Skip to main content

General information about the Certified Security Features service

Last update:

The Certified Security Features service provides software and hardware-software tools designed to protect information on a server. Security tools are installed on or connected to the server.

You should use server security tools if your system is subject to increased information security requirements. Such requirements are set by:

  • for protecting government systems (GIS up to K1 inclusive);
  • protecting personal data (ISPDN up to UZ-1 inclusive);
  • complying with the requirements of FSTEC of Russia Orders No. 17 and No. 21;
  • meeting international information system standards.

Depending on your infrastructure specifics and the list of requirements you need to meet, you can order:

You can view the features of each tool and choose the right one using the Brief description of security tools and Implementing security measures using provided server security tools tables.

For additional infrastructure protection, you can configure a cloud firewall, basic firewall, as well as connect a hardware or virtual firewall.

Description of security tools

Kaspersky Endpoint SecuritySecret Net LSPSecret Net StudioDallas Lock SDZSobol PAK
PurposeProtection of virtual and physical servers against various threats, network and fraudulent attacks, protection of the virtualization environment and system virtual machinesProtection of Linux OS on virtual and physical servers against unauthorized accessProtection of Windows OS on virtual and physical servers against unauthorized access, antivirusBlocking unauthorized OS boot attempts and OS authenticity verificationBlocking unauthorized OS boot attempts and OS authenticity verification, confidential information protection
Security tool typeSoftwareSoftwareSoftwareHardware-software module for installation in a dedicated serverHardware-software module for installation in a dedicated server
Compatible servicesAll Selectel productsAll Selectel productsAll Selectel productsDedicated servers hosted in the A-CODDedicated servers hosted in the A-COD

Implementing security measures using provided server security tools

Information security measure contentImplement within the client's area of responsibility
IAF.1Identification and authentication of users who are the operator's employeesDallas Lock SDZ (before OS boot begins), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
IAF.2Identification and authentication of devices, including stationary, mobile, and portable onesSecret Net Studio, Secret Net LSP
IAF.3Identifier management, including creation, assignment, and destruction of identifiersDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
IAF.4Authentication tool management, including storage, issuance, initialization, locking of authentication tools, and taking measures in case of loss and (or) compromise of authentication toolsDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
IAF.5Protection of feedback when entering authentication informationDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
IAF.7Identification and authentication of file system objects, executable and running modules, database management system objects, objects created by application and special software, and other access objectsSecret Net Studio (in OS)
UPD.1Management (creation, activation, locking, and destruction) of user accounts, including external usersDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
UPD.2Implementation of required methods (discretionary, mandatory, role-based, or other method), types (read, write, execute, or other type), and access control rulesDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
UPD.3Management (filtering, routing, connection control, unidirectional transmission, and other management methods) of information flows between devices, information system segments, and information systemsSecret Net Studio, Secret Net LSP (local firewall)
UPD.4Separation of user, administrator, and information system operation personnel rolesDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
UPD.6Limiting unsuccessful login attempts to the information system (access to the information system)Dallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
UPD.10Locking an information system access session after a set time of user idleness (inactivity) or upon user requestSecret Net Studio, Secret Net LSP
UPD.11Permission (prohibition) of user actions allowed before identification and authenticationSecret Net Studio, Secret Net LSP
UPD.17Ensuring trusted boot of computing equipmentDallas Lock SDZ, Sobol PAK
OPS.1Management of starting (requests to) software components, including identifying components to be run, configuring component startup parameters, and monitoring software component startupSecret Net Studio, Secret Net LSP
ZNI.1Accounting of machine-readable information carriersSecret Net Studio, Secret Net LSP
ZNI.5Control over the use of information input (output) interfaces to machine-readable information carriersSecret Net Studio, Secret Net LSP
ZNI.8Destruction (erasure) of information on machine-readable carriers during their transfer between users, to third-party organizations for repair or disposal, and control over destruction (erasure)Secret Net Studio, Secret Net LSP
RSB.1Defining security events to be logged and their retention periodsSecret Net Studio, Secret Net LSP
RSB.2Defining the composition and content of information about security events to be loggedSecret Net Studio, Secret Net LSP
RSB.3Collection, recording, and storage of information about security events during the set retention timeDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
Kaspersky Endpoint Security
RSB.4Responding to security event logging failures, including hardware and software errors, failures in collection mechanisms, and reaching memory capacity limits (capacity)Dallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
RSB.5Monitoring (viewing, analyzing) security event logging results and responding to themDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
RSB.7Protection of information about security eventsDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
AVZ.1Implementation of antivirus protectionSecret Net Studio (AVZ module)
Kaspersky Endpoint Security
AVZ.2Updating the database of malicious computer program (virus) signaturesSecret Net Studio (AVZ module)
Kaspersky Endpoint Security
SOV.1Intrusion detectionSecret Net Studio (local IDS)
SOV.2Updating the decision rule databaseSecret Net Studio (local IDS)
ANZ.3Monitoring the performance, settings, and correct functioning of software and security toolsSecret Net Studio, Secret Net LSP
ANZ.4Monitoring the composition of hardware, software, and security toolsDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
ANZ.5Monitoring password generation and rotation rules, user account creation and deletion, access control implementation, and user permissions in the information systemSecret Net Studio, Secret Net LSP
OTsL.1Control over software integrity, including security tool softwareDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
OTsL.6Limiting user rights for entering information into the information systemDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
ZSV.9Implementation and management of antivirus protection in the virtual infrastructureSecret Net Studio (AVZ module)
Kaspersky Endpoint Security
ZIS.1Separation of functions within the information system for managing (administering) the information system, managing (administering) the security system, information processing functions, and other information system functionsDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
ZIS.15Protection of archive files, security tool and software settings, and other data not subject to change during information processingDallas Lock SDZ (before OS boot), Sobol PAK
Secret Net Studio, Secret Net LSP (in OS)
ZIS.17Dividing the information system into segments (information system segmentation) and ensuring protection for information system segment perimetersSecret Net Studio, Secret Net LSP (local firewall)
ZIS.21Excluding user access to information created by the previous user through registries, RAM, external storage devices, and other shared information system resourcesSecret Net Studio, Secret Net LSP
ZIS.22Protecting the information system against information security threats aimed at causing a denial-of-service in the information systemSecret Net Studio (local IDS)
ZIS.24Termination of network connections upon their completion or after a inactivity time interval set by the operatorSecret Net Studio, Secret Net LSP (local firewall)