Kibernetinio saugumo teisinis reglamentavimas ir praktiniai aspektai
Recenzentas / Rewiewer |
Licencinė sutartis Nr. MRU-EDT-1978.
Magistro baigiamojo darbo tema – „Kibernetinio saugumo teisinis reglamentavimas ir praktiniai aspektai“. Temos aktualumas grindžiamas vis nemažėjančiu kibernetinių incidentų ir nusikaltimų elektroninių duomenų bei informacinių sistemų saugumui fiksavimu ir teisės aktų atnaujinimu kibernetinio saugumo srityje. Baigiamąjį darbą sudaro keturi skyriai. Pirmajame skyriuje apžvelgiami kibernetinio saugumo teoriniai aspektai. Antrajame skyriuje analizuojamas tarptautinis ir Europos Sąjungos kibernetinio saugumo teisinis reglamentavimas. Trečiajame skyriuje nagrinėjamas kibernetinio saugumo teisinis reglamentavimas Lietuvoje. Ketvirtajame skyriuje analizuojama teismų praktika, nagrinėjant baudžiamąsias bylas dėl nusikalstamų veikų elektroninėje erdvėje, siekiant atskleisti šių veikų kvalifikavimo probleminius aspektus ir specifinius ypatumus. Darbe pateikiamos išvados ir pasiūlymai. Tyrimo objektas – kibernetinio saugumo teisiniai ir praktiniai aspektai, o tikslas – išanalizuoti kibernetinio saugumo teisinį reglamentavimą ir praktinius aspektus. Šiam tikslui pasiekti iškelti keturi uždaviniai: pirmuoju siekta išanalizuoti kibernetinio saugumo sampratą ir kibernetines grėsmes, antruoju – išnagrinėti kibernetinio saugumo teisinį reglamentavimą Europos Sąjungoje bei tarptautiniu lygmeniu, trečiuoju – įvertinti kibernetinio saugumo teisinį reglamentavimą Lietuvoje, ketvirtuoju – atskleisti teismų praktikoje taikomų nusikalstamų veikų elektroninių duomenų ir informacinių sistemų saugumui kvalifikavimo problematiką ir šių veikų specifinius ypatumus. Atlikus teisės aktų analizę nustatyta, kad Lietuvoje pakankamas teisinis reglamentavimas, kuris atitinka pagrindines tarptautines bei Europos Sąjungos kibernetinio saugumo nuostatas. Išnagrinėjus teismų praktiką nustatyti kvalifikavimo probleminiai aspektai taikant ir aiškinant baudžiamojo įstatymo normas dėl nusikaltimų elektroninėje erdvėje, tačiau Lietuvos Aukščiausiasis Teismas formuoja vieningą šių nusikalstamų veikų normų taikymo praktiką. Nusikalstamos veikos elektroninėje erdvėje pasižymi specifiniais ypatumais, kadangi jos gali būti vykdomos naudojant įvairią programinę įrangą ir iš bet kurios vietos, todėl sudėtinga nustatyti nusikalstamas veikas įvykdžiusius asmenis ir patraukti juos baudžiamojon atsakomybėn. Tokiose bylose yra svarbus specialistų dalyvavimas, siekiant tinkamai pagrįsti neteisėtą techninių priemonių panaudojimą. Tiek teorinės medžiagos analizės metu, tiek bylų analizės metu nustatyta, kad asmenims nesilaikant saugumo principų naudojantis internetu ir išmaniosiomis technologijomis bei įmonėms netaikant apsaugos priemonių sudaromos prielaidos nusikalstamų veikų elektroninėje erdvėje atsiradimui. Todėl svarbu laikytis kibernetinės higienos principų, o įmonėms taikyti tinkamas kibernetinio saugumo priemones, ypač panaikinti prieigas prie informacinių sistemų buvusiems darbuotojams. Tyrime taikyti dokumentų analizės, lyginamasis ir apibendrinimo metodai.
The title of the Master's thesis is “Legal Regulation of Cybersecurity and Practical Aspects”. The relevance of the topic is based on the continuously increasing recording of cyber incidents and crimes against the security of electronic data and information systems, as well as the ongoing updates of legal acts in the field of cybersecurity. The thesis consists of four chapters. The first chapter reviews the theoretical aspects of cybersecurity. The second chapter analyzes the international and European Union legal regulation of cybersecurity. The third chapter examines the legal regulation of cybersecurity in Lithuania. The fourth chapter analyzes court practice by examining criminal cases related to offenses committed in cyberspace, aiming to reveal problematic aspects of the qualification of these offenses and their specific features. The thesis presents conclusions and recommendations. The object of the research is the legal and practical aspects of cybersecurity, while the aim is to analyze the legal regulation of cybersecurity and its practical application. To achieve this aim, four objectives were set: the first was to analyze the concept of cybersecurity and cyber threats; the second – to examine the legal regulation of cybersecurity at the European Union and international levels; the third – to evaluate the legal regulation of cybersecurity in Lithuania; the fourth – to reveal the problems of qualification of criminal offenses against the security of electronic data and information systems in court practice, as well as the specific features of these offenses. The analysis of legal acts revealed that Lithuania has a sufficient legal framework that complies with the main international and European Union cybersecurity requirements. The analysis of court practice identified problematic aspects of qualification in the application and interpretation of criminal law norms related to cybercrime; however, the Supreme Court of Lithuania forms a consistent practice in the application of these legal norms. Criminal offenses in cyberspace have specific characteristics, as they can be committed using various software and from any location, which makes it difficult to identify perpetrators and bring them to criminal liability. Therefore, the involvement of specialists is important in such cases in order to properly substantiate the unlawful use of technical measures. Both the analysis of theoretical material and case law showed that failure of individuals to comply with security principles when using the Internet and smart technologies, as well as the lack of protective measures by organizations, creates conditions for the occurrence of cybercrime. Therefore, it is important for internet users to follow the principles of cyber hygiene, and for organizations to implement appropriate cybersecurity measures, especially to remove access to information systems for former employees. The research applied document analysis, comparative, and generalization methods.