Answer the question
In order to leave comments, you need to log in
Is it possible to lower the ISPD security class?
Good afternoon, dear habrazhiteli!
When establishing the level of security, it is necessary to determine the relevance of threats of a certain type (1st, 2nd or 3rd).
According to Decree 1119, paragraph 6: "Threats of the 1st type are relevant to the information system, if it is also affected by threats related to the presence of undocumented (undeclared) capabilities in the system software used in the information system." The organization providing the documents claims that due to the lack of FSTEC certificates for undeclared capabilities for operating systems (OS), all personal data information systems (PDIS) using the OS will receive the 1st (highest) level of security.
Therefore, in accordance with clause 9.a “The need to ensure the 1st level of protection of personal data during their processing in the information system is established if at least one of the following conditions is present: a) threats of the 1st type and the information system are relevant for the information system processes either special categories of personal data or biometric personal data or other categories of personal data;
It's no secret that most companies in ISPD use a regular licensed Windows that does not have FSTEC certificates, which means that the class will also be the highest, the first. Accordingly, the requirements for the protection of such ISPDs will be the highest.
And now the question is: is it possible to lower the level of security at least to the 3rd, while remaining within the framework of the new legislation?
Maybe someone has come across something similar?
Answer the question
In order to leave comments, you need to log in
Look at Resolution 1119 (clause 6) for the concept of the relevance of a personal security threat and think about how the presence or absence of an FSTEC certificate affects it. Based on this, already draw conclusions.
7. Determination of the type of threats to the security of personal data relevant to the information system is carried out by the operator
Of course you can, it's all done!
You here
dlp-expert.ru/blog/3375/23096
And here
habrahabr.ru/post/200894/
Yes, and yet, you write “The organization providing the documents claims that due to the lack of FSTEC certificates for undeclared capabilities for operating systems (OS), all personal data information systems (PDIS) using the OS will receive the 1st (highest ) security level. “
Please explain what kind of organization?
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question