Answer the question
In order to leave comments, you need to log in
How to prepare for the FSTEC audit on information security?
Ask for help from the more experienced.
In the fall, the organization is expected to be audited by the FSTEC on information security. What actions need to be taken in this regard?
What can be read to an inexperienced administrator of a personal data protection system so that everything is written in a simple, understandable language from A to Z?
Will it be a problem that the computers in the organization are running Windows XP, which will no longer be supported by Microsoft from April?
Answer the question
In order to leave comments, you need to log in
As for reading, it’s difficult, because laws need to be read (and they are difficult to remember), a consultant + to help. And there were several articles on Habré.
You conduct an audit of the processing of personal data (what data, what is done with it, where it is transferred, where it is stored, etc.), you create a threat model, then you determine the level of security. For each action - documents (acts).
You conduct an audit of all systems for processing / transferring / storing PD. If the existing means of protection do not fit the level of security, you finish it.
With Windows - by and large - pofik, the main thing is to close all "undocumented features".
ispdn.ru there are a lot of discussions on the forum, even with examples of acts.
> What measures should be taken in connection with this?
If no action has been taken yet, then he will shoot himself.
You can't do anything quickly.
Wait for the inspection, the FSTEC will draw up an inspection report with an order to eliminate violations.
1. If your company is a FSTEC licensee, then you do not need to do anything, because if you do not know what to do, then other specially trained people do it.
2. If your company is not a FSTEC licensee, but has an IP protection agreement with a FSTEC licensee, then you don’t need to do anything either, just inform these people about the fact of verification
3. If you do not have a license or an agreement with a licensee, prepare to attract organizations and officials to administrative responsibility.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question