Regulatory framework
A reference of federal laws, GOSTs, FSTEC orders and Government regulations in the field of information security, personal data protection and critical information infrastructure.
152-FZ On Personal Data
Core law regulating the processing of personal data in Russia: defines the rights of data subjects, obligations of operators, processing principles and protection requirements.
187-FZ On the Security of Critical Information Infrastructure
Law establishing requirements for the protection of CII objects: categorisation, the State system for detecting computer attacks, incident response and obligations of subjects.
149-FZ On Information, Information Technologies and the Protection of Information
Basic law on information: defines the concept of information, the order of its processing and transfer, information protection requirements and liability for violations.
63-FZ On Electronic Signature
Law regulating the use of electronic signatures: types of signatures, certification, legal significance of electronic documents and trust in them.
161-FZ On the National Payment System
Law on payment infrastructure: requirements for payment system participants, processing and protection of financial data, and the order of money transfers.
99-FZ On Licensing of Certain Types of Activity
Law defining the licensing procedure for technical protection of confidential information and other types of activity related to information security.
40-FZ On the Federal Security Service
Law defining the powers of the FSB in the field of information security, including the organisation of cryptographic information protection and state control over encryption.
184-FZ On Technical Regulation
Law on the fundamentals of technical regulation: state standards, mandatory requirements for products, works and services, and the order of conformity assessment.
98-FZ On Commercial Secrets
Law on the protection of commercial secrets: definition of the composition of information, the trade secret regime, protection measures and liability for disclosure.
GOST R 50922-2006 Information Protection. Basic Terms and Definitions
National standard establishing the basic terms and definitions in information protection: confidentiality, integrity, availability, threats and protection measures.
GOST R ISO/IEC 27001-2019 Information Security Management Systems
National standard establishing the requirements for an information security management system (ISMS), based on the international standard ISO/IEC 27001.
GOST R 56546-2015 Vulnerabilities of Information Systems
Standard establishing a classification of information system vulnerabilities and the rules for their description and identification.
GOST R 56938-2016 Information Protection in the Use of Virtualisation Technologies
Standard establishing general provisions on the protection of information in the use of virtualisation technologies.
GOST R ISO 9001-2015 Quality Management Systems
National standard establishing requirements for quality management systems, based on the international standard ISO 9001:2015.
GOST R 15408-2006 Methods and Means of Information Protection
Standard establishing a classification of methods and means of protection against unauthorised access, based on the Common Criteria.
FSTEC Order No. 21 Personal Data Protection Measures
Main by-law on the protection of personal data: defines the composition and content of organisational and technical measures to ensure the security of personal data.
FSTEC Order No. 117 Requirements for Information Protection in State Information Systems
Current (in force from 1 March 2026) requirements for the protection of information in state information systems.
FSTEC Order No. 17 (superseded) Requirements for Information Protection in State Information Systems
Previous edition of the requirements for the protection of information in state information systems (now superseded by Order No. 117).
FSTEC Order No. 239 Requirements for Ensuring the Security of Significant CII Objects
Requirements for ensuring the security of significant objects of critical information infrastructure.
FSTEC Order No. 108 Licensing Control over the Development of Information Security Tools
Order establishing the procedure for licensing control over the development and production of information security tools.
FSTEC Order No. 77 Certification Procedure for Informatization Objects
Order establishing the procedure for attestation (certification) of informatization objects for compliance with information protection requirements.
FSTEC Order No. 55 Certification System for Information Security Tools
Order establishing the procedure for certification of information security tools in the system of the FSTEC of Russia.
Government Regulation No. 1119 Requirements for the Protection of Personal Data
Defines four levels of protection of personal data and the criteria for classifying information systems to a corresponding level.
Government Regulation No. 79 On Licensing of Technical Protection of Confidential Information
Regulation on the licensing of activities for the technical protection of confidential information.
FSTEC "Safe PRO" Competition
Annual FSTEC competition for the best Russian developments in the field of ensuring the security of information in key areas.