The draft order of the FSTEC, which amends the current requirements for the secure storage of data not constituting a state secret in government bodies and at CII facilities, has been published on the legal acts portal. Consideration of the document will be carried out on the portal until August 7.
According to the document, which was reviewed by the Kommersant newspaper, CII facilities will have to fulfill a number of new requirements. These include:
- mandatory provision of antivirus protection for systems, prevention of intrusions into the infrastructure, and control of information protection in general;
- the ability of data transmission channels to withstand twice the normal amount of traffic;
- storage for three years of information about cyber incidents: date and time of the start and end of the attack, type of threat, its volume (Gbit/s), a list of network addresses that are the source of threats, and the protection measures that were taken.
The document refers to cyberattacks based on the "denial of service" (DDoS attacks) model as security threats. Such attacks are aimed at blocking a resource or stopping the operation of the entire information system by sending an increased number of requests to its server.
Under Russian law, critical information infrastructure objects include information systems, networks, and automated control systems operating in the following areas:
- healthcare;
- science;
- transport;
- communications;
- energy;
- banking and other areas of the financial market;
- fuel and energy complex;
- nuclear energy;
- defense and rocket and space industry;
- mining, metallurgical and chemical industries.
The CII also includes telecommunications networks that connect these objects.
Read materials on the topic:
Moscow Public Wi-Fi Will Block Access to Prohibited Information
Russia Becomes World Leader in Number of Databases Leaked to the Darknet
Runet Under Total Control: Roskomnadzor to Start Managing All Networks of Russian Providers
Russia Finds a Way to Protect Infrastructure from FPV Drones