Use cryptographic means protection (CIPF) topic is very controversial and slippery. However, the PD Operator has such a right, in the event of actual threats, to apply CIPF to ensure protection. But it is not always clear how to use this right. And now the FSB makes life easier, a document of methodological recommendations applicable both to state IS and to all other PD Operators has been released. Let's take a closer look at this document.

And so, it happened, the 8th Center of the FSB posted describing recommendations in the field of development of regulatory legal acts for the protection of PD. At the same time, the same document is recommended to be used by ISPD operators when developing particular threat models.

So what does the FSB think about how and where to apply CIPF?

It is important enough that this document published only on the FSB website,has no registrationin the Ministry of Justice andbears no signatureand- that is, its legal significance and binding stays within the guidelines. It's important to remember this.

Let's look inside, the preamble of the document defines that recommendations “for federal executive authorities ... other state bodies ... that ... adopt regulatory legal acts that define threats to the security of personal data that are relevant when processing personal data in information systems ah of personal data (hereinafter referred to as ISPD) exploited in the course of the relevant types of activities”. Those. explicit reference is made to state information systems.

However, at the same time, these same norms “it is also advisable to be guided by the development private threat models operators of information systems of personal data who have made a decision on the use of funds cryptographic protection information(hereinafter referred to as CIPF) to ensure the security of personal data”. Those. the document in this case becomes universal for all users.

When is it necessary to use SKZI?

The use of CIPF to ensure the security of personal data is necessary in the following cases:

  1. if personal data is subject to cryptographic protection in accordance with the law Russian Federation;
  2. if there are threats in the information system that can only be neutralized with the help of CIPF.

  1. transfer of personal data over communication channels that are not protected from interception by the offender of the information transmitted through them or from unauthorized influences on this information (for example, when transferring personal data over public information and telecommunication networks);
  2. storage of personal data on storage media, unauthorized access to which the offender cannot be excluded using non-cryptographic methods and methods.

And that's where we come. If the second point is also quite logical, then the first one is not so obvious. The fact is that, according to the current version of the law "On Personal Data" name, surname and patronymic are already personal data. Accordingly, any correspondence or registration on the site (taking into account how much data is currently required during registration) formally falls under this definition.

But, as they say, there are no rules without exceptions. There are two tables at the end of the document. Here is just one line Apps #1.

Current threat:

1.1. carrying out an attack while within the controlled zone.

Reason for absence (the list is slightly shortened):

  1. employees who are users of ISPD, but who are not users of CIPF, are informed about the rules of work in ISPD and responsibility for non-compliance with the rules for ensuring information security;
  2. CIPF users are informed about the rules for working in ISPD, the rules for working with CIPF and responsibility for non-compliance with the rules for ensuring information security;
  3. the premises in which the cryptographic information protection system is located are equipped with entrance doors with locks, ensuring that the doors of the premises are permanently locked and opened only for authorized passage;
  4. approved the rules for access to the premises where the CIPF is located, during working and non-working hours, as well as in emergency situations;
  5. a list of persons entitled to access to the premises where the CIPF is located was approved;
  6. differentiation and control of user access to protected resources;
  7. registration and accounting of user actions with PD;
  8. on workstations and servers on which CIPF is installed:

    certified means of protecting information from unauthorized access are used;
  9. certified anti-virus protection tools are used.

That is, if users are informed about the rules and responsibilities, and protective measures are applied, then it turns out that there is nothing to worry about.

  • to ensure the security of personal data during their processing in ISPD, cryptographic information protection tools that have passed the conformity assessment procedure in the prescribed manner should be used.

True, it says a little lower that a list of certified cryptographic information protection tools can be found on the website of the TsLSZ FSB. The fact that conformity assessment is not certification has been said repeatedly.

  • in the absence of CIPF conformity assessment procedures that have passed in accordance with the established procedure ... at the stage of a preliminary design or draft (sketch-technical) project, the information system developer with the participation of the operator (authorized person) and the proposed CIPF developer prepares a justification for the expediency of developing a new type of CIPF and determines the requirements for its functional properties.

It really pleases. The fact is that certification the process is very long - up to six months or more. Often, customers use the latest operating systems that are not supported by the certified version. According to this document, customers can use products that are in the process of certification.

The document states that:

When using communication channels (lines) from which it is impossible to intercept the protected information transmitted through them and (or) in which it is impossible to carry out unauthorized actions on this information, in the general description of information systems, it is necessary to indicate:

  1. description of methods and means of protecting these channels from unauthorized access to them;
  2. conclusions based on the results of studies of the security of these communication channels (lines) from unauthorized access to protected information transmitted through them by an organization entitled to conduct such studies, with reference to the document containing these conclusions.

  • security characteristics (confidentiality, integrity, availability, authenticity) that must be provided for the processed personal data;
  • communication channels (lines) used in each subsystem or in the information system as a whole, including cable systems, and measures to limit unauthorized access to protected information transmitted via these communication channels (lines), indicating communication channels (lines) in which unauthorized access to protected information transmitted through them is impossible, and measures implemented to ensure this quality;
  • media of protected information used in each subsystem of the information system or in the information system as a whole (with the exception of communication channels (lines)).
  • Commenting...

    Alexey, good afternoon!
    In the response of the 8th Center, nothing is indicated about the need to use certified cryptographic information protection tools. But there are "Methodological recommendations ..." approved by the leadership of the 8th Center of the FSB of Russia dated March 31, 2015 No. 149/7/2/6-432, in which there is such a paragraph in the second part:

    To ensure the security of personal data during their processing in ISPD, CIPF should be used that have passed the conformity assessment procedure in the prescribed manner. The list of CIPF certified by the FSB of Russia is published on the official website of the Center for Licensing, Certification and Protection of State Secrets of the FSB of Russia ( Additional information it is recommended to obtain information about specific information security tools directly from the developers or manufacturers of these tools and, if necessary, from specialized organizations that have conducted case studies of these tools;

    Why is this not a requirement to use certified CIPF?

    There is an order of the FSB of Russia dated July 10, 2014 No. 378, in which subparagraph "d" of paragraph 5 states: "the use of information security tools that have passed the procedure for assessing compliance with the requirements of the legislation of the Russian Federation in the field of information security, in the case when the use of such tools is necessary to neutralize current threats."

    A little confusing is this "when the use of such means is necessary to neutralize actual threats." But all this necessity should be described in the intruder model.

    But in this case, again, in Section 3 of the "Methodological recommendations ..." of 2015, it is indicated that "When using communication channels (lines) from which it is impossible to intercept the protected information transmitted over them and (or) in which it is impossible to carry out unauthorized actions to this information, in the general description of information systems, it is necessary to indicate:
    - description of methods and means of protecting these channels from unauthorized access to them;
    - conclusions based on the results of studies of the security of these communication channels (lines) from unauthorized access to the protected information transmitted through them by an organization entitled to conduct such studies, with reference to the document containing these conclusions.

    I’m all this for what - yes, there is no need to use cryptographic information protection always and everywhere while ensuring the security of processing personal data. But for this it is necessary to form a model of the violator, where all this is described and proved. You wrote about two cases when you need to use them. But the fact that in order to ensure the security of processing PD over open communication channels, or if the processing of these PD goes beyond the boundaries of the controlled zone, you can use uncertified cryptographic information protection tools - it's not so simple. And it may happen that it is easier to use certified cryptographic information protection tools and comply with all requirements during their operation and storage than to use uncertified means and butt heads with the regulator, who, seeing such a situation, will try very hard to poke his nose.

    unknown comments...

    The case when the use of such means is necessary to neutralize current threats: the requirement of the Order of the FSTEC of Russia No. 17 of February 11, 2013 (requirements for state and municipal ISPDs),

    clause 11. To ensure the protection of information contained in the information system, information security tools are used that have passed conformity assessment in the form of mandatory certification for compliance with information security requirements in accordance with Article 5 of Federal Law No. 184-FZ of December 27, 2002 "On technical regulation".

    Alexey Lukatsky comments...

    Proximo: FSB recommendations are illegitimate. Order 378 is legitimate, but must be considered in the context of all legislation, and it says that the specifics of conformity assessment are established by the Government or the President. Neither one nor the other such NPA did not release t

    Alexey Lukatsky comments...

    Anton: in the state, the certification requirement is established by law, the 17th order simply repeats them. And we are talking about PDN

    unknown comments...

    Alexey Lukatsky: No. FSB recommendations are illegitimate "How illegitimate? I'm talking about the document dated 05/19/2015 No. %40fsbResearchart.html), but not about the document dated February 21, 2008 No. 149/54-144.

    Another specialist also previously made a request to the FSB on a similar topic, and he was told that the "Methodology ..." and "Recommendations ..." of the FSB of 2008 should not be used if you are talking about these documents. But again, these documents have not been officially canceled. And these documents are legitimate or not, I believe, will be decided by the inspectors from the FSB already in place during the inspection.

    The law says that you need to protect PD. By-laws from the Government, the FSB, the FSTEC determine exactly how they need to be protected. The NPA from the FSB says: "Use certified. If you do not want certified, prove that you can use it. And please, attach a conclusion to this from a company that has a license to issue such conclusions." Something like this...

    Alexey Lukatsky comments...

    1. Any recommendation is a recommendation, not a mandatory requirement.
    2. The manual of 2015 has nothing to do with PD operators - it applies to states that write threat models for subordinate institutions (subject to clause 1).
    3. The FSB does not have the right to conduct checks on commercial operators of PD, and for governments, the issue of using uncertified cryptographic information protection is not worth it - they are required to use certified solutions, regardless of the presence of PD - these are the requirements of FZ-149.
    4. Bylaws say how to protect and that's okay. But they cannot determine the form of assessment of remedies - this can only be done by the NPA of the Government or the President. FSB is not authorized to do this

    unknown comments...

    According to Regulation 1119:

    4. The choice of information security tools for the personal data protection system is carried out by the operator in accordance with the regulatory legal acts adopted Federal Service Security of the Russian Federation and the Federal Service for Technical and Export Control pursuant to Part 4 of Article 19 of the Federal Law "On Personal Data".
    13.y. The use of information security tools that have passed the procedure for assessing compliance with the requirements of the legislation of the Russian Federation in the field of information security, in the case when the use of such tools is necessary to neutralize current threats.

    How to justify the non-relevance of the threat when transmitting PD through the channels of the telecom operator?

    Those. if not SKZI, then apparently
    - terminal access and thin clients, but at the same time the data of the information security system of the terminal
    access must be certified.
    - protection of channels by the telecom operator, responsibility on the telecom operator (provider).

    Alexey Lukatsky comments...

    Irrelevance is determined by the operator and he does not need anyone for this

    The main tasks of protecting information during its storage, processing and transmission through communication channels and on various media, solved with the help of CIPF, are: 1.

    Ensuring secrecy (confidentiality) of information. 2.

    Ensuring the integrity of information. 3.

    Authentication of information (documents). To solve these problems, it is necessary to implement the following

    processes: 1.

    Implementation of the actual information security functions, including:

    encryption/decryption; creation/verification of EDS; creating/testing mock inserts. 2.

    Monitoring the state and managing the functioning of the means of KPI (in the system):

    status control: detection and registration of cases of violation of the operability of means of KPI, attempts of unauthorized access, cases of compromise of keys;

    operation management: taking measures in case of the listed deviations from the normal functioning of the KPI means. 3.

    Carrying out maintenance of KZI facilities: implementation of key management;

    execution of procedures related to the connection of new network subscribers and / or the exclusion of retired subscribers; elimination of identified shortcomings of the CIPF; commissioning of new versions of CIPF software;

    modernization and replacement technical means CIPF for more advanced and / or replacement of funds whose resource has been depleted.

    Key management is one of the most important functions of cryptographic information protection and consists in the implementation of the following main functions:

    key generation: defines a mechanism for generating keys or key pairs with a guarantee of their cryptographic qualities;

    key distribution: defines the mechanism by which keys are reliably and securely delivered to subscribers;

    key retention: defines the mechanism by which keys are securely and securely stored for future use;

    key recovery: defines the mechanism for recovering one of the keys (replacement with a new key);

    key destruction: defines the mechanism by which obsolete keys are securely destroyed;

    key archive: a mechanism by which keys can be securely stored for later notarized recovery in conflict situations.

    In general, in order to implement the listed functions of cryptographic information protection, it is necessary to create a system of cryptographic information protection that combines the actual means of CSI, service personnel, premises, office equipment, various documentation (technical, regulatory), etc.

    As already noted, in order to obtain guarantees of information protection, it is necessary to use certified means of KPI.

    Currently, the most widespread is the issue of protecting confidential information. To solve this issue, under the auspices of FAPSI, a functionally complete set of cryptographic protection of confidential information has been developed, which allows solving the listed tasks of protecting information for a wide variety of applications and conditions of use.

    This complex is based on the cryptographic cores "Verba" (system of asymmetric keys) and "Verba-O" (system of symmetric keys). These cryptocores provide data encryption procedures in accordance with the requirements of GOST 28147-89 "Information processing systems.

    Cryptographic protection" and digital signature in accordance with the requirements of GOST R34.10-94 "Information technology. Cryptographic protection of information. Procedures for the development and verification of an electronic digital signature based on an asymmetric cryptographic algorithm.

    The tools included in the CIPF complex allow you to protect electronic documents and information flows using certified encryption mechanisms and electronic signature practically in all modern information technologies, including allow to carry out: the use of CIPF in offline mode;

    secure information exchange in off-line mode; secure information exchange in on-line mode; protected heterogeneous, i.e. mixed information exchange.

    To solve systemic issues of the use of cryptographic information protection tools, under the leadership of D. A. Starovoitov, the Vityaz complex cryptographic information protection technology was developed, which provides for cryptographic data protection in all parts of the system at once: not only in communication channels and system nodes, but also directly at user workplaces in the process of creating a document, when the document itself is protected. In addition, within the framework common technology"Vityaz" provides a simplified, easily accessible to users technology for embedding licensed cryptographic information protection tools into various applied systems, which makes the range of use of these CIPF very wide.

    Below is a description of the means and methods of protection for each of the listed modes.

    Use of CIPF offline.

    When working autonomously with CIPF, the following types of cryptographic information protection can be implemented: creation of a protected document; file protection;

    creation of a protected file system; creation of a protected logical drive. At the request of the user, the following types of cryptographic protection of documents (files) can be implemented:

    encryption of a document (file), which makes its content inaccessible both when storing a document (file) and when it is transmitted via communication channels or by courier;

    development of an insert imitator, which provides control over the integrity of the document (file);

    the formation of an EDS, which ensures control of the integrity of the document (file) and authentication of the person who signed the document (file).

    As a result, the protected document (file) turns into an encrypted file containing, if necessary, an EDS. The digital signature, depending on the organization of the information processing process, can also be represented by a file separate from the signed document. Further, this file can be output to a floppy disk or other medium, for delivery by courier, or sent via any available e-mail, for example over the Internet.

    Accordingly, upon receipt of an encrypted file by e-mail or on one or another medium, the cryptographic protection actions performed are performed in the reverse order (decryption, verification of imitate insertion, verification of digital signature).

    For implementation battery life The following certified means can be used with CIPF:

    text editor "Lexicon-Verba", implemented on the basis of CIPF "Verba-O" and CIPF "Verba";

    software complex CIPF "Autonomous workplace", implemented on the basis of CIPF "Verba" and "Verba-O" for Windows 95/98/NT;

    cryptographic disk driver PTS "DiskGuard".

    Protected word processor "Lexicon-Verba".

    The Lexicon-Verba system is a full-featured text editor with support for document encryption and electronic digital signature. To protect documents, it uses the Verba and Verba-O cryptographic systems. The uniqueness of this product lies in the fact that the functions of encryption and text signing are simply included in the functions of a modern text editor. Encryption and signing of the document in this case turns from special processes into simply standard actions when working with a document.

    At the same time, the Lexicon-Verba system looks like a regular text editor. Text formatting options include full customization fonts and paragraphs of the document; tables and lists; footers, footnotes, sidebars; the use of styles and many other functions of a text editor that responds modern requirements. "Lexicon-Verba" allows you to create and edit documents in Lexicon, RTF, MS Word 6/95/97, MS Write formats.

    Autonomous workplace.

    The CIPF "Autonomous Workplace" is implemented on the basis of the CIPF "Verba" and "Verba-O" for Windows 95/98/NT and allows the user to perform the following functions in interactive mode:

    encryption / decryption of files on keys; encryption / decryption of files with a password; affixing/removal/verification of electronic digital signatures (EDS) under files;

    checking encrypted files;

    EDS affixing + encryption (in one action) of files; decryption + removal of EDS (in one action) under files;

    hash file calculation.

    CIPF "Autonomous Workplace" is advisable to use for the daily work of employees who need to provide:

    transfer of confidential information to in electronic format by hand or courier;

    sending confidential information over a public network, including the Internet;

    protection against unauthorized access to confidential information on personal computers employees.

    As practice shows, few organizations remember and are guided by the order of FAPSI (the successor of which is the FSB of Russia) dated June 13, 2001 N 152 "On approval of the Instruction on organizing and ensuring the security of storage, processing and transmission over communication channels using cryptographic information protection tools with limited access, not containing information constituting a state secret.

    But the Instruction is mandatory when using certified CIPF to ensure the security of information limited access(subject to protection in accordance with the legislation of the Russian Federation).And this is PD, all kinds of secrets, GIS, NPCs, future CIIs.

    From 2008 to 2012, there was an indulgence for PD in the form of “Standard requirements for the organization and operation of encryption (cryptographic) means designed to protect information that does not contain information constituting a state secret if they are used to ensure the security of personal data during their processing in personal data information systems”, approved by the leadership of the 8th Center of the FSB of Russia on February 21, 2008 No. 149/6/6-622. But after the release of RF PP No. 1119, this document lost its relevance and the FSB of Russia said that it was necessary to be guided by the Instruction.

    Within the state control over the implementation of the provisions of this Instruction, there are a large number of violations.

    There are many questions regarding the application of the Instruction, because it was written at a time when certified cryptographic information protection tools were used in rare organizations in single copies. Now, when sert. cryptography is becoming ubiquitous, making it difficult to follow the Instruction verbatim.

    Immediately I want to draw attention to the fact that the Instructions in conjunction with 99-FZ give unambiguous results on the need to obtain a license from the FSB of Russia or conclude an agreement with a licensee:

    Article 12 of 99-FZ: "one. In accordance with this Federal Law, the following types of activities are subject to licensing:

    1) ... performance of work ... in the field of information encryption, Maintenance encryption (cryptographic) means, information systems and telecommunication systems protected using encryption (cryptographic) means (except if the maintenance of encryption (cryptographic) means, information systems and telecommunication systems protected using encryption (cryptographic) means is carried out for own needs legal entity or individual entrepreneur);


    12. Installation, installation (installation), adjustment of encryption (cryptographic) means, with the exception of encryption (cryptographic) means of protecting fiscal data, designed for use as part of cash register equipment certified by the Federal Security Service of the Russian Federation.

    13. Installation, installation (installation), adjustment of information systems protected using encryption (cryptographic) means.

    14. Installation, installation (installation), adjustment of telecommunication systems protected using encryption (cryptographic) means.

    15. Mounting, installation (installation), adjustment of the means of production of key documents.

    20. Maintenance of encryption (cryptographic) tools provided for by the technical and operational documentation for these tools ( except for the case if the specified work is carried out to ensure own needs legal entity or individual entrepreneur).

    28. Production and distribution of key documents and (or) initial key information for the development of key documents using hardware, software and firmware, systems and complexes for the production and distribution of key documents for encryption (cryptographic) means.”

    But the Instruction contains more stringent requirements.

    FAPSI Instruction No. 152: 4. Security of storage, processing and transmission through communication channels using CIPF of confidential information, the owners of which do not have FAPSI licenses, FAPSI licensees organize and provide ... on the basis of contracts for the provision of services for the cryptographic protection of confidential information.

    6. To develop and implement measures to organize and ensure the security of storage, processing and transmission of confidential information using CIPF, the FAPSI licensee creates one or more cryptographic protection authorities ...”

    Key takeaway next: an organization without a license from the FSB cannot independently organize work on the correct operation of the cryptographic information protection system. To do this, the organization must contact the licensee, conclude a service agreement with him. The FSB licensee has a OKZI in its structure, which organizes security work in the customer organization and controls their implementation (and sometimes performs it himself).

    PS : I also had a lot of questions regarding the application of individual points of the Instruction, the most interesting ones I asked the regulator and in the next article I will share the most interesting information ...

    It is also interesting to see what difficulties you, colleagues, had, or vice versa, the positive experience of using the Instruction.