New developments in information security certification

New developments in information security certification

About a year ago, on April 3, 2018, the Federal Service for Technical and Export Control of Russia published Order No. 55. It approved the Regulations on the certification system for information protection means.

This defined who participates in the certification system. It also clarified the organization and procedure for certifying products used to protect confidential information that constitutes state secrets, the means for which also need to be certified through the specified system.

So, what exactly do the Regulations refer to as products that need certification?

• Means to combat foreign technical intelligence and means to control the effectiveness of technical information protection.
• IT security means, including secure information processing systems.

The participants in the certification system include:

• Authorities accredited by the Federal Service for Technical and Export Control.
• Testing laboratories accredited by the Federal Service for Technical and Export Control.
• Manufacturers of information protection means.

To undergo certification, the following steps must be taken:

• Submit an application for certification.
• Wait for a decision on conducting certification.
• Undergo certification testing.
• Prepare an expert conclusion and a draft certificate of conformity based on the results.

Then the certificate may be issued or the issuance may be refused.

In addition, in one way or another, the following occurs:
• Issuance of a duplicate certificate.
• Marking of protection means.
• Amendments to already certified protection means.
• Extension of the certificate.
• Suspension of the certificate.
• Termination of its validity.

The 13th point of the Regulations should be quoted:

“13. Certification tests of information protection means are conducted on the material and technical base of the testing laboratory, as well as on the material and technical bases of the applicant and/or manufacturer located within the territory of the Russian Federation.”

Not long ago, on March 29, 2019, the Federal Service for Technical and Export Control published another update titled “Information message from the Federal Service for Technical and Export Control of Russia dated March 29, 2019, No. 240/24/1525».

The document has modernized the information security protection certification system. Thus, the Information Security Requirements have been approved. These requirements establish levels of trust in technical means of information protection and in the means of ensuring information technology security. They, in turn, define the conditions for the development and manufacture of information protection means, testing of information protection means, as well as for ensuring the security of information protection means during their application. There are six levels of trust in total. The lowest level is the sixth. The highest is the first.

First and foremost, the trust levels are intended for developers and manufacturers of protection means, applicants for certification, as well as for testing laboratories and certification bodies. Compliance with the trust level requirements is mandatory for the certification of information protection means.
All of this will come into effect on June 1, 2019. Due to the approval of the trust level requirements, the FSTEC will no longer accept applications for the certification of protection means for compliance with the requirements of the guideline document 'Protection Against Unauthorized Access. Part 1. Software for Information Protection Means. Classification According to the Control Level of Undeclared Capabilities.'

Information protection means that comply with the first, second, and third trust levels are used in information systems that process information containing state secrets.

The application of protection means from the fourth to the sixth trust levels for GIS and ISPDn of the corresponding classes/levels of protection is presented in the table:

New developments in information security certification

Special attention should be paid to the fact that:

The validity of certificates of compliance for information protection means, for which the specified compliance assessment will not be conducted before January 1, 2020, based on paragraph 83 of the Regulation on the Certification of Information Protection Means, approved by the order of FSTEC of Russia dated April 3, 2018, No. 55, may be suspended.

While lawmakers continue to work on improving certification requirements, we provide cloud infrastructure, complying with all applicable laws. The solution provides a ready-made infrastructure, a prepared solution for compliance with Federal Law 152.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster