Technical information security: from audit to certification

A technical information security (TPI) complex is not a standalone device or a piece of software, but a system of organisational and engineering measures that prevent restricted information from leaking through technical channels and guard it against unauthorised modification or blocking. Such complexes are built at information-activity facilities where speech information circulates and/or information is processed by technical means. The typical stages of creating a TPI complex are a survey of the IAF, substantiation and development of the threat model and the necessary documentation, deployment of protection tools, and documented confirmation of compliance with regulatory requirements.

A comprehensive information-protection system (CIPS) provides protection in information and communication systems (automated systems) in accordance with the requirements of the applicable regulatory and legal documents in the field of information protection. A TPI complex and a CIPS address different tasks: the former protects the information-activity facility against leakage through technical channels, the latter protects the information within the system in which it is processed.

Building TPI complexes and CIPS is a mandatory requirement for government bodies, institutions and enterprises that process official information, information constituting a state secret, or state information resources. Medium and large businesses need TPI wherever commercial secrets or critical technological information circulate, wherever regulators impose requirements or contractual obligations demand protection — from meeting rooms and executive offices to server rooms.

NVP «Plasmotekhnika» performs TPI work as a full cycle: from audit and design to certification and ongoing support. We are at once a systems integrator and a manufacturer of our own TPI tools holding expert conclusions from the State Service of Special Communications, so we design complexes around equipment whose characteristics are documented. A distinct line of work is supporting the transition from a CIPS to ICS security authorization under Cabinet of Ministers Resolution No. 712.

The decision to build a TPI complex is usually taken by several people at once: the head of the institution cares about the legitimacy of the result; the IT director, about compatibility with the existing infrastructure and subsequent support; the CISO, about compliance with regulatory requirements and the availability of expert conclusions; the security service, about the contractor’s reliability. This page and its related documents provide answers for each of them.

TPI services

Each service can be ordered separately or as part of an integrated project. The scope of work is fixed in the technical specification after the facility has been surveyed.

  • Protection audit. Survey of the information-activity facility, analysis of potential information-leakage channels and assessment of the existing protection measures. The result is a report listing non-conformities together with prioritised recommendations.
  • Design of CIPS and TPI complexes. Development of the threat model, the technical specification, and the design and operational documentation in accordance with the regulatory documents of the TPI system. We build CIPS in class «3» information and communication systems and web portals, as well as in class «1» and «2» automated systems in which official information and information constituting a state secret circulate.
  • Implementation. Supply and installation of protection tools, configuration, development of organisational and administrative documentation, and training of the client’s personnel.
  • Certification of TPI complexes. Preparation for and conduct of the certification of technical information security complexes at information-activity facilities — through to obtaining the documents that confirm compliance with requirements.
  • State examination of a CIPS. Organising the state examination of a CIPS in information and communication systems: preparing the set of documents, liaising with the body conducting the examination, and supporting the client through to a positive result.
  • Instrumental control of information protection at information-activity facilities. Measurement of the parameters of compromising electromagnetic emanations and pickups and of acoustic and vibroacoustic leakage channels using specialised measuring equipment.
  • Detection of eavesdropping devices at information-activity facilities. Special inspections of premises and equipment for covert information-gathering devices — either as a one-off before important events or regularly on a schedule.

Stages of work

A typical project to build a TPI complex proceeds through seven stages. The sequence is arranged so that each stage produces a documented result that is used in the next.

  1. Survey of the information-activity facility. We determine what information is processed, where and in what environment, and whether speech information circulates at the facility; we record the facility’s boundaries, the set of technical means and the influencing factors.
  2. Development of the threat model and technical specification. We formalise which threats the facility is protected against and agree the requirements for the future complex with the client.
  3. Design. We prepare the design documentation: the set of protection tools, placement diagrams, configuration parameters and organisational measures.
  4. Implementation. We supply and install equipment, configure the protection tools, develop the operational and organisational-administrative documentation, and train the responsible personnel.
  5. Preliminary testing and trial operation. We verify that the complex functions under the facility’s real operating conditions and address any issues identified.
  6. Certification. We carry out instrumental control, draw up the certification materials and support the client through to obtaining the certificate of compliance — and, for a CIPS, through to a positive result of the state examination.
  7. Support. Scheduled instrumental control, keeping documentation up to date, supporting configuration changes and re-certification where required.

Proof: our own products, licences and conclusions

In information-protection projects, the client is entitled to demand documents rather than promises. Our arguments are our own products and our permit documents.

«Plasmotekhnika» is a manufacturer of its own TPI tools. All products hold expert conclusions from the State Service of Special Communications (conclusion numbers — [TBC]). Manufacturer status also brings a practical advantage: we control the configurations, delivery timelines and subsequent servicing ourselves, without depending on third-party suppliers.

ProductProtection typePurpose
PLASMA-ZV-ARM/MONOPassiveSecure workstation (workstation in protected design) for processing restricted information; passive protection against leakage via technical channels
PLASMA-ZARM/AZActiveWorkstation with active protection against leakage via technical channels
PLASMA DDOne-way data transferData diode — a one-way security gateway between networks of different levels

We perform TPI work under licences and permit documents (details — [TBC]). The full list of documents with their details — for the client’s CISO and security service — is published on the «Licences & expert conclusions» page.

Frequently asked questions

How does certification of a TPI complex differ from authorization under Resolution No. 712?

Certification of a TPI complex and the state examination of a CIPS are well-established procedures for confirming protection. For information and communication systems, Cabinet of Ministers Resolution No. 712 introduced a new mechanism — security authorization: target security profiles, assessment and inclusion of the system in the register of authorized systems. We support both routes, as well as the transition from an existing CIPS to authorization — details on the «Authorization under Resolution No. 712» page.

How long does it take to build a TPI complex?

The timeline depends on the number of facilities, the category of information and the condition of the existing infrastructure, so an honest estimate is only possible after a survey. Based on its results we provide a schedule with fixed stages and checkpoints. We plan the work so that it does not block the institution’s day-to-day activities.

Can a TPI complex be built on existing hardware?

In part — the suitability of existing equipment is determined during the survey and instrumental control. For workstations that process restricted information, it is often more sensible to use factory-built secure workstations: our PLASMA-ZV-ARM/MONO and PLASMA-ZARM/AZ hold expert conclusions from the State Service of Special Communications.

How often is instrumental control needed after certification?

The frequency is determined by the TPI regulatory documents and the terms of the certificate of compliance. Unscheduled control is advisable after configuration changes, renovation of premises, or the relocation or replacement of equipment.

What is required from the client to start work?

A request with a brief description of the facility and the category of information being processed is enough. If required, we conclude a non-disclosure agreement before any materials are handed over. The company’s details, licences and conclusions for a reliability check are on the «Licences & expert conclusions» page.

Order an audit or the development of a technical specification

Describe your facility and the category of information in the request form at the bottom of the page — we will get back to you with a survey plan and a list of the source data required. If you already have a technical specification, send it to us: we will prepare an implementation proposal with a breakdown of the stages. Phone for consultations: +38 (044) 204-83-62. Office: 03056, Kyiv, vul. Politekhnichna 16, office 021.

Need a consultation or a technical brief?

Leave a request — a specialist engineer will get in touch within one business day.

By submitting the request, you agree to the privacy policy.