Rostelecom-Solar defended the personal data and objects of the KII of the operator Tyvasvyazinform
Customers: Tyvasvyazyinform Product: Comprehensive information security projects Second product: External IT and Security Audit Projects (PCI DSS and SIS) Project date: 2021/02 - 2021/07
|
2021: Compliance with 152-FZ requirements
On August 10, 2021, Rostelecom-Solar announced a comprehensive project to ensure the compliance of the Tyvasvyazinform telecom operator with the requirements of legislation in the field of personal data (152-FZ) and the security of critical information infrastructure ( 187-FZ). Thanks to the introduced security tools, Tyvasvyazinform has secured the data of its subscribers and key information systems on which the company depends. The project lasted five months.
At the first stage, requirements for the information security system were formed and work was carried out on classification according to 152-FZ and categorization according to 187-FZ. When designing the personal data protection system and CII, the specialists of the Rostelecom-Solar Integration Directorate took into account the intersections of the requirements of 152-FZ and 187-FZ and developed an optimal set of technical and organizational measures to ensure the IB, closing the requirements of both laws. This made it possible to significantly optimize the project from a financial point of view.
Work on the categorization of CII facilities was carried out in accordance with the agreed FSB and FSTEC methodological recommendations for CII entities operating in the field of communications. In addition, Rostelecom-Solar experts used their own methodology to calculate criteria for the significance of CII objects, which provides maximum economic efficiency. A list of critical processes and their supporting systems has been identified.
{{quote 'In fact, we have formed a single protection system that meets the requirements of both 152-FZ and 187-FZ. Even at the start, we drew up such a plan for the implementation of protection tools, which allowed us to save time and work, as well as the customer's money. At the same time, almost all information protection tools deployed within the framework of the project were developed by Russian vendors, therefore, when the requirements for import substitution during the protection of KII become mandatory, Tyvasvyazinform will also meet these requirements of the regulator, "said Nikolai Belobrov, head of the center for complex projects of the Rostelecom-Solar Integration Directorate. }}
During the project, Rostelecom-Solar specialists also conducted an audit of the telecom operator's network IT infrastructure and proposed options for its modernization.
Tvasvyazinform has its developed telecommunications network throughout the republic, so the security of these customers is a key criterion for us, "says Orlan-ool Vladimirovich Ondar, technical director of Tvasvyazinform. - It is important for us not only to comply with modern legislation, but also to provide services to customers qualitatively and without interruptions. Colleagues from Rostelecom-Solar helped us protect the systems on which it depends. |