Preview

Herald of Dagestan State Technical University. Technical Sciences

Advanced search

Method for recording Certification Tests of an Automated System in a Secure Design

https://doi.org/10.21822/2073-6185-2026-53-2-142-152

Abstract

Objective. The purpose of the study is to develop a method for logging the results of certification tests of an automated system in a secure design, reflecting the necessary and sufficient measures to verify information security requirements depending on the established security level of the system. The scientific novelty of the article lies in the fact that for the first time, based on the analysis of scientific papers and current regulatory legal acts of the Russian Federation, a general methodological approach has been formulated and put into practice, and a methodology for logging certification tests of automated systems in secure execution has been created.
Method. The following methods of scientific knowledge are used: description, analysis, systematization, assessment of information security risks, theory of information protection.
Result. Using the Linux system as an example, this article substantiates the methods for conducting certification tests and describes the results confirming the automated system's compliance with information security requirements. It also provides a rationale for the list of software controls used to assess the security of the system under test. The material covers the necessary checks for antivirus software and protection against unauthorized access, as well as requirements for certification testing of virtualization protection systems and testing of telecommunications equipment.
Conclusion. The method presented in this paper can be used in conducting certification tests of various automated systems. It will make it possible to demonstrate the system's compliance with current information security requirements as clearly as possible and significantly reduce the time required for the development of certification documents, thereby reducing the cost of certification work.

About the Author

A. D. Trofimovich
I.M. Gubkin Russian State University of Oil and Gas (NRU)
Russian Federation

Alexander D. Trofimovich, Postgraduate Student, Department of Integrated Security of Critical Facilities

65 Leninsky Ave., Moscow 119991



References

1. Decree of the Government of the Russian Federation dated November 01, 2012 No. 1119 "On Approval systems" http://pravo.gov.ru/proxy/ips/?docbody=&nd=102160483&ysclid=mhnu9xiea0530228819 (In Russ)

2. Order of the FSTEC of Russia dated February 11, 2013 No. 17 "On Approval of Requirements for the Protection of Information not constituting a State Secret contained in State Information systems": https://fstec.ru/dokumenty/vse-dokumenty/prikazy/prikaz-fstek-rossii-ot-11-fevralya-2013-g-n-17?ysclid=mhnu4wo9w1625032675 (In Russ)

3. Order of the FSTEC of Russia dated December 25, 2017 No. 239 "On approval of requirements for ensuring the security of significant objects of critical information infrastructure". http://publication.pravo.gov.ru/document/0001201803270041 (In Russ)

4. Methodological document of the FSTEC of Russia dated May 02, 2024 "Methodology for assessing the indicator of the state of technical information protection and ensuring the security of significant objects of the critical information infrastructure of the Russian Federation". https://fstec.ru/dokumenty/vsedokumenty/spetsialnye-normativnye-dokumenty/metodicheskij-dokument-ot-2-maya-2024-g?ysclid=mhnu6o2ogd555215018 (In Russ)

5. Methodological document of the National Coordination Center for Computer Incidents "Methodological recommendations for measures to assess the degree of protection against computer attacks" https://gossopka.ru/upload/iblock/a63/hwj5wwz7is5zm42pyzl587s52jubuer7/Metodicheskie-rekomendatsii-po-otsenke-stepeni-zashchishchennosti.pdf (In Russ)

6. Methodological document of the FSTEC of Russia dated February 05, 2021 "Methodology for assessing information security threats". https://fstec.ru/dokumenty/vse-dokumenty/spetsialnye-normativnyedokumenty/ metodicheskij-dokument-ot-5-fevralya-2021-g?ysclid=mhnu5weg1u594814950 (In Russ)

7. Order of the FSTEC of Russia dated April 29, 2021 No. 77 "On Approval of the Procedure for Organizing and Conducting Work on Certification of Informatization Facilities for Compliance with the Requirements for the Protection of Restricted Access Information that is not a State Secret". http://publication.pravo.gov.ru/document/0001202108100027 (In Russ)

8. Order of the FSTEC of Russia dated February 18, 2013 No.21"On Approval of the Composition and Content of organizational and technical measures to ensure the security of personal data during their processing in personal Data Information Systems". https://fstec.ru/dokumenty/vse-dokumenty/prikazy/prikaz-fstekrossii-ot-18-fevralya-2013-g-n-21?ysclid=mhnu4gjs7g182687367 (In Russ)

9. Vanteeva A. E., Omelchenko T. A., Nikishova A.V. Investigation of the possibility of increasing the effectiveness of the certification process of an object of informatization. NBI tehnologii. 2022;16(1):5-9. DOI: 10.15688/NBIT.jvolsu.2022.1.1 (In Russ)

10. Zulkarneev I. R., Kozlov A. E., Semakin A. E. Automation of the certification process for information security requirements. Bezopasnost informacionnogo prostranstva. 2018;43-1(172):171-174. (In Russ)

11. Kriventsev V.A., Selifanov V.V., Zvyagintseva P.A. Conducting certification tests of an automated system in a secure design. Interekspo Geo_Sibir. - 2019. DOI: 10.33764/2618-981X-2019-9-30-34 (In Russ)

12. Gavrilenko D.V. Organizational structure of the system of certification of informatization facilities according to information security requirements. Text:direct. Molodoi uchenii. 2013;5(52):143-148 (In Russ)

13. Makeev S.A. The content of the program and methods of certification testing of information systems for compliance with information security requirements. Pravovaya informatika. 2015;3:19-23. (In Russ)

14. Golushko A.P. The lack of forms of organizational and administrative documents as a problem of certification of informatization facilities for compliance with information security requirements. Aktualnie problemi aviacii i kosmonavtiki. 2017; 2(13):200-202. (In Russ)

15. Medvedev N.V., Kvasov P.M., Cirlov V.L. Standards and information security policy of automated systems. Vestnik MGTU im. N.E. Baumana. Seriya «Priborostroenie». 2010;1:103-111. (In Russ)

16. Burkova E.V. The task of assessing the security of personal data information systems. Vestnik ChGU. – 2016;1:112-118. (In Russ)

17. Barabanov A.V., Markov A.S., Cirlov V.L. Methodological apparatus for assessing the compliance of automated systems with information security requirements. Spetstekhnika i svyaz. 2011;3:48-52. (In Russ)

18. Barabanov A.V. Methodology for assessing the compliance of automated systems with the requirements for protecting information from unauthorized access using selective control. Vestnik MGTU im. N.E. Baumana. Seriya «Priborostroenie». 2011; no. SPEC:104-115. (In Russ)

19. Aleshnikov S.I., Demin S.A., Fedorov S.B., Fedorov A.S. Problems of information security of an organization (enterprise) and ways to solve them. Vestnik Baltiiskogo federalnogo universiteta im. I. Kanta. Seriya: Fiziko-matematicheskie i tekhnicheskie nauki. 2013;10:147-154. (In Russ)

20. Goldobina A.S., Selifanov V.V. Evaluation of the effectiveness of protection tools for state information systems. Interekspo Geo_Sibir. 2019; 6(1):115-121. (In Russ)

21. Starikova A.A., Makarova D.G. Evaluation of the effectiveness of information security system management in state information systems. Interekspo Geo_Sibir. 2017. (In Russ)

22. Selifanov V.V., Gordeev A.S., Karmanov I.N. Information security requirements for inter-network interaction of state information systems with other information systems. Interekspo Geo_Sibir. 2018;7: 277-282. (In Russ)

23. Order of the FSTEC of Russia dated April 03, 2018 No. 55 "On approval of the Regulations on the Certification system of information security tools".Oficialnii internet_portal pravovoi informacii, available at: http://publication.pravo.gov.ru/document/0001201805140022 (In Russ)


Review

For citations:


Trofimovich A.D. Method for recording Certification Tests of an Automated System in a Secure Design. Herald of Dagestan State Technical University. Technical Sciences. 2026;53(2):142-152. (In Russ.) https://doi.org/10.21822/2073-6185-2026-53-2-142-152

Views: 171

JATS XML


Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.


ISSN 2073-6185 (Print)
ISSN 2542-095X (Online)