Skip to main content

Compliance with Security Standards

International standards and Russian legislation

Selectel infrastructure complies with international standards and Russian legislation on information security and personal data protection. For more information about the reports and certificates confirming compliance with security requirements, see the Security page on selectel.ru.

Existing Selectel clients can obtain additional documents certifying compliance with the appropriate standards:

  • FSTEC orders: threat assessment results;
  • PCI DSS: AOC, responsibility matrix;
  • GOST 57580: responsibility matrix;
  • SOC 2: report.

To request additional documents, create a ticket.

We confirm that Selectel products comply with security standards and legislative requirements with certificates, accreditations, audit reports, and conclusions — learn more in the Product Information Security Compliance Matrix section.

Product Information Security Compliance Matrix

You can download certificates, attestations, audit reports, and conclusions on the Security at Selectel page on selectel.ru.

Certified segment of the Selectel Cloud Platform and S3Dedicated servers in the A-Data CenterColocation (colocation)Dedicated ServersSelectel Cloud PlatformS3 (S3)Managed DatabasesManaged Kubernetes (MKS)Container Registry as a Service (CRaaS)Cloud powered by VMware, including DaaS
FSTEC Order No. 21 (152‑FZ)Compliance Certificate, UZ-1Efficiency assessment report, UZ-1Efficiency assessment report, UZ-1Efficiency assessment report, UZ-1Efficiency assessment report, UZ-1Efficiency assessment report, UZ-1Efficiency assessment report, UZ-1Efficiency assessment report, UZ-1Efficiency assessment report, UZ-1Efficiency assessment report, UZ-1
FSTEC Order 117 (GIS)Compliance Certificate, K1Suitable for further certification of the Customer's IS
AS GuidelineCompliance Certificate, 1GCompliance Certificate, 1G
GOST 57580Report (R=0.95)Report (R=0.95)Report (R=0.95)Report (R=0.95)Report (R=0.95)Report (R=0.95)Report (R=0.95)Report (R=0.95)Report (R=0.95)
ISO 27001, 27017, 27018, GOST R ISO/IEC 27001CertificateCertificateCertificateCertificateCertificateCertificateCertificateCertificateCertificate
PCI DSSPCI DSS 4.0.1 Service Provider CertificatePCI DSS 4.0.1 Service Provider CertificatePCI DSS 4.0.1 Service Provider CertificatePCI DSS 4.0.1 Service Provider CertificatePCI DSS 4.0.1 Service Provider CertificatePCI DSS 4.0.1 Service Provider CertificatePCI DSS 4.0.1 Service Provider CertificatePCI DSS 4.0.1 Service Provider CertificatePCI DSS 4.0.1 Service Provider Certificate
GDPRPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the clientPossibility to conclude DPA and SCC with the client
SOC 2® Type IReport

Personal data

In accordance with the requirements of 152-FZ and GDPR, you may entrust Selectel with the processing of personal data. The list of actions with personal data performed by Selectel as a processor on your behalf includes: storage and deletion. To conclude a processing agreement under 152-FZ or a DPA, SCC under GDPR, create a ticket.

Types of information security tools according to security levels and GIS classes

The table summarizes the basic composition of required information security tools (IS tools) that Selectel can provide as services.

The composition of information security tools for a personal data information system (PDIS) can be modified based on technical specifics of the system, threat models, and the information security intruder model.

The need for cryptographic protection for ISPDn is determined by the threat model and depends on the ability to neutralize threats using other measures. Cryptographic protection for GIS is always used, regardless of the security level and system class, if the system meets one or more of the following conditions:

  • communication channels that extend beyond the controlled zone exist;
  • information can only be protected using cryptographic information security tools;
  • legal validity of electronic documents and their protection against alteration is required.

The decision regarding the adequacy of applied information security tools is made by the information system owner or the FSTEC licensee conducting the attestation.

Personal Data Information System (PDIS) security level (FSTEC-21)GIS class (FSTEC-117)Information security tools available from Selectel
SL 4SL 3SL 2SL 1C 3C 2C 1

Operating System

Astra Linux OS. RED OS.
Can be used together with unauthorized access protection tools, IdM, other security tools, or independently

Protection against unauthorized access

The choice of security tool depends on the OS on the server.
For Windows Secret Net Studio, for Linux Secret Net LSP.
Can be used together with a certified OS or instead of a certified OS
IdM/IAM/PAM
MFAMulti-factor *
Trusted bootDallas Lock security software **..
Sobol hardware and software complex ***
FirewallingUserGate.
Host-based firewall included in Secret Net Studio and Secret Net LSP
Protection against malwareKaspersky.
Antivirus module included in Secret Net Studio
IDS/IPSIntrusion Detection System included in UserGate.
Host-based IDS included in Secret Net Studio
Vulnerability identificationVulnerability scanning service
Cryptographic protectionGOST-VPN service
SIEMRuSIEM, provided as a license
Anti-DDoS

The need for DDoS protection depends on the threat types
Free basic Selectel protection against L3-L4 DDoS attacks.
Partner solutions — L3-L7 protection from DDoS-Guard, Curator and StormWall
WAFRelevant for IS that includes a web interface or API. FSTEC-certified solutions are required for Order 117.
WAF solutions, UserGate WAF license
Backup systemCloud server backup.
Dedicated server backup.
Cyber Backup Cloud

* Two-way two-factor authentication is required for all privileged access. Exceptions only for local non-privileged access. K1 requires the use of a hardware authentication device, such as a phone with TOTP or USB tokens.

** Dallas Lock has a FSTEC certificate and can be used for system attestation according to GIS data protection requirements.

* ** The Sobol hardware and software complex has FSB and FSTEC certificates and can be used to raise the cryptographic protection class to KS2 and KS3.