Developers: | Rostelecom-Solar, Rostelecom-Solar (formerly Solar Security, Solar Security) |
Date of the premiere of the system: | 2022/08/04 |
Technology: | Information Security - Information Leakage Prevention |
Main article: IT outsourcing
2022: Launch of a service to legitimize the leak protection system
On August 4, 2022, RTK-Solar announced the launch of a service for legitimizing the leak protection system (DLP) in Russian organizations. These services will help legally competently formalize the implementation of the DLP system in the organization in order to avoid civil, administrative and criminal liability as a result of the system.
The use of DLP systems in the company has certain requirements for the process of protection against leaks. First of all, this is the observance of the fundamental constitutional rights of employees and the rights of personal data subjects. It is also necessary, competently from the point of view of the right, to organize the process of protecting information of limited access, official, commercial secrets, preventing signs of corruption and other types of fraud in the company. In addition, as a result of legitimization of the DLP system, data from it can be used as a source of evidence for incidents that occurred in the company, including in court.
RTK-Solar specialists recommend starting the process of legitimizing DLP even before the start of the implementation project, defining a list of limited access information, the procedure for its use, protection and access to it. At the stage of implementation of the system, the process of legitimization begins with the introduction of rules for the use of computer equipment and communications by employees. For example, employees should not use personal mail for business purposes, store personal information on corporate devices. Based on the results of the training, employees should understand that corporate (service) communication channels are controlled by default.
The legitimization stage itself assumes that the company introduces the Commercial Secret regime, determines the list of restricted information, introduces a ban on its disclosure and determines responsibility for violating this ban. Employees are notified in writing of automated workstation monitoring using the DLP system. As a result, the risk of violation of the rights and freedoms of workers is reduced, and it becomes possible to use these DLP systems in litigation as acceptable evidence.
We have repeatedly received requests from our customers not only for the technical, but also for the legal implementation of the Solar Dozor DLP system. At the beginning of August 2022, we provided the service of legitimizing DLP in several organizations public sector and. transport industries As a result of such projects, customers noted that they managed to streamline and systematize the processes of protecting limited access information, to build an incident response system from scratch. The legitimization of DLP seems to customers to be a complex and confusing process, which requires the development and adoption in the company of a whole set of documents covering a variety of areas and interests of several departments (labor relations, personal data trade secrets, information resources). Our DLP Legal Implementation Services help customers understand this process quickly and successfully. said Alexey Kubarev, head of the business development department of the Dozor Product Center "RTK-Solar."
|