Customers: Dry
Contractors: Leta IT-company Product: Projects of external audit of IT and security (in tch PCI DSS and SUIB)Project date: 2011/03
|
The Leta company, the operator of the typified IT services, announced end of the complex project on personal data protection (PDN) in Sukhoi company. The personal data information system (ISPDN) implemented within the project completely answers provisions of Federal law No. 152-FZ, the relevant bylaws and other elements of the existing regulatory base in the field of protection of PDN.
In information systems of Sukhoi company the considerable volume of personal data is processed. Protection of all confidential information including PDN, is the major task for the customer. At the time of the beginning of the project the standards of security and technological solutions existing in Sukhoi company provided the high level of personal data protection required according to riskoriyentirovanny assessment, reported in Leta. The analysis of the existing standards and technologies on compliance to the newest requirements of the Russian legislation was a key task of this project.
Works took place on the typified scheme repeatedly approved by Leta company in projects of similar scale. At the first stage specialists of Leta carried out the analysis of the existing documents and processes on IT and cybersecurity. Then the complex analysis of collected information was carried out and technical specifications and the engineering design on creation of a system of protection of PDN are developed. Further necessary organizational and administrative documentation was created — at its development Leta relied on all set of collected data and also was guided by requirements of the existing regulatory base in the field of protection of PDN. At the fourth stage setup necessary program and the hardware is carried out.
"Our company spent considerable efforts to development of standards of security and implementation of the relevant technical solutions. Naturally, we wanted to save these practices, bringing the system of personal data protection into accord to requirements of the existing regulatory base — Sergey Burov, the head of department of PDITR and TZI, Sukhoi company noted. — We well understood as far as it is a difficult task, and looked for the partner with adequate skill level and in the most data domain, and in technology of maintaining projects of similar scale. The Leta company helped us to solve an assigned task".