This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Attestation testing of automation facilities

Attestation testing of automation facilities

What is attestation of informatization facilities?

Attestation of informatization facilities to information security requirements (mandatory and voluntary) precedes the commissioning of the informatization facility for permanent operation and is caused by the need to confirm that the information protection system of the informatization facility meets information security requirements.

FINTECH JSC conducts attestation testing of automation facilities in its own testing laboratory accredited in the established manner. Our specialists have many years of experience in conducting certification testing for government customers, including the bodies of the FSB and FSTEC of Russia.

Legislative framework of attestation

Attestation works are performed in accordance with the following documents:

  • "Regulations on the attestation of informatization facilities to information security requirements" (approved by the Chairman of the State Technical Commission under the President of the Russian Federation on 25.11.1994);
  • The National Standard of the Russian Federation of restricted distribution GOST RO 0043-003-2012 "Information protection. Attestation of informatization facilities. General provisions" (adopted and put into effect by order of Rosstandart dated 17.04.2012 No. 2-st RO).

Stages of attestation testing

As part of the attestation, the specialists of FINTECH JSC perform the following works:

  • Analysis of initial data on the informatization facility being attested;
  • Preliminary familiarization with the informatization facility being attested;
  • Expert survey of the informatization facility and analysis of the developed documentation on information protection for compliance with the requirements of regulatory documentation;
  • Testing of individual information protection tools and systems at the facility being attested using special control equipment and test tools;
  • Comprehensive attestation testing of the informatization facility under real operating conditions;
  • Testing of virtualization tools and data storage systems for compliance with security requirements;
  • Analysis of the results of the survey and testing, preparation of reporting documentation (protocols, conclusions) and issuance of a Certificate of Conformity (in case of a positive conclusion);
  • Periodic control and additional verification of the effectiveness of the information protection system of the informatization facility.

Certificate of conformity: what it provides and for how long

The Certificate of Conformity issued based on the results of the works confirms that the informatization facility meets information security requirements. The presence of a valid Certificate of Conformity at the facility gives the right to process information for the period specified in the Certificate (no more than 3 years).

We also conduct periodic control of the effectiveness of the information protection system throughout the entire validity period of the certificate.

Related services and technologies