The state corporation for the organization of air traffic of the Russian Federation will import substitution of information security products from the Pentagon supplier
Customers: State Corporation for the Organization of Air Traffic in the Russian Federation (State Corporation for ATM, FSUE) Project date: 2023/10 - 2024/12
Project's budget: 399 589 330 руб.
|
The State Corporation for the Organization of Air Traffic in the Russian Federation (State ATM Corporation) plans to import replace the subsystems of its automated information security control system based on imported software. The corresponding purchase is planned to be carried out in October[1]The initial contract price is indicated by the amount of about 400 million rubles.
Earlier, in August, the State ATM Corporation conducted a request for prices for the performance of these works[2]. As follows from the terms of reference published then, the purchase is justified, among other things, by presidential decrees No. 166 of March 30, 2022 and No. 250 of May 1, 2022, establishing a number of prohibitions regarding the use of imported software at critical information infrastructure facilities CUES ().
The information security management system of the State Corporation implements management of key information security processes of the office segment of the organization's information infrastructure - both in the General Directorate and in branches. Accordingly, the project should cover both the general management of the State Corporation for ATM and 14 branches in different cities of the country.
Several subsystems of the information security management system of the state corporation are implemented on the basis of imported software, the vendor of which is a company based in Britain, Micro Focus follows from the published terms of reference. In particular, the information security event collection, correlation and analysis subsystem is implemented on Micro Focus - ArcSight ESM a comprehensive information security management platform based on the same name. SIEM The information security incident management subsystem is created on the Micro Focus Service Manager platform, and the integration module c State system of detection, prevention and elimination of consequences of computer attacks is on it.
Micro Focus solutions are based on developments inherited from corporations Hewlett Packard Enterprise and Borland. The company is known, among other things, for cooperating on deliveries software with. US Department of Defense On resources, Pentagon for example, you can find its license agreements with Micro Focus[3]
And in 2017, ArcSight became famous for the fact that its developer, Hewlett Packard Enterprise, as it turned out, provided the source code of the platform to the Russian authorities for examination in order to obtain the right to sell it in Russia[4]. However, Micro Focus, the new owner of ArcSight, in the same year announced its refusal to provide its source code for examination to states, in her opinion, "posing a great risk" to security[5].
In 2022, against the backdrop of Western sanctions, Micro Focus ceased to fulfill its existing contractual obligations to customers in the Russian Federation, as stated in its explanations to the balance sheet published in the Russian tax base. And since January 31, 2023, Micro Focus has been owned by Open Text Corporation.
In addition to import substitution, among the procurement goals, the State ATM Corporation is to reduce the total costs of information security incident management, optimize activities to identify and respond to information security incidents, develop the analytical base used in the subsystems of the information security management system, etc.
The project is financed from an extrabudgetary source - from the state corporation's own funds, indicated in the August terms of reference.
The deadline for the work there was also indicated by 420 days from the date of conclusion of the contract.
Notes
- ↑ Import substitution of the automated information security management system of FSUE State ATM Corporation.
- ↑ Tender: Execution of work on import substitution of the automated information security management system of FSUE State ATM Corporation
- ↑ DEPARTMENT OF DEFENSE ENTERPRISE SOFTWARE INITIATIVE LICENSE AGREEMENT.
- ↑ Hewlett Packard disclosed to Russia the source code of the software used by the Pentagon
- ↑ The new owner of ArcSight will close access to the source code for "dangerous" governments