| Customers: Angarsk Electrolysis Chemical Combine (AECC), Federal State Unitary Enterprise
Contractors: Leta IT-company Product: Projects of external audit of IT and security (in tch PCI DSS and SUIB)Project date: 2014/01 - 2014/08
|
On August 27, 2014 the LETA company announced completion of works on reduction of an automated system in the protected execution of the Angarsk Electrolysis Chemical Combine in compliance with requirements of information security of ROSATOM State Corporation.
Project Tasks
At the enterprise and interactions between the enterprises of ROSATOM State Corporation in 2012 are developed for ensuring effective and safe network processing of information the industry requirements for information security obligatory for accomplishment by all organizations entering into structure of Rosatom State Corporation, their subsidiaries and affiliates.
AEHK is selected by one of pilot platforms on implementation of the industry standard of information security. Effective joint work of specialists of LETA company and the staff of plant promoted project implementation in a short time.
To specialists of LETA company formulated and set the tasks of a system design of information security support (SOIB) of plant, delivery and implementation of information security tools, certifications by the constructed SOIB on compliance to security requirements of information on a class of security 1G according to requirements of FSTEC of Russia.
Project Progress
Work in the project was continued six months and consisted of four stages:
- on initial stage the list of threats for enterprise information systems and engineering design of SOIB is updated. The developed engineering design underwent careful approval in Department of protection of the state secret and information of Rosatom State Corporation.
- implementation of all subsystems of SOIB – firewalling, protection of communication channels, antivirus protection, leak detection of confidential information, the analysis of security, monitoring of events of information security and protection of workstations against unauthorized access is carried out.
- on completion of works acceptance tests are carried out.
- specialists of LETA prepared a set of the documents necessary for representation of ASZI of plant to certification on compliance to security requirements of information on a class of security 1G which became the final stage of work on the project.
Project Results
Improvement of an information security system, its reduction in compliance to requirements of regulators and to industry standards of ROSATOM State Corporation - one of priority tasks for JSC AEHK. Defining by a factor when choosing the contractor for work on the project - presence at experts of LETA of the corresponding competences, experience of successful projects implementation at the enterprises of nuclear sector.
"Questions of information security in nuclear sector, in fact, are questions of nuclear security therefore tasks of fulfillment of requirements of regulating documents of Rosatom and regulators in the field of data protection are of particular importance, – Alexander Malyavkin, the CEO of LETA noted. – The project implemented by us in Angarsk became continuation of our cooperation with structures of ROSATOM State Corporation and the first project in the nuclear industry of Russia on complete reduction of an enterprise information system in compliance to the industry standard. It would be desirable to note that the successful solution of a difficult task of implementation of requirements of the industry standard became possible thanks to effective joint work of experts of our company and employees of "AEHK"".
