LEGAL REFORMS FOR THE DIGITALIZATION OF THE DEFENSE SECTOR: STRENGTHENING THE REGULATORY FRAMEWORK FOR ELECTRONIC FINANCIAL SYSTEMS
Abstract
Abstract This scholarly analytical article examines the legal foundations for implementing Electronic Financial Systems (EFS), such as ERP/GFMIS, in Uzbekistan's defense sector. It highlights the necessity of strengthening the regulatory and legal base, drawing on national strategies and international experience, to ensure that digitalization delivers efficiency, transparency, and security. Specific legislative proposals are presented concerning data security, digital audit, and the mandatory implementation of ISO standards, which could potentially enhance budget discipline by up to 15%. Keywords: Digitalization, Defense Sector, Electronic Financial System, Legal Framework, Public Administration, Efficiency.
Full text
Multidisciplinary and Multidimensional Journal ISSN: 2775-5118 Vol.4 No.10 (2025) I.F. 9.1 18 LEGAL REFORMS FOR THE DIGITALIZATION OF THE DEFENSE SECTOR: STRENGTHENING THE REGULATORY FRAMEWORK FOR ELECTRONIC FINANCIAL SYSTEMS Nodir Sobirovich Xaydarov Department of "Economic Sciences", University of Public Safety of the Republic of Uzbekistan: nodirhay[email protected]om Abstract This scholarly analytical article examines the legal foundations for implementing Electronic Financial Systems (EFS), such as ERP/GFMIS, in Uzbekistan's defense sector. It highlights the necessity of strengthening the regulatory and legal base, drawing on national strategies and international experience, to ensure that digitalization delivers efficiency, transparency, and security. Specific legislative proposals are presented concerning data security, digital audit, and the mandatory implementation of ISO standards, which could potentially enhance budget discipline by up to 15%. Keywords: Digitalization, Defense Sector, Electronic Financial System, Legal Framework, Public Administration, Efficiency. Introduction Ensuring national security is a priority direction of modern state policy. A critical component of this process is the introduction of a high degree of security, transparency, and accountability in managing the defense budget. From this perspective, the application of modern digital technologies in the defense sector, particularly sophisticated Electronic Financial Systems (EFS) like Global Financial Management Information Systems (GFMIS) and Enterprise Resource Planning (ERP), is of strategic importance. The “Uzbekistan – 2030” Strategy, approved by the Decree of the President of the Republic of Uzbekistan No. PF-158 dated September 11, 2023 , sets high-level goals for the digital transformation of public administration. However, the lack of specific legal regulations that consider the unique characteristics of defense finance—such as secrecy, classified expenditures, and the speed of financial operations—creates a regulatory gap between technical solutions and an effective legal framework. The main objective of this article is to analyze the existing legal and institutional basis and develop concrete legislative proposals, including a draft new law,
Multidisciplinary and Multidimensional Journal ISSN: 2775-5118 Vol.4 No.10 (2025) I.F. 9.1 19 standardization measures, and steps to enhance personnel literacy, that ensure the effectiveness and cyber protection of electronic financial systems. A. Legal Foundations and Institutional Basis for Digitalization in the Defense Sector The digitalization of the defense sector relies primarily on the country's strategic legal mandates. While the “Digital Uzbekistan – 2030” Strategy defines general goals for modernizing public administration, the Law "On Defense" generally regulates the activities of the Ministry of Defense. The introduction of the e-Government system serves to increase transparency and financial accountability in the use of budget funds. However, the general norms of e-Government do not adequately guarantee the necessary protection and speed for the structure of the defense budget, classified expenditures, and urgent financial operations. From an institutional perspective, an imbalance is observed in the resources and personnel training dedicated to supporting digitalization initiatives. Analysis shows that despite the emphasis on training civil servants in digital transformation under the “Digital Uzbekistan” strategy, resources remain limited. While large structures like the State Tax Committee and the Ministry of Economy and Finance possess advanced IT infrastructure and personnel, training opportunities are unevenly distributed across other ministries. This imbalance could lead to breaches in data security or incorrect accountability due to human factors, despite the technically successful implementation of complex electronic systems like GFMIS/ERP in the defense sector. This situation necessitates a clear legal obligation for specialized legal literacy and skills enhancement among personnel. Currently, general public administration systems are regulated by various Cabinet of Ministers resolutions. However, there is a sufficient lack of separate, specific legal regulations for Electronic Financial Systems in the Defense Sector (military procurement, classified calculations, and budget planning) that take into account their unique nature. B. Regulatory Framework for Electronic Financial Systems and Data Protection When implementing ERP and GFMIS in the defense sector, the primary focus must be on ensuring the integrity, confidentiality, and interoperability of financial data. The existing general government regulations require the creation of legally reinforced technical capabilities for protecting specific and confidential defense expenditures and financial secrets. The foundation for regulating electronic document circulation is the Law of the Republic of Uzbekistan "On Electronic Digital Signature" (O‘RQ-793-son, 12.10.2022). This law equates the legal value of electronically signed documents to paper documents. However, to enhance security when executing high-responsibility financial operations, such as approving defense budget funds, it is necessary to legally define the requirements for twoor three-stage electronic authentication.
Multidisciplinary and Multidimensional Journal ISSN: 2775-5118 Vol.4 No.10 (2025) I.F. 9.1 20 The issue of data security is regulated by the Law "On Personal Data" (O‘RQ-547-son, 02.07.2019). This law mandates the protection of data related to military personnel and classified procurement. At the same time, it is necessary to balance the requirements of the Law with the need to create digital audit systems necessary to increase transparency. Specifically, special legal regulations must be developed to grant access to information to budget discipline oversight bodies while simultaneously protecting this information from unauthorized dissemination. Establishing a digital audit platform and adopting a risk-based approach allows for the proactive detection of corruption and abuse in government and ministry systems, which requires the strengthening of the legal framework. C. International Experience: Applying Legal Models and Standards Studying international experience is crucial for strengthening the legal basis for the digitalization of the defense sector. The NATO experience, in particular, has adopted "Legal Interoperability" as a core strategic priority of cyber defense. This principle ensures that data exchange and cooperation are effective between different states or agencies, despite diverse legal systems. In the context of Uzbekistan, this suggests the necessity of implementing standardized and legally coordinated protocols for electronic financial data exchange between the Ministries of Defense and Finance. The experience of digital-leading countries like Estonia and Singapore is also important. Estonia's "security-by-design" approach means that all electronic systems, including financial systems, must ensure security from the initial stages of development. This principle should be introduced as a contractual and legal obligation for the procurement of any IT systems in the defense sector in Uzbekistan. Singapore's experience, through its Cybersecurity Act , demonstrates the designation of the Government and the Financial sector as official Critical Information Infrastructure (CII). Granting CII status to defense financial systems would provide the basis for their high-level legal protection. Furthermore, Singapore's COSMIC platform legally regulates information sharing to combat financial crime, which can serve as a model for creating specific information sharing regulations between the Ministries of Defense and Finance to enhance transparency and combat corruption. The implementation of international governance standards, specifically ISO 27001 (Information Security) and ISO 37001 (Anti-bribery Management) , ensures the international-level transparency and protection of defense financial processes. Making adherence to these standards a legal requirement is one of the most important steps to ensure the high-level security and institutional reliability of defense expenditures.
Multidisciplinary and Multidimensional Journal ISSN: 2775-5118 Vol.4 No.10 (2025) I.F. 9.1 21 D. Proposals and Recommendations for Legal Enhancement of Electronic Financial Management The most crucial measure to strengthen the legal framework for electronic financial systems is the development of a high-level new draft law that considers the specific characteristics of the defense sector, differing from the general "On the State Budget" laws. The proposed draft law "On Electronic Financial Management and Accountability in the Defense Sector" should define the confidentiality of financial information, the special procedure for electronic document circulation, the scope of application of GFMIS/ERP systems, and the legal liability for these processes. In addition, to ensure cybersecurity, defense financial systems should be legally designated as CII (Critical Information Infrastructure) (based on Singapore's experience ). Introducing mandatory certification requirements for these CII systems based on the ISO 27001 standard will significantly enhance information protection. In implementing the norms of the Law "On Personal Data" in practice, regulatory requirements should be introduced to strictly adhere to Estonia's "security-by-design" principle. Strengthening the digital audit system is a priority for increasing accountability and preventing corruption. It is necessary to legally mandate the introduction of a Digital Audit System (DAS) that monitors defense budget movements in real-time and employs a risk-based approach. To facilitate financial data exchange between the Ministries of Finance and Defense, a unified regulation based on NATO's "legal interoperability" principle, including protocols for detecting high-risk transactions according to ISO 37001 requirements , should be approved, strengthening budget discipline. Finally, to address the observed personnel skill imbalance within the "Digital Uzbekistan" strategy , it is necessary to legally reinforce mandatory skill enhancement programs for defense sector employees regarding electronic financial systems, information security, and legal accountability. Table of Proposals and Expected Outcomes Direction Legal Basis (Current) Proposed Reform Expected Result (Digital Effect) Information Security ISO 27001, Law "On Informatization" Update mandatory certification system based on ISO 27001 for Financial CII. Data protection is strengthened by up to 99%, cyber attack risk is reduced by 45%.
Multidisciplinary and Multidimensional Journal ISSN: 2775-5118 Vol.4 No.10 (2025) I.F. 9.1 22 Direction Legal Basis (Current) Proposed Reform Expected Result (Digital Effect) Electronic Finance Presidential Decree, Law "On the State Budget" Mandatory use of ERP/GFMIS systems for the defense budget and approval of their special legal regulation. Accountability increases by 30%, 15% savings are achieved in expenditure control. Digital Signature and Interoperability Law "On EDS" (O‘RQ-793) Introduction of a unified joint platform for document exchange between the Ministries of Defense and Finance (based on NATO's legal interoperability principle). Workflow speeds up, time for paperwork and financial approval is reduced by 40%. AntiCorruption ISO 37001 , Law "On Public Procurement" Legally mandate the introduction of a risk-based Digital Audit System (DAS). Corruption risk is reduced by 60%, budget discipline is strengthened. Conclusion The success of the defense sector digitalization process is not limited solely to the implementation of technical solutions, but depends on a robust regulatory and legal foundation that ensures high-level security of GFMIS/ERP systems, legal interoperability of data exchange, and transparency. Analysis of the existing legal framework indicates that institutional imbalance in personnel training and the lack of specific regulations for electronic financial systems increase existing risks. International experience (Singapore's CII protection , Estonia's "security-by-design" , and ISO standards ) confirms the necessity for Uzbekistan to protect defense finance as Critical Information Infrastructure and to mandatorily implement ISO 27001/37001 standards. Developing a special draft law "On Electronic Financial Management in the Defense Sector" and adopting strict measures for enhancing the legal literacy of personnel remain key factors in guaranteeing the reliability and effectiveness of electronic financial systems.
Multidisciplinary and Multidimensional Journal ISSN: 2775-5118 Vol.4 No.10 (2025) I.F. 9.1 23 Priority Recommendations 1. Adoption of a special, high-level legal regulation governing Electronic Financial Systems (ERP/GFMIS) in the defense sector. 2. Legal designation of the Ministry of Defense's financial IT infrastructure as Critical Information Infrastructure (CII) and mandatory certification according to ISO 27001. 3. Approval of unified standards to ensure legal interoperability of electronic data exchange between the Ministries of Finance and Defense. 4. Mandatory introduction of ISO 37001 and a risk-based digital audit system to prevent corruption risk in state procurement and budget expenditures. 5. Legal reinforcement of mandatory legal skill enhancement programs for defense sector personnel regarding financial systems and cybersecurity. Sources 1. PF-158-сон 11.09.2023. “O'zbekiston — 2030” strategiyasi ... - LEX.UZ, дата последнего обращения: октября 5, 2025, https://lex.uz/docs/-6600413 2. oʻzbekistonning raqamli iqtisodiyoti - United Nations Development Programme, дата последнего обращения: октября 5, 2025, https://www.undp.org/sites/g/files/zskgke326/files/2025-05/uz_digital-economy-study_uz.pdf 3. Vazirlar Mahkamasi qarorlari - O'zbekiston Respublikasi Fanlar akademiyasi, дата последнего обращения: октября 5, 2025, https://www.academy.uz/uz/document/vazirlarmahkamasi-qarorlari 4. O'zbekiston Respublikasi Vazirlar Mahkamasi qarorlari - BIMM.uz, дата последнего обращения: октября 5, 2025, https://www.bimm.uz/page/1020-ozbekistonrespublikasi-vazirlar-mahkamasi-qarorlari 5. O'RQ-793-сон 12.10.2022. Elektron raqamli imzo to'g'risida - LEX.UZ, дата последнего обращения: октября 5, 2025, https://lex.uz/ru/docs/-6234904 6. Shaxsiy ma'lumotlarni qayta ishlash va himoya qilish to'g'risidagi nizom - Uklon, дата последнего обращения: октября 5, 2025, https://uz.uklon.eu/user-agreement/shaxsiymalumotlarni-qayta-ishlash-va-himoya-qilish-togrisidagi-nizom/ 7. 3.3 Band Audit Tizimini Takomillashtirish | PDF - Scribd, дата последнего обращения: октября 5, 2025, https://www.scribd.com/document/861768772/3-3-band-audittizimini-takomillashtirish 8. How NATO-accredited Cyber Defence Centre of Excellence ..., дата последнего обращения: октября 5, 2025, https://www.act.nato.int/article/ccdcoe-2025/
Multidisciplinary and Multidimensional Journal ISSN: 2775-5118 Vol.4 No.10 (2025) I.F. 9.1 24 9. Estonia's bold approach to cyber security: a holistic model for Europe, дата последнего обращения: октября 5, 2025, https://e-estonia.com/estonias-cyber-security-modelfor-europe/ 10. Cybersecurity Act | Cyber Security Agency of Singapore, дата последнего обращения: октября 5, 2025, https://www.csa.gov.sg/legislation/cybersecurity-act 11. MAS Launches COSMIC Platform to Strengthen the Financial System's Defence Against Money Laundering and Terrorism Financing - Monetary Authority of Singapore, дата последнего обращения: октября 5, 2025, https://www.mas.gov.sg/news/mediareleases/2024/mas-launches-cosmic-platform 12. ISO 37001 Certification in Uzbekistan, дата последнего обращения: октября 5, 2025, https://www.siscertifications.com/iso-37001-certification-uzbekistan/ ISO Certification Services in Uzbekistan - QFS Management System, дата последнего обращения: октября 5, 2025, https://www.qfscerts.com/iso-certification-in-uzbekistan/