IaaS 152-FZ: So, you need security

IaaS 152-FZ: So, you need security

No matter how many myths and legends surrounding compliance with 152-FZ are discussed, something always remains in the background. Today, we want to address the not-so-obvious nuances that both large companies and small enterprises might encounter:

  • the subtleties of classifying personal data into categories — when a small online store collects data that relates to a special category, often without even realizing it;

  • where backups of collected personal data can be stored and how to manage them;

  • the difference between a certificate and a compliance conclusion, what documents to request from the provider, and similar matters.

Lastly, we will share our own experience of undergoing certification. Let's go!

The expert for today's article will be Alexey Afanasev, a specialist in information security for cloud providers "IT-GRAD" and #CloudMTS (part of the MTS group).

Subtleties of Classification

We often encounter clients wanting to quickly determine the required level of security for their information system without an audit. Some materials available online create the false impression that this is a simple task and that making a mistake is rather difficult.

To determine the security level, it is crucial to understand what data will be collected and processed by the client’s information system. Sometimes, it can be quite challenging to clearly define the protection requirements and the category of personal data that the business operates with. The same types of personal data can be evaluated and classified very differently. Therefore, opinions may differ between the business and the auditor or even the inspector. Let's consider a few examples.

Fleet. It seems to be a fairly traditional type of business. Many fleets operate for decades, and their owners hire individual entrepreneurs and private persons. Generally, employee data falls under the requirements of UZ-4. However, working with drivers requires not only collecting personal information but also conducting medical checks at the fleet's premises before the start of a shift, and the information gathered in the process immediately falls into the category of medical data – which is considered sensitive personal data. Furthermore, the fleet may request certificates, which will then be kept in the driver's file. A scanned copy of such a certificate in electronic form contains health information as well as sensitive personal data. Therefore, UZ-4 is not sufficient; at least UZ-3 is required.

Online store. It seems that the names, emails, and phone numbers being collected fall into the publicly available category. However, if your customers indicate dietary preferences, such as halal or kosher, such information could be considered data about religious beliefs and affiliations. Therefore, during inspections or other monitoring activities, the inspector might classify the data you collect as sensitive personal data. If the online store gathered information on whether a customer prefers meat or fish, that data could be categorized as other personal data. By the way, what about vegetarians? This too can relate to philosophical beliefs, which also fall into the sensitive category. But, on the other hand, it may simply reflect the choice of a person who has eliminated meat from their diet. Unfortunately, there is no straightforward guideline that clearly defines the category of personal data in such 'subtle' situations.

Advertising agency with any western cloud service processes public data of its clients — full names, email addresses, and phone numbers. This user data, of course, falls under Personal Data (PD). The question arises: is it legal to conduct such processing? Is it even possible to transfer such data outside of Russia without anonymization, for example, storing backups in foreign clouds? Certainly, it is. The agency has the right to store this data outside of Russia, however, initial collection, according to our legislation, must be performed on the territory of Russia. If you are backing up such information, calculating statistics based on it, conducting research, or performing other operations with it — all this can be done on western resources. The key point from a legislative perspective is where the collection of PD occurs. Therefore, it is important not to confuse initial collection and processing.

As these brief examples show, working with PD is not always straightforward and simple. It is necessary not only to be aware that you are working with them but also to know how to properly classify them, understand how information systems operate, in order to accurately determine the required level of security. In some cases, there may be a question of what volume of PD is actually necessary for the organization to function. Is it possible to forgo the most 'serious' or simply unnecessary data? Additionally, the regulator recommends anonymizing PD wherever possible. 

As in the examples above, one may sometimes encounter the situation where monitoring bodies interpret the collected PD somewhat differently than you evaluated them yourself.

Of course, you can enlist the help of an auditor or systems integrator, but will this 'assistant' be responsible for the chosen solutions in the event of an inspection? It should be noted that responsibility always lies with the owner of the personal data information system – the personal data operator. That is why, when a company undertakes such work, it is important to turn to serious players in the market of such services, for example, companies that carry out certification activities. Certification companies have extensive experience in conducting such work.

Options for constructing a personal data information system

Building a Personal Data Information System (PDIS) is not only a technical issue but also a legal one. The IT director or security director must consult with a lawyer. Since companies often do not have a specialist with the required profile, it's worthwhile to consider hiring auditors or consultants. Many tricky aspects may not be immediately obvious.

Consultation will help identify which personal data you are dealing with and what level of protection is required. Accordingly, you will gain an understanding of the information system that needs to be created or supplemented with protective measures and documentation.

Often, companies are faced with two options:

  1. Build a corresponding information system on their own software and hardware solutions, possibly within their own server room.

  2. Turn to a cloud provider and choose a flexible solution, such as an already accredited 'virtual server room.'

Most information systems that process personal data use a traditional approach, which is difficult to call easy or successful from a business perspective. When choosing this option, it is essential to understand that the technical project will include a description of the equipment, including software and hardware solutions and platforms. This means you will face the following difficulties and limitations:

  • difficulty in scaling;

  • long project implementation time: it requires selecting, purchasing, installing, configuring, and describing the system;

  • a lot of 'paperwork', for example — developing a complete documentation package for the entire PDIS.

Moreover, businesses typically only understand the 'top' level of their information system — the business applications in use. In other words, IT personnel are qualified in their narrow field. There is a lack of understanding of how all the 'lower levels' work: software and hardware protective measures, storage systems, backups, and, of course, how to configure protective measures while meeting all requirements and building the 'hardware' part of the configuration. It is important to understand that this is a vast body of knowledge that lies outside the client's business. This is where the experience of a cloud provider offering an accredited 'virtual server room' can be invaluable.

Cloud providers, in turn, have several advantages that can undoubtedly meet 99% of businesses' needs in the field of personal data protection:

  • capital expenditures are transformed into operating expenses;

  • the provider guarantees the necessary level of security and availability based on a tested standard solution;

  • there is no need to maintain a staff of specialists to ensure the operation of the personal data information system at the hardware level;

  • providers offer much more flexible and scalable solutions;

  • provider specialists have all the necessary certifications;

  • compliance is at least as high as when building your own architecture, considering the requirements and recommendations of regulators.

The old myth that personal data cannot be placed in the cloud is still remarkably popular. It is truthful only in part: personal data cannot indeed be placed in just any cloud. Compliance with certain technical measures and the use of specific certified solutions is required. If the provider meets all legal requirements, the risks associated with personal data leaks are minimized. Many providers have a separate infrastructure for processing personal data in accordance with Federal Law 152. However, choosing a supplier should also be approached with an understanding of certain criteria, which we will definitely touch on below. 

Clients often come to us with some concerns about placing personal data in a provider's cloud. Well, let's discuss them right away.

  • Data can be stolen during transmission or migration.

There is no need to worry about this — the provider offers the client the creation of a secure data transmission channel based on certified solutions, enhanced authentication measures for contractors and employees. It remains to choose the appropriate means of protection and implement them in cooperation with the client.

  • Mask show-ups will arrive and take/seal/power off the server.

It's entirely understandable for clients to be concerned that their business processes may be disrupted due to insufficient control over the infrastructure. This concern often arises from clients whose hardware was previously located in small server rooms rather than in specialized data centers. In reality, data centers are equipped with modern measures for both physical and informational security. Any operation within such a data center is practically impossible to execute without sufficient justification and documentation, and such activities require adherence to a whole set of procedures. Moreover, 'pulling' your server out of the data center can impact other clients of the provider, which is something no one wants. Additionally, no one can specifically point to 'your' virtual server, so if someone did wish to steal it or stage a masquerade, they would first have to navigate a plethora of bureaucratic hurdles. During that time, you would likely have migrated to another platform several times.

  • Hackers will breach the cloud and steal data

The internet and print media are filled with headlines about how yet another cloud has fallen victim to cybercriminals, and millions of records containing personal data have leaked online. In the overwhelming majority of cases, vulnerabilities were found not on the provider's side, but within the information systems of the victims: weak or even default passwords, 'holes' in website engines and databases, and the sheer carelessness of businesses in choosing security measures and organizing data access procedures. All certified solutions are checked for vulnerabilities. We also regularly conduct 'control' penetration tests and security audits, both independently and with the help of external organizations. For a provider, this is a matter of reputation and business as a whole.

  • The provider/employees of the provider will steal personal data for selfish reasons

This is quite a sensitive issue. A number of companies in the cybersecurity field 'scare' their clients, insisting that 'insider threats are more dangerous than hackers from outside.' While this may be true in some cases, a business cannot be built without trust. From time to time, there are news reports about employees leaking customer data to malicious actors, and sometimes internal security is organized much worse than external security. It's essential to understand that any major provider is highly averse to negative incidents. The actions of provider employees are well-regulated, with defined roles and areas of responsibility. All business processes are designed in such a way that data breaches are highly unlikely and are always noticeable to internal services, so clients shouldn't worry about problems from this side.

  • You pay little because you are paying for services with your business data.

Another myth: clients renting secure infrastructure at a comfortable price are actually paying for it with their data – this is often thought by specialists who enjoy reading a couple of conspiracy theories before bed. First of all, the possibility of conducting any operations with your data beyond those specified in the directive is essentially zero. Secondly, a reasonable provider values their relationship with you and their reputation—besides you, they have many other clients. It is more likely that the opposite scenario occurs, wherein the provider will vigorously protect their clients' data, which is crucial for their business.

Choosing a cloud provider for personal data processing

Currently, the market offers a variety of solutions for companies that are personal data operators. Below is a general list of recommendations for choosing the right one.

  • The provider should be prepared to sign an official contract describing the responsibilities of the parties, the SLA, and areas of responsibility regarding personal data processing. In fact, between you and the provider, in addition to the service contract, a directive for personal data processing should be signed. In any case, it is worth studying them carefully. It is important to understand the delineation of areas of responsibility between you and the provider.

  • Please note that the segment must meet the requirements, meaning it should have a certificate indicating a security level not lower than what is required by your information system. Sometimes, providers only publish the first page of the certificate, which is not very informative, or refer to an audit or compliance procedures without publishing the certificate itself ("was there really a boy?"). It is worth requesting it — this is a public document that indicates who conducted the certification, its validity period, the cloud location, etc.

  • The provider must provide information on where their sites (protection facilities) are located so that you can control the placement of your data. Remember, the initial collection of personal data must be carried out on the territory of the Russian Federation, so it is advisable to see the addresses of the data centers in the contract/certificate.

  • The provider must use certified security tools and cryptographic tools. Of course, most providers do not publicly disclose the technical protection means they use and the architecture of solutions. However, as a client, you must be aware of this. For example, to connect remotely to the management system (management portal), it is necessary to use protective measures. The provider cannot circumvent this requirement and will provide you with (or require you to use) certified solutions. Test the resources, and you will immediately understand how everything is structured. 

  • It is highly desirable that the cloud provider offers additional services in the field of information security. These can include various services: DDoS protection and WAF, antivirus service, sandboxing, etc. All of this will allow you to receive protection as a service, freeing you from the burden of building security systems and allowing you to focus on business applications.

  • The provider must be licensed by the FSTEC and the FSB. Typically, such information is available directly on the website. Be sure to request these documents and verify that the addresses of the services provided, the name of the provider company, etc., are correctly indicated. 

Let's summarize. Renting infrastructure will allow you to avoid CAPEX and only keep your business applications and data under your responsibility while transferring the heavy burden of certifying the hardware and software-hardware systems to the provider.

How we underwent certification

Recently, we successfully completed the re-certification of the 'Protected Cloud FZ-152' infrastructure to comply with the requirements for working with personal data. The work was carried out by the 'National Certification Center'.

At present, the 'Protected Cloud FZ-152' has been certified for hosting information systems that participate in the processing, storage, or transmission of personal data (ISPDn) in accordance with the requirements of level UZ-3.

The certification procedure involves checking the compliance of the cloud provider's infrastructure with the protection level requirements. The provider itself offers IaaS services and is not an operator of personal data. The process involves an assessment of both organizational (documentation, orders, etc.) and technical measures (configuration of protection means, etc.).

It cannot be called trivial. Despite the fact that GOST standards for programs and methodologies for conducting certification events appeared back in 2013, there are still no strict programs for cloud objects. Certification centers develop these programs based on their own expertise. With the emergence of new technologies, the programs become more complex and modernized, accordingly, the certifier must have experience working with cloud solutions and understand the specifics.

In our case, the object of protection consists of two locations.

  • The data center directly houses cloud resources (servers, storage systems, network infrastructure, protection means, etc.). Undoubtedly, such a virtual data center is connected to public networks, thus certain requirements for firewalling must be fulfilled, for example, the use of certified firewalls.

  • The second part of the object consists of cloud management means. These are workstations (administrator workstations) from which the secure segment is managed.

The locations are linked via VPN-channel based on cryptographic protection means (SKZI).

Since virtualization technologies create conditions for the emergence of threats, we also use additional certified protection means.

IaaS 152-FZ: So, you need securityStructural diagram 'from the certifier's perspective'

If a client requires certification of their ISPDn, after renting IaaS they will only need to evaluate the information system beyond the level of a virtual data center. This procedure involves checking the infrastructure and the software used on it. Since you can refer to the provider's certificate for all infrastructure issues, you only need to focus on the software.

IaaS 152-FZ: So, you need securityAbstraction Level Segregation

In conclusion, here’s a brief checklist for companies that are already working with personal data or are just planning to do so. So, how to process data without getting burned.

  1. For auditing and developing threat models and intruder profiles, invite an experienced consultant from one of the certification laboratories, who will help draft the necessary documents and guide you to the technical solution stage.

  2. When choosing a cloud provider, pay attention to the presence of a certificate. It’s a good sign if the company has publicly posted it directly on its website. The provider should be licensed by the FSTEC and FSB, and the service they offer must be certified.

  3. Ensure that you will have an official contract signed and a mandate for personal data processing. Based on this, you can conduct both compliance checks and ISPDn certification. If these tasks seem burdensome during the technical project stage and the creation of project and technical documentation, it might be worthwhile to engage third-party consulting firms from among the certification laboratories.

If you have questions regarding personal data processing, we would be happy to see you at our webinar on September 18, this Friday. Features of Building Certified Clouds.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster