
(2)a database meeting one of the conditions listed in the Second Schedule shall be classified at the high security level;
(3)any other database shall be classified at the basic security level.
(c)A database meeting the conditions of more than one security level shall be classified at the higher level.
(d)The Regulations applicable to each security level —
(1)basic level: Regulations 2, 4, 6, 8, 11, 17, 18;
(2)medium level: all Regulations applicable at the basic level, plus Regulations 3, 5, 7, 9, 10, 12, 14, 15, 16;
(3)high level: all Regulations.

Commencement

22.

These Regulations shall come into force on the eighth day of Iyar 5778 (23 April 2018).

Transitional Provision

23.
(a)Notwithstanding Regulation 22, a database owner who held a database at the time these Regulations came into force shall have 18 months from that date to comply with all provisions applicable to that database.
(b)The Registrar may, upon application, extend the period referred to in subsection (a) where satisfied that the database owner has made substantial progress toward compliance.

Repeal

24.

Regulations 2, 3, 9, 10, 12, 13, 14 and 15 of the Privacy Protection Regulations (Conditions for Holding Data and its Transfer between Databases), 5746-1986 are repealed.

Relationship to Other Legislation

25.

These Regulations do not derogate from the obligations imposed on database owners under any other enactment relating to the security or protection of information.

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

First Schedule — Medium Security Level Databases

No.Type of Database
1A database managed by a public body within the meaning of the Freedom of Information Law, 5758-1998
2A database used for direct mailing or direct marketing containing information on more than 10,000 persons
3A database containing information on a person's financial situation and containing information on more than 10,000 persons
4A database containing information on a person's health or medical condition and containing information on more than 10,000 persons
5A database used for the provision of insurance services containing information on more than 10,000 persons
6A database in which access is provided to more than 10 authorised holders who are not employees of the database owner
7A database containing information collected in the course of providing medical, financial, social, or legal services

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

Second Schedule — High Security Level Databases

No.Type of Database
1A database managed by a banking corporation within the meaning of the Banking (Licensing) Law, 5741-1981, or by a credit card company
2A database managed by a licensed insurer within the meaning of the Supervision of Financial Services (Insurance) Law, 5741-1981
3A database managed by a health maintenance organisation (Kupat Cholim) or a hospital
4A database managed by an internet service provider containing information about its subscribers
5A database containing biometric information about more than 5,000 persons
6A database containing information on more than 100,000 persons
7A database in which access is provided to more than 100 authorised holders who are not employees of the database owner
8A database managed by a telecommunications company containing information about its subscribers

Need to cite this law in a foreign court?

Eli Shimony Israeli Attorneys-at-Law provides certified Expert Legal Opinions on Israeli law within 24–48 hours, accepted by courts worldwide.

Contact Us →

תקנות הגנת הפרטיות (אבטחת מידע), תשע"ז-2017

data security

information security

database

privacy regulations

אבטחת מידע

מאגר מידע

ממונה אבטחת מידע

GDPR Israel

breach notification

בתקנות אלה — "אירוע אבטחה" — אירוע הנוגע לאבטחת מידע במאגר; "אירוע אבטחה חמור" — אירוע אבטחה שיש בו חשש לפגיעה בפרטיות מספר רב של אנשים, לנזק ממשי לנושאי המידע, להפרה של חובות החיסיון החלות על בעל המאגר, לפגיעה בתפקוד בעל המאגר, ובכלל זה אבדן נתונים, שינויים בלתי מורשים בנתונים, או חשיפת מידע לגורמים בלתי מורשים; "גורם מורשה" — בעל הרשאה לגשת למאגר מידע שאינו עובד של בעל המאגר; "הגדרת מסמך המאגר" — מסמך שנערך לפי תקנה 2; "ממונה על אבטחת מידע" — מי שמונה לפי תקנה 3; "מיקור חוץ" — ביצוע שירותים הכרוכים בגישה למאגר מידע על ידי מי שאינו עובד של בעל המאגר; "מנהל" — מי שמנהל מאגר מידע בשם בעל המאגר; "נוהל אבטחה" — נוהל כתוב שנקבע לפי תקנה 4; "סקר אבטחה" — סקר שנתי של יישום הוראות תקנות אלה, כאמור בתקנה 16; "סקר סיכונים" — סקר שנועד לזהות איומים ופגיעויות של מאגר המידע ולהעריך את הסיכונים הנובעים מהם; "רמת אבטחה בסיסית", "רמת אבטחה בינונית", "רמת אבטחה גבוהה" — רמת האבטחה שנקבעת לפי תקנה 21 והתוספות לתקנות אלה; "התקן נייד" — כל ציוד קצה נייד שמשמש לגישה למאגר מידע, ובכלל זה טלפון נייד, מחשב נייד, לוח או התקן אחסון נייד; "מידע ביומטרי" — מאפיין ביולוגי ייחודי של אדם המשמש לזיהויו, ובכלל זה טביעת אצבע, דפוס קשתית העין, וזיהוי פנים.

(א) בעל מאגר מידע יערוך מסמך הגדרות כתוב לכל מאגר מידע שבידיו, ובו יפרט — (1) שם המאגר ומטרות השימוש במידע שבו; (2) סוגי המידע המוחזק במאגר; (3) קטגוריות האנשים שעליהם מוחזק מידע; (4) שמות בעלי ההרשאות לגישה למאגר ותחום הרשאתם; (5) אופן העברת מידע אל המאגר וממנו, לרבות פרטי הגורמים המקבלים מידע; (6) מיקום המאגר ומיקום המערכות שבאמצעותן הוא מנוהל. (ב) בעל המאגר יעדכן את מסמך ההגדרות בכל אימת שחל שינוי מהותי באחד מהפרטים האמורים בסעיף קטן (א).

(א) בעל מאגר מידע ברמת אבטחה בינונית או גבוהה ימנה ממונה על אבטחת מידע. (ב) הממונה על אבטחת מידע יהיה אחראי על — (1) גיבוש נהלי האבטחה ופיקוח על יישומם; (2) ביצוע סקרי אבטחה תקופתיים; (3) טיפול באירועי אבטחה; (4) הדרכת עובדים בנושאי אבטחת מידע. (ג) לא ימונה לתפקיד ממונה על אבטחת מידע מי שמכהן בתפקיד אחר בארגון שיש בו ניגוד עניינים. (ד) בעל מאגר שמספר הנרשמים בו אינו עולה על אלף רשאי למנות ממונה על אבטחת מידע חיצוני. (ה) בעל מאגר ימסור לממונה על אבטחת מידע את הסמכויות והמשאבים הדרושים לביצוע תפקידו.

(א) בעל מאגר מידע יגבש ויישם נהלי אבטחה כתובים לכל מאגר מידע שבידיו. (ב) נהלי האבטחה יעסקו, לכל הפחות, ב — (1) ניהול הרשאות גישה וביטולן; (2) אבטחה פיזית של מערכות המאגר; (3) טיפול במדיה ניידת; (4) עדכוני תוכנה ותחזוקת מערכות; (5) גיבוי ושחזור המאגר; (6) זיהוי ותיעוד אירועי אבטחה; (7) ניהול גישה של ספקי מיקור חוץ. (ג) נהלי האבטחה יעודכנו לפחות אחת לשנה ובכל אימת שחל שינוי מהותי.

(א) בעל מאגר ברמת אבטחה בינונית או גבוהה יערוך מיפוי כתוב של מערכות המאגר, שיכלול — (1) רשימת רכיבי חומרה המשמשים לאחסון או עיבוד המאגר; (2) רשימת רכיבי תוכנה המשמשים לניהול המאגר או לגישה אליו; (3) תיאור ממשקי התקשורת בין הרכיבים השונים. (ב) בעל מאגר ברמת אבטחה גבוהה יבצע, בנוסף, סקר סיכונים של המאגר בתדירות שלא תפחת מאחת לשלוש שנים. (ג) סקר הסיכונים יזהה איומים על סודיות, שלמות וזמינות המאגר, יעריך את הסיכונים ויאמוד את יעילות אמצעי הבקרה הקיימים. (ד) בעל המאגר יפעל בהתאם לממצאי הסקר.

(א) בעל מאגר מידע ייישם אמצעי אבטחה פיזיים וסביבתיים בהתאם לרמת האבטחה של המאגר. (ב) אמצעי האבטחה הפיזיים יכללו — (1) הגבלת גישה פיזית לאזורים שבהם ממוקמות מערכות המאגר לבעלי הרשאה בלבד; (2) ניהול רשימות של כניסות פיזיות לאזורים מוגנים; (3) אמצעים להגנה על מערכות המאגר מפני נזקים סביבתיים כגון שריפה, הצפה ותנאי מזג אוויר קיצוניים. (ג) בעל המאגר יבחן את אמצעי האבטחה הפיזיים בצורה תקופתית.

(א) בעל מאגר מידע ייישם אמצעי אבטחה בתחום ניהול כוח האדם ביחס לעובדים בעלי גישה למאגר. (ב) אמצעים אלה יכללו — (1) הגדרת דרישות אבטחה לתפקידים הכוללים גישה למאגר; (2) הדרכה בנושאי מודעות לאבטחת מידע לעובדים בעלי גישה; (3) הסרה מיידית של הרשאות גישה עם סיום תפקיד או עזיבת ארגון; (4) נקיטת אמצעים הולמים כאשר עובד חשוד בהפרת מדיניות האבטחה. (ג) עובדים בעלי גישה למאגר ברמת אבטחה גבוהה יחתמו על כתב התחייבות לסודיות.

(א) גישה למאגר מידע תינתן אך ורק לאנשים הזקוקים לה לצורך מילוי תפקידם. (ב) בעל המאגר — (1) ינהל רשימה עדכנית של כל בעלי ההרשאות לגישה לכל מאגר ותחום הרשאתם; (2) יקבע נוהל מוגדר למתן הרשאות גישה ולביטולן; (3) יבחן את הרשאות הגישה לפחות אחת לשנה ויבטל הרשאות שאינן נדרשות עוד; (4) יבטל הרשאות גישה באופן מיידי עם סיום העסקה או שינוי תפקיד. (ג) גישה למידע רגיש תינתן על בסיס הצורך לדעת בלבד.

(א) מערכות המאגר ידרשו זיהוי ואימות של כל משתמש לפני מתן גישה. (ב) אמצעי האימות יהיו מידתיים לרמת האבטחה של המאגר ולרגישות המידע. (ג) לגבי מאגרים ברמת אבטחה בינונית וגבוהה — (1) תאכף מדיניות סיסמאות שתכלול דרישות מינימום לאורך ולמורכבות; (2) תידרש החלפת סיסמאות תקופתית; (3) יופעלו מנגנוני איתור ותגובה לניסיונות כניסה כושלים חוזרים. (ד) לגבי מאגרים ברמת אבטחה גבוהה, יאכף בעל המאגר אמצעי אימות חזקים, לרבות אימות דו-שלבי עבור גישה מרחוק.

(א) בעל המאגר ייישם בקרות לניטור ותיעוד הגישה למאגר. (ב) יומני הגישה יתעדו, לכל הפחות — (1) זהות האדם שגישה למאגר; (2) מועד הגישה; (3) הפעולות שבוצעו במאגר. (ג) יומני הגישה יישמרו לתקופה שלא תפחת מ-24 חודשים. (ד) בעל המאגר יבחן את יומני הגישה באופן תקופתי ויחקור דפוסי גישה חריגים.

(א) בעל המאגר ינהל תיעוד של אירועי אבטחה המשפיעים על המאגר. (ב) כל אירוע אבטחה יתועד, לרבות — (1) תיאור האירוע; (2) מועד האירוע; (3) היקף ההשפעה המשוער; (4) האמצעים שננקטו בתגובה. (ג) אירע אירוע אבטחה חמור, ידווח עליו בעל המאגר לרשם מאגרי המידע בתוך 72 שעות מרגע שנודע לו על קיומו, ויגיש דוח מלא בתוך 30 ימים. (ד) הדיווח לרשם יכלול את כל הפרטים הנזכרים בסעיף קטן (ב), וכן פרטים על אמצעי מניעה שאומצו למניעת הישנות האירוע.

(א) בעל מאגר ברמת אבטחה בינונית או גבוהה יגבש מדיניות כתובה לשימוש בהתקנים ניידים בעלי גישה למאגר. (ב) מדיניות ההתקנים הניידים תכסה — (1) סוגי ההתקנים הניידים המורשים לגשת למאגר; (2) דרישות לאבטחת התקנים ניידים, לרבות נעילת מסך ואמצעי הצפנה; (3) נהלים לטיפול בהתקנים ניידים שאבדו או נגנבו, לרבות יכולת מחיקה מרחוק; (4) הגבלות על הורדת מידע מהמאגר אל ההתקן הנייד ואחסונו.

(א) בעל המאגר יתחזק את המערכות המחזיקות את המאגר ומעבדות אותו במצב מאובטח ומעודכן. (ב) לשם כך — (1) יחיל עדכוני אבטחה ותיקוני תוכנה בתוך זמן סביר מרגע פרסומם; (2) ינהל מלאי של גרסאות התוכנה שבשימוש; (3) ייישם בקרות למניעת התקנת תוכנה בלתי מורשית; (4) יסיר תוכנה שאינה נדרשת עוד ואינה מתוחזקת עוד על ידי יצרנה.

(א) בעל המאגר ייישם אמצעים להגנה על מידע המועבר ברשתות תקשורת. (ב) מידע רגיש ופרטי כניסה המועברים בין מערכות יוצפנו באמצעות פרוטוקולים מקובלים בתעשייה. (ג) בעל מאגר ברמת אבטחה בינונית או גבוהה ייישם בקרות אבטחת רשת מידתיות לרמת הסיכון, לרבות הגבלת גישה לממשקי רשת ממקורות בלתי מורשים.

(א) בעל מאגר המתקשר עם ספק מיקור חוץ לביצוע שירותים הכרוכים בגישה למאגר — (1) יבצע בדיקת נאותות לוודא שהספק מיישם אמצעי אבטחה נאותים; (2) יכלול בחוזה עם הספק הוראות המחייבות אותו לשמור על אבטחת המאגר. (ב) החוזה עם ספק מיקור החוץ יכלול — (1) תיאור אמצעי האבטחה שעל הספק לנקוט; (2) הוראות בדבר חובת הספק לדווח על אירועי אבטחה; (3) זכות ביקורת לטובת בעל המאגר; (4) הוראות בדבר טיפול במידע עם סיום ההתקשרות. (ג) בעל המאגר נושא באחריות לקיום הוראות תקנות אלה, חרף ההתקשרות עם ספק מיקור חוץ.

(א) בעל מאגר ברמת אבטחה בינונית או גבוהה יערוך סקר אבטחה שנתי לבחינת מידת עמידתו בהוראות תקנות אלה. (ב) בעל מאגר ברמת אבטחה גבוהה יבצע, בנוסף, בדיקות חדירה למערכות המאגר בתדירות שלא תפחת מאחת לשלוש שנים. (ג) בעל המאגר ינהל תיעוד של כל סקרי האבטחה ובדיקות החדירה שבוצעו. (ד) בעל המאגר יפעל בהתאם לכל הממצאים וההמלצות שעלו מסקרי האבטחה ומבדיקות החדירה.

(א) בעל המאגר ישמור תיעוד אבטחה, יומני גישה ורשומות אירועים לתקופה מינימלית של 24 חודשים. (ב) תיעוד לשמירה יכלול — (1) יומני גישה למאגר; (2) רשומות אירועי אבטחה; (3) דוחות סקר אבטחה ובדיקות חדירה; (4) רשומות שינויים בהרשאות גישה.

(א) בעל המאגר ייישם נהלי גיבוי להבטחת זמינות המאגר ושלמותו. (ב) נהלי הגיבוי יכסו — (1) תדירות הגיבויים; (2) המדיה לאחסון הגיבויים ואמצעי ההגנה עליה; (3) בדיקת תהליכי השחזור; (4) אחסון עותקי גיבוי במיקום פיזי נפרד ממערכות העיקריות. (ג) בעל המאגר יבדוק תקופתית את יכולת שחזור המאגר מגיבוי.

(א) בעל מאגר המתקשר עם מנהל או מחזיק מורשה יוודא שהמנהל או המחזיק המורשה מיישמים את הוראות תקנות אלה החלות על אותו מאגר. (ב) המנהל או המחזיק המורשה יישמו את כל אמצעי האבטחה הנדרשים לפי תקנות אלה ביחס למאגר שבידיהם. (ג) המנהל או המחזיק המורשה ידווחו לבעל המאגר מיד על כל אירוע אבטחה המשפיע על המאגר.

(א) הרשם רשאי, לפי בקשה, להעניק פטור מהוראה מסוימת בתקנות אלה, אם שוכנע שבעל המאגר מיישם אמצעים חלופיים המספקים הגנה שוות ערך או גבוהה יותר. (ב) הרשם רשאי לפרסם הנחיות ומסגרות עבודה לסיוע לבעלי מאגרים בעמידה בהוראות תקנות אלה. (ג) הרשם יוכל לפרסם, מעת לעת, רשימות של תקנים ומסגרות אבטחה מאושרות לצורך הוכחת ציות.

(א) הוראות תקנות אלה יחולו על בעלי מאגרים בהתאם לרמת האבטחה של כל מאגר. (ב) רמת האבטחה של מאגר מידע תיקבע כדלקמן — (1) מאגר שמתקיים בו אחד מהתנאים המפורטים בתוספת הראשונה — ייסווג ברמת אבטחה בינונית; (2) מאגר שמתקיים בו אחד מהתנאים המפורטים בתוספת השנייה — ייסווג ברמת אבטחה גבוהה; (3) כל מאגר אחר — ייסווג ברמת אבטחה בסיסית. (ג) מאגר העומד בתנאים של יותר מרמת אבטחה אחת — ייסווג לפי הרמה הגבוהה יותר. (ד) התקנות החלות על כל רמת אבטחה — (1) רמה בסיסית: תקנות 2, 4, 6, 8, 11, 17, 18; (2) רמה בינונית: כל התקנות החלות על הרמה הבסיסית, בנוסף לתקנות 3, 5, 7, 9, 10, 12, 14, 15, 16; (3) רמה גבוהה: כל התקנות.

תקנות אלה יחולו מיום ח' באייר התשע"ח (23 באפריל 2018).

(א) על אף האמור בתקנה 22, בעל מאגר מידע שהחזיק במאגר ערב תחילת תקנות אלה יהיה לו 18 חודשים ממועד תחילת תקנות אלה לציית לכלל הוראותיהן החלות על אותו מאגר. (ב) הרשם רשאי, לפי בקשה, להאריך את התקופה האמורה בסעיף קטן (א) אם שוכנע שבעל המאגר ביצע התקדמות מהותית לקראת ציות.

תקנות 2, 3, 9, 10, 12, 13, 14 ו-15 לתקנות הגנת הפרטיות (תנאי החזקת מידע ועברתו בין מאגרי מידע), התשמ"ו-1986 — בטלות.

אין בתקנות אלה כדי לגרוע מן החובות המוטלות על בעלי מאגרים מכוח כל חיקוק אחר העוסק באבטחה או הגנה על מידע.

⚠ Disclaimer: This is an unofficial AI-assisted translation. The Hebrew version published in the official records (Reshumot) is the sole binding and legally valid text.