Doctrine of information security of the Russian Federation. V

Information Security Doctrine Russian Federation(project)

I. General provisions

1. This Doctrine of Information Security of the Russian Federation (hereinafter referred to as the Doctrine) is a system of official views on ensuring national security Russian Federation in information sphere.
In this Doctrine, the information sphere is understood as a set of information, objects of informatization, information systems and communication networks, information technologies, as well as entities whose activities are related to these technologies and ensuring information security, and mechanisms for regulating the social relations that arise in this case.
2. This Doctrine, based on an analysis of challenges and threats and an assessment of the state of information security of the Russian Federation, identifies the main directions for ensuring national interests in the information sphere from the perspective of implementing strategic national priorities.
3. Legal basis This Doctrine consists of the Constitution of the Russian Federation, generally recognized principles and norms international law and international treaties of the Russian Federation, federal constitutional laws, federal laws, as well as regulatory legal acts of the President of the Russian Federation and the Government of the Russian Federation.
4. This Doctrine is a strategic planning document in the field of ensuring the national security of the Russian Federation, which develops the provisions of the National Security Strategy of the Russian Federation, approved by Decree of the President of the Russian Federation of December 31, 2015 No. 683, and also takes into account the provisions of other strategic planning documents in the Russian Federation Federation in the field of national security.
5. This Doctrine serves as the basis for the formation of state policy in the field of ensuring information security of the Russian Federation, developing measures to improve the information security system of the Russian Federation, including the development of sectoral strategic planning documents of the Russian Federation in the information sphere or affecting this area, as well as for the development of public relations related to activities in the field of information security of the Russian Federation.
6. This Doctrine uses the following basic concepts:
a) the national interests of the Russian Federation (hereinafter referred to as national interests) in the information sphere - the totality of the state’s needs to ensure the security and sustainable development of the individual, society and the state as it relates to the information sphere;
b) information security of the Russian Federation - the state of protection of the individual, society and state from internal and external threats in the information sphere, which ensures the implementation of the constitutional rights and freedoms of citizens of the Russian Federation (hereinafter referred to as citizens), a decent quality and standard of living, sovereignty, territorial integrity and sustainable socio-economic development of the Russian Federation, defense and security of the state;
c) the information security system of the Russian Federation - a set of forces carrying out coordinated and planned activities to ensure the information security of the Russian Federation, and the means they use;
d) forces for ensuring information security of the Russian Federation - government bodies, divisions and officials (authorized) persons of state bodies and organizations of various forms of ownership, solving tasks in accordance with the legislation of the Russian Federation to ensure information security of the Russian Federation;
e) means of ensuring information security of the Russian Federation - organizational, technical, software, hardware and other means used by the forces ensuring information security of the Russian Federation;
f) information infrastructure of the Russian Federation - a set of informatization objects, information systems and communication networks located on the territory of the Russian Federation, territories under the jurisdiction of the Russian Federation or used on the basis of international treaties of the Russian Federation.

II. National interests in the information sphere

7. Information technologies have acquired a global cross-border nature and have become an integral part of all spheres of activity of the individual, society and state. Their effective use is a factor in accelerating the economic development of the state and the formation information society. The information sphere plays an important role in ensuring the implementation of the strategic national priorities of the Russian Federation.
8. National interests in the information sphere are:
a) compliance with the constitutional rights and freedoms of man and citizen in the field of obtaining and using information, including privacy when using information technology, information support for the participation of citizens in government, the political life of society, as well as the preservation of cultural, historical and spiritual-moral values ​​of a multinational the people of the Russian Federation;
b) ensuring the stable and uninterrupted functioning of the information infrastructure of the Russian Federation, including the critical information infrastructure of the Russian Federation and the unified telecommunications network of the Russian Federation, in peacetime, during the period of immediate threat of aggression and in wartime;
c) development of the information technology industry in the Russian Federation, as well as improvement of the activities of industrial, scientific and scientific-technical organizations in the development, production and operation of information security means, provision of services in the field of information security;
d) communicating to the Russian and international public and explaining objective and reliable information about the state policy of the Russian Federation and the official position of its top political leadership on socially significant events in the country and the world, promoting the dissemination of the spiritual and cultural values ​​of the peoples of Russia around the world;
e) promoting the formation of an international legal regime aimed at countering the threats of the use of information technologies to disrupt strategic stability, strengthening equal strategic partnerships in the field of information security, as well as ensuring the sovereignty of the Russian Federation in information space.
9. The implementation of national interests in the information sphere is aimed at the formation safe environment circulation of reliable information in the interests of ensuring the constitutional rights and freedoms of citizens, sustainable socio-economic development of the country, as well as national security.

III. Main threats and current state information security of the Russian Federation

10. The expansion of the areas of use of information technologies, while being a positive factor for economic development and improving the functioning of public and state institutions, at the same time gives rise to new challenges and threats to national security. This is due to the growing tendency to use the possibilities of cross-border information circulation in the information space to achieve geopolitical, military-political and other goals to the detriment of international security and strategic stability, as well as the use of information technologies for terrorist, criminal and other illegal purposes.
11. One of the main negative factors affecting the state of information security of the Russian Federation is the increase in the capabilities of leading foreign countries to exert information and technical influence on the information infrastructure of the Russian Federation, including critical information infrastructure, in order to achieve their military goals. At the same time, technical intelligence is being intensified in relation to Russian government agencies, scientific organizations and enterprises of the military-industrial complex.
12. The scope of the use by special services of individual states of information and psychological influences aimed at destabilizing the internal political and social situation in various regions of the world, leading to the undermining of sovereignty and violation of the territorial integrity of other states, is expanding.
This activity involves religious, ethnic, human rights and other organizations, including public ones, and structures, as well as individual groups of citizens. At the same time, the capabilities of information technology are widely used.
There is a tendency to increase the volume of materials in foreign media containing a biased and biased assessment of the foreign and domestic policies of the Russian Federation. Russian media are often subjected to outright discrimination abroad, and obstacles are created for Russian journalists to carry out their professional activity. The information impact on the population of Russia, primarily on young people, is increasing with the aim of eroding cultural and spiritual values, undermining the moral foundations, historical foundations and patriotic traditions of its multinational people.
13. Various terrorist and extremist organizations widely use mechanisms of information influence on individual, group and public consciousness in order to escalate interethnic and social tension, incite ethnic and religious hatred or enmity, promote extremist ideology, as well as attract new supporters to terrorist activities. To achieve their illegal goals, terrorist and extremist organizations are developing new technologies for destructive influence on critical information infrastructure objects.
14. The scale of computer crime is increasing, primarily in the monetary, foreign exchange, banking and other areas of the financial market, and the number of incidents related to the violation of the legal rights of citizens to protect personal and family secrets, personal data when using information systems and communication networks is increasing. . Methods, ways and means of committing crimes using information technologies are becoming more and more sophisticated.
The increase in threats to information security occurs against the backdrop of the continuing practice of introducing information technologies without linking them with ensuring information security.
15. The state of information security of the Russian Federation in the field of national defense is characterized by an increase in the use of information technologies by foreign states and non-state entities for military-political purposes to carry out actions aimed at undermining the sovereignty, political independence of states and posing a threat to global and regional security.
16. The state of information security of the Russian Federation in the field of state and public safety characterized by a constant increase in the level of complexity, scale and coordination computer attacks on the critical information infrastructure of the Russian Federation and intelligence activities of foreign states against the Russian Federation, as well as the growing threats of using information technologies to damage the sovereignty and territorial integrity of the Russian Federation, political and social stability in society.
17. The state of information security of the Russian Federation in the economic field is characterized by the Russian Federation lagging behind leading foreign countries in the development of competitive information technologies, including supercomputers, and their use to create products and provide services based on them. Remains high level dependence of the domestic economy and industry on foreign information technologies (electronic component base, software, Computer Engineering and means of communication). This state of affairs determines the dependence of the socio-economic development of the Russian Federation on the export policies of foreign countries, pursued by them in order to realize their geopolitical interests.
18. The state of information security of the Russian Federation in the field of science, technology and education is characterized by insufficient effectiveness of scientific research related to the creation of promising information technologies, low level implementation of domestic developments, as well as insufficient staffing in the field of information security.
Measures to ensure the integrity, stability of operation and security of the information infrastructure of the Russian Federation using domestic information technologies and products often do not have a comprehensive basis.

19. The state of information security of the Russian Federation in the field of strategic stability and equal strategic partnership is characterized by the desire of individual states to use technological superiority to dominate the information space. The current distribution of critical Internet resources between countries does not allow for fair shared management them on the principles of interstate trust.
The lack of norms for regulating interstate relations in the information space and corresponding international legal mechanisms that take into account the specifics of information technologies makes it difficult to form an international information security system designed to promote strategic stability and promote equal strategic partnerships.

IV. Main directions of ensuring information security of the Russian Federation

20. The activities of government bodies in the field of ensuring information security of the Russian Federation are based on the following principles:
legality and legal equality of all participants in public relations in the information sphere, based on the constitutional right of citizens to freely search, receive, transmit, produce and disseminate information in any legal way;
maintaining a balance between the need of citizens and society for the free exchange of information and the necessary restrictions on the dissemination of information in order to ensure national security, including in the information sphere;
sufficiency of forces and means to ensure information security of the Russian Federation, determined, among other things, by constant monitoring threats in the information sphere;
compliance with generally accepted principles and norms of international law when carrying out activities to ensure information security of the Russian Federation, taking into account the restrictions established by the legislation of the Russian Federation.
21. The strategic goals of ensuring the information security of the Russian Federation in the field of national defense are the creation of conditions for the peaceful development of the information space and the realization of national interests in the information sphere.
In accordance with the military policy of the Russian Federation, ensuring information security in the field of national defense, as well as the interests of the allies of the Russian Federation, is aimed at:
on strategic containment and prevention of military conflicts that may arise as a result of the aggressive use of information technologies;
to improve the information security system of the Armed Forces of the Russian Federation, other troops, military formations and bodies, including the development of forces and means of information warfare;
to identify, assess and forecast threats to the Russian Federation and its Armed Forces in the information sphere;
to counter information influence on Russian citizens, including those aimed at undermining the historical foundations and patriotic traditions associated with the defense of the Fatherland.

22. The strategic goals of ensuring information security of the Russian Federation in the field of state and public security are strengthening state sovereignty, maintaining political and social stability in society, realizing fundamental rights and freedoms of man and citizen, as well as protecting the critical information infrastructure of the Russian Federation.
Ensuring information security of the Russian Federation in the field of state and public security is aimed at:
to counter the use of information technologies to promote the ideology of terrorism and the spread of ideas of extremism, xenophobia, national exclusivity in order to undermine socio-political stability, forcibly change the foundations of the constitutional system of the Russian Federation, violate its unity and territorial integrity;
to counter intelligence and other activities of special services and organizations of foreign states using technical means and information technologies, as well as individuals, aimed at harming the national security of the Russian Federation;

to increase the security of the critical information infrastructure of the Russian Federation and the sustainability of its functioning, including the development of mechanisms for preventing and detecting threats to information security and eliminating the consequences of their implementation, including protecting the population and territories from emergency situations caused by information and technical impacts on critical infrastructure facilities of the Russian Federation;
to improve the security of the functioning of the information infrastructure of the Russian Federation, including for the sustainable interaction of government authorities, preventing foreign control over its functioning, including ensuring the integrity, stability of operation and security unified network telecommunications of the Russian Federation, as well as ensuring the security of information transmitted through it and processed in information systems on the territory of the Russian Federation;
to improve the safety of operation of weapons, military and special equipment and automated systems management;
to increase the effectiveness of preventing and combating crimes committed using information technologies;
to ensure the protection of information containing information constituting state secrets, other restricted access information, including by increasing the security of the information technologies used;
to improve approaches, methods and methods for the safe use of products and services created on the basis of information technology;
to increase the efficiency of information support for state policy of the Russian Federation;
to neutralize information influences aimed at eroding traditional Russian spiritual and moral values.
23. The strategic goal of ensuring the information security of the Russian Federation in the economic field is to reduce to the minimum possible level the influence on the state of national security of the Russian Federation of negative factors caused by the insufficient development of domestic sectors of information technology and the electronics industry.
Ensuring information security of the Russian Federation in the economic field is aimed at:
to create an innovative information technology and electronics industry that makes a significant contribution to the formation of the country’s gross domestic product;
to achieve the technological independence of the Russian Federation in the field of information technology through the creation, development and widespread implementation of world-class domestic information technologies and information security tools, as well as products and services based on them;
to increase competitiveness Russian companies the information technology industry, including through the creation of favorable conditions for carrying out activities in the Russian Federation;
for the development of domestic competitive electronic component base and technologies for its production, meeting the needs of the domestic market for such products and the entry of these products into the world market.
24. The strategic goal of ensuring the information security of the Russian Federation in the field of science, technology and education is to support the innovative and accelerated development of the information security system of the Russian Federation and the information technology industry.
Ensuring information security of the Russian Federation in the field of science, technology and education is aimed at:
to achieve competitive advantages the Russian information technology industry and the development of scientific and technical potential in the field of ensuring information security of the Russian Federation;
to create information technologies that are fundamentally resistant to various types impacts;
to conduct scientific research and experimental developments in the field of advanced information technologies and information security means;
to increase human resources in the field of information security, as well as information technology;
to create conditions to ensure the protection of citizens from threats of various types when using information technologies, including through the formation of a culture of personal information security.
25. The strategic goal of ensuring information security in the field of strategic stability and equal strategic partnership is the formation of a sustainable system of non-conflict interstate relations in the information space.
Ensuring information security of the Russian Federation in the field of strategic stability and equal strategic partnership is aimed at:
to maintain the sovereignty of the Russian Federation in the information space by implementing an independent and independent policy in order to protect national interests in the information sphere;
to promote the formation of an international information security system that ensures effective counteraction to the use of information technologies for aggressive, terrorist, extremist and criminal purposes;
to create international legal mechanisms that take into account the specifics of information technologies in order to prevent and resolve interstate conflicts in the information space;
on the development of a national management system for the Russian segment of the Internet with the leading role of states in this process.

V. Organizational basis for ensuring information security of the Russian Federation

26. The information security system of the Russian Federation is integral part national security systems.
Ensuring information security is carried out on the basis of a combination of legislative, law enforcement, law enforcement, judicial, control and other forms of activity of government bodies of the Russian Federation in interaction with local governments, organizations of various forms of ownership, public organizations and citizens.
27. The information security system of the Russian Federation is built on the basis of the delimitation of powers of legislative, executive and judicial authorities in this area, taking into account the jurisdiction of federal government bodies, government bodies of constituent entities of the Russian Federation, as well as local government bodies, determined by the legislation of the Russian Federation in security areas.
28. The structure of the information security system of the Russian Federation is determined by the President of the Russian Federation.
29. The main subjects of the organizational basis of the information security system of the Russian Federation are: the Federation Council of the Federal Assembly of the Russian Federation, the State Duma of the Federal Assembly of the Russian Federation, the Government of the Russian Federation, the Security Council of the Russian Federation, federal executive authorities, the Bank of Russia, the Military-Industrial Commission of the Russian Federation , interdepartmental and state commissions created by the President of the Russian Federation and the Government of the Russian Federation, executive authorities of the constituent entities of the Russian Federation, local government bodies, judicial authorities taking part in solving the problems of ensuring information security of the Russian Federation in accordance with the legislation of the Russian Federation.
Participants in the information security system of the Russian Federation are the owners of critical information infrastructure facilities of the Russian Federation and organizations of various forms of ownership that operate these elements; media and mass communication; organization of monetary, foreign exchange, banking sector and other areas of the financial market; telecom operators; information system operators; organizations engaged in the development, production and operation of information security tools, as well as the provision of services in the field of information security; organizations carrying out educational activities in this area; information holders; public associations; other organizations and citizens who, in accordance with the legislation of the Russian Federation, participate in solving problems of ensuring information security of the Russian Federation.
30. As part of ensuring the functioning of the information security system of the Russian Federation, government authorities solve the following tasks:
ensuring the implementation of the rights of citizens and organizations to lawful activities in the information sphere;
monitoring and assessing the state of information security of the Russian Federation, forecasting and identifying threats to information security, identifying priority areas for preventing and neutralizing these threats;
planning, carrying out and assessing the effectiveness of a set of measures aimed at detecting, preventing and promptly eliminating the consequences of the implementation of threats to the information security of the Russian Federation;
organization of activities and coordination of interaction between forces ensuring information security of the Russian Federation;
improvement of regulatory, organizational, technical, operational-search, intelligence, counterintelligence, scientific and technical, information and analytical, personnel and resource support for information security of the Russian Federation;
development and implementation of measures of state support for organizations engaged in the development, production and operation of information security means, provision of services in the field of information security, as well as organizations engaged in educational activities in this area.
31. The development and improvement of the information security system of the Russian Federation is achieved by:
strengthening the vertical and centralizing management of the information security forces of the Russian Federation at the federal, interregional, regional, municipal and facility levels (informatization objects, operators of information systems and communication networks);
improving the forms and methods of interaction between the information security forces of the Russian Federation in order to increase their readiness to counter threats in the information sphere;
improving information, analytical and scientific and technical support functioning of the information security system of the Russian Federation;
increasing the efficiency of interaction between government agencies, local government bodies, organizations of various forms of ownership and citizens when solving problems in the field of information security of the Russian Federation.
32. The implementation of this Doctrine is carried out on the basis of sectoral strategic planning documents of the Russian Federation. In order to update sectoral strategic planning documents, the Security Council of the Russian Federation determines a list of priority areas for ensuring information security of the Russian Federation in the medium term, taking into account the provisions of the strategic forecast of the Russian Federation.
33. Control over the implementation of this Doctrine is carried out by the Security Council of the Russian Federation in accordance with its regulations.
34. The results of monitoring the implementation of this Doctrine are reflected in the annual report of the Secretary of the Security Council of the Russian Federation to the President of the Russian Federation on the state of national security and measures to strengthen it.

PS. Regarding the questions about the already adopted package of Yarovaya laws, in general content and direction it is largely reminiscent of the so-punished “Patriot Act”, which was adopted in the USA after September 11, 2001 with approximately the same justification and which lasted in the USA for 14 years , until it was replaced by the Freedom Act, which somewhat limited the powers of the intelligence services compared to the Patriot Act. I believe that in our case, terrorism is only a pretext for a general expansion of the powers and capabilities of the intelligence services. As I have written more than once, the ongoing Cold War will continue to be accompanied by tightening the screws in the information environment, where Russia will focus on Chinese model control over information. The published draft doctrine as a whole is also in line with this trend, although it may undergo some changes.

7. Law “On State Secrets”

The laws that allow information to be classified as secrets are based on the principles of information sovereignty and international rules. Regulation of relations arising in connection with the classification of information as state secrets, their classification and declassification in the interests of ensuring the security of the Russian Federation is carried out in accordance with the Law “On State Secrets”.

7.1. Basic Concepts

State secret - protected state information in the field of military, foreign policy, economic, intelligence, counterintelligence and operational investigative activities, the dissemination of which could harm the security of the Russian Federation.

Carriers of information constituting state secrets , - material objects, including physical fields, in which information constituting state secrets is reflected in the form of symbols, images, signals, technical solutions and processes.

Classified as classified - details indicating the degree of secrecy of the information contained in their medium, affixed on the medium itself and (or) in the accompanying documentation for it.

Level of secrecy - a category characterizing the importance of such information, possible damage if it is disclosed, the degree of restriction of access to it and the level of its protection by the state.

7.2. List of information constituting state secrets

State secrets are:

I. Information in the military field:

On the content of strategic and operational plans and other combat control documents; on the preparation and conduct of military operations, strategic and mobilization deployment of troops and their most important indicators characterizing the organization, strength, deployment, combat and mobilization readiness, combat and other military training, weapons and logistics of the Armed Forces. border troops and other military formations;

On the direction of development of certain types of weapons and military equipment, their quantity, tactical and technical characteristics, organization and production technology, research and development work related to the development of new types of weapons and military equipment, modernization of existing models, as well as others works planned or carried out in the interests of the country;

On the forces and means of Civil Defense, on the readiness of populated areas, regions and individual objects for the protection, evacuation and dispersal of the population, to ensure their livelihoods and the production activities of national economic facilities in wartime or in other emergency situations;

On geodetic, gravimetric, cartographic, hydrographic and hydrometeorological data and characteristics important for the defense of the country.

