V
V
Vadim Shandrinov2013-06-07 17:24:34
linux
Vadim Shandrinov, 2013-06-07 17:24:34

How can we protect the personal data we process on a Linux+Apache+MySQL+Django server?

Dear! Tell me how to meet the requirements of the law FZ-152 for the Ubuntu server + Apache + Django + MySQL + self-written software on Django?
There is a development of a workflow automation system for a private school, while DVP. Personal data: full name and phone numbers of students and their parents (publicly available identifying data). I would like to put the server outside so that students and parents can view their data from the outside. By https, we will buy a certificate.
I read and read laws / opinions and there is no understanding - what needs to be done? What software to install and whether it is necessary?
habrahabr.ru/qa/32163/ - I saw that we will do administrative measures (writing internal documents and appointing employees).
PP-1119 dated November 1, 2012 - I read, I understood that we have "Public PD of the operator's employees or public PD of less than 100,000 PD subjects who are not employees of the operator", with an understanding of the level of threats - an ambush ...
And now the questions:
- Possible holes in system software - is this the first type of threat? or third? This depends on the level of protection.
- What kind of beast is the "electronic message log" from the 2nd level of protection? is this syslog?
- Even if we provide the 4th, the lowest, level of security - which certified information security tools should be used for our technology stack and should they? built-in firewalls on IPtables - does it satisfy? Only 2 ports will be open outside (https + non-standard ssh)
- How to compile (and compile) a threat model?
— Should the hosting provider where we install a dedicated server be certified? access to the server room and all that ...
- do I need to register anything with the regulators? and what, if necessary?
Thank you in advance :)

Answer the question

In order to leave comments, you need to log in

3 answer(s)
O
Otkrick, 2013-06-07
@suguby

You do not have public data unless all students and parents write a statement about it. All means of protection must be certified by the FSTEC, such means have an electronic journal. First of all, you need to find out what personal data you have, whether all data carriers are ready to declare public availability. Then it's easier to suggest something.
In any case, you need to send a notification that you are a PD operator (to Roskomnadzor).

S
Sergey, 2013-06-08
@bondbig

Simple https is not good, you need it with GOST encryption. For example Trusted TLS.

X
xrays72, 2013-06-08
@xrays72

Buy a dedicated server from a hoster and install this OS on it www.altlinux.ru/products/certified-systems

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question