[an error occurred while processing the directive]
RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2
Project

Implementation of information security tools in Federal Drug Control Service of the Russian Federation of FDCS

Customers: Federal Drug Control Service of the Russian Federation of FDCS

Moscow; Government and social institutions

Product: Complex projects on information security

Project date: 2010/03  - 2015/11
The Federal Drug Control Service of the Russian Federation (FSKN of Russia) is the federal executive authority performing functions on development of state policy, legal regulation, control and supervision in the field of trafficking in narcotics and psychotropic substances and also in the field of counteraction to their illicit trafficking.

For accomplishment of the direct functions of FSKN of Russia uses a number of the specialized departmental information systems (IS), one of which is the integrated system of operational identification (ISOI). It provides collecting, the analysis, processing, storage and transfer of dactyloscopic information – fingerprints, palms, hands and also photoinformation – facsimiles and subjective portraits. ISOI processes personal data (PDN) and cannot legitimately be operated at failure to follow statutory requirements on data protection in the information systems containing and processing PDN (Federal law 152-FZ).

For the purpose of reduction of security of PDN in ISOI to the set normative level, accomplishment of statutory requirements and for providing the real high level of the information security (IS), FSKN of Russia held a competition on accomplishment of all complex of works on development and deployment of means of protecting and also on preparation for certification and certification of ISOI for requirements 152-FZ, FSTEC and FSB.

Creation of an end-to-end system of protection of PDN processed in ISOI and also ensuring their security when using the ISOI mobile complexes and software and hardware complexes based on the palmar scanner became a project task; with the subsequent certification of all number of the IC and application solutions.

The project was developed and implemented in 3 stages, since 2010. Each of stages had own justification and the right of its production was defined on a competitive basis. Based on all three tenders by the contractor on execution of works became "nuclear heating plant", proposing optimal technological solutions and also the best conditions of contract performance.

At the first stage the system of protection of PDN processed in the central ISOI was developed and implemented directly certification for security requirements of information is carried out it.

At the second stage the system of protection of PDN processed by means of the ISOI mobile complexes and software and hardware complexes based on the palmar scanner is created, certification for security requirements of information is carried out them.

At the third stage recertification of a system of protection of ISOI after validity period of Certificates of compliance is carried out.

During the project:

  • The private model of security risks of PDN describing security risks of information at all ISOI levels is finished and approved with FSB of the Russian Federation (federal, regional, to the ISOI components connected to the IC). Processing allowed to optimize considerably costs for creation and maintenance of a system of protection.
  • The system of protection is designed in such a way that all transactions with PDN are executed taking into account requirements of information security.
  • Protection of communication channels federal and the regional levels of a system of operational identification is organized.
  • Certification of a system on compliance to requirements for security of information of FSTEC of Russia is executed.

o At the first stage – local ICs federal and the regional levels of a system o At the second and third stages – the ISOI components connected to the IC – the special mobile complexes (MC) intended for operational input and verification of dactyloscopic information and facsimiles, and software and hardware complexes based on the palmar scanner (PTKL).

Works on each of stages of the project included:

  • Carrying out inspection of the IC PDN.
  • Class definition of the IC PDN.
  • Refining of safety requirements of PDN.
  • Development and approval of the Customer of technical specifications on the system of protection of PDN, including installation of necessary information security tools, cryptographic (cryptographic) tools.
  • Project development of organizational and administrative documents on security of information.
  • Delivery and implementation of technical means of an information security system.
  • Development and approval of the customer of the program and technique of carrying out evaluation tests.
  • Carrying out evaluation tests on compliance to requirements for security of information and development of the conforming reporting documents with issue of certificates of compliance to requirements.

Project implementation covered Central office of FDCS and also 7 regional governments of UFSKN in Moscow, Noginsk, Kolomna, Lyubertsy and Odintsovo.

Area manager of complex information security support of "nuclear heating plant" Inna Sergienko: "The integrated system of operational identification of FSKN of Russia is implemented using the specialized software and the equipment developed directly for the customer and which is not standard. It became the main complexity of the project and demanded the choice of the technical components of a system of protection which are built in ISOI taking into account its architectural features and integrated with the ISOI technical components. Together with the customer we booked audit, completely implemented actions for technical protection of the IC, including installation of necessary software and hardware tools, executed the subsequent certification. It allowed to put ISOI into commercial operation".