News
Application of new requirements for information protection in state information systems
The Requirements determine the need to implement measures (processes) in state bodies and organizations, as well as information protection measures in relation to information systems and the information and communication infrastructure on which these systems are based. In order to implement measures (processes) in state bodies and organizations in accordance with paragraph 14 of the Requirements, it is necessary to develop and approve information protection policies, internal information protection standards, and internal information protection regulations in state bodies and organizations as a priority. When creating state information systems and other information systems after March 1, 2026, it is necessary to follow the provisions of the Requirements. When implementing information protection measures in state information systems and other information systems before the approval of the methodological document "Composition and content of measures and actions to protect information
As of March 1, 2026, the Requirements for protecting information contained in state information systems and other information systems of state bodies, state unitary enterprises, and state institutions have been updated.
Order of the Federal Service for Technical and Export Control dated April 11, 2025, No. 117 "On Approval of the Requirements for Protecting Information Contained in State Information Systems and Other Information Systems of State Bodies, State Unitary Enterprises, and State Institutions" (Registered with the Ministry of Justice of the Russian Federation on June 16, 2025, No. 82619)
The requirements are applied to ensure the protection (by non-cryptographic methods) of information, to prevent unauthorized access to information, and to prevent special effects on information (information carriers) in order to extract, destroy, distort, or block access to information contained in information systems operating on the territory of the Russian Federation.
The order of the Federal Service for Technical and Export Control dated February 11, 2013, No. 17, which approved similar requirements, is recognized as invalid, with the amendments made to it.
It is provided that certificates of compliance for state information systems and other information systems issued before the date of entry into force of this item
FSTEC has published recommendations for fixing software configuration errors
- The use of weak user passwords, which creates threats of brute force attacks and account compromise. The absence of mandatory authentication for accessing databases (which creates threats of unauthorized access and information leakage). The Windows operating system uses the outdated SMBv1 protocol, which creates threats of unauthorized access attacks. Windows also uses the outdated NTLMv1 protocol, which creates threats of unauthorized access attacks. The presence of a "Guest" account in the local "Administrators" group: creates a threat of unauthorized access with elevated privileges. Storing credentials in plain text: creates a threat of authentication data leakage. The presence of open, unused ports: creates a threat of their use by attackers. Activated automatic user login to the server
NIIAS is 70 years old!
Stages of development February 14, 1956 - The USSR Minister of Railways B.P. Beshchev signed an order on the establishment of the Design Bureau of the Main Directorate of Signalling and Communications (KB TsSh). The Institute was engaged in the creation of new devices of railway automation, telemechanics, as well as developments in the field of information technology. In 1987, on the basis of the KB TsSh and the divisions of the All-Union Research Institute of Railway Transport (VNIIGT), the Research Institute of Railway Automation (NIIZHA) was created. In 2000, the Research Institute of Railway Engineering was transformed into the Russian Research and Design Institute of Informatization, Automation, and Communications in Railway Transport (VNIIS of the Russian Ministry of Railways). In 2007, the VNIIS of the Russian Ministry of Railways was transformed into the Research and Design Institute of Informatization, Automation, and Communications in Railway Transport (NIIS OJSC).
Latest Feed
Application of new requirements for information protection in state i…
FEDERAL SERVICE FOR TECHNICAL AND EXPORT CONTROL INFORMATIONAL MESSAGE ON CLARIFYING THE PROVISIONS OF THE REQUIREMENTS FOR THE PROTECTION OF INFORMATION CONTAINED IN STATE INFORMATION SYSTEMS, OTHER INFORMATION SYSTEMS OF STATE BODIES, STATE UNITARY ENTERPRISES, AND STATE INSTITUTIONS, APPROVED BY FSTEC ORDER NO. 117 OF APRIL 11, 2025, No. 240/22/1492 of March 12, 2026 On March 1, 2026, the Requirements for the Protection of Information Contained in State Information Systems and Other Information Systems of State Bodies, State Unitary Enterprises, and State Institutions, approved by Order No. 117 of the Federal Service for Technical and Export Control dated April 11, 2025 (hereinafter referred to as the Requirements), came into force.
As of March 1, 2026, the Requirements for protecting information cont…
Order 117 of the FSTEC comes into force on March 1, 2026.
FSTEC has published recommendations for fixing software configuration…
The Federal Service for Technical and Export Control's website features recommendations for eliminating common configuration (setup) errors of system-wide and application software (software), which contribute to the implementation of information security threats by malicious actors in targeted computer attacks, the FSTEC reported on Monday. The errors addressed by the document were identified based on the analysis of information security incidents in 2024-2025.
NIIAS is 70 years old!
We would like to congratulate NIIAS JSC on its 70th anniversary! We wish you continued success and achievements in the creation and implementation of intelligent control systems, ensuring train safety and stability of railway traffic.