UCSA
United Cyber Security Association

Legal

Code of Ethics and Professional Conduct for UCSA Members

The regulation defines professional, ethical, and conduct standards for members of the United Cybersecurity Association of Georgia (UCSA).

Approved by
the Director of UCSA
Order
No. ___
Date
“_” __________ 20__

Article 1. General provisions

1.1. This Code of Ethics and Professional Conduct for UCSA Members (the “Regulation”) sets professional, ethical, and conduct standards for members of the United Cybersecurity Association of Georgia (UCSA).

1.2. The purpose of the Regulation is to:

  • a) establish high professional and ethical standards in the organization;
  • b) promote responsible activity in the field of cybersecurity;
  • c) ensure trust among the organization’s members, partners, and other persons;
  • d) ensure that cybersecurity knowledge and technical capabilities are used only for lawful and ethical purposes;
  • e) protect the reputation and interests of the organization;
  • f) prevent conflicts of interest, discrimination, harassment, bullying, and other improper conduct;
  • g) ensure responsible use of the organization’s educational and technical resources.

1.3. The Regulation applies to:

  • a) all members of the organization;
  • b) persons authorized to lead or represent the organization, within the scope of their relevant activity;
  • c) persons participating in the organization’s events, unless the event terms provide otherwise;
  • d) persons acting in the name of the organization, within the scope of the relevant activity.

1.4. Compliance with the Regulation does not replace obligations under Georgian law, the organization’s charter, or other mandatory rules.

Article 2. Core ethical principles

A UCSA member is guided by the following principles in their activity:

2.1. Legality. A member must comply with Georgian law and the applicable legal rules of the relevant jurisdiction.

2.2. Responsibility. A member is responsible for the consequences of their decisions and actions and must not use professional knowledge to violate the rights of others.

2.3. Good faith. A member acts in good faith, honestly, and in accordance with professional standards.

2.4. Confidentiality. A member protects confidential information known to them and does not use it for personal or third-party interests without authorization.

2.5. Professionalism. A member continually develops their knowledge and skills and does not accept an assignment they lack the competence to perform properly.

2.6. Respect. A member respects the dignity, rights, views, and professional activity of other people.

2.7. Responsible cybersecurity. Technical cybersecurity knowledge and tools are used only in a lawful, authorized, educational, research, or defensive environment.

2.8. Knowledge sharing. The organization encourages knowledge sharing, but knowledge must not be shared in a way that violates the rights, security, or lawful interests of others.

Article 3. Standards of professional conduct

3.1. In professional activity, a member must:

  • a) present facts accurately and in good faith;
  • b) not appropriate another person’s work;
  • c) cite relevant sources and authors;
  • d) not falsify the results of research, testing, audit, or other activity;
  • e) not conceal a material circumstance whose concealment may cause significant harm to a third party;
  • f) not knowingly disseminate false information;
  • g) respect professional standards and best practices.

3.2. A member must refrain from statements that create a false impression of their qualifications, certification, experience, or status with UCSA.

Article 4. Ethical standards for technical cybersecurity activity

4.1. Any technical activity, including:

  • OSINT;
  • penetration testing;
  • vulnerability assessment;
  • security assessment;
  • red teaming;
  • threat intelligence;
  • digital forensics;
  • malware analysis;
  • exploit development;
  • social engineering;
  • network security testing;
  • CTF;
  • security research,

may be carried out only where there is an appropriate legal basis and authorization.

4.2. Security testing of a third party’s information system is not permitted without the prior permission of the relevant owner or authorized person.

4.3. A member is prohibited from using access, accounts, credentials, technical capability, or other resources obtained in the organization’s training environment outside the purpose defined by the organization.

4.4. A training laboratory or CTF environment must not be used for unauthorized action against real third-party systems.

4.5. A member must not use UCSA’s name or membership status to justify a technical action they are not authorized to carry out.

Article 5. Responsible disclosure

5.1. UCSA supports the responsible disclosure of cybersecurity vulnerabilities.

5.2. A member who has discovered a security vulnerability should, to the extent possible, try to provide the information to the relevant system owner or authorized person in a responsible and legally permissible form.

5.3. A member must refrain from using a discovered vulnerability for purposes that go beyond security research or responsible disclosure.

5.4. Public dissemination of information about a vulnerability in a manner that increases the risk of harm to third parties is not permitted unless there is an appropriate legal or ethical basis.

Article 6. Confidentiality

6.1. A member must protect confidential information of the organization, its members, partners, clients, training participants, and other persons.

6.2. The following are subject to particular protection:

  • a) passwords and authentication data;
  • b) API keys and other secret credentials;
  • c) information about security vulnerabilities;
  • d) internal network information;
  • e) personal data;
  • f) non-public research results;
  • g) the organization’s internal documents;
  • h) confidential information related to partners.

6.3. Confidential information may be used only within the purpose for which the member lawfully received it.

Article 7. Protection of personal data

7.1. A member must respect other persons’ right to private life and the principles of personal data protection.

7.2. The collection, processing, storage, or dissemination of personal data must take place only where there is an appropriate legal basis.

7.3. Conducting OSINT does not confer an unrestricted right to collect and use a person’s personal data.

7.4. The fact that information is publicly available does not automatically mean that collecting, processing, combining, or disseminating it in any form is ethically or legally permitted.

Article 8. Conflicts of interest

8.1. A member must inform the organization of any circumstance that may give rise to an actual or potential conflict of interest.

8.2. Where a conflict of interest exists, a member must refrain from taking the relevant decision or participating in the process if such participation may affect their objectivity.

8.3. A member must not use UCSA membership or authority granted to them to obtain personal financial benefit where this conflicts with the interests of the organization.

Article 9. Non-discrimination and prohibition of harassment

9.1. UCSA does not tolerate discrimination, harassment, bullying, threats, or degrading treatment.

9.2. A member must respect the dignity of every other member and event participant.

9.3. Discrimination against a person is not permitted, including on the basis of:

  • sex;
  • age;
  • views;
  • nationality;
  • ethnic origin;
  • disability;
  • professional status;
  • level of experience;
  • or any other ground protected by law.

9.4. Sexual harassment, threats, intimidation, incitement to violence, and targeted humiliation are especially prohibited.

Article 10. Use of the organization’s name and brand

10.1. A UCSA member may state their membership status only while membership is in force.

10.2. A member may not present their own statement or commercial offer as UCSA’s official position unless they have authority to do so.

10.3. Use of UCSA’s logo, name, brand, and other identity elements must comply with brand rules established by the organization.

10.4. A member is prohibited from using the organization’s name in a way that may create a false impression that the organization supports or authorizes that person’s activity.

Article 11. Intellectual property

11.1. A member must respect the intellectual property rights of other persons and of the organization.

11.2. The following are not permitted:

  • a) plagiarism;
  • b) presenting another person’s code, research, or educational material as one’s own work;
  • c) unauthorized commercial distribution of the organization’s educational materials;
  • d) knowing infringement of another person’s copyright.

11.3. When publishing research, educational material, or a technical work, a member must properly cite the relevant authors and sources.

Article 12. Use of artificial intelligence

12.1. A member may use artificial intelligence tools in professional and educational activity if such use complies with the law, professional ethics, and confidentiality requirements for the relevant information.

12.2. A member must not enter confidential information into a public or commercial AI system without appropriate authorization.

12.3. When using AI-generated information in professional activity, a member is responsible for verifying its accuracy and suitability.

12.4. Use of artificial intelligence does not relieve a member of professional responsibility.

Article 13. Organization events

13.1. At UCSA events, a member must comply with:

  • a) instructions of the event organizer;
  • b) security rules;
  • c) the rights of other participants;
  • d) confidentiality requirements;
  • e) any special rules of the relevant event.

13.2. An event participant is prohibited from using the event’s technical infrastructure against other participants or third parties.

13.3. The terms of a CTF, hackathon, or other technical event may be defined by additional special rules.

Article 14. Gifts, benefits, and corrupt practices

14.1. A member must not offer or accept a gift, financial benefit, or other advantage that may influence their professional decision.

14.2. Offering, receiving, or requesting a bribe, unlawful payment, or other unlawful benefit in the name of the organization is prohibited.

Article 15. Complaints and reporting of ethical breaches

15.1. Any member or other interested person has the right to notify the organization of a possible breach of this Regulation.

15.2. A report may be submitted:

  • a) in writing;
  • b) by email;
  • c) through the organization’s electronic platform;
  • d) in another form determined by the organization.

15.3. A report should include, to the extent possible:

  • a) a description of the breach;
  • b) the likely time and place of the breach;
  • c) information about the persons concerned;
  • d) evidence, if it exists.

15.4. Knowingly submitting a false accusation intended to harm or discredit another person may itself constitute an ethical breach.

Article 16. Ethics commission

16.1. An ethics commission may be established in the organization to consider ethical breaches.

16.2. The ethics commission is formed by the Director of the organization, unless the charter or another internal document provides otherwise.

16.3. A member of the ethics commission may not take part in considering a matter if they have a direct or indirect personal interest.

16.4. The ethics commission must:

  • a) examine the matter impartially;
  • b) give the person concerned an opportunity to present their position;
  • c) assess the information and evidence submitted;
  • d) prepare a corresponding conclusion or recommendation.

Article 17. Ethical breaches and response

17.1. An ethical breach may include:

  • a) a breach of the requirements of this Regulation;
  • b) a breach of the organization’s charter;
  • c) unauthorized use of the organization’s technical resources;
  • d) unlawful cybersecurity activity;
  • e) unauthorized disclosure of confidential information;
  • f) misuse of the organization’s name;
  • g) discrimination or harassment;
  • h) concealment of a conflict of interest;
  • i) plagiarism or infringement of intellectual property;
  • j) causing significant harm to the organization’s reputation;
  • k) a breach of any other obligation provided by the Regulation.

17.2. Depending on the nature, gravity, and consequences of the breach, the following response measures may be used:

  • a) an oral warning;
  • b) a written warning;
  • c) temporary removal from the relevant event or programme;
  • d) temporary restriction of access to the organization’s technical resources;
  • e) temporary suspension of membership;
  • f) raising the question of expulsion from the organization in accordance with the charter;
  • g) where provided by law, transmitting relevant information to a competent authority.

17.3. The response measure must be proportionate to the nature and gravity of the breach.

17.4. Use of the measures provided in this Article does not exclude other liability under Georgian law.

Article 18. Procedural safeguards

18.1. When an ethical breach is considered, the person must be given an opportunity to learn the material allegation against them and to present their explanation.

18.2. When a decision is taken, the following must be taken into account:

  • a) the nature of the breach;
  • b) the gravity of the breach;
  • c) the harm caused;
  • d) whether the breach is repeated;
  • e) the degree of the person’s cooperation;
  • f) other relevant circumstances.

18.3. A discriminatory approach is not permitted when responding to the same facts.

Article 19. Secure channel for responsible disclosure

19.1. UCSA may establish a dedicated channel for receiving information about security vulnerabilities or other cybersecurity incidents.

19.2. Members and other persons are encouraged to report significant security vulnerabilities to the organization or the relevant system owner in accordance with responsible disclosure principles.

19.3. The organization may define a separate procedure for responsible disclosure.

Article 20. Familiarization with and acknowledgement of the Regulation

20.1. Upon joining the organization, a member is provided with information about the operation of this Regulation.

20.2. By signing a membership agreement or confirming membership terms through the organization’s electronic platform, a member confirms that they have read the Regulation and undertake to comply with its requirements.

20.3. If a new edition of the Regulation is approved, the organization may notify members of the change by email or through the organization’s electronic platform.

Article 21. Final provisions

21.1. This Regulation is an internal document of the organization and applies together with the organization’s charter and Georgian law.

21.2. If any provision of the Regulation is held invalid or of no effect, this does not affect the operation of the remaining provisions.

21.3. The requirements of the Regulation are interpreted in accordance with the organization’s charter, Georgian law, and the principles of professional ethics in cybersecurity.

21.4. Amendments and additions to the Regulation are made by decision of the body or person authorized by the organization.

Legal