---
title: "General information about the Certified Security Features service"
sidebar_label: "General information"
sidebar_position: 1
description: "Basic information about certified server security features: description, comparison of server security tools, list of implemented security measures"
---

import {CustomTable} from '@selectel/docux/components'
import Formbricks from '@theme/MDXComponents/Formbricks'

# General information about the Certified Security Features service

As part of the Certified Security Features service, software and hardware-software tools designed for information security on a server are provided. Security tools are installed on the server or connected to it.

You should use server security tools if your system is subject to increased information security requirements. Such requirements are set by:

* for protecting government systems (GIS up to K1 inclusive);
* protecting personal data (ISPDN up to UZ-1 inclusive);
* complying with the requirements of FSTEC of Russia Orders No. 17 and No. 21;
* meeting international information system standards.

Depending on your infrastructure specifics and the list of requirements you need to meet, you can order:

* [Kaspersky Endpoint Security](/certified-security-features/kaspersky-endpoint-security.mdx) — a comprehensive solution for threat protection;
* [Secret Net LSP](/certified-security-features/secret-net-lsp.mdx) — a tool for protection against unauthorized access for Linux OS;
* [Secret Net Studio](/certified-security-features/secret-net-studio.mdx) — a tool for protection against unauthorized access for Windows OS;
* [Dallas Lock trusted boot tool](/certified-security-features/dallas-lock.mdx) — a trusted boot tool for dedicated servers in the [Certified Data Center Segment (A-COD](/certified-data-center-segment/));
* [Sobol hardware-software security module](/certified-security-features/pac-sobol.mdx) — a trusted boot tool for dedicated servers in the [Certified Data Center Segment (A-COD](/certified-data-center-segment/)).

You can view the features of each tool and choose the right one using the [Brief description of security tools](#server-protection-tools-description) and [Implementing security measures using provided server security tools](#security-measures-list-realizing) tables.

For additional infrastructure protection, you can configure a [cloud firewall](/cloud-servers/firewalls/), [basic firewall](/basic-firewall/), as well as connect a hardware or virtual [firewall](/firewalls/).

## Description of security tools \{#server-protection-tools-description}

<CustomTable>
  <table data-sticky>
    <thead>
      <tr>
        <td />

        <th>Kaspersky Endpoint Security</th><th>Secret Net LSP</th><th>Secret Net Studio</th><th>Dallas Lock SDZ</th><th>Sobol PAK</th>
      </tr>
    </thead>

    <tbody>
      <tr>
        <th>Purpose</th><td>Protection of virtual and physical servers against various threats, network and fraudulent attacks, protection of the virtualization environment and system virtual machines</td><td>Protection of Linux OS on virtual and physical servers against unauthorized access</td><td>Protection of Windows OS on virtual and physical servers against unauthorized access, antivirus</td><td>Blocking unauthorized OS boot attempts and OS authenticity verification</td><td>Blocking unauthorized OS boot attempts and OS authenticity verification, confidential information protection</td>
      </tr>

      <tr>
        <th>Security tool type</th><td>Software</td><td>Software</td><td>Software</td><td>Hardware-software module for installation in a dedicated server</td><td>Hardware-software module for installation in a dedicated server</td>
      </tr>

      <tr>
        <th>Compatible services</th><td>All Selectel products</td><td>All Selectel products</td><td>All Selectel products</td><td>[Dedicated servers hosted in the A-COD](/certified-data-center-segment/)</td><td>[Dedicated servers hosted in the A-COD](/certified-data-center-segment/)</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## Implementing security measures using provided server security tools \{#security-measures-list-realizing}

<CustomTable>
  <table data-sticky>
    <thead>
      <tr>
        <td />

        <th>Information security measure content</th><th>Implement within the client's area of responsibility</th>
      </tr>
    </thead>

    <tbody>
      <tr>
        <th>IAF.1</th><td>Identification and authentication of users who are the operator's employees</td><td>Dallas Lock SDZ (before OS boot begins), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>IAF.2</th><td>Identification and authentication of devices, including stationary, mobile, and portable ones</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>IAF.3</th><td>Identifier management, including creation, assignment, and destruction of identifiers</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>IAF.4</th><td>Authentication tool management, including storage, issuance, initialization, locking of authentication tools, and taking measures in case of loss and (or) compromise of authentication tools</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>IAF.5</th><td>Protection of feedback when entering authentication information</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>IAF.7</th><td>Identification and authentication of file system objects, executable and running modules, database management system objects, objects created by application and special software, and other access objects</td><td>Secret Net Studio (in OS)</td>
      </tr>

      <tr>
        <th>UPD.1</th><td>Management (creation, activation, locking, and destruction) of user accounts, including external users</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>UPD.2</th><td>Implementation of required methods (discretionary, mandatory, role-based, or other method), types (read, write, execute, or other type), and access control rules</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>UPD.3</th><td>Management (filtering, routing, connection control, unidirectional transmission, and other management methods) of information flows between devices, information system segments, and information systems</td><td>Secret Net Studio, Secret Net LSP (local firewall)</td>
      </tr>

      <tr>
        <th>UPD.4</th><td>Separation of user, administrator, and information system operation personnel roles</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>UPD.6</th><td>Limiting unsuccessful login attempts to the information system (access to the information system)</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>UPD.10</th><td>Locking an information system access session after a set time of user idleness (inactivity) or upon user request</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>UPD.11</th><td>Permission (prohibition) of user actions allowed before identification and authentication</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>UPD.17</th><td>Ensuring trusted boot of computing equipment</td><td>Dallas Lock SDZ, Sobol PAK</td>
      </tr>

      <tr>
        <th>OPS.1</th><td>Management of starting (requests to) software components, including identifying components to be run, configuring component startup parameters, and monitoring software component startup</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>ZNI.1</th><td>Accounting of machine-readable information carriers</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>ZNI.5</th><td>Control over the use of information input (output) interfaces to machine-readable information carriers</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>ZNI.8</th><td>Destruction (erasure) of information on machine-readable carriers during their transfer between users, to third-party organizations for repair or disposal, and control over destruction (erasure)</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>RSB.1</th><td>Defining security events to be logged and their retention periods</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>RSB.2</th><td>Defining the composition and content of information about security events to be logged</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>RSB.3</th><td>Collection, recording, and storage of information about security events during the set retention time</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)<br />Kaspersky Endpoint Security</td>
      </tr>

      <tr>
        <th>RSB.4</th><td>Responding to security event logging failures, including hardware and software errors, failures in collection mechanisms, and reaching memory capacity limits (capacity)</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>RSB.5</th><td>Monitoring (viewing, analyzing) security event logging results and responding to them</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>RSB.7</th><td>Protection of information about security events</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>AVZ.1</th><td>Implementation of antivirus protection</td><td>Secret Net Studio (AVZ module)<br />Kaspersky Endpoint Security</td>
      </tr>

      <tr>
        <th>AVZ.2</th><td>Updating the database of malicious computer program (virus) signatures</td><td>Secret Net Studio (AVZ module)<br />Kaspersky Endpoint Security</td>
      </tr>

      <tr>
        <th>SOV.1</th><td>Intrusion detection</td><td>Secret Net Studio (local IDS)</td>
      </tr>

      <tr>
        <th>SOV.2</th><td>Updating the decision rule database</td><td>Secret Net Studio (local IDS)</td>
      </tr>

      <tr>
        <th>ANZ.3</th><td>Monitoring the performance, settings, and correct functioning of software and security tools</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>ANZ.4</th><td>Monitoring the composition of hardware, software, and security tools</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>ANZ.5</th><td>Monitoring password generation and rotation rules, user account creation and deletion, access control implementation, and user permissions in the information system</td><td>Secret Net Studio, Secret Net LSP</td>
      </tr>

      <tr>
        <th>OTsL.1</th><td>Control over software integrity, including security tool software</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>OTsL.6</th><td>Limiting user rights for entering information into the information system</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>ZSV.9</th><td>Implementation and management of antivirus protection in the virtual infrastructure</td><td>Secret Net Studio (AVZ module)<br />Kaspersky Endpoint Security</td>
      </tr>

      <tr>
        <th>ZIS.1</th><td>Separation of functions within the information system for managing (administering) the information system, managing (administering) the security system, information processing functions, and other information system functions</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>ZIS.15</th><td>Protection of archive files, security tool and software settings, and other data not subject to change during information processing</td><td>Dallas Lock SDZ (before OS boot), Sobol PAK<br />Secret Net Studio, Secret Net LSP (in OS)</td>
      </tr>

      <tr>
        <th>ZIS.17</th><td>Dividing the information system into segments (information system segmentation) and ensuring protection for information system segment perimeters</td><td>Secret Net Studio, Secret Net LSP (local firewall)</td>
      </tr>

      <tr>
        <th>ZIS.21</th><td>Excluding user access to information created by the previous user through registries, RAM, external storage devices, and other shared information system resources</td><td>Secret Net Studio, Secret Net LSP </td>
      </tr>

      <tr>
        <th>ZIS.22</th><td>Protecting the information system against information security threats aimed at causing a denial-of-service in the information system</td><td>Secret Net Studio (local IDS)</td>
      </tr>

      <tr>
        <th>ZIS.24</th><td>Termination of network connections upon their completion or after a inactivity time interval set by the operator</td><td>Secret Net Studio, Secret Net LSP (local firewall)</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

<Formbricks />
