Gmail addresses of ministries outside the law

The Ministry of Public Administration told "Vijesta" that they sent an appeal not to do this. Until now, no decision has been made to regulate the creation and use of e-mail addresses until the recovery of those under the gov.me internet label.

36766 views 14 comment(s)
Cyber ​​attacks and laws "change" (illustration), Photo: Shutterstock
Cyber ​​attacks and laws "change" (illustration), Photo: Shutterstock
Disclaimer: The translations are mostly done through AI translator and might not be 100% accurate.

By creating and using email addresses on the gmail service for communication due to a cyber attack, the Government and several of its departments violated the Law on Electronic Administration, according to which official addresses for electronic communication cannot be located on the information and communication infrastructure outside of Montenegro. Above.

The Ministry of Public Administration (MJU) told "Vijesta" that they had sent an appeal not to do so. They also said that, since the beginning of the cyber attack, which has caused content on the gov.me domain and official e-mails to be unavailable for several days, they have not made any decision to regulate the creation and use of e-mail addresses until the recovery of those under the gov.me internet label. .

When asked by "Vijesti", they also said that they had created recommendations in this regard, and that they would deliver them to the institutions as soon as possible.

"The MJU did not pass a special Decision on the opening of e-mail accounts, which would be an exception to the application of the Law on Electronic Administration. On the contrary, the MJU appealed that the institutions that are under the gov.me domain do not open unique official addresses for electronic communication, which would be located on the information and communication infrastructure outside of Montenegro. Namely, the Operational Team for Countering Cyber ​​Incidents considered the above-mentioned issue and in that direction created recommendations and measures, which will be delivered to the institutions as soon as possible, in order to "raise the awareness" of the institutions that even in such an emergency situation, for security reasons, the provisions must not be violated of the Law on Electronic Administration, which regulate the issue of unique official addresses and electronic communication. The Ministry of Justice is making efforts to make the unique official addresses of organs and employees in organs functional and work processes easier, since during the resulting cyber attacks, institutions are forced to use paper communication more," writes the answer to "Vijesta".

Cyber ​​attacks on the Government's IT infrastructure began on August 20. On the same day and the day after, the information system of the Assembly was also exposed to cyber attacks. The Assembly announced that their system "did not suffer data damage", that "it was not in offline mode and it functions stably at full capacity".

However, the websites of the Government and government departments, which are under the gov.me domain, are not available for days and there is no information when access to the content will be possible again. Likewise, e-mail addresses located on the gov.me domain are not functional.

In order to continue communication with citizens, the economy and the media, some officials use private emails, while the Government and some departments have created email addresses on gmail.

The government's public relations team, specifically, these days communicates with the media from the address pr.vlada.gov.me@gmail.com. The Ministry of Science and Technological Development (mntr.gov.me@gmail.com) and the Ministry of Defense (pr.odbrana@gmail.com) also have a gmail address.

Article 24 of the Law on Electronic Administration stipulates that the public administration department "assigns a unique official address for electronic communication to a state administration body and an employee of that body, if that body has been assigned a domain and has an open account on the active directory of the state administration body."

In the same Law, in Article 25, it is stated that the official addresses for electronic communication from Article 24 cannot be located on the information and communication infrastructure outside of Montenegro.

"And they must be created under the national domain, unless otherwise determined by a special law or a confirmed international treaty," the law says.

On September 6, the Government sent an email to the media informing them that due to technical problems caused by cyber attacks, apart from not being able to publish the materials from the session on the gov.me portal, "it is not possible to distribute them in electronic form". At the time, they also announced that, "keeping in mind the strict security standards, the information service of the General Secretariat of the Government is working on finding an alternative solution."

In the meantime, they delivered the materials to the media via the WeTransfer service.

When "Vijesti" asked, among other things, to clarify the strict security standards mentioned in relation to the publication of materials from the session, they said that, when it comes to information security in the building of the General Secretariat of the Government, the Law on Information Security and the Regulation on Information Security Measures are applied. , that the Ministry of Justice is responsible for its implementation.

Minister of Public Administration in technical mandate Marash Dukaj yesterday at the Government session, he said that they are constantly working to make the system work as soon as possible, and that they are doing so in accordance with the suggestions of partners - experts from the FBI, France. He said that experts from Great Britain are also expected in the coming days.

Yesterday, he repeated his earlier allegations - that this is a very serious attack, which no country has ever experienced and which costs millions.

In the first days of the cyber attack, it was announced that it was possible that they were coming from Russia, but Dukaj later said that it was the international criminal group "Cuba ransomware" (Cuba ransomware). BIRN reported a few days ago that, according to their sources, the attack came from within and that the malicious code spread from a computer connected to a government server.

Gase CIRT, establish the Agency for Information Security

By the end of the year, Montenegro will have an amended Law on Information Security, which implies the shutdown of CIRT and the formation of the Agency for Cyber ​​Security, Dukaj said yesterday at the Government session.

CIRT is the National Computer and Computer Incident Response Team.

It was formed in 2012, within the then Ministry of Information Society, headed by Vujica Lazović.

At the end of 2020, CIRT moved from MJU to the Directorate for the Protection of Secret Data.

See more: