RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2
Project

Rosenergoatom implemented technology of the analysis of security of the IT system

Customers: Rosenergoatom, Federal State Unitary Enterprise concern

Product: MaxPatrol SIEM

Project date: 2017/03  - 2017/06

Content

On September 5, 2017 the NPO VS company announced the project of creation of an analysis system of security for identification and operational elimination of vulnerabilities in JSC Rosenergoatom Concern network.

Project Tasks

For risk minimization of emergence of incidents of information security, providing compliance to requirements of the legislation, the management of Rosenergoatom Concern made the decision on creation of a specialized analysis system of security which will allow to conduct permanent monitoring of mechanisms of information security support, excepting influence of a human factor.

The NPO VS company acted as the contractor.

Project Progress

At the first stage specialists of NPO VS company conducted information examination of automation objects, including organizational and normative providing and large-scale inventory used at the enterprise program and the hardware.

On the basis of the received results the security analysis system is designed. The hardware and software system Max Patrol in which mechanisms of testing for penetration (Pentest), system checks (Audit) and control of compliance to standards (Compliance) in combination with support of the analysis of different operating systems, DBMS and web applications are provided was taken as a technical basis (in total more than 80 systems, including the application software).

On the next stage the staff of Rosenergoatom Concern was trained to work with a security analysis system, and specialists of NPO VS company created documentation on a system.

Start of a system in operation became the third stage of the project.

The project on creation of a system covers central office of concern and four branches. Other divisions should be connected within the second queue.

File:Aquote1.png
High importance of an object means high responsibility. This project brought to our specialists unique experience of customer interaction in the conditions of tough regulations and critical infrastructures. Any NPP is an independent division with the set of software and hardware tools therefore for each of stations it was necessary to study technical solutions in an individual order. Besides, there is a number of the regulations reflecting requirements of the Russian legislation in relation to strategic objects, they also needed to be considered during the work on the project.

Alexander Scherbakov, manager with key clients of NPO VS company
File:Aquote2.png

Project Results

The security analysis system created by specialists of NPO VS based on the product Max Patrol carries out inventory of nodes of corporate network, search of vulnerabilities and errors of a configuration of the software, defines the services and protocols used in network for identification of a possibility of unauthorized influence. Based on scanning a system creates reports with recommendations about elimination of the revealed shortcomings.

File:Aquote1.png
The variety of types of the malware which is actively used today by malefactors considerably increases importance of monitoring of network regarding vulnerabilities. Thanks to specialists of NPO VS company at the enterprise the independent analysis system of security allowing a message permanent monitoring of network is created. Now we at any time can obtain up-to-date information about the level of security of our corporate network.

Dmitry Korotkikh, the head of this project in department of IT project management and integration of Rosenergoatom
File:Aquote2.png