Document from CIS Legislation database © 2003-2021 SojuzPravoInform LLC

It is registered

Ministry of Justice of Ukraine

May 26, 2021

No. 696/36318

ORDER OF ADMINISTRATION OF PUBLIC SERVICE OF SPECIAL COMMUNICATION AND INFORMATION SECURITY OF UKRAINE

of May 7, 2021 No. 278

About approval of Requirements to the means of cryptographic information security intended for protection of the classified information which is not the state secret and confidential information in state bodies, local government bodies, at the companies, in organizations and the organizations which belong to the sphere of their management, the military forming created according to the law

According to article 14 of the Law of Ukraine "About Public service of special communication and information security of Ukraine", to Item 10 of the Regulations on Administration of Public service of special communication and information security of Ukraine approved by the resolution of the Cabinet of Ministers of Ukraine of September 3, 2014 No. 411, to item 4 of the resolution of the Cabinet of Ministers of Ukraine of February 8, 2021 No. 92 "Questions of ensuring information security in information, telecommunication and information and telecommunication systems" for the purpose of enhancement of system of cryptographic information security of PRIKAZYVAYU:

1. Approve Requirements to the means of cryptographic information security intended for protection of the classified information which is not the state secret and confidential information in state bodies, local government bodies, at the companies, in organizations and the organizations which belong to the sphere of their management, the military forming created according to the law which are applied.

2. To provide to the director of the department of information security of Administration of Public service of special communication and information security of Ukraine submission of this order in accordance with the established procedure on state registration in the Ministry of Justice of Ukraine.

3. This order becomes effective from the date of its official publication.

4. To impose control of execution of this order on the vice-chairman of Public service of special communication and information security of Ukraine according to distribution of obligations.

Chairman of Service lieutenant colonel

Yu.Shchigol

It is approved:

First Deputy Minister of digital transformation of Ukraine

 

A. Vyskub

Approved by the Order of Administration of Public service of special communication and information security of Ukraine of May 7, 2021 No. 278

Requirements to the means of cryptographic information security intended for protection of the classified information which is not the state secret and confidential information in state bodies, local government bodies, at the companies, in organizations and the organizations which belong to the sphere of their management, the military forming created according to the law

1. These Requirements establish requirements to the means of cryptographic information security intended for protection of the classified information which is not the state secret and confidential information during its use in information and telecommunication systems and also which are used in state bodies, local government bodies, at the companies, in the organizations and the organizations relating to the sphere of their management in the military forming created according to the law.

2. In these Requirements terms are used in the values given in Regulations on the procedure for development, production and operation of means of cryptographic information security approved by the order of Administration of Public service of special communication and information security of Ukraine of July 20, 2007 No. 141, registered in the Ministry of Justice of Ukraine on July 30, 2007 for No. 862/14129.

3. Also the hardware intended for cryptographic information security are used to protection of the classified information which is not the state secret and confidential information which is processed and protected in information and telecommunication systems program, hardware-software (further - means of KZI) in which by results of state examination in the sphere of cryptographic information security realization of methods of protection is confirmed, considering type and category of means of KZI.

In means of KZI of types And, B (subspecies of B 1 and B 2) of categories "Sh" and "K" shall be implemented:

mechanisms of control of integrity of cryptographic transformations and protection of key data (for software of KZI - control of integrity of the software), reliable testing for correctness of functioning and blocking of work in case of identification of violations;

mechanisms of protection against violation of confidentiality of information owing to wrong actions of the operator or in case of variations in work of components of means of KZI;

mechanisms of differentiation of access to functions of means of KZI, to the cryptographic scheme and key data;

the confidential channel of receipt of information which is subject to protection;

mechanisms of destruction of key data after the expiration of their action;

mechanisms of protection of key data on their carriers from unauthorized reading (except open parameters of cryptographic transformations);

mechanisms of protection of means of KZI from implementation by the violator of deliberate external impact;

mechanisms of protection against violation of confidentiality and integrity of key data;

mechanisms of protection of critical information (key data) against undocumented opportunities of application software;

maintaining electronic registers of attempts of unauthorized actions.

4. The software of means of KZI needs to be researched on lack of undocumented functions (functions of software which are not registered or do not correspond to those which are stated in documentation when which using violation of confidentiality, availability or integrity of the processed information is possible). Such research is carried out when conducting state examination in the sphere of cryptographic information security.

5. Compliance of means of KZI to these Requirements proves to be true by results of state examination in the sphere of cryptographic information security.

6. For protection of the classified information which is not the state secret and confidential information in state bodies, local government bodies at the companies, in organizations and the organizations which belong to the sphere of their management the military forming created according to the law the means of KZI intended for cryptographic protection of the office information and/or information which is the state secret which have the existing certificate on the admission to operation can be applied.

Director of the department of information security of Administration of Gosspetssvyaz

I. Stelnik

 

Disclaimer! This text was translated by AI translator and is not a valid juridical document. No warranty. No claim. More info

Effectively work with search system

Database include more 50000 documents. You can find needed documents using search system. For effective work you can mix any on documents parameters: country, documents type, date range, teams or tags.
More about search system

Get help

If you cannot find the required document, or you do not know where to begin, go to Help section.

In this section, we’ve tried to describe in detail the features and capabilities of the system, as well as the most effective techniques for working with the database.

You also may open the section Frequently asked questions. This section provides answers to questions set by users.

Search engine created by SojuzPravoInform LLC. UI/UX design by Intelliants.