25 December 2023, 19:47 · 25th Knesset · vote no. 40223

Third readingVote on the billelectronic vote

הצעת חוק התמודדות עם תקיפות סייבר חמורות במגזר השירותים הדיגיטליים ושירותי האחסון (הוראת שעה - חרבות ברזל), התשפ"ד-2023Bill on Coping with Serious Cyber Attacks in the Digital Services Sector and Storage Services (temporary provision - Operation Iron Swords), 2023 · automatic translation · suggest a correction

Law passed: 8 for, 0 against

8 of 120 voted — counted from roll-call records (no official result is published)

8 of 120 members voted. The plenum has no quorum: a decision passes by a simple majority of those voting. A special majority (61 votes) is needed only for no-confidence motions and some provisions of Basic Laws. Glossary →

What was put to the vote

«לקבל את הצעת החוק בקריאה שלישית»

Third reading: The final vote. A bill that passes its third reading becomes law. Glossary →

Bill: חוק התמודדות עם תקיפות סייבר חמורות במגזר השירותים הדיגיטליים ושירותי האחסון (הוראת שעה - חרבות ברזל), התשפ"ד-2023Law on Coping with Serious Cyber Attacks in the Digital Services Sector and Storage Services (temporary provision - Operation Iron Swords), 2023auto

About the law and the debate

Official summary of the law (Knesset)

The Law authorizes an authorized manager from the Israel Security Agency, the Cyber Directorate, or the Military Intelligence Directorate's Malmab unit to determine that a cyberattack occurring or about to occur against a person whose business is the provision of storage services or digital services constitutes a severe cyberattack, if he believes there is a real concern that it will harm state security, public security, or the continuity of essential supplies and services. This determination will be made subject to the following conditions: the attack occurred during the Iron Swords War; the attack has a real impact that is not limited to the attacked supplier; and the attack is a severe cyberattack in light of its characteristics. In addition, it was determined that the authority to determine that a cyberattack is severe is also granted to the Head of the Cyber Defense Division in the IDF, if he finds that the attack is liable to harm the continuity of the IDF's operational functioning due to the aforementioned conditions. In a case where a cyberattack is determined to be severe, the Law establishes a graduated course of action: first, the authorized employee will detail to the supplier the factual basis for his determination that the cyberattack is severe, and will allow the supplier an opportunity to act to detect, prevent, or contain the attack as soon as possible. Following this, the supplier will be required to update the authorized employee on the actions taken, or to submit an affidavit regarding the implementation of security guidelines in accordance with the standard. If the supplier did not submit an affidavit, or the authorized employee finds that the supplier did not act appropriately to detect, prevent, or contain the attack, the authorized employee may issue instructions for carrying out cyber defense actions. In addition, the Law establishes provisions regarding the duty of confidentiality and restriction on the use of information. The Law further establishes a duty to report to the Attorney General and to the Knesset Foreign Affairs and Defense Committee regarding cases in which instructions were given under the Law. The Law is established as a temporary provision for a period of seven months.

automatic translation · suggest a correction

Hebrew original

החוק מסמיך מנהל מוסמך משירות הביטחון הכללי, ממערך הסייבר או מהמלמ"ב לקבוע כי תקיפת סייבר שמתרחשת או עומדת להתרחש אצל מי שעיסוקו אספקת שירותי אחסון או שירותים דיגיטליים, היא תקיפת סייבר חמורה, אם סבר כי קיים חשש ממשי שתפגע בביטחון המדינה, בביטחון הציבור או בקיום האספקה והשירותים החיוניים. קביעה זו תיעשה בכפוף לתנאים הבאים: התקיפה התרחשה במהלך מלחמת חרבות ברזל; התקיפה בעלת השפעה ממשית שאינה מוגבלת לספק הנתקף, והתקיפה היא תקיפת סייבר חמורה בהתחשב במאפייניה. בנוסף, נקבע כי הסמכות לקבוע כי תקיפת סייבר היא חמורה נתונה גם לרח"ט הגנה בסייבר בצה"ל, אם מצא שיש בתקיפה כדי לפגוע ברציפות התפקוד המבצעי של צה"ל בשל התנאים כאמור. במקרה שנקבע כי תקיפת סייבר היא חמורה, החוק קובע הליך פעולה מדורג: ראשית, העובד המוסמך יפרט לספק את התשתית העובדתית לקביעתו כי תקיפת סייבר היא חמורה, ויאפשר לספק הזדמנות לפעול לצורך איתור התקיפה, מניעתה או בלימתה בהקדם האפשרי. בהמשך לכך, הספק יידרש לעדכן את העובד המוסמך בדבר הפעולות שביצע או למסור תצהיר בדבר יישום הנחיות אבטחה בהתאם לתקן. אם הספק לא הגיש תצהיר או העובד המוסמך מצא שלא פעל באופן הולם לאיתור התקיפה, מניעתה ובלימתה, יהיה רשאי העובד המוסמך למסור הוראות לביצוע פעולות הגנה בסייבר. בנוסף, החוק קובע הוראות בעניין חובת סודיות והגבלת שימוש במידע. עוד קובע החוק חובת דיווח ליועצת המשפטית לממשלה ולוועדת החוץ והביטחון של הכנסת בדבר המקרים בהם ניתנו הוראות לפי החוק. החוק נקבע כהוראת שעה למשך שבעה חודשים.

All arguments and speakers are on the bill page →

By party on the day of the vote

coalition3 for · 0 against
opposition5 for · 0 against
  • for
  • abstained
  • against
Yesh Atidיש עתידopposition5 for · 0 against — majority for

Party page →

Likudהליכודcoalition1 for · 0 against — majority for

Party page →

Shasהתאחדות הספרדים שומרי תורה תנועתו של מרן הרב עובדיה יוסף זצ"לcoalition1 for · 0 against — majority for

Party page →

United Torah Judaismיהדות התורהcoalition1 for · 0 against — majority for

Party page →

Roll call (8)
Numbers and sources
For
8
Against
0
Abstained
0
Present, did not vote
0

Only members with a record are counted. No record does not mean the member was absent. Official results for votes after July 2021 are not published in the open data.

Source: vote page on the Knesset website ↗

Bill on Coping with Serious Cyber Attacks in the Digital Services Sector and Storage Services (temporary provision - Operation Iron Swords), 2023 — 25 December 2023 · How the Knesset Votes