Review of Russian legislation in the field of information security. Information and Information Security Law

The law "On Information, Informatization and Information Protection" dated February 20, 1995 No. 24-FZ (adopted by the State Duma on January 25, 1995) should be considered fundamental among Russian laws on information security issues. It gives the main definitions and outlines the directions for the development of legislation in this area.

Let's quote some of these definitions:

    information - information about persons, objects, facts, events, phenomena and processes, regardless of the form of their presentation;

    documented information (document) - information recorded on a material carrier with details that allow its identification;

    information processes - processes of collection, processing, accumulation, storage, search and dissemination of information;

    Information system - an organizationally ordered set of documents (arrays of documents) and information technologies, including the use of computer technology and communication tools that implement information processes;

    informational resources - individual documents and individual arrays of documents, documents and arrays of documents in information systems (libraries, archives, funds, data banks, other information systems);

    information about citizens (personal data)- information about the facts, events and circumstances of the life of a citizen, allowing to identify his personality;

    confidential information - documented information, access to which is restricted in accordance with the legislation of the Russian Federation;

    user (consumer) of information- a subject applying to an information system or an intermediary to obtain the information he needs and using it.

We will of course not discuss the quality of the data in the Law of Definitions. Let us only pay attention to the flexibility of defining confidential information, which is not limited to information constituting a state secret, as well as to the concept of personal data, which lays the foundation for the protection of the latter.

The law identifies the following goals for information protection:

    prevention of leakage, theft, loss, distortion, falsification of information;

    prevention of threats to the security of the individual, society, state;

    prevention of unauthorized actions to destroy, modify, distort, copy, block information;

    prevention of other forms of unlawful interference in information resources and information systems, ensuring the legal regime of documented information as an object of property;

    protection of the constitutional rights of citizens to maintain personal secrecy and confidentiality of personal data available in information systems;

    preservation of state secrets, confidentiality of documented information in accordance with the law;

    ensuring the rights of subjects in information processes and in the development, production and application of information systems, technologies and means of their support.

Note that the Law puts the preservation of confidentiality of information in the first place. Integrity is also presented quite fully, although in second place. Very little has been said about accessibility ("prevention of unauthorized actions to ... block information").

Let's continue quoting:

"Any documented information, mishandling of which may cause damage to its owner, owner, user or other person, is subject to protection."

In fact, this provision states that the protection of information is aimed at ensuring the interests of the subjects of information relations.

    in relation to information classified as state secrets - by authorized bodies on the basis of the Law of the Russian Federation "On State Secrets";

    in relation to confidential documented information - by the owner of information resources or an authorized person on the basis of this Federal Law;

    in relation to personal data - by federal law."

Here, three types of protected information are clearly distinguished, the second of which includes, in particular, commercial information. Since only documented information is subject to protection, a necessary condition is the fixation of commercial information on a tangible medium and the supply of its details. Note that in this part of the Law we are talking only about confidentiality; other aspects of information security are forgotten.

Let us note that the protection of state secrets and personal data is undertaken by the state; other confidential information is the responsibility of its owners.

How to protect information? As a basic law, it proposes powerful universal means for this purpose: licensing and certification. Let's quote article 19.

    Information systems, databases and data banks intended for information services for citizens and organizations are subject to certification in the manner prescribed by the Law of the Russian Federation "On Certification of Products and Services".

    Information systems of state authorities of the Russian Federation and state authorities of the constituent entities of the Russian Federation, other state bodies, organizations that process documented information with restricted access, as well as the means of protecting these systems are subject to mandatory certification. The procedure for certification is determined by the legislation of the Russian Federation.

    Organizations performing work in the field of design, production of information security tools and processing of personal data receive licenses for this type of activity. The procedure for licensing is determined by the legislation of the Russian Federation.

    The interests of the consumer of information when using imported products in information systems are protected by the customs authorities of the Russian Federation on the basis of an international certification system.

Here it is difficult to refrain from a rhetorical question: are there any information systems in Russia without imported products? It turns out that in this case, only customs is protecting the interests of consumers ...

And a few more points, now from Article 22:

2. The owner of documents, an array of documents, information systems ensures the level of information protection in accordance with the legislation of the Russian Federation.

3. The risk associated with the use of non-certified information systems and means of their support lies with the owner (owner) of these systems and means. The risk associated with the use of information obtained from a non-certified system lies with the consumer of the information.

4. The owner of documents, an array of documents, information systems may apply to organizations that certify the means of protecting information systems and information resources in order to analyze the sufficiency of measures to protect his resources and systems and obtain advice.

5. The owner of documents, an array of documents, information systems is obliged to notify the owner of information resources and (or) information systems about all facts of violation of the information protection regime.

From point 5 it follows that all (successful) attacks on the IP should be detected. Recall in this regard one of the results of the survey (see lecture 1): about a third of American respondents did not know if their IP had been hacked in the last 12 months. Under our law, they could be prosecuted...

2. The protection of the rights of subjects in this area is carried out by the court, the arbitration court, the arbitration court, taking into account the specifics of the offenses and the damage caused. Very important are the paragraphs of article 5 concerning the legal effect electronic document and electronic digital signature:

3. The legal force of a document stored, processed and transmitted using automated information and telecommunication systems may be confirmed by an electronic digital signature. The legal force of an electronic digital signature is recognized if there are software and hardware tools in the automated information system that ensure the identification of the signature, and if the established mode of their use is observed.

4. The right to certify the identity of an electronic digital signature is exercised on the basis of a license. The procedure for issuing licenses is determined by the legislation of the Russian Federation.

Thus, the Law offers an effective means of controlling the integrity and solving the problem of "non-repudiation" (the inability to refuse one's own signature).

These are, in our opinion, the most important provisions of the Law "On Information, Informatization and Information Protection". On the next page, other laws of the Russian Federation in the field of information security will be considered.

General provisions of 149 FZ

Information Law. Safety 149 was adopted by the State Duma on July 8, 2006, and approved by the Federation Council on July 14, 2006. The last changes were made on November 25, 2017. Federal Law 149 contains 18 articles. It concerns legal relations arising in the course of activities related to the search, provision, production or transfer of materials or information, the use of the system and the development of information protection measures, the use or application of the information received.

Summary of Federal Law No. 149 on information, inf. technologies and information protection:

  • 1 st. - the area regulated by the law;
  • 2 tbsp. — terms and concepts;
  • 3 art. — a list of legal principles of regulation in this area;
  • 4 tbsp. - acts and regulations that control this area;
  • 5 st. — information is an object of legal relations;
  • 6 art. - persons with information;
  • 7 art. — information available to the public, open and public;
  • 8 art. - lists the persons who have the right to access information;
  • 9 st. — restrictions and prohibitions;
  • 10 st. — distribution and provision of information to third parties;
  • 11 art. — documentation and accounting;
  • 12 st. — methods of regulation and control over this sphere;
  • 13 art. — systems and programs;
  • 14 art. - Mrs. systems containing important information;
  • 15 art. - the use of television communication networks in the described field of activity;
  • 16 art. — data protection and security measures;
  • 17 art. - responsibility, punishments and types of crimes;
  • 18 art. — enumeration of invalid provisions.

This Federal Law has the main principles used to determine information security and for protection measures:

  • Any person residing on the territory of Russia has the right to search for public and publicly available information, use the information found for distribution and transmission by any known means;
  • Citizens have the right to use, distribute or transfer only publicly available information, it is forbidden to request any data related to secret or private;
  • Restrictions or prohibition on access to information can only be carried out in connection with certain provisions of the legislation of the Russian Federation;
  • Information is distributed and transferred to persons only in case of their request for this information;
  • Any organization, firm or company with a commercial program undertakes to provide detailed information about its own activities and a description of the characteristics of the company in the public domain. Exceptions can be used only if they comply with the conditions and requirements of this Federal Law;
  • The information system is controlled and protected by government agencies;
  • All systems, operation of information and data issued on official websites or in official documents must be in Russian.

Not only citizens (individuals), but also legal entities have the right to have information. At physical and legal persons, various powers in this area and the rights, duties and powers are determined by the legislation, namely the regulatory acts of the Russian Federation and the described Federal Law.

Federal Law 149 lists the rights that a person who owns information has:

  • Rights to allow or restrict access to information belonging to the owner;
  • The right to transfer data or information to third parties in connection with the execution and conclusion of the contract;
  • The right to use, disseminate information at your own discretion, as the owner wishes.

Federal Law 149 lists the duties that a person who owns information has:

  • Observance of the rights, duties and powers of other citizens to which the information may relate;
  • Application of a ban or restriction on access to data, if these data must be withdrawn from access in accordance with the provisions of the regulations, acts and laws of Russia;
  • The application of measures and methods to ensure the protection and security of information that belongs to this person.

Any information, information and data permitted for distribution and use must be open and provided in a free manner. Encryption is possible only in exceptional cases, formalized in this law. If, during the transfer or dissemination of information, the activity occurs without the participation of the media (for more details, control is carried out so that the data is reliable and has the identification of the person who published it.

The owner of a website on the Internet or any other resource where information is distributed is obliged to place their own data in a special column or heading:

  • Full name;
  • E-mail address;
  • Residence address.

Such data about the owner of the site may be needed not only by citizens visiting the site, but also by employees of the authorities. Any person who has difficulty accessing information or has questions for the owner has the right to send a letter. A letter is also sent to the owner if any violations are found in the Internet resource.

According to the legislation of the Russian Federation, any propaganda is also prohibited. Among the prohibitions are propaganda of war and violence, propaganda of religious or racial hatred, propaganda of suicide (psychic influence), etc. For the listed types of open or closed propaganda, the author of the text will bear criminal or administrative responsibility, depending on the severity of the crime.

Secret, classified or important materials, documentation, information must be documented. The design of such papers and the methods of their storage are formalized in the Federal Law on the Execution. authorities.

The owner of information or any materials while browsing Internet pages may find that their own information is used without permission. In such a case, the owner has the right to file a copyright infringement claim against the site owner. When filing a claim, a power of attorney is drawn up, which must be certified by a notary.

Download law on information technology and information protection

Citizens, employees or officials who violate the established provisions, requirements and conditions of the law will be liable. In the event that a citizen has discovered a violation of his own rights in the area described above, he has the right to file a lawsuit with the judicial authorities to receive compensation and damages, depending on the situation:

  • If the person has suffered moral damage;
  • Damage to honor and business reputation;
  • Protection of honor and dignity.

The owner of an Internet resource, page or site has the right to buy information from a person. It often happens that third parties sell materials without the knowledge of the author. In such cases, the copyright infringement claim will be ignored. These terms and conditions apply not only to the sale of information, but also to obtaining a license to use copyright.

In cases where violations of the law have been detected repeatedly on the same sites and resources, employees of the control bodies have the right to restrict access to them. On the official websites of the Federal authorities, you can find a document with a complete list of sites and resources, access to which has been restricted or completely prohibited.

