- Home
- Questions and Answers
- Information Security
Information Security
Detailed expert answers on information security: VPN and NGFW configuration, DLP and SIEM implementation, cryptographic information protection tools, electronic signature and encryption, PKI infrastructure. Data protection solutions.
Information Security
314 questionsWhat is a VPN in simple words?
VPN (Virtual Private Network) is a technology that creates an encrypted tunnel between your device and the Internet. All traffic passes through this tunnel, protecting data from interception. It is like a secret corridor through which your data travels safely. VPN is used to protect personal data and access corporate resources. For government systems, a VPN must use certified CIPF. The installation service will help you deploy a VPN in your infrastructure.
How to choose a VPN for business?
For business, a VPN is chosen based on the network scale, the number of employees and regulatory requirements. Key criteria: support for certified CIPF, compliance with 187-FZ and 152-FZ, and the ability to integrate with existing infrastructure. It is recommended to use server VPN solutions (Site-to-Site) to unite branches and Remote Access for remote employees. The "Fintech" company offers installation and configuration of corporate VPN solutions with a guaranteed level of security.
How to set up a VPN for remote access for employees?
To organize remote access for employees to the corporate network via VPN, you need to: 1) deploy a VPN server at the network boundary, 2) configure PKI certificates for client authentication, 3) install VPN clients on work devices. For government systems, the use of certified CIPF is mandatory. The "Fintech" company offers installation and configuration of corporate VPN solutions.
What is the catch of a free VPN?
The catch of free VPN services is that they make money by selling user data to advertisers, limit speed and traffic, and may contain malware. Free VPNs do not guarantee confidentiality and do not use certified CIPF. For government and corporate systems, the use of free VPNs is unacceptable. The "Fintech" company offers reliable corporate VPN solutions with a security guarantee.
What happens if the VPN is on all the time?
An always-on VPN provides continuous protection of all data, but may slow down the Internet speed due to encryption and routing of traffic through remote servers. Problems with access to some local services are also possible. For corporate systems, it is recommended to use a VPN with certified CIPF and split tunneling settings to balance security and performance. The installation service will help you configure the optimal VPN configuration.
How does a VPN protect data on public Wi-Fi networks?
When connecting to public Wi-Fi networks, traffic can be intercepted by attackers. VPN encrypts all traffic, making it unreadable to interceptors. This is especially important for employees working remotely and when using mobile devices to access corporate resources. For organizations whose employees often work outside the office, a VPN is a mandatory element of protection. The installation service will help you configure a corporate VPN solution.
Is there a built-in VPN in my phone?
Android and iOS have built-in VPN clients, but they only support limited protocols (PPTP, L2TP/IPSec, IKEv2). For full functionality and the use of certified CIPF, it is recommended to install specialized VPN applications. For corporate systems, we offer the configuration of VPN clients using PKI certificates. The installation service will help you deploy a corporate VPN solution.
What is a firewall in simple words?
A firewall is a virtual checkpoint that filters incoming and outgoing traffic, letting only safe data through and blocking threats. It works like a security guard: checks data packets, verifies them against the rules and decides whether to allow or block. Integration with SIEM and SOC provides comprehensive protection. The installation service will help you deploy a firewall in your network.
What is a firewall?
A firewall is a computer network security system that restricts the passage of incoming, outgoing and intra-network traffic. It is a software or hardware-software tool that decides whether to allow or block a data packet. Modern firewalls integrate with SIEM and NGFW for deep traffic analysis. The installation service will help you configure a firewall.
Where is a firewall installed?
A firewall is installed at the boundary between the organization's internal network and external networks (usually the Internet). It can also be placed inside the corporate network in front of segments with confidential data. Firewalls can be hardware (installed in server racks) and software (on servers and workstations). The installation service will help you correctly place and configure a firewall in your infrastructure.
How does a firewall differ from a router?
A router forwards data between networks, directing packets in the right direction, but does not analyze their contents. A firewall filters traffic and prevents attacks, making decisions based on security rules. Modern firewalls integrate with NGFW and SIEM. The installation service will help you choose and configure the right solution.
What is another name for a firewall?
A firewall is also called an edge firewall, security firewall or network firewall. All these terms denote the same protection tool — a network traffic filtering system. Modern solutions include NGFW (next-generation firewalls) with extended functions. The installation service will help you deploy a firewall in your organization.
What are some examples of firewalls?
Examples of firewalls: hardware — Cisco ASA, FortiGate, Check Point; software — UserGate, pfSense, OPNSense; built-in — Windows Firewall, iptables in Linux. Modern NGFW solutions combine filtering with IPS, antivirus and application control. The installation service will help you choose and configure the optimal solution for your network.
What does a firewall protect against?
A firewall protects a computer network from unauthorized access, port scanning, network attacks and malware. It controls network traffic, blocks suspicious connections and prevents data leaks. Integration with SIEM and SOC provides comprehensive security monitoring. The installation service will help you properly configure protection. To study related concepts, we also recommend reading about Captcha, DDoS attack, Unauthorized access and Sandbox.
What is DLP in simple words?
DLP (Data Loss Prevention) is a system that prevents employees from accidentally or deliberately taking secret data outside the company. It controls correspondence in messengers and email, blocks sending files to flash drives and cloud storage, and also records suspicious actions. DLP helps comply with the requirements of 152-FZ on personal data. Read more about protection approaches in the technologies section.
What is a DLP system?
A DLP system (Data Loss Prevention) is software for protecting corporate information from leaks and unauthorized access. It controls all communication channels: email, messengers, social networks, cloud storage, USB flash drives and document printing. When confidential data is detected, the system blocks the transfer and notifies the security service. DLP systems integrate with SIEM and CIPF. Learn more about data protection in the technologies section.
What is the difference between DLP and SIEM?
DLP and SIEM are different classes of security systems. DLP prevents internal data leaks by controlling the transfer of confidential information. SIEM collects and analyzes security events from the entire IT infrastructure to detect cyber attacks. In a modern infrastructure, DLP and SIEM work in tandem: DLP blocks leaks, and SIEM records violation attempts. Both systems integrate with SOC for prompt response. Read more about protection in the technologies section.
What are some examples of DLP systems?
Popular on the Russian market are InfoWatch Traffic Monitor, Solar Dozor, SearchInform KIB, StaffCop Enterprise and Garda DLP. Among international solutions are Microsoft Purview, Forcepoint DLP and Symantec DLP. When choosing DLP, it is important to consider integration with SIEM and compliance with 152-FZ requirements. The design service will help you choose the optimal solution for your organization.
What types of DLP systems are there?
DLP systems are classified by architecture: network (control traffic at the network boundary), agent-based (installed on workstations) and hybrid. By analysis method they are divided into content-based (check file contents), contextual (analyze transfer conditions) and behavioral (track anomalies in user actions). Full-featured platforms integrate with SIEM and CIPF. Read more about the choice in the technologies section.
Is DLP software or hardware?
DLP is primarily software. It can be implemented as agent software on end devices (laptops, workstations) and as network sensors to intercept traffic at gateways. In some cases, hardware accelerators are used to process large amounts of data, but the basis of DLP is a software platform. To protect data, DLP integrates with CIPF and access control systems. Learn more in the technologies section.
What is the DLP process?
The DLP (Data Loss Prevention) process includes three stages: data collection (interception of traffic and user activity), analysis (content, contextual or behavioral) and response (blocking transfer, warning or recording an incident). Modern DLP systems use machine learning to identify anomalies. For comprehensive protection, DLP integrates with SIEM and SOC. Read more about implementation in the our services section.
What is SIEM in simple words?
SIEM is a system that collects all security events from the entire company's IT infrastructure (logs of servers, firewalls, antiviruses), analyzes them and alerts about suspicious activity. It is like a security control center that sees what is happening across the network. SIEM helps detect attacks that are individually unnoticeable. For comprehensive protection, SIEM integrates with SOC and DLP systems. Learn more about monitoring approaches in the technologies section.
What is the difference between DLP and SIEM?
DLP and SIEM are different classes of security systems. DLP prevents internal data leaks by controlling the transfer of confidential information (email, messengers, USB). SIEM collects and analyzes security events from the entire IT infrastructure to detect cyber attacks. DLP blocks data transfer, SIEM alerts analysts about threats. In a modern infrastructure they work in tandem: DLP sends data to SIEM for comprehensive analysis. Read more about protection in the technologies section.
What are SIEM and SOC?
SIEM (Security Information and Event Management) is a software platform for collecting and analyzing security events. SOC (Security Operations Center) is a monitoring and incident response center where analysts work using SIEM as their main tool. SIEM is a technology, SOC is a team and processes. For effective SOC operation, integration with SIEM and other systems is necessary. The design service will help you organize a SOC in your company.
Are SIEM systems free?
There are no fully free ready-made SIEM systems. However, there are powerful open source solutions: Wazuh, ELK Stack, Security Onion. They require self-configuration and do not have ready-made correlation rules. There are conditional free versions (for example, Splunk Free with a data volume limit). For government information systems and CII facilities, it is recommended to use commercial SIEM solutions. The design service will help you choose the optimal solution.
What is the essence of SIEM?
The essence of SIEM is the centralized collection, normalization and correlation of security events from all devices and systems of the company. SIEM aggregates logs, brings them to a unified format, analyzes relationships and identifies anomalies. When suspicious activity is detected, the system alerts SOC analysts. SIEM also provides long-term data storage for investigations and compliance with regulatory requirements. Read more about protection in the technologies section.
What are some examples of SIEM programs?
On the Russian market: MaxPatrol SIEM (Positive Technologies), Kaspersky Unified Monitoring and Analysis Platform, RuSIEM, Ankey SIEM, KOMRAD Enterprise SIEM. International solutions: Splunk Enterprise Security, IBM QRadar, ArcSight. When choosing SIEM, it is important to consider integration with SOC and compliance with 187-FZ requirements for CII facilities. The design service will help you choose the optimal solution.
Are SIEM and Splunk the same thing?
No. SIEM is a class of systems for managing security information and events. Splunk is a specific product that can be used as a SIEM platform (Splunk Enterprise Security). Splunk is one implementation of the SIEM approach, along with IBM QRadar, ArcSight and Russian solutions. For CII facilities in Russia, it is recommended to use domestic SIEM solutions. Read more about the choice in the technologies section.
What is a SOC in simple words?
SOC (Security Operations Center) is a security monitoring center that monitors the company's IT infrastructure around the clock, detects hacker attacks and protects data. It is like a security service, but in the digital world. A SOC uses SIEM systems to collect events and alerts analysts about threats. A SOC can be organized as an internal department or as an outsourced service. Learn more about protection in the technologies section.
What does SOC mean?
The SOC abbreviation has several meanings. In the field of information security and cybersecurity — Security Operations Center (a center for monitoring and responding to cyber incidents). In electronics — System on a Chip. In energy — State of Charge (battery charge level). In the context of our activities, a SOC is an information security monitoring center that uses SIEM and other tools. Read more about SOC in the technologies section.
What is SOC in a PC?
In the context of PCs and electronics, SOC (System-on-a-Chip) is a single microchip that combines a central processor, graphics processor, modem and controllers. Examples: Apple M-series chips, Snapdragon, MediaTek. In information security, SOC means Security Operations Center — a security monitoring center. In the context of our activities, a SOC is an information security center that uses SIEM to protect IT infrastructure. Learn more in the technologies section.
SOC and SIEM — what are they?
SOC (Security Operations Center) is a center for monitoring and responding to incidents where security analysts work. SIEM (Security Information and Event Management) is a software platform that collects and analyzes security events. SIEM is the main tool used by a SOC for monitoring. A SOC includes people, processes and technologies, and SIEM is one of the key technologies in a SOC. The technical support service helps organize a SOC.
What is a SOC in Russia?
In Russia, a SOC is a department responsible for 24/7 monitoring and protection of an organization's IT infrastructure. The main task of a SOC is proactive detection, analysis and response to cyber threats. For CII facilities and government information systems, the creation of a SOC is recommended by regulators. More than 90% of large organizations in Russia plan to create their own SOCs or use MSSP services. Read more about approaches in the technologies section.
What are SOC analysts of levels L1, L2, L3?
Analysts of three levels work in a SOC. L1 (first level) are primary triage operators who process alerts from SIEM and classify incidents. L2 (second level) are analysts for in-depth investigation and response. L3 (third level) are threat hunting, forensic analysis and correlation rule development experts. To train analysts, we offer training services.
How much does a SOC analyst earn?
The salary of a SOC analyst depends on the skill level and region. In Moscow and St. Petersburg, an L1 analyst can earn from 80,000 to 150,000 rubles, L2 — from 150,000 to 250,000 rubles, L3 — from 250,000 rubles and above. The demand for SOC analysts in Russia is constantly growing, especially in connection with the requirements of 187-FZ for CII facilities. The training service helps prepare specialists for working in a SOC.
What does PKI stand for?
PKI stands for Public Key Infrastructure. It is a set of technologies, processes and policies for managing digital certificates and cryptographic keys. PKI ensures secure data exchange and authentication in networks. In Russia, PKI must use certified CIPF. Read more about the components in our glossary.
What is PKI?
PKI (Public Key Infrastructure) is a set of policies, technologies and hardware tools for creating, managing, storing and revoking digital certificates. PKI is based on asymmetric encryption: the public key is available to everyone, the private key is only to the owner. A digital certificate connects the public key to a specific user. The design service helps implement PKI in your organization. Learn more about data protection in the technologies section.
What is a PKI certificate?
A PKI certificate (digital public key certificate) is a digital document that connects a public cryptographic key to a specific owner. It acts as a digital identity card. The certificate is signed by a certification authority (CA) that guarantees authenticity. In Russia, certificates must comply with CIPF requirements. Read more about security in the technologies section.
What is the difference between PKI and PSK?
PSK (Pre-Shared Key) uses a single common secret to authenticate all devices in a group. PKI assigns each device a unique digital identifier (a certificate from a trusted certification authority). PKI is more secure and scalable, but more complex to implement. In Russia, PKI must use certified CIPF. The design service will help choose the optimal approach.
Is PKI the same as SSL?
No, these are different concepts. SSL (Secure Sockets Layer) is an encryption protocol that uses a certificate to protect the connection between a client and a server. PKI is an infrastructure for managing certificates and keys that underlies SSL/TLS. PKI is broader in functionality: it includes certificate management, signatures, encryption and authentication. In Russia, PKI must use CIPF. Read more about security in the technologies section.
What are the 4 main principles of PKI?
The four main principles of PKI: secure storage of private keys (tokens); verification of the user's identity (registration authority); issuance and signing of certificates (certification authority); storage and revocation of certificates (certificate management system). These components ensure trust in the digital environment. In Russia, all PKI components must comply with CIPF requirements. The design service will help implement a full PKI infrastructure.
Why is a PKI infrastructure needed?
PKI provides the necessary tools for data encryption, authentication and protection against unauthorized access. It is used for SSL/TLS, electronic signatures, secure mail and VPN. In Russia, PKI must use certified CIPF and comply with the requirements of the FSB of Russia. The design service helps design and implement a reliable PKI infrastructure.
What is an NGFW (next-generation firewall)?
NGFW (Next-Generation Firewall) is a next-generation firewall that combines the functions of a traditional firewall with deep packet inspection (DPI), an intrusion prevention system (IPS) and application control. Unlike a classic firewall, it analyzes traffic at the application layer and can identify applications and block threats regardless of ports and protocols.
How does an NGFW (next-generation firewall) work?
An NGFW inspects traffic at all levels of the OSI model. In addition to traditional packet filtering, it performs deep packet inspection (DPI), identifies applications by signatures and behavioral analysis, detects and blocks attacks in real time with an intrusion prevention system (IPS), filters URLs and scans traffic for malware.
Where is an NGFW (next-generation firewall) applied?
NGFW is used to protect the network perimeter, segment internal networks and protect data centers. It is deployed at the boundary between the corporate network and the Internet, as well as in front of segments with confidential data. In government information systems, the use of NGFW must comply with the requirements of the FSTEC of Russia.
What advantages does an NGFW (next-generation firewall) provide?
NGFW provides a higher level of protection compared to classic firewalls: deep packet inspection (DPI), an intrusion prevention system (IPS), application control regardless of ports and protocols, antivirus traffic inspection, URL and web content filtering, and DDoS protection. This allows detecting and blocking modern threats that traditional firewalls miss.
What are the NGFW (next-generation firewall) requirements in Russia?
The requirements for NGFW in Russia depend on the type of facility being protected. In government information systems, the use of NGFW must comply with the requirements of the FSTEC of Russia. For critical information infrastructure (CII) facilities, the requirements of 187-FZ apply. It is recommended to use certified solutions and integrate NGFW with SIEM and SOC.
How is an NGFW (next-generation firewall) different from analogues?
NGFW differs from a traditional firewall by its ability to inspect traffic at the application layer. A classic firewall filters packets by addresses and ports, while NGFW performs deep packet inspection, identifies applications by signatures and behavior, and combines IPS, antivirus and URL filtering in one device. This makes it more effective against modern threats.
How to implement an NGFW (next-generation firewall) in an organization?
To implement an NGFW in an organization, you need to: 1) choose a solution that meets the security requirements, 2) develop a security policy and filtering rules, 3) deploy the NGFW at the network boundary and configure traffic segmentation, 4) integrate it with SIEM and SOC for monitoring. The installation service includes NGFW deployment and configuration.
What relates to personal data under 152-FZ?
According to 152-FZ, personal data (PD) is any information that relates directly or indirectly to a specific individual. This includes identification data (full name, date of birth, place of birth), contact data (phone, address, email), passport data, TIN, SNILS, as well as digital traces (IP address, geolocation, cookies) and even photographs or voice if a person can be identified by them. A special category is formed by biometric data (fingerprints, face, voice), which requires enhanced protection and the mandatory use of CIPF tools during processing.
What is 152-FZ in simple words?
152-FZ is a law that protects your personal information. It obliges any organization (bank, online store, government body) to ask for your consent to collect data, store it confidentially and protect it from leaks, and also delete it on first request. Serious fines are provided for violating the law, up to turnover fines of 3% of annual revenue for companies.
What is the penalty for violating 152-FZ in 2025-2026?
Serious liability is provided for violating 152-FZ. This includes administrative fines (up to 700 thousand rubles for processing without consent), turnover fines for data leaks (up to 3% of annual revenue, but not less than 1 million rubles) and even criminal liability under Article 137 of the Criminal Code of the Russian Federation (imprisonment for up to 5 years). Website blocking and disqualification of officials are also possible. To avoid these risks, it is necessary to use certified protection tools such as CIPF and undergo regular security audits.
When is consent for personal data processing not required?
The consent of the subject is not required when data processing is necessary for the execution of a contract (for example, placing an order in a store), compliance with legal requirements (submitting reports to the tax authority), protecting the life and health of a person, as well as for the administration of justice. The full list of exceptions is specified in Article 6 of 152-FZ. In these cases too, the operator is obliged to ensure data confidentiality and use the necessary protection measures, including CIPF tools when transferring data.
What amendments to 152-FZ came into force in 2025?
Significant amendments to 152-FZ came into force on July 1, 2025: a ban was introduced on the use of foreign services (databases, cloud storage) for the primary collection and storage of data of Russians. Data collection through foreign web analytics is also considered a violation. Now businesses are obliged to use exclusively Russian infrastructure included in the Register of Domestic Software. Turnover fines for data leaks have also been increased — up to 3% of annual revenue.
Who is a personal data operator according to 152-FZ?
A personal data operator is any legal or natural person who organizes and carries out data processing, determining its purposes and composition. These can be government bodies, banks, online stores, employers, medical institutions and any other structures. The operator is charged with the obligation to ensure the security of systems, for which firewalls, SIEM systems and DLP systems are used. You can check whether you are an operator and learn about the procedure on the Roskomnadzor website.
How not to violate 152-FZ when working with personal data?
To comply with 152-FZ, it is necessary to complete several key steps: submit a notification to Roskomnadzor, obtain the consent of subjects for processing (in written or electronic form), publish a Privacy Policy on the website, and ensure data storage on the territory of the Russian Federation using Russian services from the Register of Domestic Software. It is also critically important to implement technical protection tools: DLP systems to prevent leaks, CIPF tools for encryption and SIEM systems for incident monitoring. Regular audit and design of secure systems will help avoid fines.
What is CII and who does the 187-FZ law affect?
CII (critical information infrastructure) is information systems, telecommunication networks and automated control systems used in vital spheres of the state. Law 187-FZ obliges government bodies and companies from critical sectors (banks, transport, communications, energy, healthcare) to protect their systems from cyber attacks and report computer incidents. To fulfill the requirements of the law, it is necessary to use certified CIPF tools and other protection measures.
Source: term "187-FZ "On the Security of Critical Information Infrastructure""
What is 187-FZ in simple words?
187-FZ is a law that obliges vital organizations to protect their computers, networks and databases from cyber attacks. Its main goal is to prevent hackers from turning off the electricity, stopping trains, hacking hospitals or disrupting the work of banks. The law requires companies to categorize systems, implement protection and report attacks to the FSTEC and the FSB. Firewalls and intrusion detection systems are used to protect CII facilities.
Source: term "187-FZ "On the Security of Critical Information Infrastructure""
What must a CII entity do according to 187-FZ?
A CII entity is obliged to categorize facilities and send the results to the FSTEC, create a security system using certified tools, implement technical protection measures (access control, encryption, antivirus protection), and also report computer attacks and interact with GosSOPKA. It is recommended to use SIEM systems and DLP solutions to ensure the security of CII facilities.
Source: term "187-FZ "On the Security of Critical Information Infrastructure""
Who falls under the scope of 187-FZ?
Government bodies and Russian legal entities that own information systems in critically important sectors fall under the scope of the CII law: healthcare, transport, communications, energy, banking, defense, nuclear, mining, metallurgical and chemical industries. Individual entrepreneurs are excluded from this list. Biometric systems and access control systems (ACS) are used to identify and authenticate users at CII facilities.
Source: term "187-FZ "On the Security of Critical Information Infrastructure""
What categories of CII facility significance exist?
187-FZ establishes three categories of CII facility significance. The first category — facilities whose security breach could lead to an emergency of federal scale. The second category — facilities whose accident creates a threat on a regional scale. The third category — facilities whose incidents could cause damage on the scale of a municipality. Particularly significant facilities for defense and security are also distinguished. Various cryptographic protection tools are used to protect facilities of different categories.
Source: term "187-FZ "On the Security of Critical Information Infrastructure""
What is a CII facility according to 187-FZ?
A CII facility is information systems, information and telecommunication networks and automated control systems of critical information infrastructure entities. These include process control systems (SCADA), databases, data transmission networks and other equipment that ensures the functioning of critical sectors. Certified tools, including firewalls and access control systems, are needed to protect such facilities.
Source: term "187-FZ "On the Security of Critical Information Infrastructure""
What amendments to 187-FZ come into force on September 1, 2025?
Amendments to 187-FZ tightening CII security requirements come into force on September 1, 2025. Mandatory certification of protection tools for all categories of facilities is introduced, requirements for incident monitoring and interaction with GosSOPKA are strengthened. The list of facilities subject to mandatory certification is also expanded. A ban on the use of foreign software at CII facilities is introduced (except for cases where there are no domestic analogues). To prepare for the changes, it is recommended to undergo certification of CII facilities. Read more about government regulation of the industry in the article Government regulation in IT.
Source: term "187-FZ "On the Security of Critical Information Infrastructure""
What is SKZI in simple words?
SKZI are programs or devices that encrypt data and create electronic signatures. They turn ordinary data into unreadable code, protecting it from theft and forgery. SKZI are used in electronic document management, bank transfers and secure communications. The SINTEZM product is a certified SKZI for electronic signatures and encryption. The research service will help you choose the optimal SKZI.
Source: term "SKZI (cryptographic information protection tool)"
What is SKZI?
SKZI (cryptographic information protection tools) are hardware, software and software-hardware complexes for data encryption, protection against unauthorized access and creating electronic signatures. In Russia, all SKZI are subject to FSB certification. The SINTEZM product is a certified SKZI. The research service will help you select the optimal solution.
Source: term "SKZI (cryptographic information protection tool)"
What are some examples of SKZI?
Examples of software SKZI: CryptoPro CSP, ViPNet CSP, Kontur.Kripto, and the SINTEZM product. Hardware SKZI: Rutoken, JaCarta. Software-hardware: ViPNet Coordinator, CryptoPro HSM. In Russia, only SKZI certified by the FSB are allowed for use. The research service will help you choose the optimal solution for your tasks.
Source: term "SKZI (cryptographic information protection tool)"
What is SKZI in a tachograph?
SKZI in a tachograph is a cryptographic information protection tool, a special cryptographic chip that encrypts data about the speed, mileage and route of a vehicle. The SKZI unit protects against data forgery, supports the operation of driver cards with an electronic signature and records coordinates via GLONASS/GPS. The service life of the SKZI unit is 3 years. The SINTEZM product is an example of software SKZI.
Source: term "SKZI (cryptographic information protection tool)"
How to determine the SKZI class?
The SKZI class is determined according to FSB Order No. 378, based on the type of threats, the level of significance and the scale of processed data. Classes: KS1 (protection against external threats), KS2 (protection against internal threats), KS3 (high protection), KV (for government systems), KA (maximum class). The class is indicated in the documentation and the FSB certificate. The SINTEZM product has an FSB certificate. The research service will help determine the required class.
Source: term "SKZI (cryptographic information protection tool)"
Who can work with SKZI?
Only authorized employees who have completed training and gained access to encryption keys and electronic signatures are allowed to work with SKZI. They must comply with operating rules, keep keys secret and promptly detect hacking attempts. The SINTEZM product is a certified SKZI for corporate use. The training service will help prepare employees.
Source: term "SKZI (cryptographic information protection tool)"
What is not allowed for a SKZI user?
A SKZI user is prohibited from: transferring keys to third parties, disclosing passwords from media, leaving media unattended, creating backup copies of keys without approval, making changes to SKZI software, and using work keys on personal computers. Violation of the rules entails liability. The SINTEZM product is a certified SKZI with clear operating rules.
Source: term "SKZI (cryptographic information protection tool)"
How can I create an electronic signature?
The fastest way is to obtain a free signature through the Gosklyuch application (a verified Gosuslugi account is required). For business (LLC/IE), the most reliable method is to contact the Certification Authority of the Federal Tax Service of Russia or its trusted representatives. You can also obtain a QES at commercial accredited certification authorities such as Kontur or Tensor. Working with a signature will require a cryptographic information protection tool, for example CryptoPro CSP.
Where can I find my electronic signature?
Information about electronic signature certificates issued in your name can be found in the personal account of the Gosuslugi portal in the "Profile" — "Electronic signature" section. The physical signature file (private key) is stored on a protected medium (token) or in the register of the certification authority. If you cannot find your signature, contact the CA where it was issued.
Can I create an electronic signature through Gosuslugi?
Yes, through Gosuslugi it is easiest to obtain a non-qualified (ENES) or qualified electronic signature (QES) using the official Gosklyuch application. The process is free and remote. For a QES, you will need to confirm your identity (through biometrics with a new-format foreign passport or in person at an MFC). This is a convenient way to obtain a legally significant signature for personal needs and business.
What does an electronic signature look like?
An electronic signature does not have a single visual appearance. In PDF and Word, it can look like a rectangular stamp with information about the owner, date and time of signing. It can also be represented as a separate file with the extension .sig, .sgn or .p7s. The signature itself is not a picture, but a set of cryptographic data confirming authorship. Its authenticity is verified using public key infrastructure (PKI).
Who issues an electronic signature?
Electronic signatures are issued by accredited certification authorities (CAs). For heads of organizations and individual entrepreneurs, a signature is issued free of charge at the CA of the Federal Tax Service of Russia. For individuals and employees of organizations — at commercial accredited CAs (for example, Tensor, SKB Kontur). The full list of accredited centers is published by the Ministry of Digital Development on the Gosuslugi portal. When obtaining a signature for employees, a machine-readable power of attorney from the head will be required.
What is a machine-readable power of attorney (MCD)?
A machine-readable power of attorney (MCD) is an electronic document in XML format that confirms the authority of an employee to sign electronic documents on behalf of a legal entity. Since September 1, 2024, the MCD has become mandatory when employees use a QES. The MCD is signed with the QES of the head and is stored in the Unified MCD repository of the Federal Tax Service of Russia. This greatly simplifies the verification of authority in electronic document management.
How long is an electronic signature valid?
The validity period of a qualified electronic signature (QES) certificate is 15 months (1 year + 3 months) for most types of certificates. For individuals, the period can be up to 3 years. After the certificate expires, the signature becomes invalid — documents signed with an expired signature lose legal force. You must promptly reissue the certificate at the certification authority. We also recommend familiarizing yourself with the concept of Tokenization.
What is data encryption?
Data encryption is the process of transforming information into unreadable code using mathematical algorithms and a key. Only users with the appropriate access key can read the data. This is the basis of security on the Internet, in e-commerce and corporate systems. For government organizations, the use of certified cryptographic information protection tools is mandatory.
What methods of data encryption are there?
There are three main methods: symmetric encryption (one key for encryption and decryption, fast, for example AES, GOST "Magma"); asymmetric encryption (a pair of keys: public and private, used for signing and key exchange, for example RSA, GOST R 34.10); hybrid encryption (a combination of symmetric and asymmetric encryption to protect session keys). In Russia, for government systems, the use of GOST algorithms implemented in certified CIPF tools is mandatory.
Why encrypt data?
Data is encrypted to ensure confidentiality during storage and transmission. This protects information from theft, unauthorized access and leaks. Encryption is mandatory when transmitting payment data, personal information and trade secrets. For Russian companies, encrypting personal data is a requirement of 152-FZ.
What are the Russian encryption standards?
Russia has national encryption standards approved by the FSB: GOST 28147-89 ("Magma") — a classic block cipher with a 256-bit key; GOST R 34.12-2015 ("Kuznechik") — a modern block cipher; GOST R 34.10-2012 — an electronic signature algorithm based on elliptic curves; GOST R 34.11-2012 ("Stribog") — a hashing algorithm. These algorithms are mandatory for government information systems and CII facilities.
Should I encrypt data on my phone?
Encrypting data on your phone is strongly recommended, as it protects your personal photos, videos, correspondence and banking data from theft in case of device loss or hacking. Modern smartphones have built-in encryption (for example, iOS and Android encrypt data by default). This is a basic protection measure that will not allow attackers to gain access to your information.
What are the two types of encryption?
Cryptography distinguishes two main types of encryption: symmetric and asymmetric. Symmetric uses one key for encryption and decryption — fast and efficient for large amounts of data. Asymmetric uses a pair of keys (public and private) — slower but safer for exchanging data over unsecured channels. They are often combined in hybrid schemes, where asymmetric encryption protects the key for the symmetric algorithm.
What is hashing and how is it different from encryption?
Hashing is a one-way mathematical transformation of data into a string of fixed length (a hash). Unlike encryption, hashing is irreversible — it is impossible to restore the original data from a hash. Hashing is used to verify data integrity, store passwords and create digital fingerprints of files. Encryption, on the contrary, is reversible and is used to ensure data confidentiality. In Russia, the GOST R 34.11-2012 ("Stribog") standard is used for hashing.
What is the difference between authentication and identification?
Identification answers the question "Who are you?" — you report your login or number to the system. Authentication proves "You are really you" — you enter a password, an SMS code or scan a fingerprint. Identification is presenting yourself to the system, authentication is confirming authenticity. The Biomark and Biovizum products are used for biometric authentication. The design service will help implement an authentication system.
What is identification in simple words?
Identification is the process of recognizing and assigning a unique name (identifier) to a person or object to distinguish them from all others. In simple words, this is the answer to the question: "Who are you?" In IT, this is entering a login when accessing an account; in everyday life, it is presenting a passport. Authentication follows identification — proof that you are really who you claim to be. The Biomark and Biovizum products provide biometric identification.
What is authentication in simple words?
Authentication is the verification of the authenticity of a user. The system makes sure that you are really you and not someone else. This is similar to a guard checking a passport at the entrance: you state your name (login), and the document proves that you are the owner of this name. The system checks: what you know (password), what you have (SMS code) or who you are (biometrics). The Biomark and Biovizum products provide biometric authentication.
What are the 3 authentication factors?
The three classic authentication factors: knowledge (something you know — password, PIN code); possession (something you have — a phone for SMS codes, a hardware token); attribute (something you are — biometrics: fingerprint, face, voice). Using two or three factors is called multi-factor authentication (MFA). The Biomark and Biovizum products are used for biometric authentication. The design service will help implement MFA.
What are authentication and identification systems?
Authentication and identification systems are complexes of tools for recognizing users and verifying their authenticity. An example is ESIA (Unified Identification and Authentication System) on Gosuslugi. It allows citizens to use one login and password to access government services. In corporate systems, the Biomark and Biovizum products are used. The design service will help implement an identification and authentication system.
Is identification possible without authentication?
Identification without authentication is possible, but it does not provide security. The system will know who you are (by login), but it will not be able to confirm that you are really that person. This is like stating your name but not showing a passport — the system can be fooled. Authentication is necessary for full protection. The Biomark and Biovizum products provide reliable biometric authentication.
What are some examples of identification?
Examples of identification: entering a login when visiting a website, scanning a fingerprint to unlock a phone, presenting a passport at a bank. In psychology, identification is the process of identifying oneself with another person or group. In IT, identification is the first step of access, followed by authentication and authorization. The Biomark and Biovizum products provide biometric identification in corporate systems.
What is verification in simple words?
Verification is the checking of authenticity or confirmation of data. In simple words, it is a process that proves that you are you, and that the information provided or documents are genuine and correct. In banks, when opening an account you are asked to upload a photo of your passport — this is identity verification. On social networks, the blue checkmark is a sign of account verification. For corporate systems, verification is integrated with access control systems and biometric systems. Learn more about approaches in the technologies section.
Why are you asked to undergo verification?
Verification is required to confirm the authenticity of an identity or data. This is necessary to protect the account from hacking, prevent fraud and fulfill legal requirements (KYC). Banks, exchanges and payment systems are required to check clients to prevent money laundering. For corporate systems, verification is integrated with biometrics and access control systems. The design service will help implement verification in your organization.
What is verification?
Verification is a systematic process of checking and confirming that a product, system or process complies with established requirements and specifications. In information security, verification is used to confirm the authenticity of users, documents and data. Biometric systems and CIPF tools are used for highly reliable verification. The Biomark product provides comprehensive solutions for biometric verification. Read more in the technologies section.
What does it mean to complete verification?
Completing verification means confirming the validity of your data or identity before a service, payment system or organization. This can be uploading a photo of your passport, confirming a phone number by SMS or a biometric check. In corporate systems, verification is used for access to resources and integration with access control systems. The Biomark and Biovizum products provide biometric verification. Learn more in the technologies section.
What word can replace verification?
Synonyms for the word "verification": check, confirmation, attestation, comparison. Depending on the context, the words "authentication", "identification" or "authenticity confirmation" can be used. In technical documentation, the term "conformity check" is often used. The Biomark and Biovizum products are used for biometric verification. Read more about approaches in the technologies section.
What is phone verification?
Phone verification is confirming that the specified mobile phone number really belongs to you. Usually the system sends a temporary code to the number that you need to enter on the website or in the application. This protects against fraudsters and confirms your identity during registration. In corporate systems, phone verification can be integrated with access control systems and biometric systems. The design service will help implement comprehensive verification.
Why is verification needed?
Verification is needed to confirm the authenticity of data and protect accounts from fraudsters. It ensures the security of financial transactions, confirms the identity of the user and helps services comply with laws (for example, against money laundering). In corporate systems, verification is integrated with biometrics and access control systems. The Biomark and Biovizum products provide biometric verification. Learn more in the technologies section.
What is access control?
Access control is a set of rules, methods and technologies that determine who is allowed to enter physical territory or use information resources. It is divided into physical (ACS) and digital (access to data and systems). It is based on identification, authentication and authorization. The Biomark biometric systems provide reliable identification. The design service will help implement access control.
What types of access control systems are there?
Access control systems are divided by architecture: standalone (for one door), networked (managed from a central server) and wireless. By identification method: electronic (cards, key fobs), biometric (fingerprints, face) and mobile (smartphone). Large organizations use the role-based model (RBAC). The Biomark biometric systems provide a high level of security. The design service will help you choose the optimal system.
What is an access control system?
An access control system (ACS) is a set of software and hardware tools that automatically determines who is allowed entry. It consists of identifiers (cards, biometrics), readers, controllers (the "brain" of the system) and locking devices (locks, turnstiles). Main functions: entry restriction, working time tracking and security. The Biomark and Biovizum products integrate with ACS. The design service will help implement the system.
What is an access controller?
An access controller is the "brain" of an access control system (ACS). It receives a signal from the reader, checks it against the database and decides whether to open the lock or deny access. Controllers are standalone (for one point) and networked (managed centrally). Integration with the Biomark biometric systems increases security. The design service will help you select and configure controllers.
Why is access control important?
Access control is important for limiting access to authorized users only, preventing data leaks and protecting critical resources. It ensures compliance with regulator requirements (for example, 152-FZ and 187-FZ) and is the basis of information security. The Biomark biometric systems provide a high level of identification. The design service will help implement effective access control.
What are the 5 principles of access control?
The five principles of access control: deterrence, detection, denial, delay and defense. These principles provide multi-level security: they deter attackers, detect intrusion attempts, block access, delay violators and protect resources. The Biomark biometric systems implement these principles in practice. The design service will help implement a comprehensive system.
What does an access control system include?
An access control system includes identifiers (cards, key fobs, biometric data), readers (scan the identifier), controllers (make a decision), actuators (locks, turnstiles) and software (rights management, time tracking). Modern ACS integrate with video surveillance and security alarms. The Biomark and Biovizum products provide biometric identification. The design service will help implement a comprehensive ACS.
What is biometrics in simple words?
Biometrics is a technology in which your unique physical features serve as a "password": a fingerprint, face or voice. The system scans your feature, turns it into a digital code and checks it against what is stored in the database. This is convenient and secure, since it is impossible to forget your biometric data or transfer it to another person. The Biomark and Biovizum products implement various biometric identification methods. Read more in the technologies section.
What is biometrics and what is it dangerous about?
Biometrics is identification by unique physical characteristics. The main danger is that, unlike a password, biometric data cannot be replaced if compromised. If a biometric database is hacked, your face or fingerprints will remain compromised forever. Biometric data is protected by 152-FZ. The Biomark and Biovizum products provide a high level of biometric data protection. Learn more about security in the technologies section.
How can I find out if I have biometrics?
You can check the presence of biometrics through the Gosuslugi portal or application. Log in, go to the "Profile" section — "Biometrics" tab. If the data has not been submitted, the message "Biometrics is not registered" will be displayed. You can also check in the "Gosuslugi Biometrics" application or on the website of the Unified Biometric System (UBS). There you can also withdraw consent to the use of biometrics. Read more about biometrics in the technologies section.
How is biometrics collected?
Biometrics (collection of face and voice) can be submitted independently through the "Gosuslugi Biometrics" application or in person at an authorized center (for example, at a bank). At the branch, you are photographed with a special camera and asked to speak a random sequence of digits into a microphone to record your voice. The data is sent to the Unified Biometric System (UBS). Submitting biometrics is a voluntary procedure. Our Biomark and Biovizum products are used for corporate biometric systems.
Why is biometrics collected?
Biometrics is submitted for remote receipt of services without presenting documents: opening bank accounts, obtaining SIM cards, receiving government services. Biometrics also increases security — unique parameters are harder to forge than a password or plastic card. In Russia, biometrics is used in the Unified Biometric System (UBS). The Biomark and Biovizum products provide biometric identification in corporate systems.
Are biometric data good or bad?
Biometric data is a convenient and secure way of identification that is harder to forge than a password. On the other hand, if biometric data leaks, it cannot be replaced. Therefore, it is important that biometric systems comply with 152-FZ requirements and use reliable encryption. Our Biomark and Biovizum products ensure secure storage and processing of biometric data. Learn more in the technologies section.
What does a person's biometrics include?
A person's biometrics includes physiological characteristics: fingerprints, iris pattern, facial features, hand geometry, as well as behavioral characteristics: voice, gait, keyboard typing manner. In Russia, identification by face, voice and fingerprints is most common. The Biomark (fingerprints) and Biovizum (face recognition) products cover the main biometric methods. Read more in the technologies section. For deeper study, we also recommend familiarizing yourself with the biometric template, eSIM and behavioral biometrics.
What is AFIS?
AFIS (automated fingerprint identification system) is a software and hardware complex for entering, storing, searching and comparing fingerprints. The systems are used in law enforcement for solving crimes, in the border service for checking entrants and at enterprises for access control. The Biomark product from the Fintech company is a modern AFIS-class solution. Installation services will help implement the system in your organization.
Source: term "AFIS (automated fingerprint identification system)"
What does AFIS mean?
In the context of information security and biometrics, AFIS stands for automated fingerprint identification system. In other areas, AFIS can mean an automated dispatch service system (for example, ambulance). In our activities, AFIS is a system for biometric identification by fingerprints. The Biomark product implements all AFIS functions. Read more in the technologies section.
Source: term "AFIS (automated fingerprint identification system)"
What is AFIS made of?
In the context of biometrics, AFIS is a complex software and hardware complex. It consists of powerful servers for data storage and processing, high-resolution fingerprint scanners (from 500 dpi) and special software for extracting minutiae and comparing fingerprints. The Biomark product includes all the necessary components for building an AFIS. Installation services will help deploy the system.
Source: term "AFIS (automated fingerprint identification system)"
What is the Papillon AFIS?
The Papillon AFIS is one of the most famous Russian automated fingerprint identification systems, developed by the Papillon company. It is used in the Ministry of Internal Affairs of Russia for maintaining fingerprint records. Our Biomark system offers similar functionality for the corporate and public sectors. Installation services will help implement an AFIS in your organization.
Source: term "AFIS (automated fingerprint identification system)"
What is the Papillon AFIS system?
The Papillon AFIS is a Russian automated fingerprint identification system for registering, processing, comparing and storing biometric data. It identifies not only by fingerprints, but also by face and iris. It is used in the Ministry of Internal Affairs, migration and border services. An alternative solution is the Biomark product from the Fintech company. Installation services will help implement the system.
Source: term "AFIS (automated fingerprint identification system)"
What is AFIS in construction?
In construction, AFIS is an automated dispatch system for building engineering systems. It is responsible for centralized control of heating, ventilation, water supply and lighting. This is a different class of systems, not related to biometrics. In our activities, AFIS means an automated fingerprint identification system — the Biomark product. Read more about biometric solutions in the technologies section.
Source: term "AFIS (automated fingerprint identification system)"
What are the advantages of AFIS?
AFIS processes huge fingerprint databases in seconds, which is practically impossible manually. It provides high identification accuracy, automatic search for matches and reliable data storage. AFIS is used in law enforcement, migration services and access control systems. The Biomark product is a modern AFIS-class solution.
Source: term "AFIS (automated fingerprint identification system)"
How do I know if I am in the Unified Biometric System?
You can find out whether your biometric data is registered in the UBS through the Gosuslugi portal. Log in, go to the "Profile" section — "Biometrics" tab. If the data has not been submitted, it will say "Biometrics is not registered". You can also check on the official UBS website by logging in through Gosuslugi. There you can also withdraw consent and delete data. The Biomark and Biovizum products are used for biometric identification.
Which banks are connected to the Unified Biometric System?
Many large banks are connected to the UBS: Sovcombank, T-Bank, Raiffeisenbank, Bank Finservice and others. The full list of partners is available on the official UBS website. Banks use the UBS for remote client identification when opening accounts and issuing loans. The Biomark and Biovizum products are used for biometric identification in corporate systems. Read more about solutions in the technologies section.
Why does the state need my biometrics?
The state needs biometrics for remote confirmation of citizens' identity when receiving financial and government services. This allows replacing a personal visit to a bank or government office, speeds up service and increases security. Biometric data is protected in accordance with 152-FZ and stored using certified CIPF tools. The Biomark and Biovizum products provide secure biometric identification.
Where is biometrics in Gosuslugi?
You can check the presence of biometrics in your personal account on the Gosuslugi portal. Log in, click on the profile icon, select the "Profile" tab and go to the "Biometrics" section. There the data status, biometrics type (simplified, standard or confirmed) and validity period will be displayed. You can also check the status through the "Gosuslugi Biometrics" application. The Biomark and Biovizum products provide biometric identification.
What does biometrics give in a bank?
Biometrics in a bank allows confirming your identity remotely, without presenting a passport. This speeds up opening accounts, issuing loans and other financial services. Banks use the UBS to verify clients' authenticity and protect against fraudsters. For corporate systems, biometric identification is provided by the Biomark and Biovizum products. The design service will help implement biometric identification in your organization.
Can I pay in Russia using face biometric identification?
Yes, in Russia you can pay using face biometric identification. Russian banks use face authentication to pay for purchases, preventing the use of photos or masks. Face data is stored in the government biometric system. The function can be disabled in the banking application. The Biomark and Biovizum products are used for biometric identification in corporate systems.
Why is a biometric passport dangerous?
A biometric passport contains an electronic chip with the owner's biometric data. The main risks are associated with the possibility of unauthorized data reading in the absence of protection. However, modern passports use encryption and protected protocols. In Russia, biometric data is protected in accordance with 152-FZ. The Biomark and Biovizum products provide secure biometric identification. We also recommend familiarizing yourself with the fingerprinting method.
How can a person be recognized by face?
You can recognize a person by face using computer programs (neural networks) that analyze biometric points: the distance between the eyes, nose shape, face contour. Face recognition systems such as Biovizum convert a face into a digital code and compare it with a database. You can also use reverse photo search through services like PimEyes or Search4Faces. The design service will help implement a face recognition system.
What is recognition by face called?
Recognition by face is called face recognition. This is a method of biometric contactless identification of a person by their face. Face recognition systems are used for access control, video surveillance and verification. The Biovizum product implements high-precision face recognition algorithms. The design service will help you choose the optimal solution.
How can I find a person by face for free?
You can find a person by face for free using neural network services: Search4Faces (VK and OK databases), PimEyes (global internet search) and Search Face mobile applications. For the best result, use a high-quality photo with clear facial features. In corporate systems, face recognition is implemented in the Biovizum product. The design service will help implement a recognition system.
What is face recognition?
Face recognition is a way of identifying or confirming a person's identity by the image of their face. Face recognition systems can be used to identify people in real time or in photos and videos. The technology is based on the analysis of biometric points and comparison with reference templates. The Biovizum product implements high-precision face recognition algorithms. The design service will help implement the system.
Which application recognizes faces?
Face recognition applications are divided into categories: for finding people by photo (PimEyes, Search4Faces), for sorting photos (Tonfotos, Apple Photos) and for security (video surveillance systems with face recognition). In corporate systems, the Biovizum product is used for access control and verification. The design service will help you select and implement a face recognition system.
Can a person be identified only by face?
Yes, modern face recognition systems can identify a person only by the image of their face using neural network algorithms. The systems analyze biometric points and compare with a database. The Biovizum product provides high-precision recognition for access control and verification. The design service will help implement a face recognition system in your organization.
How does face recognition work?
Face recognition works in several stages: detecting a face in an image, analyzing key biometric points (distance between the eyes, nose shape, face contour), converting into a digital code (vector) and comparing with a database. Modern algorithms are based on deep neural networks. The Biovizum product implements these algorithms for security systems. The design service will help implement the system.
What is fingerprinting?
Fingerprinting (dactyloscopy) is a method of identifying a person by fingerprints and palms. It is based on the fact that the pattern of papillary lines on the skin is unique for each person and does not change throughout life. The procedure includes scanning or taking fingerprints with special inks. Used in forensics, migration records and access control systems. The Biomark product supports fingerprint identification. Installation services will help implement fingerprint equipment.
How does the fingerprinting procedure work?
Fingerprinting is a safe process of scanning or taking fingerprints that lasts a few minutes. In the classic version, printing ink is applied to the fingers and rolled on a form (fingerprint card). In the modern version, fingers are placed on a glass scanner that instantly reads the pattern and sends the data to the database. The procedure is carried out at the Ministry of Internal Affairs or migration centers. The Biomark product supports modern scanning methods.
Who needs to undergo fingerprinting?
Employees of law enforcement agencies, military personnel, employees of the Ministry of Emergency Situations and customs, as well as foreign citizens for legal stay and work in the Russian Federation are required to undergo fingerprinting. Voluntary fingerprinting can be completed by anyone for personal safety. The Biomark product is used for fingerprint identification in corporate systems. Installation services will help implement the equipment.
Where can a foreign citizen undergo fingerprinting?
Foreign citizens can undergo fingerprinting at the territorial department of the Ministry of Internal Affairs (department for migration issues) at their place of stay or at specialized migration centers. In Moscow, the procedure can be completed at the Multifunctional Migration Center. The procedure requires a passport with a notarized translation, a migration card and a document on registration. The Biomark product is used for fingerprint identification.
How much does fingerprinting cost in the Russian Federation?
The cost of fingerprinting in the Russian Federation for foreign citizens is from 4,100 rubles. For citizens of the Russian Federation, voluntary fingerprinting is carried out free of charge at territorial departments of the Ministry of Internal Affairs. For obtaining visas and foreign passports, fingerprints are taken when submitting documents at a visa center or consulate. The Biomark product is used for fingerprint identification in corporate systems.
Who is required to undergo fingerprinting?
The following are subject to mandatory fingerprinting: suspects and accused of committing crimes, convicts, law enforcement officers, military personnel, employees of the Ministry of Emergency Situations and customs, foreign citizens when obtaining a patent or temporary residence permit, as well as all unidentified corpses. The Biomark product is used for fingerprint identification in government and corporate systems. Installation services will help implement the equipment.
How many days does fingerprinting take?
The fingerprint capture procedure itself takes from 5 to 15 minutes. Issuing a supporting document at the migration center takes 5-10 days. At the Ministry of Internal Affairs, for voluntary submission, a certificate can be issued on the day of application. For obtaining visas, fingerprints are taken directly when submitting documents. The Biomark product provides fast scanning and processing of fingerprint data.
What is TLS in simple words?
TLS is an encryption protocol that creates a secure channel between your browser and a website. Thanks to TLS, data (passwords, card numbers, messages) cannot be intercepted. The padlock icon in the address bar means that TLS is used.
How is TLS different from SSL?
SSL is a legacy protocol (1990s), TLS is its modern replacement. SSL contains known vulnerabilities and should not be used. TLS is an evolution of SSL with improved security and speed.
Which TLS version is the most secure?
TLS 1.3 is the most secure and fastest version. It speeds up the handshake, removes outdated algorithms and provides better protection. It is recommended to use TLS 1.2 at minimum.
What is SSO in simple words?
SSO is when you enter your login and password once and get access to all programs and services at work at once. You don't need to remember ten different passwords — one login works for everything.
Where is SSO used in Russia?
In Russia, SSO is implemented through ESIA (Unified Identification and Authentication System). When you log in to Gosuslugi and then go to an MFC or bank, no re-login is needed — that is SSO. In corporate environments, SSO is used for access to internal systems.
How is SSO different from MFA?
SSO and MFA solve different tasks. SSO is convenience — one login for all systems. MFA is security — multi-factor authentication (password + SMS + biometrics). SSO can be combined with MFA for convenience and security at the same time.
What is digital security in simple words?
Digital security is the protection of your gadgets, accounts and data from hackers and fraudsters. Strong passwords, antivirus, updates — all these are elements of digital security.
What are the main threats on the internet?
The main threats: phishing (fake websites and emails), ransomware (file encryption with a ransom), password theft, fake Wi-Fi, social engineering. Protection is passwords, MFA, encryption and vigilance.
How to secure your computer?
Install antivirus, enable the firewall, update the system, use unique passwords, enable MFA, don't click suspicious links, create data backups.
How is an antivirus different from an antivirus scanner?
An antivirus scanner (for example, Dr.Web CureIt!) is a utility for a one-time system check without constant background protection. Full antivirus software is installed as a resident program and works in real time, blocking threats before they launch. In the corporate segment, monitors are also integrated with SIEM systems for centralized collection of security events, which is important for information security monitoring centers (SOC).
Why is it important in Russia to choose an antivirus from the Software Register?
Choosing an antivirus included in the Register of Domestic Software guarantees compliance with legal requirements (152-FZ, 187-FZ) and the absence of the risk of sudden termination of support (as happened with many Western vendors). This is critical for state structures and critical information infrastructure facilities. Within the framework of import substitution, domestic antiviruses provide technical support and database updates even under sanctions restrictions.
What are the main signs of a virus infection?
Key signs of infection: sudden slowdown of the system, processor overheating without visible reasons (hidden miner), the appearance of unknown files or the disappearance of documents, as well as disabling of the antivirus software itself or the impossibility of updating it. If you notice this, immediately disconnect the device from the network and run a check with a portable scanner. In corporate networks, such incidents require immediate response and isolation of the segment through network firewalls.
How to choose an antivirus for a weak PC?
For weak PCs (1-2 GB RAM) it is better to choose "light" solutions that minimize the load on the processor and disk subsystem. Pay attention to cloud antiviruses — they shift the main analysis load to the provider's servers. It is also worth disabling unused modules (antispam, parental control). Consultation on selecting the optimal configuration can be obtained within the security systems design service.
Why do you need an antivirus on your phone?
Smartphones are also vulnerable to Trojans, spyware and phishing applications. A mobile antivirus scans installed applications, blocks dangerous links in SMS and protects confidential data used to log in to the Fast Payment System (FPS) or confirm operations via the Electronic Signature. Built-in OS tools are often insufficient against sophisticated targeted attacks.
How does an antivirus interact with CIPF?
An antivirus and cryptographic protection tools (CIPF) work in a pair: the antivirus scans files before CIPF begins to encrypt or sign them. If the antivirus detects malicious code during the operation of the crypto gateway, this will prevent the leak of encrypted data. The compatibility of the antivirus with specific CIPF is checked during attestation testing of informatization facilities. For the study of related concepts, we also recommend familiarizing yourself with Antispam filter, SAZ and SDZ.
Where to find an antispam filter on the phone?
In most modern smartphones (Android and iOS), the antispam filter is built into the Phone application. To enable it on Android, go to Settings -> Apps -> Phone -> Caller ID and spam (or a similar section). On iOS: Settings -> Phone -> Silence Unknown Callers. There are also third-party applications (for example, Kaspersky Who Calls, Yandex with Alice, Truecaller) that offer advanced blocking functions. For corporate protection, contact the systems design service.
How to disable the antispam filter?
To disable the antispam filter on Android, go to Settings -> Apps -> Phone -> Caller ID and spam and deactivate the "Filter spam calls" option. On iPhone, a similar option is located in Settings -> Phone -> Silence Unknown Callers. If you use a third-party application (Yandex with Alice, Kaspersky Who Calls), it needs to be disabled in the settings of the application itself or in the phone settings in the "Call blocking and identification" section.
Why do spam calls still come through if the filter is enabled?
Spammers constantly change numbers and bypass black lists, so the filter may let some calls through. It may also depend on the database of your antispam application: if it has not been updated, a new fraudster number may not be recognized. Regularly update your applications and use several levels of protection: for example, a built-in filter + a caller ID from the operator. Fraudsters also use number spoofing, which complicates filtering.
What is antispam in the context of email?
In email, the antispam filter analyzes incoming letters and sorts them: legitimate letters go to the Inbox, suspicious ones to the Spam folder. Corporate filters can automatically delete letters with viruses or malicious links, and also block letters from senders with a bad reputation. Integration with SIEM makes it possible to log all spam incidents for subsequent analysis and configuration of security rules.
Can antispam mistakenly block important letters?
Yes, this is called a false positive. To avoid this, administrators add trusted senders to whitelists and configure the sensitivity of the filter. If an important letter ends up in spam, the user can mark it as "Not spam" — this retrains the filtering algorithm for future messages. In corporate systems, exceptions are also configured for critical counterparties and government bodies.
Is antispam needed at the level of the telecom operator?
Yes, operator antispam blocks mass automated calls and SMS at the network level, before they reach your phone. It is especially relevant for protection against 'probing' calls and fraudsters posing as banks or government bodies. This service is often provided free of charge and is deactivated at the subscriber's request. In Russia, operators actively use antispam systems within the framework of the requirements of Federal Law 38 'On Communications'.
How does antispam help protect business from phishing?
Antispam filters block phishing letters that try to extort passwords, bank card data or confidential information from employees. Modern antispam solutions use ML algorithms to analyze suspicious links, imitation domains and non-standard sender addresses. In conjunction with DLP systems, antispam also controls outgoing messages, preventing data leaks through mail channels.
How is a proxy different from a VPN?
The main difference: VPN encrypts all traffic at the operating system level, creating a secure tunnel, and provides full confidentiality. A proxy server works only with specific applications (for example, a browser) and does not encrypt data — it only substitutes the IP address. VPN protects against traffic interception by the provider, a proxy only hides the IP. For corporate protection, a combination of a proxy and a firewall is often used.
Where to get a proxy server?
Proxy servers can be obtained in three ways: free public (unstable, slow, unsafe — they can intercept data), paid private (stable, fast, suitable for business and personal use) and your own server (maximum security and control, deployed on VPS or in the company's infrastructure).
What are the risks of using free proxies?
Free proxies are often overloaded, slow and unstable. The main risk is that they can intercept your traffic: logins, passwords, card data (especially on HTTP sites). Also, the owners of free proxies can sell your metadata to advertisers, inject malicious advertising or use your resources for attacks. For working with the digital ruble and FPS, the use of public proxies is unacceptable.
How to configure a proxy in Windows?
Proxy configuration in Windows is done in the Settings -> Network and Internet -> Proxy section. Enable the "Use a proxy server" option, enter the IP address and port of the proxy. An alternative method is configuration in the browser through extensions (for example, FoxyProxy) or in the browser's network settings. For corporate networks, configuration is often done centrally through Group Policy (GPO).
Which proxy servers work in Russia?
Private proxies with SOCKS5 and HTTPS protocols located on Russian servers or servers in friendly countries work stably in Russia. It is important to choose servers that do not violate the legislation of the Russian Federation and use them in accordance with 187-FZ for corporate purposes. For government systems, only certified proxy solutions from the Register of Domestic Software are used.
What tasks does a proxy server solve in a corporate network?
In a corporate network, a proxy server is used for: filtering and caching web traffic (speeding up loading), organizing access control to external resources within security policies (blocking unwanted sites), load balancing between servers (Reverse Proxy), ensuring anonymity when working with external services, auditing user actions (request logging) and protection from malicious sites through integration with antivirus software.
Can a proxy be used to bypass blocks in Russia?
Yes, proxy servers are often used to bypass geographic blocks and access restrictions to foreign sites. However, it is important to remember that using a proxy to bypass legislative restrictions may violate Russian legislation (in particular, the requirements for storing data on the territory of the Russian Federation). For legal use of a proxy for corporate purposes, it is recommended to use servers located in Russia and comply with the requirements of 187-FZ and 152-FZ.
How is a WAF different from an ordinary firewall?
An ordinary firewall works at the network and transport levels (L3-L4), analyzing IP addresses, ports and protocols. A WAF works at the application level (L7) and analyzes the contents of HTTP requests: parameters, headers, request body. For example, a firewall will let an SQL injection through if it comes on an allowed port 443 (HTTPS), while a WAF will block it, seeing malicious code in the request parameters.
What Russian WAF solutions are on the market?
Both own developments and localized solutions are presented in Russia. Popular domestic WAFs include PT Application Firewall (Positive Technologies), Webmonitorx ProWAF, SolidWall WAF and UserGate WAF. Most of them are included in the Register of Domestic Software and have FSTEC certificates, which makes them mandatory for use in state information systems and at CII facilities.
How does a WAF protect against DDoS attacks?
A WAF protects against L7 DDoS attacks (at the application level) that imitate the behavior of real users (for example, mass GET requests to heavy pages or POST requests with large amounts of data). Unlike network DDoS protections, a WAF analyzes behavioral patterns: the frequency of requests from one IP, User-Agent, cookies and timings. Cloud WAFs also integrate with CDN for load distribution and traffic filtering at the network edge.
Is a WAF a cloud service or local software?
A WAF can be both cloud (SaaS) and local (on-premise). Cloud WAF does not require equipment installation, is easily scaled, updated centrally and is suitable for small and medium-sized businesses. Local WAF is installed in the company's infrastructure and provides full control over data, which is critical for government structures and CII facilities. The choice of variant is discussed at the stage of security system design.
How does a WAF integrate with SIEM systems?
A WAF generates event logs (blocks, warnings, anomalies) that are transferred to the SIEM system via syslog, SNMP or API protocols. In SIEM, WAF logs are correlated with data from other protection tools (firewalls, antiviruses, DLP, EDR) to detect complex attacks and restore the attack chain. This allows the information security monitoring center (SOC) to promptly respond to incidents and conduct investigations.
Is it difficult to configure a WAF and does it require special knowledge?
Configuring a WAF requires professional knowledge in the field of web application security, since incorrect configuration can lead to false blocks of legitimate traffic (false positives) or, on the contrary, to missing attacks. Modern WAFs support a learning mode in which the system analyzes typical traffic and automatically forms rules. For complex projects, it is recommended to involve specialists — the design service and training courses help avoid typical errors.
Which attacks cannot a WAF prevent?
A WAF does not protect against all types of threats. It cannot prevent network-level attacks (for example, L3/L4 DDoS), vulnerabilities in server software, insider threats (employee actions) and physical data theft. Also, a WAF cannot protect against attacks using legitimate requests (for example, business logic attacks). Therefore, a WAF should be used in combination with other protection tools: firewalls, EDR/XDR, antiviruses and monitoring systems.
How is IPS different from IDS (intrusion detection system)?
IDS only detects attacks and notifies the administrator, but does not block traffic. It is a passive monitoring tool. IPS actively intervenes: resets connections, blocks IP addresses and prevents the spread of threats in real time. IPS is an evolution of IDS, providing proactive protection. Both systems are often integrated with SIEM for centralized management and event analysis.
How does IPS protect against zero-day (0-day) attacks?
An IPS uses behavioral analysis and machine learning to detect zero-day attacks. The system builds a baseline profile of normal traffic and detects anomalies (for example, non-standard packet sequences, unusual request sizes, data uncharacteristic of a given protocol). Modern IPSs also use reputation analysis and Threat Intelligence to detect new attack patterns without the need for signatures.
Can an IPS work together with an antivirus?
Yes, an IPS and antivirus complement each other, creating layered protection. The antivirus protects at the file system level, analyzing files and processes on end devices. An IPS protects at the network level, blocking malicious traffic before it reaches the device. Together they cover different attack vectors and provide comprehensive protection.
What Russian IPS solutions are available on the market?
The Russian market offers IPS solutions from domestic vendors: UserGate, PT Network Security (Positive Technologies), Kaspersky, Continent IPS (Kod Bezopasnosti). Most of them are included in the Register of Domestic Software and certified by FSTEC, which makes it possible to use them in government systems and at CII facilities.
Where is it better to deploy an IPS — at the network edge or inside segments?
It is recommended to use a combined approach: at the network edge (in front of the data center) for protection from external attacks, and inside segments (between departments, between server zones) for controlling internal traffic and preventing lateral movement of attackers. This creates layered protection (defense in depth). The correct architecture is developed within the security systems design service.
How does an IPS affect network performance and latency?
Modern IPS solutions operate in inline mode (all traffic passes through them) and can create additional delays of up to 1-2 ms, which is usually imperceptible to users. Performance depends on the power of the equipment (processor, memory) and the volume of analyzed traffic. For high-load networks, hardware IPS accelerators or a distributed architecture with load balancing are recommended, which is discussed at the design stage.
How does an IPS help in incident investigation?
An IPS saves detailed logs of all events: blocked packets, attacker IP addresses, attack types, timestamps, as well as full or partial traffic dumps (when configured). These data are transferred to SIEM and stored in data storage systems (DSS) for forensic analysis. When investigating an incident, analysts can reconstruct the chronology of the attack, identify penetration vectors and understand which systems were at risk.
How is NDR different from EDR?
EDR (Endpoint Detection and Response) protects specific end devices (PCs, servers), analyzing activity at the OS level. NDR protects the network as a whole, analyzing traffic between devices. They complement each other: NDR sees the movement of attackers between devices, and EDR — what exactly happens on the infected host. Together they provide full-fledged protection, especially when integrated with SIEM.
What Russian NDR solutions are on the market?
Both own developments and localized solutions are presented in Russia. Popular domestic NDRs include Kaspersky NDR, Positive Technologies NDR (PT Network Attack Discovery) and Garda NDR. Most of them support work with CII facilities and can integrate with other protection tools within the framework of import substitution.
Can NDR analyze encrypted traffic (HTTPS)?
Modern NDR systems analyze metadata of encrypted traffic: packet sizes, time intervals, connection directions, request frequency, TLS certificates (in the unencrypted part). This makes it possible to detect anomalies even without decryption. Deep analysis of HTTPS content requires integration with DPI (Deep Packet Inspection) or TLS inspection systems, which is discussed at the design stage.
How does NDR help in incident investigation?
NDR saves the full history of network interactions (metadata, flows, logs) in data storage systems. When an incident is detected, analysts can reconstruct the time line of the attack: from the first contact (implantation) to the moment of detection and the attacker's actions (C2, movement, exfiltration). This is critically important for information security monitoring centers (SOC) when conducting forensics.
What data does NDR collect?
NDR collects network traffic metadata: source and destination IP addresses, ports, protocols, packet sizes, timestamps, number of connections, volume of transferred data, session duration. It is important that NDR does not intercept the contents of user traffic (files, messages, e-mail contents), which complies with legal requirements, including the protection of electronic signatures and personal data.
Is it difficult to implement NDR in the existing infrastructure?
The implementation of NDR requires configuring network equipment (SPAN ports on switches, TAP aggregators for physical traffic interception) and integration with existing security systems (SIEM, SOAR, Firewall). For large distributed networks, several sensors may need to be installed in different segments. Professional design makes it possible to minimize the impact on network performance and ensure correct operation of the system.
What are the requirements for NDR for CII facilities?
For CII facilities, NDR solutions must be certified by FSTEC of Russia, included in the Register of Domestic Software, support work with Russian operating systems (Astra Linux, RED OS) and integrate with state monitoring systems (GosSOPKA). Compliance with information protection requirements established by FSTEC orders is also required.
How is EDR different from an ordinary antivirus?
An ordinary antivirus uses signature analysis and protects against known threats for which signatures have already been created. EDR uses behavioral analysis and machine learning to detect unknown attacks (zero-day), APT threats and fileless attacks. EDR also provides tools for incident investigation (forensics) and automatic response (isolation, process blocking), while an antivirus simply blocks or removes a malicious file.
What data does EDR collect from endpoint devices?
EDR collects extensive telemetry from endpoint devices: running and terminated processes, network connections (outgoing and incoming), changes in the system registry, file operations (creation, modification, deletion), user activity (logins, application launching), loading of drivers and kernel modules. These data are transferred to the central console for analysis and can be stored in data storage systems for subsequent incident investigation.
What Russian EDR solutions are available on the market?
The Russian market offers EDR solutions from leading domestic vendors: Kaspersky EDR, PT EDR (Positive Technologies), Garda EDR, Solar Dozor (Solar Security). Most of them are included in the Register of Domestic Software and certified by FSTEC, which makes it possible to use them in government systems and at CII facilities.
How does EDR help in investigating information security incidents?
EDR saves the full history of events on endpoint devices over a long period. When an incident is detected, analysts can reconstruct the entire chronology of the attack: how the malicious code got onto the device (the attack vector), which processes it launched, which files it created or modified, which network connections it established, which accounts it used. This is critically important for information security monitoring centers (SOC) during forensic analysis.
Does EDR affect the performance of computers and servers?
Modern EDR agents use lightweight drivers and are optimized for minimal impact on performance. On average, the load on the processor is 1-3%, which is imperceptible to the user. However, for weak PCs, it is recommended to use resource saving modes and configure the frequency of data collection. The choice of the correct configuration is discussed at the stage of security system design.
Is it difficult to implement EDR in an organization?
The implementation of EDR requires installing agents on all endpoint devices (PCs, servers, laptops, including remote ones) and configuring a central management console. For large organizations with a distributed infrastructure, several management servers may need to be deployed and network policies configured. Professional design and staff training on training courses will help avoid typical errors.
How does EDR protect against ransomware attacks?
EDR protects against ransomware in several ways. First, behavioral analysis detects suspicious activity characteristic of extortionists: mass file encryption, changing extensions, attempts to delete shadow copies (VSS). Second, when such activity is detected, EDR can automatically isolate the device from the network, block the malicious process and start recovery from backups. Third, EDR helps investigate the attack and understand how the attacker entered the system to prevent repeated attacks.
How is XDR different from EDR?
EDR protects only endpoint devices (PCs, servers), analyzing activity at the OS level. XDR protects the entire infrastructure: devices, network, cloud, e-mail, identity systems. XDR is an evolution of EDR that provides end-to-end threat detection and automatic correlation of events from different sources. You can learn more in the article about EDR.
How is XDR different from SIEM?
SIEM collects and correlates logs from the entire infrastructure, but requires manual configuration of rules and often generates many false positives. XDR automates the correlation process, uses ML to reduce noise and offers built-in response scenarios. XDR also integrates more deeply with protection tools for automatic threat blocking without human participation.
What Russian XDR solutions are available?
The Russian market offers XDR solutions from domestic vendors: Kaspersky XDR, Positive Technologies XDR (based on PT Ecosystem), Solar XDR (from the company RTC-Solar). Most of them support integration with Russian OS (Astra Linux, RED OS) and cloud platforms, and are also included in the Register of Domestic Software, which makes it possible to use them in government systems and at CII facilities.
How does XDR help in incident investigation?
XDR automatically links events from different sources (EDR, NDR, e-mail, cloud) into a single attack timeline. An analyst can see the whole picture: from the moment of penetration (for example, a phishing e-mail) to the final impact (for example, data encryption). This is critically important for information security monitoring centers (SOC), where the speed of investigation directly affects the minimization of damage.
Can XDR replace SIEM?
XDR does not completely replace SIEM, but complements it. SIEM is better for compliance with regulatory requirements (for example, storing logs for 3 years for CII), and XDR is for operational detection and response. The optimal strategy is to use them together: SIEM for collection and long-term storage, XDR for automated analysis and real-time response.
Is it difficult to implement XDR?
The implementation of XDR is more complex than EDR, since it requires integration with a large number of data sources: EDR, NDR, mail gateways, cloud platforms, access control systems. For large organizations, several months may be needed for deployment and configuration of correlations. Professional design and staff training on training courses are key success factors.
What are the requirements for XDR for CII facilities?
For CII facilities, XDR solutions must be certified by FSTEC of Russia, included in the Register of Domestic Software, support work with Russian operating systems and GOST cryptographic algorithms, and also ensure integration with state monitoring systems (GosSOPKA). Special attention is paid to data protection and logging of all security events.
How is SOAR different from SIEM?
SIEM collects logs and detects threats. SOAR takes detected incidents and automatically responds to them. Roughly speaking, SIEM says "something went wrong", and SOAR — "block the IP, isolate the device, disable the account". SIEM and SOAR complement each other: SIEM for detection, SOAR for response.
Source: term "SOAR (Security Orchestration, Automation and Response)"
What is a playbook in SOAR?
A playbook is a pre-written scenario of automatic response to an incident. For example, a playbook for a phishing e-mail may include: extracting attachments, checking hashes against threat databases, blocking the sender, notifying the employee. Playbooks are developed by SOC analysts and continuously improved on the basis of experience.
Source: term "SOAR (Security Orchestration, Automation and Response)"
What Russian SOAR solutions are available?
The Russian market offers SOAR solutions from domestic vendors: R-Vision SOAR, Security Vision SOAR, UDV SOAR. Most of them are included in the Register of Domestic Software and certified by FSTEC, which makes it possible to use them in government systems and at CII facilities.
Source: term "SOAR (Security Orchestration, Automation and Response)"
How does SOAR help the SOC?
SOAR automates the routine tasks of information security monitoring center (SOC) analysts: collecting context information, blocking IP addresses, isolating devices. This frees up time for complex investigations and reduces the response time to threats. SOAR also provides a unified console for managing all incidents and controlling SLA.
Source: term "SOAR (Security Orchestration, Automation and Response)"
Can SOAR completely replace analysts?
SOAR does not replace analysts, but makes their work more effective. Complex, non-standard incidents require human analysis and decision-making. SOAR automates only routine, repetitive tasks, allowing analysts to focus on strategic aspects of security. Analysts also develop and maintain playbooks.
Source: term "SOAR (Security Orchestration, Automation and Response)"
Is it difficult to implement SOAR?
The implementation of SOAR requires integration with dozens of different protection tools: SIEM, EDR, firewalls, DLP, antiviruses. It is also necessary to develop and test playbooks for typical incidents. Professional design and staff training on training courses are key success factors.
Source: term "SOAR (Security Orchestration, Automation and Response)"
What metrics does the implementation of SOAR improve?
The implementation of SOAR makes it possible to significantly improve key SOC metrics: MTTD (Mean Time to Detect) — reduces threat detection time through automatic correlation and data enrichment; MTTR (Mean Time to Respond) — reduces response time from hours to minutes through automatic playbooks; reduces the number of false positives and increases analyst productivity by 3-5 times.
Source: term "SOAR (Security Orchestration, Automation and Response)"
How is UEBA different from classic security systems (antiviruses, firewalls)?
Classic systems (firewalls, antiviruses) work according to known signatures and rules — they know what to look for. UEBA works on the basis of behavioral analysis, detecting deviations from normal behavior. This makes it possible to detect attacks that do not have known signatures (for example, zero-day, APT, insider threats), which classic systems will simply miss.
What is a baseline in UEBA?
A baseline is a model of typical activity of a user or device, built by ML algorithms on the basis of historical data over 3-6 months. The profile includes: typical login and logout time, used applications, volume of transferred data, geolocation, frequency of actions, typical work patterns. Any deviation from the profile is considered an anomaly and assessed on a risk scale.
Can UEBA detect insider threats?
Yes, UEBA effectively detects insider threats (malicious or careless actions of employees). For example, if an employee starts downloading an anomalously large amount of data, connects external devices, works at uncharacteristic times, tries to bypass control systems or sends data to a personal e-mail — UEBA marks these actions as suspicious. It is important to configure profiles and thresholds correctly to reduce false positives.
What data does UEBA analyze and where does it come from?
UEBA analyzes data from many sources: application logs (Active Directory, ERP, CRM), network traffic (via NDR), activity in corporate systems, data from EDR/XDR, authentication logs (successful and failed logins), data from DLP systems (file transfer, printing), as well as data from SIEM systems. The more data sources, the more accurate the profiles.
What Russian UEBA solutions are available on the market?
On the Russian market, UEBA is often part of comprehensive solutions: Solar Dozor, MaxPatrol SIEM (Positive Technologies) with a UEBA module, Kaspersky UEBA, Garda UEBA. Many solutions integrate with Russian cryptographic protection systems, support work with Russian OS and are included in the Register of Domestic Software.
Is it difficult to implement UEBA in an organization?
The implementation of UEBA requires collecting and processing large volumes of data from various sources, which can take 3-6 months. It is necessary to correctly configure ML algorithms, determine thresholds for each profile and integrate UEBA with existing systems (SIEM, DLP, EDR). It is also important to train SOC analysts to work with the system.
How does UEBA help with compliance with 152-FZ and 187-FZ?
UEBA helps organizations comply with the requirements of 152-FZ (protection of personal data) and 187-FZ (CII protection), detecting unauthorized access to data and suspicious user actions. When anomalies are detected, the system generates an alert, allowing a prompt response to threats and prevention of leaks.
What is UA in simple words?
UA (unauthorized access) is when someone gains access to your data or system without permission. For example, a hacker guesses a password, an employee looks into other people's files, or an attacker penetrates the server room. Cryptographic protection tools, passwords and access control systems are used for protection.
What laws regulate protection from UA?
The main laws: 152-FZ "On Personal Data" (protection of personal information), 187-FZ "On CII Security" (protection of critical infrastructure) and FSTEC orders that establish requirements for protection tools against UA for government systems.
What is PT against UA?
PT against UA is information protection tools against unauthorized access. This is a complex of software, hardware and software-hardware solutions that prevent attempts to penetrate, steal or modify data. They include CIPF, authentication systems, firewalls and access control systems.
How to detect an UA attempt?
UA attempts are detected using SIEM systems that analyze logs and security events, intrusion detection systems (IDS/IPS), as well as DLP systems that track suspicious user actions. Regular audit of access journals also helps to notice anomalies in time.
What to do when UA is detected?
When UA is detected, it is necessary to immediately: isolate the infected network segment, block compromised accounts, record all traces for investigation and notify the information security monitoring center (SOC). After the incident, a forensic analysis must be carried out and security policies updated.
What typical UA channels exist?
The main UA channels: unpatched vulnerabilities in web applications and servers, weak passwords on administrative interfaces, infected removable media, phishing attacks through e-mail and messengers, as well as zero-day (0-day) vulnerabilities. It is important to conduct regular vulnerability scans and pentests.
What are the requirements for UA protection for CII?
For CII facilities, the use of certified protection tools from the register of domestic software is required, mandatory categorization of facilities, notification of FSTEC about incidents and regular attestation testing. The use of foreign software at CII facilities is also prohibited.
What are the requirements for APT in government systems?
APT for government systems must be included in the Register of Domestic Software, have an FSTEC or FSB certificate, ensure the integrity of its own code and logs, and have centralized management and SIEM integration functions.
Can APT replace CIPF?
No, APT and CIPF are different classes of protection tools. APT protects against malware, and CIPF provides cryptographic data protection (encryption, electronic signature). They work in tandem, creating comprehensive information system protection.
How to choose the appropriate APT?
The choice of APT depends on the requirements of regulators (FSTEC, FSB), the type of the protected system (government, commercial, CII), the number of users and the infrastructure architecture. Advice on selection can be obtained within the security systems design service.
What Russian APTs exist?
The Russian market offers certified solutions: Kaspersky Anti-Virus (certified version), Dr.Web (certified version), Kaspersky Endpoint Security. Most of them are included in the Register of Domestic Software and have FSTEC certificates.
How often should APT be updated?
APT should be updated daily to ensure the relevance of antivirus databases. Critical security updates should be installed immediately after their release. In government systems, updates must be carried out in accordance with approved regulations.
Can free antiviruses be used to protect government systems?
No, for government systems and CII facilities, the use of free antiviruses is not allowed. The use of certified APTs included in the Register of Domestic Software and having FSTEC or FSB certificates is required. Free antiviruses do not provide the necessary level of protection.
Why is a trusted boot tool needed?
A trusted boot tool (TBT) protects the system from attacks at the early boot stage, when the OS has not yet been launched and antiviruses are not working. This makes it possible to prevent the injection of bootkits and rootkits that can intercept system control before the start of protection.
What Russian TBT solutions are available on the market?
The Russian market offers certified solutions: Dallas Lock, Sobol, ViPNet SafeBoot, Accord-HTBM. Most of them meet the requirements of 187-FZ and can be used at CII facilities.
How is TBT different from Secure Boot?
Secure Boot is a built-in UEFI mechanism that checks the digital signatures of loaders. TBT is a more comprehensive solution that can include hardware tokens, biometric authentication and extended integrity checking mechanisms not available in standard Secure Boot.
Is TBT a hardware or software solution?
TBT can be both software (integrated into UEFI or the boot record) and hardware (physical expansion cards, USB tokens). For CII facilities, hardware modules that provide the maximum level of protection from physical intervention are often used.
What is a hardware trusted boot module (HTBM)?
HTBM is a specialized hardware device installed on the motherboard that performs system integrity checking before the BIOS/UEFI starts. HTBM is considered the most reliable type of TBT, since it is physically separated from the main system and cannot be compromised by software attacks.
Is the use of TBT mandatory for commercial organizations?
For commercial organizations, the use of TBT is not mandatory, unless they work with personal data or are CII facilities. However, for banks, insurance companies and other organizations working with confidential information, the use of TBT is recommended as a security best practice.
Why is a removable media control tool needed?
RMCT prevents the leak of confidential data through USB flash drives and external disks, blocks system infection through infected media and makes it possible to track employee actions with external devices. This is a mandatory requirement for systems working with personal data and at CII facilities.
What functions does RMCT perform?
RMCT performs the functions of access control to media, control of their connection, automatic encryption of data on removable devices, audit of all operations and antivirus check of connected media together with antivirus software.
How does RMCT integrate with DLP systems?
RMCT is often a module of DLP systems, providing control at the level of connected devices. DLP receives from RMCT data about all operations with external media and can apply security policies, for example, block the writing of certain file types or encrypt all data.
What Russian RMCT solutions are available?
In Russia, RMCT is often part of comprehensive solutions: Secret Net Studio, Dallas Lock, Solar Dozor. Most of them are certified by FSTEC and included in the Register of Domestic Software.
Can RMCT be bypassed?
RMCT uses several levels of protection: control at the OS level, hardware identification of devices, encryption and audit. To bypass RMCT, it is necessary to have administrative rights or use specialized methods that can also be detected by the system. Regular updates and audits help minimize bypass risks.
How does RMCT affect system performance?
Modern RMCTs use optimized algorithms and practically do not affect system performance. The impact on the speed of operation is less than 1-2% even with active use of external media.
Is the use of RMCT mandatory for small business?
For small business, the use of RMCT is not mandatory, unless the company works with personal data or is a CII facility. However, to protect trade secrets and prevent leaks, it is recommended to use RMCT as part of a comprehensive security system.
Who needs cyber insurance and is it mandatory?
Recommended for all organizations working with digital data, especially processing personal data or related to CII. Legally not mandatory, but often required for government contracts.
What risks does cyber insurance cover in Russia?
Personal data leaks, ransom payments, legal expenses, IT system recovery, loss of profit and PR services.
What requirements do insurers impose?
Antivirus software, backup systems, security policies, SIEM systems, incident response plans and staff training.
How much does cyber insurance cost in Russia?
From 50,000 to 200,000 rubles per year for small business, 200,000 to 1 million for medium, from 1 million for large enterprises.
How do I get cyber insurance?
Choose a company, undergo a cybersecurity audit, provide documents, sign a contract. In an insured event notify the insurer within 24-48 hours.
Can an insurer refuse to pay under a cyber policy?
Yes, if minimum security requirements were not met, the insurer was not notified on time, or the incident occurred due to insiders.
Does cyber insurance protect against ransomware?
Yes, most policies cover ransom payments and system recovery. Insurers require quality backup to minimize the need for payment.
What is PCI DSS in simple words?
PCI DSS is an international set of security rules for companies that accept payment by bank cards. These rules protect customer data from theft and fraud. If your business accepts cards, you are obliged to comply with PCI DSS. Read about payment security in the article Fintech.
Who needs PCI DSS?
PCI DSS is needed by all organizations that accept, transmit or store payment card data. These are banks, online stores, payment systems, delivery services, hotels, restaurants — any business that works with cards. Even if you have a small online store, you are obliged to comply with PCI DSS.
What are the 12 PCI DSS requirements?
12 requirements cover six areas: network protection (firewalls, changing passwords), protection of card data (encryption), vulnerability management (antiviruses, updates), access control (authentication, restriction of rights), monitoring and testing, information security policies. The full list of requirements is in the article Cloud security.
How long is the PCI DSS certificate valid?
The PCI DSS certificate is valid for 12 months. After 10 months, you need to start the renewal procedure — undergo a repeated audit or fill out a new self-assessment questionnaire and conduct a quarterly network scan. The certificate must be renewed every year.
What happens if you do not comply with PCI DSS?
Non-compliance with PCI DSS entails serious consequences: fines from payment systems (up to $100,000 per month), suspension of payment acceptance, lawsuits from affected customers and reputational losses. In some cases — revocation of the payment acceptance license. Read about security risks in the article Fraud.
How to prepare for a PCI DSS audit?
To prepare for the audit, it is necessary: to conduct an internal security review (you can order certification testing), implement encryption of card data, set up firewalls and a monitoring system, train employees in security rules, prepare documentation on security policies. It is recommended to involve a qualified specialist (QSA).
How does PCI DSS differ from ISO 27001?
PCI DSS is a specialized security standard for payment data. ISO 27001 is a general information security management standard that is suitable for any data. PCI DSS is mandatory for companies that accept cards. ISO 27001 is voluntary, but is often required for large clients and tenders. They can complement each other.
What is OAuth in simple words?
OAuth is a way to log into a website without creating a new login and password. You press “Sign in with Google” or “Sign in with VKontakte”, give permission, and the site gets access only to what you allowed (for example, your name and email). Your password is never transferred to the site. It is like a digital pass with limited rights instead of handing over the keys to the whole apartment. Read about data security in the article Information security.
How does OAuth 2.0 work?
OAuth 2.0 works on the principle of a “digital pass”: you give permission to a service (for example, Google), and it issues a temporary key (token) to the application to access your data. The application does not know your password and cannot get access to what you did not allow. The process involves four parties: the resource owner (you), the client (application), the authorization server (Google) and the resource server (API). The token is valid for a limited time and can be revoked at any moment. Read about how tokens work in the article Security token.
How does OAuth 1.0 differ from OAuth 2.0?
OAuth 2.0 is a modern version of the protocol. It is simpler to use for developers (does not require complex request signing), supports more scenarios (mobile applications, smart devices, server-to-server) and uses refresh tokens to extend access without re-entering. OAuth 2.0 also relies more on HTTPS for security. Today OAuth 2.0 is used everywhere, while OAuth 1.0 is considered outdated.
Why do you need OAuth instead of just transferring a password?
OAuth is safer than transferring a password. If the application turns out to be fraudulent, with OAuth you give it access only to limited data (for example, only to your name), not to the entire account. You can revoke access at any moment in your account settings. When transferring a password, you risk the entire account — an attacker can get access to all your data, including email, documents and payment information. Read about account protection in the article Verification.
Is OAuth safe and what are the risks?
OAuth is considered safe when used correctly. Tokens are transmitted over a secure channel (HTTPS), have a limited validity period and a limited scope of rights. However, there are risks: token interception (MITM attack), phishing (a fake login page), CSRF attacks and client secret compromise. To protect yourself, use HTTPS, short token lifetimes, the state parameter to protect against CSRF and PKCE for mobile applications.
Where is OAuth used and which companies use it?
OAuth is used in almost all modern web and mobile applications. The buttons “Sign in with Google”, “Sign in with Facebook”, “Sign in with Yandex”, “Sign in with VKontakte” are OAuth. OAuth is also used in APIs for exchanging data between services (for example, CRM integration with email services), in corporate systems for single sign-on (SSO) and in IoT devices. It is used by Google, Facebook, GitHub, Microsoft, Yandex, VKontakte and thousands of other services. Read about setting up APIs in the article Infrastructure.
What is the difference between OAuth and single sign-on (SSO)?
OAuth is an authorization protocol (what is allowed to be done with your data), while SSO (Single Sign-On) is a solution for authentication (who you are). SSO allows you to log into a system once and get access to all applications without re-entering a password. OAuth can be used as part of an SSO solution, but these are different concepts. SSO is often built on SAML or OpenID Connect protocols (which uses OAuth 2.0 for authentication). OAuth gives access to data, SSO simplifies login to several systems.
What is CAPTCHA in simple words?
CAPTCHA is a test that checks that you are a human, not a bot. Websites use CAPTCHA to protect against spam, fake activity and automatic attacks. You may be asked to enter distorted letters, select pictures with certain objects or simply tick the “I am not a robot” box. Read about website protection in the article Information security.
What types of CAPTCHA are there?
The main types: text (entering distorted characters), interactive (the “I am not a robot” box plus selecting pictures), audio (listening and entering digits), invisible (works in the background) and slider CAPTCHA (assembling a puzzle or moving the slider). The most popular type is reCAPTCHA from Google. Read about protection technologies in the article Antivirus software.
Why do you need CAPTCHA?
CAPTCHA protects websites from bots and automatic programs. Without CAPTCHA, attackers could create millions of fake accounts, leave spam in comments, buy up all the tickets to events or hack accounts by brute-forcing passwords. CAPTCHA also protects servers from excessive load.
Why can't I pass the CAPTCHA?
The reasons can be different: you have a VPN or proxy on, an ad blocker (AdBlock) is active, JavaScript is disabled, cookies are turned off or you send requests too quickly. Try disabling the VPN and blockers, clearing the browser cache and reloading the page. Read about browser settings in the article Incognito mode.
Can you bypass CAPTCHA?
Technically yes, there are CAPTCHA solving services that use real people or neural networks. However, using such services violates the rules of many websites and can lead to a block, and in some cases to liability under Art. 272 of the Criminal Code of the Russian Federation (illegal access to computer information). For ordinary users, the best way is to correctly pass the CAPTCHA with clean browser settings.
Is Google CAPTCHA safe?
Yes, reCAPTCHA from Google is a legitimate and safe service. However, in Russia using reCAPTCHA is complicated — the service may not load due to blocks or send data to foreign servers, which violates the 152-FZ on data localization. Russian websites are increasingly switching to domestic analogues (Yandex SmartCaptcha).
How does invisible CAPTCHA work?
Invisible CAPTCHA works in the background, requiring no action from the user. The system analyzes user behavior: mouse movements, typing speed, browser history, time on the page. If the behavior looks “human”, the verification passes unnoticed. If there are suspicions, a standard task appears. Read about protection from tracking in the article Digital footprint.
What is incognito mode in simple words?
Incognito mode is a browser private mode that does not save history, cookies and entered data after closing the window. It is like a one-time session — after closing the window no traces remain. But remember: the provider and websites still see your activity. Read about data protection in the article Digital footprint.
How to enable incognito mode?
The fastest way is to press Ctrl+Shift+N on a computer (Windows) or Cmd+Shift+N (Mac). On a phone, open the browser, press the three dots (Chrome) or the tabs icon (Safari) and select “New incognito tab” or “Private Browsing”. Read about browser settings in the article Infrastructure.
Who sees my actions in incognito mode?
Incognito hides history only from other users of your device. Your internet provider, the network owner (work, cafe) and the websites you visit still see your activity. They see your IP address and which websites you open. For complete anonymity, use a VPN. Read about protection from surveillance in the article Information security.
Is history saved in incognito mode?
No, history in incognito mode is not saved on the device. After closing the window, all data (history, cookies, cache) is deleted. However, your provider and websites can save logs of your activity. Also, bookmarks and downloaded files will remain on the device.
How is incognito different from a VPN?
Incognito hides history only on your device — from other users of the same computer. A VPN hides your activity from the provider and everyone on the network, encrypts traffic and changes the IP address. Incognito is for local privacy, VPN is for complete anonymity on the internet. Read about VPN in the article VPN.
Can you catch a virus in incognito mode?
Yes, incognito mode does not protect from viruses. It hides history, but does not block malicious files and phishing sites. If you download a virus or follow a dangerous link, the device will be infected even in incognito. Use an antivirus and be careful on the internet. Read about protection from viruses in the article Antivirus software.
Why does incognito not make me invisible on the internet?
Incognito is a browser feature that works only on your device. When you visit a website, your computer still sends a request over the internet — and both the provider and the site see your IP address. Incognito does not encrypt traffic and does not change the IP. For complete invisibility, use a VPN, and use incognito only for local privacy. Read about data protection in the article Digital footprint.
What is an information security incident?
An IS incident is any event that violates or creates a threat of violation of the confidentiality, integrity or availability of information. Examples: password cracking, data leak, DDoS attack, infection with a ransomware virus, unauthorized access to a system. Read about types of threats in the article Cyber fraud.
What types of incidents are there in the field of information security?
The main types of incidents: malware (viruses, encryptors), unauthorized access (account hacking), data leaks (theft or accidental sending of confidential information), DDoS attacks (availability violation), social engineering (phishing), insider threats (employee actions). Each type requires its own approach to response and prevention. Read about protecting against them in the article Information security.
What is the difference between a security event and an IS incident?
An event is any change in the system (for example, a failed login attempt, an antivirus trigger, a configuration change). An incident is an event that caused or could cause real damage (for example, a successful account hack, data theft, system infection). Not all events become incidents, but every incident begins with an event. Read about event monitoring in the article SIEM system.
What to do when an IS incident is detected?
When an incident is detected, it is necessary to: immediately isolate infected systems from the network, save all logs and evidence for the investigation, notify management and the security service, involve investigation specialists (forensics), notify regulators if necessary (Roskomnadzor, FSTEC, Bank of Russia). After elimination, conduct an analysis of the causes and update protection measures. Read about the response plan in the article SOAR.
What are the 3 foundations of information security?
The CIA triad: Confidentiality (access only for authorized persons), Integrity (protection from unauthorized changes) and Availability (data is available when needed). These three principles underlie all information security measures. An IS incident is a violation of one or more of these principles. Read more in the article Information security.
Which incidents are subject to mandatory notification of regulators?
Incidents related to the leak of personal data (152-FZ) are subject to mandatory notification — within 24 hours from the moment of detection to Roskomnadzor. Also incidents at critical information infrastructure facilities — notification to FSTEC within 24 hours. For financial organizations — notification to the Bank of Russia in accordance with the regulator's requirements. Fines are provided for untimely notification.
How to prevent information security incidents?
Preventing incidents requires a comprehensive approach: regular software updates and elimination of vulnerabilities, use of antiviruses, EDR, SIEM and firewalls, regular training of employees in cybersecurity basics (especially the fight against phishing), implementation of secure access policies (MFA, the principle of least privilege), regular data backup (backup system) and penetration testing.
What is multi-factor authentication in simple words?
This is a method of identity verification that requires confirmation from different categories: a password (something you know) + an SMS code (something you have) or a fingerprint (something you are). Even if the password is stolen, without the second factor you will not be able to log in. It is like two locks on a door — one lock can be broken, but two is already almost impossible. Read about other protection methods in the article Information security.
How does MFA differ from 2FA?
2FA (two-factor) uses exactly two factors (password + SMS code). MFA (multi-factor) — two or more factors (password + fingerprint + push notification). 2FA is a special case of MFA. If the system uses three factors, this is already MFA, not 2FA. Read about the difference between authentication and authorization in the article Authentication.
Which MFA method is the most reliable?
The most reliable are hardware U2F keys (YubiKey, Rutoken). They are physically isolated from the internet, not subject to phishing and do not require data transmission over the network. The second most reliable are authenticator applications (Google Authenticator, Yandex Key, Authy). SMS is the least reliable method due to vulnerability to SIM swapping and message interception. Read about choosing a method in the article Biometrics.
What is the main drawback of MFA?
Dependence on external factors (phone, internet, cellular communication). If you lose the phone with the authenticator or end up in a zone without communication, access may be lost. Therefore, it is important to save the backup recovery codes that are issued when MFA is set up. Store them in a reliable place (for example, in a safe) — they will help restore access if you lose the device. Read about backup in the article Data backup.
What is an example of multi-factor authentication?
A classic example is logging into internet banking: entering a login and password (knowledge) + confirmation via an SMS code or push notification in the mobile bank (possession). Another example is logging into a Google account using a password + a code from Google Authenticator + a fingerprint (already three factors). In Russian government systems, login via ESIA with confirmation by SMS and an electronic signature is used. Read about setup in the article OAuth.
How to enable MFA in popular services (Google, Yandex, VKontakte)?
In Google: Account settings → Security → Two-step verification → Follow the instructions. In Yandex: Account settings → Security → Two-factor authentication. In VKontakte: Settings → Security → Login confirmation. Usually you can choose a method: SMS, an authenticator application (Google Authenticator, Yandex Key) or push notifications. It is recommended to use an authenticator application — it is safer than SMS.
Is it mandatory to use MFA for government systems in Russia?
Yes, for many government systems in Russia the use of MFA is mandatory or strongly recommended. For example, the State Services portal (ESIA) uses two-factor authentication — a password + an SMS code or confirmation through the application. To access Electronic Budget, SMIV and other government information systems, MFA using an electronic signature and additional factors is also required. This complies with the requirements of 152-FZ and 187-FZ.
What is tokenization in simple words?
Tokenization is replacing sensitive data (for example, a card number) with a random set of characters — a token. The token has no value for hackers, since it does not contain the original information. Example: when paying via Apple Pay or Mir Pay, your card number is not transmitted to the seller; instead, a unique token is used. Even if the seller's database is hacked, the tokens cannot be used for other payments. Read about data protection in the article Information security.
What is tokenization in the blockchain?
This is the representation of real assets (real estate, stocks, gold, works of art) in the form of digital tokens on the blockchain. This allows dividing indivisible assets (for example, owning 0.5% of an apartment), accelerating transactions, increasing liquidity and ensuring transparency. Examples: tokenized real estate (RealT), tokenized gold (PAX Gold). Read about the blockchain in the article Blockchain.
What risks does tokenization have?
The main risks of tokenization: technology limitations (tokens do not work in all systems), hacking risks in case of token compromise in a vulnerable system (if the Token Vault is hacked), regulatory risks (different legislation in countries regarding tokenized assets). However, in general, tokenization is significantly safer than storing data in open form or even encryption, since tokens do not contain the original information. Read about data protection in the article PCI DSS.
How does tokenization differ from encryption?
Encryption is a reversible transformation of data using a key. If you have the key, you can decrypt the data and get the original information. Encryption can be broken mathematically. Tokenization is replacing data with a random substitute (a token) that does not contain the original information. The token cannot be “decrypted”, since it simply does not store data. The connection between the token and the real data is stored separately in the Token Vault. Tokenization is considered safer for payment data. Read about encryption in the article Data encryption.
Where is tokenization used?
Tokenization is used in three main areas: information security (protection of card numbers, passport data, SNILS, INN), blockchain (digital assets, cryptocurrencies) and artificial intelligence (dividing text into tokens for neural networks). It is also used in payment systems (Apple Pay, Google Pay, Mir Pay, SBP), in access control systems and in IoT. Read about application in the article Artificial intelligence.
What is tokenization in the context of 152-FZ on personal data?
In the context of 152-FZ, tokenization helps protect personal data by replacing it with tokens. This allows organizations to process data without storing real information, which reduces the risks of leaks and regulator fines. Tokenization is one of the methods of personal data de-identification allowed by law. However, it is important that the token storage system (Token Vault) is protected in accordance with the requirements of 152-FZ and the use of cryptographic information protection.
What is tokenization in NLP and artificial intelligence?
In NLP (natural language processing), tokenization is the division of text into small fragments — tokens (words, subwords, syllables or characters). Models (ChatGPT, Yandex GPT, GigaChat) convert these tokens into numerical identifiers for processing. There are different approaches: word tokenization (division into words), subword (BPE, WordPiece) and character (division into separate characters). The choice of method affects the quality of the model's work. Read about artificial intelligence in the article Artificial intelligence.
What is authentication in simple words?
Authentication is verifying the identity of a user. This is the answer to the question “Prove that you really are who you claim to be”. For example, entering a password, scanning a fingerprint or Face ID. Read about what happens next in the article Authorization.
What is the difference between authentication and authorization?
Authentication is identity verification (“Who are you?”). Authorization is determining access rights (“What are you allowed to do?”). Authentication always comes first, authorization follows. For example, when entering a bank, you first show your passport (authentication), and then the cashier checks whether you can withdraw money (authorization). Read more about the difference in the article Authorization.
What types of authentication are there?
The main types: single-factor (only a password), two-factor (password + SMS code or push), multi-factor (three or more factors), passwordless (biometrics, email link, hardware key). The most secure are multi-factor and passwordless. Read about MFA in the article Multi-factor authentication (MFA).
What 3 authentication factors exist?
The three main factors: knowledge (password, PIN code), possession (phone, token, bank card) and inherence (fingerprint, face, voice, retina). For maximum security, a combination of all three factors is used (for example, password + token + fingerprint). Read about biometrics in the article Biometrics.
Which authentication method is the most reliable?
The most reliable is passwordless authentication using hardware U2F keys (YubiKey, Rutoken) combined with biometrics. The second most reliable are authenticator applications (Google Authenticator, Yandex Key, Authy). SMS codes are the least reliable method due to vulnerability to SIM swapping and message interception. Read about protection in the article Information security.
What is adaptive authentication?
Adaptive (or contextual) authentication is an approach in which the system analyzes the context of the login: geolocation, device, time, user behavior. If everything is fine, the login proceeds without additional requests. If there are suspicions (for example, logging in from another country), the system requests an additional factor (an SMS code or push notification). This improves security without sacrificing convenience.
How is authentication used in Russian government systems?
In Russia, government systems (for example, the State Services portal, Electronic Budget, SMIV) use ESIA (Unified Identification and Authentication System) for citizens and organizations to log in. This allows using a single login and password for access to all government services. For enhanced security, two-factor authentication (password + SMS code or push notification) and an electronic signature are used.
What is authorization in simple words?
Authorization is checking a user's rights after logging into the system. It answers the question “What are you allowed to do?”. For example, after logging into your email, you can read your own letters, but you cannot read others'. Read about how the login happens in the article Authentication.
What is the difference between authentication and authorization?
Authentication is “Who are you?” (identity verification, login by password). Authorization is “What are you allowed to do?” (rights verification, access to files and functions). Authentication always comes first, authorization second. Read more in the article Authentication.
Which authorization model is the most popular?
RBAC (Role-Based Access Control) — access based on roles. Rights are assigned to roles (administrator, manager, employee), not to each user separately. This is simple and convenient for management. Read about rights configuration in the article Access control.
What comes first: authorization or authentication?
Authentication always comes first — you prove who you are (enter a password). Only after that the system checks your rights (authorization). Without authentication, authorization is impossible. Read about the processes in the article Authentication.
What is RBAC in simple words?
RBAC (Role-Based Access Control) is an authorization model where access rights are assigned to roles, not to people. For example, all “Administrators” can delete files, while all “Employees” can only read them. If an employee is promoted to administrator, they automatically receive new rights. Read about access rights in the article Access control.
Nothing found
Try changing your search criteria or choose another category.
Did not find an answer to your question?
Leave a request — our specialists will contact you and help you solve any task in the field of information security and automation.