Abstract
The article examines an institutional and legal model for ensuring information security in the development of the information society through the reconciliation of the interests of the individual, society and the state. The article conceptualises information security as a comprehensive legal institution enabling the exercise of human information rights, societal digital resilience and the protection of the state’s legitimate security interests. Formal legal, systemic-structural, comparative legal, institutional and functional methods were applied, together with an analytical validation of the model using current data on cyber incidents, third-party risks and inter-agency integration of personal data. The legislation of the Republic of Uzbekistan, the Cybersecurity Strategy for 2026–2030, international standards and foreign research published in 2024–2026 were analysed. The article proposes a three-circuit model and a five-stage balancing test. It specifies mechanisms for integrating the model into existing public administration institutions, a package of legal measures and a three-stage implementation pathway through 2030. The study substantiates the introduction of an impact assessment for draft legal acts and public information systems in relation to digital rights and information security.
References
Конституция Республики Узбекистан. Принята на референдуме 30.04.2023. URL: https://lex.uz/docs/-6445145
Закон Республики Узбекистан «О принципах и гарантиях свободы информации» от 12.12.2002 № 439-II. URL: https://lex.uz/docs/-52268
Закон Республики Узбекистан «О кибербезопасности» от 15.04.2022 № ЗРУ-764. URL: https://lex.uz/docs/-5960604
Закон Республики Узбекистан «О персональных данных» от 02.07.2019 № ЗРУ-547, с изменениями, внесенными Законом от 26.03.2026 № ЗРУ-1125. URL: https://lex.uz/ru/docs/4396428; https://lex.uz/docs/8104580
Указ Президента Республики Узбекистан «Об определении Стратегии кибербезопасности Республики Узбекистан и совершенствовании системы предупреждения киберпреступности» от 10.03.2026 № УП-38. URL: https://lex.uz/ru/docs/8079286
Ахмедов Б.А. Институциональные основы обеспечения информационной безопасности в Республике Узбекистан. – Ташкент: Высшая школа стратегического анализа и прогнозирования Республики Узбекистан, 2017. – 123 с. (Akhmedov B.A. Institutional Foundations for Ensuring Information Security in the Republic of Uzbekistan. – Tashkent, 2017. – 123 p.).
OECD. OECD Policy Framework on Digital Security. – Paris: OECD Publishing, 2022. – 38 p. URL: https://www.oecd.org/content/dam/oecd/en/publications/reports/2022/12/oecd-policy-framework-on-digital-security_a0b1d79c/a69df866-en.pdf
National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. – Gaithersburg, 2024. – 32 p. URL: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
International Telecommunication Union. Global Cybersecurity Index 2024. – Geneva: ITU, 2024. URL: https://www.itu.int/en/ITU-D/Cybersecurity/Documents/GCIv5/2401416_1b_Global-Cybersecurity-Index-E.pdf
UN Human Rights Committee. General Comment No. 34: Article 19 — Freedoms of Opinion and Expression. CCPR/C/GC/34. – Geneva, 2011. URL: https://www2.ohchr.org/english/bodies/hrc/docs/gc34.pdf
United Nations General Assembly. The Right to Privacy in the Digital Age. Resolution A/RES/77/211, adopted on 15 December 2022. – New York: United Nations, 2023. – 10 p. URL: https://digitallibrary.un.org/record/3999709
Council of Europe. Modernised Convention for the Protection of Individuals with Regard to the Processing of Personal Data (Convention 108+). – Strasbourg, 2018. – 35 p. URL: https://edoc.coe.int/en/international-law/7729-convention-108-convention-for-the-protection-of-individuals-with-regard-to-the-processing-of-personal-data.html
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive) // Official Journal of the European Union. – 2022. – L 333. – P. 80–152. URL: https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
Deibert R.J. Toward a Human-Centric Approach to Cybersecurity // Ethics & International Affairs. – 2018. – Vol. 32, No. 4. – P. 411–424. DOI: https://doi.org/10.1017/S0892679418000618
Dunn Cavelty M., Egloff F.J. The Politics of Cybersecurity: Balancing Different Roles of the State // St Antony’s International Review. – 2019. – Vol. 15, No. 1. – P. 37–59. URL: https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Dunn_Cavelty_Egloff_2019%20STAIR%20Issue%2015.1.pdf
Chiara P.G. Towards a Right to Cybersecurity in EU Law? The Challenges Ahead // Computer Law & Security Review. – 2024. – Vol. 53. – Article 105961. DOI: https://doi.org/10.1016/j.clsr.2024.105961.
Magnusson L., Iqbal S., Elm P., Dalipi F. Information Security Governance in the Public Sector: Investigations, Approaches, Measures, and Trends // International Journal of Information Security. – 2025. – Vol. 24. – Article 177. DOI: https://doi.org/10.1007/s10207-025-01097-x.
Qandeel M. Understanding Constitutional Principles for the Advancement of Digital Rights in Palestine // Middle East Law and Governance. – 2024. – Vol. 16, No. 3. – P. 400–429. DOI: https://doi.org/10.1163/18763375-20241444.
Poulsen A., Song Y.J.C., Fosch-Villaronga E., et al. Digital Rights and Mobile Health in Southeast Asia: A Scoping Review // Digital Health. – 2024. – Vol. 10. – Article 20552076241257058. DOI: https://doi.org/10.1177/20552076241257058.
Sinozic T., Jahnel J. Technology Assessment for Human Security: Aligning Security Cultures with Human Security in AI Innovation // TATuP – Zeitschrift für Technikfolgenabschätzung in Theorie und Praxis. – 2024. – Vol. 33, No. 2. – P. 16–21. DOI: https://doi.org/10.14512/tatup.33.2.16.
Cotta B., Righettini M.S. Governing Cybersecurity in the Digital Age: Mapping Comprehensive Policy Mixes with the Nodality–Authority–Treasure–Organization Lens // Review of Policy Research. – 2026. – Vol. 43, No. 4. – Article e70113. DOI: https://doi.org/10.1111/ropr.70113.
Teichmann F.M.J. Platform Governance under NIS2 and the Cyber Resilience Act: Cybersecurity by Design as Social Practice // Information, Communication & Society. – Published online 06.01.2026. DOI: https://doi.org/10.1080/1369118X.2025.2609780.
European Union Agency for Cybersecurity. ENISA Threat Landscape 2024. – Athens: ENISA, 2024. URL: https://www.enisa.europa.eu/publications/enisa-threat-landscape-2024.
Verizon. 2025 Data Breach Investigations Report. – 2025. URL: https://www.verizon.com/business/resources/reports/dbir/.
Министерство цифровых технологий Республики Узбекистан. Количество услуг на my.gov.uz будет расширено: информация о постановлении Президента Республики Узбекистан от 15.07.2026 № ПП-265. URL: https://gov.uz/ru/digital/news/view/194413.
Министерство цифровых технологий Республики Узбекистан. Задачи и функции. URL: https://www.digital.gov.uz/ru/digital/pages/tasks_and_functions.
Министерство цифровых технологий Республики Узбекистан. О персональных данных. URL: https://www.digital.gov.uz/ru/advice/61/document/2116.