Ministry of Digital Development teaches government agencies to protect themselves from cyber attacks: Reporting, Import Substitution and Bug Bounty

Carding

Professional
Messages
2,829
Reputation
17
Reaction score
2,087
Points
113
The agency has introduced the information security parameter in the rating of digital transformation of government agencies.

Federal and regional executive authorities will start reporting on the cyber security of their IT systems, the Ministry of Digital Development told Kommersant. The ministry clarified that the indicator "Information Security" was included in the digital transformation rating in July and will be calculated on a monthly basis.

This includes such criteria as the creation of a structural unit for ensuring information security, import substitution in the field of cybersecurity, measures to assess the level of security of systems (including Bug Bounty-testing IT systems for penetration by white hackers), etc.

In 2022, the Ministry of Digital Development proposed to introduce the concept of Bug Bounty in Russian legislation, which would recognize the legality of the activities of white hackers. However, the project did not receive the support of law enforcement agencies, who were afraid of the risk of unauthorized access to significant data, a government source told Kommersant. Therefore, the Ministry of Digital Development itself "encourages the public sector to master the testing mechanism, in particular through information security reporting."

Some regions have already started preparing such reports. For example, in the Nizhny Novgorod Region, Minister of Digital Development and Communications Alexander Sinelobov told Kommersant that information security reports are already being prepared there. In Crimea, Kommersant was informed that in some ministries and municipalities "civil servants are trying to work in a new format in a test mode" and " previously, most consider the introduction of such reporting a necessary step."

However, not all regions are ready for such innovations. So, in Bashkortostan, Kommersant was told that in the region "they do not see the need to prepare such reports, since all IT is already centralized in the Ministry of Digital Resources." In Udmurtia, they also admitted that "they do not conduct such work."
 
Top