“APPROVED”
President
of the Russian Federation
Vladimir Putin
"9" September 2000, No. Pr-1895
Doctrine of the Information Security of the Russian Federation
The Doctrine of the Information Security of the Russian Federation is the body of official views on the goals, tasks, principles and main directions of ensuring the information security of the Russian Federation.
This Doctrine provides the basis for:
the shaping of the state policy of ensuring the information security of the Russian Federation;
preparation of propositions on improving the legal, methodological, scientific-technical and organizational support of the information security of the Russian Federation;
development of target-specific programs of ensuring the information security of the Russian Federation.
This Doctrine elaborates the Concept of the National Security of the Russian Federation with reference to the information sphere.
I. INFORMATION SECURITY OF THE RUSSIAN FEDERATION
1. The National Interests of the Russian Federation in the Information Sphere and the Securing Thereof
The present stage in the development of society is characterized by the growing role of the information sphere which represents a combination of information, the information infrastructure, the agents that gather, form, disseminate and use information as well as the system of regulating the social relations arising from this. The information sphere, being a pivotal element in the life of society, exerts a strong influence on the state of the political, economic, defense and other components of the security of the Russian Federation. The national security of the Russian Federation depends to a substantial degree on ensuring the information security, a dependence that will increase with technological progress.
By information security of the Russian Federation is meant the protection of its national interests in the information sphere that are determined by the balance of the interests of the individual, society and the state.
The interests of the individual in the information sphere consist in the exercise of the constitutional rights of man and citizen to have access to information, to use information in the pursuit of activities allowed under the law, for the purpose of physical, spiritual and intellectual development as well as in the protection of the information that ensures personal security.
The interests of society in the information sphere consist in ensuring the interests of the individual in that sphere, in strengthening democracy, in creating a rule-of-law social state, in achieving and maintaining social harmony and spiritual renewal of Russia.
The interests of the state in the information sphere consist in creating conditions for harmonious development of the Russian information infrastructure, for the exercise of the constitutional rights and freedoms of man and citizen in obtaining information and using it for the purpose of ensuring the immutability of the constitutional system, the sovereignty and territorial integrity of Russia, political, economic and social stability, in unconditionally ensuring legality, law and order, and promoting equal and mutually beneficial international cooperation.
Based on the national interests of the Russian Federation in the information sphere, the strategic and current tasks are determined in the domestic and foreign policy of the state aimed at ensuring information security.
Four main components of the national interests of the Russian Federation in the information sphere can be identified.
The first component of the national interests of the Russian Federation in the information sphere includes respect of the constitutional rights and freedoms of man and citizen in obtaining and using information, spiritual renewal of Russia, the preservation and strengthening of the moral values of society, the traditions of patriotism and humanism, the cultural and scientific potential of the country.
To achieve this it is required:
to use the information infrastructure more effectively in the interests of social development, consolidation of the Russian society and the spiritual revival of the multinational people of the Russian Federation;
to improve the system of forming, storing and rational use of the information resources which constitute the basis of the scientific, technological and spiritual potential of the Russian Federation;
to secure the constitutional rights and freedoms of man and citizen to freely search for, obtain, transfer, produce and disseminate information by any legal methods, and to obtain authentic information on the state of the environment;
to ensure the constitutional rights and freedoms of man and citizen to personal and family secrets, the secret of correspondence, telephone conversations, postal, telegraph and other messages, to the protection of one's honor and good name;
to strengthen the mechanisms of legal regulation of relations in the protection of intellectual property, to create conditions for compliance with the restrictions on access to confidential information established under the federal laws;
to guarantee freedom of mass information and a ban on censorship;
not to allow propaganda and agitation that contribute to the kindling of social, racial, national or religious hatred and hostility;
to enforce a ban on the collection, storage, use and dissemination of information on the private life of a person without that person's consent and other information to which access is limited under the federal legislation.
The second component of the national interests of the Russian Federation in the information sphere comprises information support of the state policy of the Russian Federation in bringing to the Russian and international public accurate information on the state policy of the Russian Federation, its official position on socially significant events in Russian and international life, with the provision of public access to open state information resources.
To achieve this it is required:
to strengthen the state mass media, to expand their potential for providing Russian and foreign citizens with authentic information in a timely manner;
to intensify the shaping of open state information resources and to husband them more effectively.
The third component of the national interests of the Russian Federation in the information sphere includes the development of modern information technologies, a domestic information industry, including an industry of informatization and telecommunications means, providing for the needs of the internal market with its products and putting these products in the world market as well as ensuring the accumulation, storage and effective use of national information resources. Under present-day conditions it is only on this basis that the problem of creating science-intensive technologies, technical modernization of industry and multiplying the achievements of the domestic science and technology can be solved. Russia must occupy a worthy place among world leaders in the microelectronics and computer industry.
To achieve this it is required:
to develop and improve the infrastructure of the single information space of the Russian Federation;
to develop the national industry of information services and use the state information resources more effectively;
to develop the production in the Russian Federation of competitive means and systems of informatization and telecommunications, to broaden the participation of Russia in international cooperation of the producers of such means and systems;
to ensure state support of national fundamental and applied research and development in the sphere of informatization and telecommunications.
The fourth component of the national interests of the Russian Federation in the information sphere comprises protection of information resources against unauthorized access, ensuring the safety of information and telecommunications systems both already deployed and being created on the territory of Russia.
To this end it is required:
to enhance the security of information systems, including communications networks, above all, the security of primary communications networks and information systems of the federal bodies of state power, the bodies of state power of the subjects of the Russian Federation, the financial and credit and banking spheres, the sphere of economic activities as well as the systems and means of informatization of armaments and military equipment, the systems of control of troops and weapons, environmentally hazardous and economically critical production facilities;
to intensify the development of the domestic production of hardware and software to protect information and methods to monitor the effectiveness thereof;
to ensure the protection of data constituting a state secret;
to broaden the international cooperation of the Russian Federation in the field of development and safe use of information resources and countering the threat of the unleashing of confrontation in the information sphere.
2. Types of Threats to the Information Security of the Russian Federation
In terms of their general thrust the threats to the information security of the Russian Federation are divided into the following types:
threats to the constitutional rights and freedoms of man and citizen in spiritual life and information activities, to individual, group and social consciousness and the spiritual revival of Russia;
threats to the information security of state policy in the Russian Federation;
threats to the development of the national information industry, including the industry of means of informatization and telecommunications, to the meeting of the domestic market demands in its production and to the emergence of these products in the world market as well as to ensuring the accumulation, storage and effective use of national information resources;
threats to the security of information and telecommunications means and systems, both already deployed and being created on the territory of Russia.
The following may be the threats to the constitutional rights and freedoms of man and citizen in the field of spiritual life and information activities, to individual, group and social consciousness and the spiritual revival of Russia:
the adoption by the federal bodies of state power, the bodies of state power of the subjects of the Russian Federation of regulatory legal acts that infringe upon the constitutional rights and freedoms of citizens in spiritual life and information activities;
the establishment of monopolies on the creation, obtaining and dissemination of information in the Russian Federation, including with the use of telecommunications systems;
obstruction, including by criminal structures, of the exercise by citizens of their constitutional rights to personal and family secrets, the secret of correspondence, telephone conversations and other messages;
irrational and excessive restrictions on the access to publicly vital information;
illegal use of special means of influence on individual, group and social consciousness;
non-compliance by federal bodies of state power, the bodies of state power of the subjects of the Russian Federation, the bodies of local government, organizations and citizens with the requirements of the federal law regulating the relations in the information sphere;
unlawful restriction of access of citizens to open information resources of the federal bodies of state power, the bodies of state power of the subjects of the Russian Federation, the bodies of local government, open archive materials and other open socially significant information;
disorganization and destruction of the system of accumulation and storage of cultural values including archives;
violation of the constitutional rights and freedoms of man and citizen in the realm of mass information;
the ouster of Russian information agencies and mass media from the internal information market and the strengthening of dependence on the spiritual, economic and political spheres of social life in Russia on foreign information structures;
depreciation of spiritual values, the promotion of specimens of mass culture based on the cult of violence, on spiritual and moral values that contradict the accepted values of Russian society;
the lowering of the spiritual, moral and creative potential of the Russian population which would significantly complicate the preparation of labor resources for the introduction and use of the latest technologies, including information technologies;
manipulation of information (disinformation, concealment or distortion of information).
The following may be the threats to the information support of the state policy of the Russian Federation:
monopolization of the information market in Russia and its individual sectors by domestic and foreign information entities;
the blocking of the activities of state mass media in informing the Russian and foreign audiences;
poor information support of the state policy of the Russian Federation due to a shortage of skilled personnel, the lack of a system of forming and implementing the state information policy.
The following may be the threats to the development of the domestic information industry, including the industry of the means of informatization and telecommunications and to the needs of the internal market for its products and the entry of these products into the world market as well as to ensuring the accumulation, storage and effective use of the national information resources:
obstructing the access of the Russian Federation to the latest information technologies, mutually beneficial and equal participation of Russian producers in the world division of labor in the industry of information services, means of informatization and telecommunications, information products as well as the creation of conditions for greater technological dependence of Russia in the field of modern information technologies;
the purchase by the bodies of state power of imported means of informatization and telecommunications even as domestic analogs exist which are not inferior to foreign specimens in terms of their characteristics;
the ouster of Russian producers of means of informatization and telecommunications from the domestic market;
growing outflow of specialists and holders of intellectual property rights abroad.
The following may be the threats to the security of information and telecommunications means and systems, both already deployed and being created on the territory of Russia:
unlawful collection and use of information;
non-compliance with the technology of information processing;
the introduction in the hardware and software products of components performing functions not stipulated in the documentation covering these products;
the development and dissemination of programs that disrupt the normal functioning of information and telecommunications systems, including the systems of information protection;
the break-up, damage, radio-electronic suppression or destruction of the means and system of information processing and telecommunications;
tampering with password and key systems protecting computerized systems of information processing and transmission;
the compromising of keys and means of cryptographic protection of information;
leakage of information through technical channels;
the introduction of electronic devices to intercept information into technical means of the processing, storage and transmission of information through communication channels as well as into the offices of the bodies of state power, enterprises, institutions and organizations irrespective of the form of ownership;
destruction, causing damage to, breaking up or stealing of machine and other information carriers;
interception of information in data transmission networks and communication lines, decoding of such information and imposition of false information;
the use of uncertified domestic and foreign information technologies, means of information protection, means of informatization and telecommunications in the creation and development of the information infrastructure in Russia;
unauthorized access to information contained in data banks and bases;
violation of lawful restrictions on the dissemination of information.
3. Sources of Threats to the Information Security of the Russian Federation
The sources of threats to the information security of the Russian Federation are divided into external and internal ones. The external sources include:
the activities of foreign political, economic, military, intelligence and information structures aimed against the interests of the Russian Federation in the information sphere;
the desire of some countries to dominate and infringe upon the interests of Russia in the world information space and to oust it from the external and internal information markets;
growing international competition for the possession of information technologies and resources;
the activities of international terrorist organizations;
the widening of the technological lead of the main world powers and the buildup of their potential to counteract the creation of competitive Russian information technologies;
the activities of space, air, sea and land technical and other means (types) of intelligence of foreign states;
the development by a number of states of the concepts of information warfare envisaging the creation of dangerous means of influencing the information spheres in other countries of the world, the disruption of the normal functioning of information and telecommunications systems, the information resources and gaining unauthorized access to them.
Internal sources include:
the critical state of the domestic industry;
the unfavorable crime situation accompanied by the tendency of the merger of state and criminal structures in the information sphere, the gaining of access by criminal structures to confidential information, the growing influence of organized crime on the life of society, the decline in the level of protection of the legitimate interests of citizens, society and the state in the information sphere;
inadequate coordination of the activities of the federal bodies of state power and the bodies of state power of the subjects of the Russian Federation in the development and implementation of a single state policy in ensuring the information security of the Russian Federation;
insufficiently developed regulatory legal framework regulating the relations in the information sphere as well as inadequate law enforcement;
insufficient development of the institutions of civil society and insufficient state control over the development of the information market in Russia;
inadequate financing of measures to ensure the information security of the Russian Federation;
insufficient economic strength of the state;
a decline in the effectiveness of the system of education and upbringing, insufficient number of qualified workers in the field of ensuring information security;
inadequate efforts of the federal bodies of state power and the bodies of state power of the subjects of the Russian Federation to inform society of their activities, explain the decisions taken and form open state resources and develop a system of citizens' access to them;
Russia's lag behind the leading countries of the world in terms of informatization of the federal bodies of state power and the bodies of state power of the subjects of the Russian Federation and bodies of local self-government, the credit and finance sphere, industry, agriculture, education, health, the services and welfare of citizens.
4. The State of the Information Security of the Russian Federation and the Main Tasks in Ensuring It
In recent years the Russian Federation has implemented a set of measures to upgrade its information security.
A beginning has been made to creating the legal framework for information security. The Law of the Russian Federation On State Secret, the Basic Principles of the Legislation of the Russian Federation on the Archive Fund of the Russian Federation and Archives, the federal laws On Information, Informatization and Information Protection, On Participation in International Information Exchange and a number of other laws have been adopted and work has begun to create the mechanisms of their implementation, to prepare draft laws regulating social relations in the information sphere.
Measures have been implemented to ensure information security in the federal bodies of state power, the bodies of state power of the subjects of the Russian Federation, in enterprises, institutions and organizations irrespective of the form of ownership. Work has got underway to create a protected information and telecommunications special-purpose system in the interests of the bodies of state power.
Contributing to success in ensuring the information security of the Russian Federation are the state system of information protection, the system of protecting state secrets, the system of licensing activities in protecting state secrets and the system of certification of information protection means.
At the same time an analysis of the state of the information security of the Russian Federation shows that its level does not quite correspond to the needs of society and the state.
The present-day political and social-economic conditions in the country tend to exacerbate the contradictions between the needs of society to expand free exchange of information and the need to preserve certain regulated restrictions on its dissemination.
The conflicting and undeveloped legal regulation of social relations in the information sphere leads to serious negative consequences. Thus, inadequate legal regulation of the relations in using the possibilities of constitutional restrictions on media freedom in the interests of protecting the foundations of the constitutional system, morality, health, the rights and legitimate interests of citizens, ensuring the country's defenses and the security of the state substantially hampers the maintenance of the necessary balance between the interests of the individual, society and the state in the information sphere. Inadequate legal regulation of relations in the field of mass media makes it more difficult to form competitive Russian information agencies and mass media on the territory of the Russian Federation.
Denial of citizens' rights to access information and manipulation of information provoke a negative reaction of the population which in some cases destabilizes the social and political situation in society.
The rights of citizens to privacy, personal and family secrets, the secret of correspondence enshrined in the Constitution of the Russian Federation do not, in practice, have adequate legal, organizational and technical support. The protection of data on natural persons (personal data) gathered by the federal bodies of state power, the bodies of state power of the subjects of the Russian Federation and the bodies of local self-government is unsatisfactory.
There is no clarity in the implementation of the state policy in the shaping of the Russian information space, the development of the system of mass information, organizing international information exchange and integration of the Russian information space into the world information space, which creates conditions for the ousting of Russian information agencies and mass media from the internal information market and the distortion of the structure of international information exchange.
State support of the activities of Russian information agencies in promoting their products in the foreign information market is inadequate.
The situation surrounding the safety of data constituting state secrets is deteriorating.
The human resource potential of the scientific and production collectives operating in the field of creating means of informatization and telecommunications has been seriously depleted by the wide-scale drift-away of the best-qualified specialists from these teams. The domestic information technology lag forces the federal bodies of state power, the bodies of state power of the subjects of the Russian Federation and the bodies of local self-government, in creating their information systems, to purchase imported technology and bring in foreign firms, which increases the probability of unauthorized access to the information being processed and the dependence of Russia on foreign producers of computer and telecommunications hardware and software.
The massive introduction of foreign information technologies in the activities of individuals, society and the state as well as wide-scale use of open information and telecommunications systems and the integration of the domestic information systems and international information systems increases the threats of the use of the "information weapon" against the information infrastructure of Russia. Work to counteract these threats in an effective and comprehensive manner is not coordinated well enough and is poorly financed. Not enough attention is paid to the development of space intelligence and radio-electronic warfare means.
The current state of affairs in the field of ensuring the information security of the Russian Federation requires that the following tasks should be addressed without delay:
the development of guidelines of the state policy in ensuring the information security of the Russian Federation as well as measures and mechanisms involved in implementing such policy;
the development and improvement of the system of ensuring the information security of the Russian Federation which follows a single state policy in the field, including the improvement of the forms, methods and means of identifying, assessing and forecasting threats to the information security of the Russian Federation as well as a system of counteracting such threats;
the development of federal target programs of ensuring the information security of the Russian Federation;
the development of criteria and methods of assessing the effectiveness of the systems and means of ensuring the information security of the Russian Federation as well as certification of such systems and means;
improving the regulatory legal framework for ensuring the information security of the Russian Federation, including mechanisms for the exercise of citizens' rights to obtain and access information, the forms and methods of the implementation of the legal standards pertaining to the interaction between the state and the mass media;
determining the responsibility of the officials of the federal bodies of state power, the bodies of state power of the subjects of the Russian Federation, the bodies of local self-government, legal entities and citizens for complying with the requirements of information security;
coordinating the activities of the federal bodies of state power, the bodies of state power of the subjects of the Russian Federation, enterprises, institutions and organizations irrespective of the form of ownership in ensuring the information security of the Russian Federation;
developing the scientific and practical principles of ensuring the information security of the Russian Federation with due regard for the current geopolitical situation, the political and social-economic conditions in Russia and the reality of the threat of the use of the "information weapon";
developing and establishing mechanisms for the formation and implementation of the national information policy of Russia;
developing the methods to make more effective the participation of the state in the shaping of the information policy of state-owned television and radio broadcasting organizations and other state-owned mass media;
ensuring the technological independence of the Russian Federation in key areas of informatization and telecommunications that determine its security, in the first place in the development of specialized computer technology, for specimens of weapons and military equipment;
developing modern methods and means of protecting information, ensuring the security of information technologies, above all, those used in the systems of control of troops and weapons, environmentally hazardous and economically important production facilities;
developing and improving the state system of information protection and the system of protecting state secrets;
the creation and development of a modern protected technological basis of state control in peacetime, in emergency situations and in wartime;
broadening the interaction with international and foreign bodies and organizations in addressing the scientific-technical and legal issues of ensuring the security of information transmitted via international telecommunications system;
ensuring conditions for vigorous development of the Russian information infrastructure, the participation of Russia in the processes of establishment and use of global information networks and systems;
the creation of a uniform system of training personnel in the field of information security and information technologies.
II. METHODS OF ENSURING THE INFORMATION SECURITY OF THE RUSSIAN FEDERATION
5. General Methods of Ensuring the Information Security of the Russian Federation
The general methods of ensuring the information security of the Russian Federation are divided into legal, organizational-technical, and economic.
The legal methods of ensuring the information security of the Russian Federation include the development of the legal acts regulating the relations in the information sphere and regulatory methodological documents on ensuring the information security of the Russian Federation. The most important areas of this activity are:
introducing amendments and additions to the laws of the Russian Federation regulating the relations in ensuring information security for the purpose of creating and improving the system of ensuring the information security of the Russian Federation, eliminating internal contradictions in federal legislation, the contradictions related to international agreements to which the Russian Federation has acceded and the contradictions between the federal laws and the laws of the subjects of the Russian Federation as well as for the purpose of specifying the legal norms which envisage liability for violations in the field of ensuring the information security of the Russian Federation;
legislation to separate the powers in the field of ensuring the information security of the Russian Federation between the federal bodies of state power, bodies of state power of the subjects of the Russian Federation, identifying the goals, tasks and mechanisms of the participation of non-governmental associations, organizations and citizens in these activities;
development and adoption of regulatory legal acts of the Russian Federation which envisage the responsibility of legal entities and natural persons for unauthorized access to information, its unlawful copying, distortion and illegal use, deliberate dissemination of false information, unlawful disclosure of confidential information, the use of in-house information or information containing commercial secrets for criminal or selfish purposes;
defining more clearly the status of foreign information agencies, mass media and journalists as well as investors if foreign investments are attracted into the development of the information infrastructure of Russia;
passing legislation to confirm the priority of the development of national communications networks and domestic production of communications satellites;
defining the status of the organizations which render the services of global information and telecommunications networks on the territory of the Russian Federation and legal regulation of the activities or these organizations;
developing a legal framework for creating regional structures ensuring information security in the Russian Federation.
The organizational and technical methods of ensuring the information security of the Russian Federation are:
the establishment and improvement of the system of ensuring the information security of the Russian Federation;
intensifying the law-enforcement activities of the federal bodies of executive power, the bodies of executive power of the Russian Federation, including prevention and stopping of violations in the information sphere as well as detection, exposure and punishment of the individuals who have perpetrated crimes and other offenses in this sphere;
developing, using and improving the means of information protection and methods to monitor the effectiveness of these means, the development of protected telecommunications systems and making the special-purpose software more reliable;
creating systems and means to prevent unauthorized access to the information being processed and special actions that cause the breakup, destruction and distortion of information as well as a change in operating procedures of the systems and means of informatization and communication;
revealing the technical devices and software which pose a threat to the normal functioning of the information and telecommunications system, preventing the interception of information in technical channels, the application of cryptographic means to protect information in the process of storage, processing and transmission via communication channels, monitoring compliance with the special information protection requirements;
certification of the means of information protection, licensing of activities in the field of protecting state secrets, standardization of the methods and means of information protection;
improving the system of certification of telecommunications equipment and software in management information systems based on information security requirements;
controlling the actions of the personnel in protected information systems, and training personnel in the field of ensuring the information security of the Russian Federation;
creating a system of monitoring the indicators and characteristics of the information security of the Russian Federation in key spheres of life and the activities of society and the state.
The economic methods of ensuring the information security of the Russian Federation include:
developing the programs of ensuring the information security of the Russian Federation and determining the procedure of financing them;
improving the system of financing of the works to implement the legal and organizational-technical methods of information protection, creating a system of insurance of natural persons and legal entities against information risks.
6. Special Features of Ensuring the Information Security of the Russian Federation in Various Spheres of Social Life
The information security of the Russian Federation is a component of the national security of the Russian Federation which is relevant to the protection of the national interests of the Russian Federation in various areas of the life of society and the state. Threats to the information security of the Russian Federation and methods of ensuring it are common to all these spheres.
Yet in each of these spheres there are special features of ensuring information security stemming from the specific nature of the objects of security, the degree of their vulnerability to the threats to the information security of the Russian Federation. In each area of the life of society and the state, along with the common methods of ensuring the information security of the Russian Federation, special methods and forms may be used in accordance with the specific factors that influence the state of the information security of the Russian Federation.
In the economic sphere. Ensuring the information security of the Russian Federation in the economic sphere plays the key role in ensuring the national security of the Russian Federation.
The areas of the economy most exposed to the threats to the information security of the Russian Federation are:
the system of state statistics;
the credit and financial system;
information and accounting computerized systems in the divisions of the federal bodies of executive power which ensure economic activities of society and the state;
the systems of accounting at enterprises, institutions and organizations irrespective of the form of ownership;
the system of collecting, processing, storage and transmission of financial, exchange, tax and customs information and information on the foreign economic activities of the state as well as enterprises, institutions and organizations irrespective of the form of ownership.
The transition to market relations in the economy has brought to the internal Russian market of goods and services a multitude of domestic and foreign commercial entities which produce and consume information, means of informatization and information protection. Uncontrolled activities of these entities in creating and protecting the systems of gathering, processing, storage and transmission of statistical, financial, exchange, tax and customs information pose a real threat to the economic security of Russia. Similar threats arise from uncontrolled involvement of foreign firms in the creation of such systems because it offers favorable conditions for unauthorized access to confidential economic information and for the monitoring of the processes of its transmission and processing by foreign special services.
The critical state of the enterprises of the national industries which develop and produce means of informatization, telecommunications and information protection leads to wide-scale use of corresponding imported means which threatens to make Russia technologically dependent on foreign states.
Computer crime involving the breaking of criminal elements into computer systems and the networks of banks and other credit institutions poses a serious threat to the normal functioning of the economy.
The inadequate regulatory legal framework that spells out the liability of agents in the economy for providing false information or concealing information on their commercial activities, the consumer qualities of their goods and services, the results of their economic activities, investments and so on, impedes the normal functioning of economic entities. At the same time substantial economic damage to economic entities may be caused by the disclosure of commercial secrets. In the systems of gathering, processing, storage and transmission of financial, exchange, tax and customs information unlawful copying of information and its distortion as a result of deliberate or accidental violations of the technology of work with information and unauthorized access to information pose the greatest danger. This applies to the federal bodies of executive power which form and disseminate information on the foreign economic activities of the Russian Federation.
The main measures to ensure the information security of the Russian Federation in the economic sphere are:
organizing and exercising state control over the creation, development and protection of the systems and means of gathering, processing, storage and transmission of statistical, financial, exchange, tax and customs information;
drastic restructuring of the system of the state statistical reporting to ensure authenticity, completeness and protection of information by introducing strict legal liability of officials for the preparation of the basic information, organization of control over the activities of such persons and the statistical information processing and analysis services as well as by limiting the commercialization of such information;
the development of national certified means of protecting information and the introduction thereof in the systems and means of gathering, processing, storage and transmission of statistical, financial, exchange, tax and customs information;
the development and introduction of national protected system of electronic payments on the basis of smart cards, the systems of electronic money and electronic trade, standardization of such systems as well as the development of a regulatory legal base for the use thereof;
the development of the regulatory legal framework of information relations in the economic sphere;
the improvement of the methods of selecting and training personnel to work in the systems of gathering, processing, storage and transmission of economic information.
In the sphere of internal politics. The most important objects of ensuring the information security of the Russian Federation in the sphere of internal politics are:
constitutional rights and freedoms of man and citizen;
the constitutional system, national harmony, the stability of state power, the sovereignty and territorial integrity of the Russian Federation;
open information resources of the federal bodies of executive power and the mass media.
In the sphere of internal politics the following are the key threats to the information security of the Russian Federation:
violation of the constitutional rights and freedoms of citizens in the information sphere;
inadequate legal regulation of the rights of various political forces to use the mass media to propagate their ideas;
dissemination of disinformation on the policy of the Russian Federation, the activities of the federal bodies of state power and the events taking place in and outside the country;
the activities of non-governmental associations aimed at violent change of the foundations of the constitutional system and breakup of the integrity of the Russian Federation, fomenting of social, racial, national and religious hostility, and disseminating these ideas in the mass media.
The main measures in ensuring the information security of the Russian Federation in the sphere of internal politics are:
creating a system of counteraction to the monopolization by domestic and foreign structures of the components of the information infrastructure, including the market of information services and the mass media;
stepping up counter-propaganda activities aimed at preventing the negative consequences of the dissemination of disinformation about the internal policy of Russia.
In the sphere of external policy. The key objects of ensuring the information security of the Russian Federation in the sphere of external policy are:
the information resources of the federal bodies of executive power implementing the external policy of the Russian Federation, the Russian missions and organizations abroad, the missions of the Russian Federation to international organizations;
the information resources of the missions of the federal bodies of executive power which implement the external policy of the Russian Federation on the territories of the subjects of the Russian Federation;
the information resources of the Russian enterprises, institutions and organizations subordinate to the federal bodies of executive power implementing the foreign policy of the Russian Federation;
the blocking of the activities of the Russian mass media to explain to the foreign audiences the goals and main guidelines of the state policy of the Russian Federation and its opinion on socially significant events in Russian and international life.
Among the foreign threats to the information security of the Russian Federation in the sphere of foreign policy the following are the most dangerous:
the information influence of foreign political, economic, military and information structures on the development and implementation of the Russian foreign policy strategy;
dissemination abroad of disinformation on the foreign policy of the Russian Federation;
the violation of the rights of Russian citizens and legal entities in the information sphere abroad;
attempts at gaining unauthorized access to information and to influence the information resources and the information infrastructure of the federal bodies of executive power which implement the foreign policy of the Russian Federation, the Russian missions and organizations abroad, the missions of the Russian Federation to international organizations.
Among the internal threats to the information security of the Russian Federation in the sphere of external policy the following are the most dangerous:
violations of the established procedure of gathering, processing, storage and transmission of information at the federal bodies of executive power which implement the foreign policy of the Russian Federation and the enterprises, institutions and organizations within their jurisdiction;
the information and propaganda activities of political forces, non-governmental associations, mass media and individuals which distort the strategy and tactics of the foreign policy activities of the Russian Federation;
insufficient provision of information to the population on the foreign policy activities of the Russian Federation.
The main measures ensuring the information security of the Russian Federation in the sphere of foreign policy are:
developing the guidelines of the state policy in improving the information support of the foreign policy of the Russian Federation;
development and implementation of a complex of measures to strengthen the information security of the information infrastructure of the federal bodies of executive power which implement the foreign policy of the Russian Federation, Russian missions and organizations abroad and the missions of the Russian Federation to international organizations;
the creation for Russian missions and organizations abroad of conditions for work to neutralize the disinformation being disseminated there on the foreign policy of the Russian Federation;
improving the information support of the work to counteract the violations of the rights and freedoms of Russian citizens and legal entities abroad;
improving the information support of the subjects of the Russian Federation on matters of foreign policy activities within their jurisdiction.
In the field of science and technology. The most important objects of ensuring the information security of the Russian Federation in the field of science and technology are:
the results of fundamental, exploratory and applied scientific research potentially vital for scientific, technological, social and economic development of the country including the information whose loss may cause damage to the national interests and prestige of the Russian Federation;
discoveries, unpatented technologies, industrial prototypes, usable models and experimental equipment;
scientific and technological personnel and the system of their training;
the systems of controlling sophisticated research complexes (nuclear reactors, particle accelerators, plasma generators and others).
Among the main external threats to the information security of the Russian Federation in the field of science and technology are:
the intention of developed foreign states to gain unlawful access to the scientific and technological resources of Russia in order to use the results obtained by Russian scientists in their own interests;
creating advantages in the Russian market for foreign scientific and technological products and the desire of developed countries to limit the development of the scientific and technical potential of Russia (by purchasing the shares of advanced enterprises with subsequent change of their core business, retaining export and import restrictions and so on);
the policy of Western countries aimed at continued destruction of the common scientific and technological space of the states -- members of the Commonwealth of Independent States inherited from the USSR by reorienting their scientific and technical links and some of the more promising scientific collectives to the Western countries;
stepping up the activities of foreign state and commercial enterprises, institutions and organizations in the field of industrial espionage with the participation of intelligence and special services.
Among the main internal threats to the information security of the Russian Federation in the field of science and technology are:
the persisting difficult economic situation in Russia leading to a dramatic reduction in the funding of scientific and technical activities, temporary decline in the prestige of science and technology, the leakage of ideas and cutting-edge developments abroad;
the inability of the enterprises in the national electronics industry to produce, on the basis of the latest micro-electronics achievements and advanced information technologies, competitive science-intensive products that would ensure an adequate level of technological independence of Russia from foreign countries which leads to forced wide-scale use of imported hardware and software in creating and developing the information infrastructure in Russia;
serious problems in the field of patent protection of the results of scientific and technological activities of Russian scientists;
difficulties in implementing measures to protect information, especially in privatized enterprises, scientific and technological institutions and organizations.
A realistic way to counter the threats to the information security of the Russian Federation in the field of science and technology is to improve the laws of the Russian Federation regulating relations in this field and the mechanisms of their implementation. To this end the state must seek to create a system of evaluation of the possible damage from the threats to the key objects of ensuring the information security of the Russian Federation in the field of science and technology, including independent scientific councils and independent expert organizations that work out recommendations for the federal bodies of state power and bodies of state power of the subjects of the Russian Federation o how to prevent unlawful or ineffective use of the intellectual potential of Russia.
In the spiritual sphere. Ensuring the information security of the Russian Federation in the spiritual sphere aims to protect the constitutional rights and freedoms of man and citizen connected with the development, growth and behavior of the individual, freedom of mass information, the use of the cultural, spiritual and moral heritage, historical traditions and norms of social life, with the preservation of the cultural legacy of all the peoples of Russia, realization of the constitutional restrictions of the rights and freedoms of man and citizen in the interests of preserving and strengthening the moral values of society, the traditions of patriotism and humanism, the health of citizens, the cultural and scientific potential of the Russian Federation, and ensuring the defense capability and security of the state.
Among the main objects of ensuring the information security of the Russian Federation in the sphere of spiritual life are:
the dignity of the individual, freedom of conscience, including the right to freely choose, hold and disseminate religious and other convictions and to act in accordance with them, freedom of thought and expression (with the exception of propaganda or agitation that incite social, racial, national or religious hatred or hostility) as well as the freedom of literary, artistic, scientific, technical and other types of creativity and teaching;
freedom of the mass media;
privacy, personal and family secrets;
the Russian language is a factor of spiritual unity of the peoples of multinational Russia, the language of communication between the peoples of the states -- members of the Commonwealth of Independent States;
the languages, moral values and cultural heritage of the peoples of the Russian Federation, large and small;
objects of intellectual property.
The greatest danger in the sphere of spiritual life is posed by the following threats to the information security of the Russian Federation:
distortion of the system of mass information both by monopolizing the mass media and by uncontrolled expansion of the foreign media sector in the domestic information space;
the deterioration and decay of the objects of the Russian cultural heritage, including archives, museum collections, libraries and architecture monuments due to underfinancing of corresponding programs and activities;
possible disruptions of social stability, damage to the health and threat to the lives of citizens due to the activities of religious associations that preach religious fundamentalism as well as totalitarian religious sects;
the use by foreign special services of the mass media operating on the territory of the Russian Federation to damage the defense capability of the country and the security of the state and to disseminate disinformation;
the inability of the contemporary civil society in Russia to inculcate to the young generation and maintain in society the socially vital moral values, patriotism and a sense of civic responsibility for the destiny of the country.
The main areas in ensuring the information security of the Russian Federation in the sphere of spiritual life are:
the development of the fundamentals of a civil society in Russia;
the creation of social and economic conditions for the creative activities and the functioning of cultural institutions;
working out civilized forms and methods of social control over the shaping, in society, of spiritual values that meet the national interests of the country, the fostering of patriotism and a sense of civic responsibility for the destinies of the country;
improving the legislation of the Russian Federation that regulates the relations regarding constitutional restrictions of the rights and freedoms of man and citizen;
state support of measures to preserve and revive the cultural heritage of the large and small peoples in the Russian Federation;
the formation of legal and organizational mechanisms for ensuring the constitutional rights and freedoms of citizens, raising their legal awareness in order to counteract conscious or unconscious violation of such constitutional rights and freedoms in the spiritual sphere;
developing effective organizational and legal mechanisms to ensure the access of the mass media and citizens to unclassified information on the activities of the federal bodies of state power and non-governmental associations, ensuring the provision of authentic data on socially significant events in social life distributed through the mass media;
developing special legal and organizational mechanisms to prevent unlawful information and psychological influences on the mass consciousness, uncontrolled commercialization of culture and science and to ensure the preservation of the cultural and historical values of the large and small peoples of the Russian Federation, rational use of the information resources of society that constitute part of the national heritage;
introducing a ban on the use of air time in the electronic media to distribute the programs that propagate violence and cruelty and anti-social behavior;
countering the negative impact of foreign religious organizations and missionaries.
In national information and telecommunications systems. The main objects of ensuring the information security of the Russian Federation in national information and telecommunications systems are:
the information resources containing data classified as state secrets and confidential information;
the means and systems of informatization (computers, information and computer complexes, networks and systems), software (operational systems, database management systems and other systemic and applied software support);
management information systems, the systems of communication and data transmission that receive, process, store and transmit limited-access information and their informative physical fields;
the technical means and systems that process publicly accessible information and are located in the premises in which limited-access information is also processed as well as the actual premises intended for the processing of such information;
the premises intended for the conduct of secret negotiations as well as negotiations in the course of which limited-access data are mentioned.
The main threats to the information security of the Russian Federation in the national information and telecommunications systems are:
the activities of the special services of foreign states, criminal communities, organizations and groups, unlawful activities of individuals aimed at gaining unauthorized access to information and controlling the functioning of information and telecommunications systems;
the forced use, due to the lag of the domestic industry, or imported software and hardware in the creation and development of information and telecommunications systems;
the violation of the established procedure of gathering, processing and transmitting information, deliberate actions and errors of the personnel of information and telecommunications systems, malfunctions of the hardware and breakdowns in software support in information and telecommunications systems;
the use of means and systems of informatization and communications that are uncertified in terms of safety requirements as well as of means of protection of information and control of their effectiveness;
the involvement in work to create, develop and protect information and telecommunications systems of organizations and firms which hold no state licenses for engaging in these types of activities.
The main areas of ensuring the information security of the Russian Federation in the national information and telecommunications systems are:
preventing the interception of information from premises and objects as well as information transmitted through communications channels by technical means;
ruling out unauthorized access to the information being processed or stored in hardware;
preventing the leakage of information through technical channels arising in the process of operating the hardware for its processing, storage and transmission;
preventing special software and hardware interventions causing the breakdown, destruction, distortion of information or malfunctions in the work of the informatization means;
ensuring information security when hooking up national information and telecommunications systems to external, including international, information networks;
ensuring the safety of confidential information at the interface of information and telecommunications systems with varying degrees of protection;
detecting information intercept devices planted into objects and the electronic hardware.
The main organizational and technical measures to protect the information in national information and telecommunications systems are:
the licensing of the activities of organizations in the field of information protection;
attestation of the objects of informatization for compliance with the requirements of information protection in the conduct of works connected with the use of data that constitute a state secret;
certification of the means of protecting information and controlling the effectiveness of their use as well as the protection of information against being leaked via the technical channels of the systems and means of informatization and communication;
the introduction of territorial, frequency, energy, spatial and temporal limitations on the regimes of the use of the hardware subject to protection;
creation and use of information and computerized systems of management in the protected version.
In the sphere of defense. The objects of ensuring the information security of the Russian Federation in the defense sphere are:
the information infrastructure of the central military control bodies and the military control bodies of all the services of the Armed Forces of the Russian Federation, formations, units and organizations constituting the Armed Forces of the Russian Federation, scientific research institutions of the Defense Ministry of the Russian Federation;
the information resources of defense industry enterprises and research institutions which fulfill state defense contracts or deal with defense problems;
the hardware and software of computerized systems of control of the troops and weapons, arms and military equipment provided with informatization means;
information resources, systems of communication and the information infrastructure of all other troops, military units and agencies.
The external threats that pose the greatest danger to the objects of ensuring the information security of the Russian Federation in the defense sphere are:
all types of intelligence activities of foreign states;
information and technical intervention (including radio-electronic warfare and breaking into computer networks) by potential enemies;
sabotage activities by the special services of foreign states pursued through information and psychological methods;
the activities of foreign political, economic and military structures directed against the defense interests of the Russian Federation.
The internal threats which pose the greatest danger to the said objects are:
violation of the established procedure of gathering, processing, storage and transmission of information in the staffs and institutions of the Defense Ministry of the Russian Federation and at defense enterprises;
intentional actions as well as errors of the personnel of special information and telecommunications systems;
unreliable functioning of special-purpose information and telecommunications systems;
possible information and propaganda activities that undermine the prestige of the Armed Forces of the Russian Federation and their combat readiness;
unresolved problems of protecting the intellectual property of the defense enterprises leading to a leakage abroad of very valuable state information resources;
problems of social protection of servicemen and their families.
The above internal threats will become particularly dangerous if the military and political situation deteriorates.
The main specific areas in improving the system of ensuring the information security of the Russian Federation in the defense sphere are:
systematic identification of threats and their sources, the structuring of the goals of ensuring information security in the defense sphere and identification of corresponding practical tasks;
certification of the general and specialized software, applied software packages and means of information protection in existing and yet-to-be-created management information systems intended for military purposes and in communications systems containing computer technology elements;
constant improvement of the means of protecting information against unauthorized access, the development of protected systems of communication and troop and weapons control, and enhancing the reliability of specialized software;
improving the structure of the functional bodies of the system of ensuring information security in the sphere of defense and coordination thereof;
improving the devices and methods of strategic and operational camouflage, intelligence and radio-electronic warfare, the methods and means of counteracting information-propaganda and psychological operations of the potential enemy;
the training of specialists in the field of ensuring defense information security.
In the law-enforcement and judiciary spheres. Among the more important objects of ensuring information security in the law-enforcement and judiciary spheres are:
the information resources of the federal bodies of executive power that perform law-enforcement functions, the judiciary bodies, their information and computer centers, scientific research institutions and educational establishments containing specialized data and operational data for service use only;
information and computer centers, their information, technical, software and regulatory support;
the information infrastructure (information and computer networks, control points, communication hubs and lines).
The external threats posing the greatest danger for the objects of ensuring information security in the law-enforcement and judiciary spheres are:
the intelligence activities of the special services of foreign states, international criminal associations, organizations and groups connected with the gathering of information that reveals the tasks, plans, technical equipment, operating methods and location of the special units and bodies of the Interior Ministry of the Russian Federation;
the activities of foreign state and private commercial structures seeking to gain unauthorized access to the information resources of the law-enforcement and judiciary bodies.
The internal threats posing the biggest danger to the above-mentioned objects are:
violation of the established procedure of gathering, processing, storage and transmission of information contained in the card indexes and computerized data banks and used to investigate crimes;
inadequate legislative and regulatory framework for information exchange in the law-enforcement and judiciary spheres;
the lack of a uniform methodology of gathering, processing and storage of operational detective, reference, criminological and statistical information;
failure of hardware and malfunctions of software in the information and telecommunications systems;
intentional actions as well as errors of the personnel directly engaged in the creation and maintenance of card indexes and computerized data banks.
Along with the widely used general methods and means of information protection specific methods and means of ensuring information security in the law-enforcement and judiciary spheres are used.
Chief of them are:
the creation of a protected multi-tiered system of integrated banks of operational-detective, reference, criminological and statistical data on the basis of specialized information and telecommunications systems;
raising the standard of professional and specialized training of the users of information systems.
In emergency situations. The most vulnerable objects in terms of ensuring the information security of the Russian Federation in emergency situations are the system of decision-making on operational actions (reactions) connected with the development of such situations and the liquidation of their consequences as well as the system of gathering and processing information on the possible occurrence of emergency situations.
Of particular significance for the normal functioning of the said objects is ensuring the security of the national information infrastructure in the event of accidents, catastrophes and natural disasters. Concealment, delay in disclosing and distortion and destruction of operational information, unauthorized access to such information of individuals or groups of persons may cause both human casualties and create various difficulties in cleaning up the aftermath of an emergency situation connected with the special character of the impact of information in extreme conditions: the agitation of large masses of people who experience mental stress; rapid emergence and spread of panic and unrest on the basis of rumors, false or inaccurate information.
In these specific conditions information security is ensured among other things by:
developing an effective system of monitoring hazardous objects whose malfunction may give rise to emergency situations and prediction of emergency situations;
improving the system of informing the population about the threats of emergency situations, and the conditions in which they arise and develop;
making more reliable the systems of processing and transmission of information that support the activities of the federal bodies of executive power;
predicting the behavior of the population under the impact of false or inaccurate information on the possible emergency situations and working out measures to assist large masses of people in such situations;
developing specialized measures to protect information systems that ensure control of environmentally hazardous or economically important production facilities.
7. The International Cooperation of the Russian Federation in the Field of Ensuring Information Security
The international cooperation of the Russian Federation in the field of ensuring information security is an inseparable component of political, military, economic, cultural and other types of interaction among the countries which form the world community. Such cooperation should contribute to enhancing the information security of all the members of the world community, including the Russian Federation.
A distinctive feature of the international cooperation of the Russian Federation in ensuring information security is that it proceeds in the context of sharper international competition for the possession of technological and information resources, for dominance in the markets, amid continued attempts to create a structure of international relations based on unilateral decisions on key problems of world policy, counteracting the strengthening of Russia's role as an influential center in the emerging multipolar world, and the widening technological lead of the main world powers and the buildup of their potential for creating an "information weapon". All this may lead to a new phase in unleashing the arms race in the information sphere, a growing threat of foreign intelligences penetrating into Russia through agents and operational-technical means, including the use of a global information infrastructure.
The main areas of international cooperation of the Russian Federation in the field of information security are:
banning the development, proliferation and application of "information weapons";
ensuring the security of international information exchanges, including the security of information when being transmitted via national telecommunications channels;
coordinated activities of law-enforcement bodies of the countries of the world community in preventing computer crime;
preventing unauthorized access to confidential information in international banking telecommunications networks and world trade information support systems, the information of international law-enforcement organizations fighting transnational organized crime, international terrorism, the spread of narcotics and psychotropic substances, illegal trade in arms and fissile materials as well as trade in people.
In pursuing international cooperation in the field of ensuring information security the Russian Federation should pay particular attention to the problems of interaction with the states -- members of the Commonwealth of Independent States. To pursue such cooperation in the main areas indicated above it is necessary to ensure Russia's active participation in all the international organizations active in the field of information security, including in the sphere of standardization and certification of the means of informatization and information protection.
III. MAIN PROVISIONS OF THE STATE POLICY OF ENSURING THE INFORMATION SECURITY OF THE RUSSIAN FEDERATION AND PRIORITY MEASURES TO IMPLEMENT IT
8. Main Provisions of the State Policy of Ensuring the Information Security of the Russian Federation
The state policy of ensuring the information security of the Russian Federation lays down the guidelines for the activities of the federal bodies of state power and bodies of state power of the subjects of the Russian Federation in this field, the procedure of fixing their duties in protecting the interests of the Russian Federation in the information sphere within their specific areas of activity and is based on maintaining a balance of the interests of the individual, society and the state in the information sphere.
The state policy of insuring the information security of the Russian Federation is based on the following main principles:
compliance with the Constitution of the Russian Federation, the laws of the Russian Federation, the universally recognized principles and norms of international law in pursuing the activities to ensure the information security of the Russian Federation;
openness in the performance of the functions of the federal bodies of state power and bodies of state power of the subjects of the Russian Federation and non-governmental associations which implies informing the public of their activities with due regard for the limitations established under the laws of the Russian Federation;
equal rights of all the participants in the process of information exchange regardless of their political, social and economic status based on the constitutional right of citizens to free search for, access to, transfer, production and dissemination of information by any lawful method;
priority development of domestic modern information and telecommunications technologies, the production of hardware and software capable of improving the national telecommunications networks, their integration into global information networks for the purpose of meeting the vital interests of the Russian Federation.
The state, in the process of implementing its functions of ensuring the information security of the Russian Federation:
carries out an objective and comprehensive analysis and forecasting of the threats to the information security of the Russian Federation, develops measures to ensure it;
organizes the work of legislative (representative) and executive bodies of state power of the Russian Federation to implement the set of measures aimed at preventing, countering and neutralizing the threats to the information security of the Russian Federation;
supports the activities of non-governmental associations aimed at providing the population with objective information on socially significant phenomena in the life of society, and at protecting society from distorted and inaccurate information;
controls the development, creation, elaboration, use, export and import of the means of information protection through their certification and licensing of information protection activities;
pursues the required protectionist policy with regard to producers of informatization and information protection means on the territory of the Russian Federation and takes measures to protect the internal market from the penetration of inferior-quality means of informatization and information products;
helps natural persons and legal entities to gain access to world information resources and global information networks;
formulates and implements the state information policy of Russia;
organizes the development of the federal program to ensure the information security of the Russian Federation combining the efforts of state and non-governmental organizations in this field;
contributes to the internationalization of global information networks and systems and to the integration of Russia in the world information community on terms of equal partnership.
Improving the legal mechanisms for the regulation of social relations arising in the information sphere is a priority area of state policy in the field of ensuring the information security of the Russian Federation.
This implies:
assessment of the effectiveness of the use of existing legislative and other regulatory acts in the information sphere and working out a program of improvement thereof;
creating organizational and legal mechanisms to ensure information security;
determining the legal status of all the agents in the information sphere, including the users of information and telecommunication systems, and determining their responsibility for compliance with the laws of the Russian Federation in this field;
establishing a system of gathering and analyzing data on the sources of threats to the information security of the Russian Federation as well as the consequences of the implementation thereof;
development of regulatory legal acts to determine the organization of investigation and legal process involving facts of unlawful actions in the information sphere as well as the procedure for eliminating the consequences of such unlawful actions;
defining crimes and offenses taking into account the specific features of criminal, civil, administrative, and disciplinary responsibility and including corresponding legal standards in the criminal, civil, administrative, and labor codes and the legislation of the Russian Federation on the civil service;
improving the system of training the personnel used in the field of ensuring the information security of the Russian Federation.
The legal support of the information security of the Russian Federation should be based, above all, on compliance with the principles of legality, the balance of the interests of the citizens, society and the state in the information sphere.
Compliance with the principles of legality requires from the federal bodies of state power and bodies of state power of the subjects of the Russian Federation, in dealing with conflicts arising in the information sphere, to strictly abide by the legislative and other regulatory acts regulating the relations in this sphere.
Compliance with the principle of the balance of interests of the citizens, society and the state in the information sphere implies the existence of legislation fixing the priority of these interests in various areas of the life of society as well as the use of various forms of public control over the activities of the federal bodies of state power and bodies of state power of the subjects of the Russian Federation. Provision of guarantees of the constitutional rights and freedoms of man and citizen pertaining to the information sphere is the key task of the state in the field of information security.
Developing the mechanisms of legal support of the information security of the Russian Federation includes measures of informatization of the legal sphere as a whole.
For the purpose of identifying and harmonizing the interests of the federal bodies of state power, bodies of state power of the subjects of the Russian Federation and other agents in the information sphere and working out the necessary decisions the state supports the formation of public councils, committees and commissions with broad representation of non-governmental associations and assists in organizing their effective work.
9. Priority Measures to Implement the State Policy of Ensuring the Information Security of the Russian Federation
The following are the priority measures in implementing the state policy of ensuring the information security of the Russian Federation:
development and introduction of the mechanisms of enforcing the legal standards regulating the relations in the information sphere as well as preparing a concept of legal support of the information security of the Russian Federation;
development and introduction of the mechanisms to enhance the effectiveness of state supervision of the activities of the state-owned mass media and the implementation of the state information policy;
adoption and implementation of federal programs to form generally accessible archives of the information resources of the federal bodies of state power and bodies of state power of the subjects of the Russian Federation, to enhance the legal awareness and computer literacy, to develop the infrastructure of the common information sphere of Russia, to counter in a concerted manner the threats of information warfare, to create safe information technologies for the systems used in the performance of vital functions of society and the state, to stop computer crime, to create a special-purpose information and telecommunications system in the interests of the federal bodies of state power and bodies of state power of the subjects of the Russian Federation, to ensure the country's technological independence in the creation and operation of defense-oriented information and telecommunications systems;
development of a system of training the personnel used in the field of ensuring the information security of the Russian Federation;
harmonizing the domestic standards in the field of informatization and information security of management information systems, general-purpose and special-purpose information and telecommunications systems.
IV. ORGANIZATIONAL BASIS OF THE SYSTEM OF ENSURING THE INFORMATION SECURITY OF THE RUSSIAN FEDERATION
10. Main Functions of the System of Ensuring the Information Security of the Russian Federation
The system of ensuring the information security of the Russian Federation is intended to implement the state's policy in this sphere.
The main functions of the system of ensuring the information security of the Russian Federation are:
developing the legal framework for ensuring the information security of the Russian Federation;
creating conditions for the exercise of the right of citizens and non-governmental associations to pursue lawful activities in the information sphere;
determining and maintaining the balance between the need of citizens, society and the state for free exchange of information and the necessary restrictions on the dissemination of information;
assessing the state of the information security of the Russian Federation, identifying the sources of internal and external threats to information security, determining priority areas of preventing, countering and neutralizing such threats;
coordinating the activities of the federal bodies of state power and other state bodies called upon to ensure the information security of the Russian Federation;
controlling the activities of the federal bodies of state power and bodies of state power of the subjects of the Russian Federation, state and inter-agency commissions engaged in ensuring the information security of the Russian Federation;
preventing, identifying and stopping the offenses and crimes involving encroachment on the lawful interests of the citizens, society and the state in the information sphere, on the legal process over crimes in this area;
developing a domestic information infrastructure as well as the industry of telecommunications and information means, making them more competitive in the internal and external markets;
organizing the development of federal and regional programs to ensure information security and coordinating activities in implementing the same;
pursuing a uniform technical policy in the field of ensuring the information security of the Russian Federation;
organizing fundamental and applied research in ensuring the information security of the Russian Federation;
protecting the state information resources, above all, in the federal bodies of state power and bodies of state power of the subjects of the Russian Federation and defense enterprises;
controlling the creation and use of information protection means through mandatory licensing of activities in this sphere and certification of information protection means;
improving and developing a single system of training the personnel to work in the field of ensuring the information security of the Russian Federation;
pursuing international cooperation in the field of ensuring information security and representing the interests of the Russian Federation in corresponding international organizations.
The competence of the federal bodies of state power and bodies of state power of the subjects of the Russian Federation and other bodies included in the system of ensuring the information security of the Russian Federation and its subsystems is determined by federal laws, regulatory legal acts of the President of the Russian Federation and the Government of the Russian Federation.
The functions of the bodies coordinating the activities of the federal bodies of state power, bodies of state power of the subjects of the Russian Federation and other government bodies which form the system of ensuring the information security of the Russian Federation and its subsystems are determined by specific regulatory acts of the Russian Federation.
11. Main Elements of Organization of the System of Ensuring the Information Security of the Russian Federation
The system of ensuring the information security of the Russian Federation is part of the system of ensuring the national security of the country.
The system of ensuring the information security of the Russian Federation is based on the delimitation of the jurisdiction of the bodies of legislative, executive and judiciary branches of power in this sphere and the jurisdictions of the federal bodies of state power and bodies of state power of the subjects of the Russian Federation.
The main elements of the organization of the system of ensuring the information security of the Russian Federation are: the President of the Russian Federation, the Federation Council of the Federal Assembly of the Russian Federation, the State Duma of the Federal Assembly of the Russian Federation, the Government of the Russian Federation, the Security Council of the Russian Federation, the federal bodies of executive power, inter-agency and state commissions established by the President of the Russian Federation and the Government of the Russian Federation, the bodies of executive power of the subjects of the Russian Federation, the bodies of local self-government, the judiciary bodies, public associations and citizens involved, under the laws of the Russian Federation, in ensuring the information security of the Russian Federation.
The President of the Russian Federation, within his constitutional powers, supervises the bodies and resources to ensure the information security of the Russian Federation; sanctions actions to ensure the information security of the Russian Federation; under the laws of the Russian Federation forms, reorganizes and abolishes the bodies and resources subordinate to him for ensuring the information security of the Russian Federation; identifies in his annual addresses to the Federal Assembly state policy priorities in ensuring the information security of the Russian Federation as well as measures to implement this Doctrine.
The houses of the Federal Assembly of the Russian Federation, proceeding on the basis of the Constitution of the Russian Federation and upon submission of the President of the Russian Federation and the Government of the Russian Federation, form the legislative framework in the field of ensuring the information security of the Russian Federation.
The Government of the Russian Federation, within its powers and consistent with the priority areas in ensuring the information security of the Russian Federation formulated in the annual addresses of the President of the Russian Federation to the Federal Assembly, coordinates the activities of the federal bodies of executive power and the bodies of executive power of the subjects of the Russian Federation and, in the process of the formation, under established procedure, of the draft federal budget for the corresponding years envisages the allocation of funds required to implement the federal programs in this field.
The Federation Council of the Russian Federation works to identify and assess the threats to the information security of the Russian Federation, promptly prepares draft decisions of the President of the Russian Federation to prevent such threats, develops suggestions in the field of ensuring the information security of the Russian Federation as well as suggestions on updating certain provisions of this Doctrine, coordinates the activities of the bodies and resources to ensure the information security of the Russian Federation, controls the implementation by the federal bodies of state power and bodies of state power of the subjects of the Russian Federation of the decisions of the President of the Russian Federation in this field.
The federal bodies of executive power ensure compliance with the laws of the Russian Federation, the decisions of the President of the Russian Federation and the Government of the Russian Federation in the field of ensuring the information security of the Russian Federation; within their competence, develop regulatory legal acts in this field and properly submit them to the President of the Russian Federation and the Government of the Russian Federation.
The inter-agency and state commissions established by the President of the Russian Federation and the Government of the Russian Federation address, consistent with their powers, the tasks of ensuring the information security of the Russian Federation.
The bodies of executive power of the subjects of the Russian Federation interact with the federal bodies of executive power on issues of compliance with the laws of the Russian Federation, the decisions of the President of the Russian Federation and the Government of the Russian Federation in the field of ensuring the information security of the Russian Federation as well as on the issues of implementing federal programs in this field; jointly with the bodies of local self-government take measures to enlist the cooperation of citizens, organizations and non-governmental associations in addressing the problems of ensuring the information security of the Russian Federation; submit to the federal bodies of executive power proposals on improving the system of ensuring the information security of the Russian Federation.
The bodies of local self-government ensure compliance with the laws of the Russian Federation in the field of ensuring the information security of the Russian Federation.
The bodies of judiciary power administer justice on cases of crimes involving encroachments on the lawful interests of the individual, society and the state in the information sphere, and provide legal defense of citizens and public associations whose rights have been violated in connection with activities to ensure the information security of the Russian Federation.
The system of ensuring the information security of the Russian Federation may include subsystems (systems) geared to the solution of local tasks in this sphere.
* * *
The implementation of priority measures to ensure the information security of the Russian Federation listed in this Doctrine implies the development of a corresponding federal program. Individual provisions of this doctrine with regard to certain spheres of the activity of society and the state may be specified in corresponding documents approved by the President of the Russian Federation.