Compliance with Security Standards
International standards and Russian legislation
Selectel infrastructure complies with international standards and Russian legislation on information security and personal data protection. For more information about the reports and certificates confirming compliance with security requirements, see the Security page on selectel.ru.
Existing Selectel clients can obtain additional documents certifying compliance with the appropriate standards:
- FSTEC orders: threat assessment results;
- PCI DSS: AOC, responsibility matrix;
- GOST 57580: responsibility matrix;
- SOC 2: report.
To request additional documents, create a ticket.
We confirm that Selectel products comply with security standards and legislative requirements with certificates, accreditations, audit reports, and conclusions — learn more in the Product Information Security Compliance Matrix section.
Product Information Security Compliance Matrix
You can download certificates, attestations, audit reports, and conclusions on the Security at Selectel page on selectel.ru.
Personal data
In accordance with the requirements of 152-FZ and GDPR, you may entrust Selectel with the processing of personal data. The list of actions with personal data performed by Selectel as a processor on your behalf includes: storage and deletion. To conclude a processing agreement under 152-FZ or a DPA, SCC under GDPR, create a ticket.
Types of information security tools according to security levels and GIS classes
The table summarizes the basic composition of required information security tools (IS tools) that Selectel can provide as services.
The composition of information security tools for a personal data information system (PDIS) can be modified based on technical specifics of the system, threat models, and the information security intruder model.
The need for cryptographic protection for ISPDn is determined by the threat model and depends on the ability to neutralize threats using other measures. Cryptographic protection for GIS is always used, regardless of the security level and system class, if the system meets one or more of the following conditions:
- communication channels that extend beyond the controlled zone exist;
- information can only be protected using cryptographic information security tools;
- legal validity of electronic documents and their protection against alteration is required.
The decision regarding the adequacy of applied information security tools is made by the information system owner or the FSTEC licensee conducting the attestation.
* Two-way two-factor authentication is required for all privileged access. Exceptions only for local non-privileged access. K1 requires the use of a hardware authentication device, such as a phone with TOTP or USB tokens.
** Dallas Lock has a FSTEC certificate and can be used for system attestation according to GIS data protection requirements.
* ** The Sobol hardware and software complex has FSB and FSTEC certificates and can be used to raise the cryptographic protection class to KS2 and KS3.