We determine the outline and applicability of the requirements
We record systems, data, classes, owners, integrations, current documents and technical limitations.
Result: boundaries and survey map.RESTART helps to bring critical and regulated IT environments to a manageable state: examination, classification of systems, threat model, design solutions, implementation of information security, documents, operation and preparation for inspections.
We need a licensed practice that understands the requirements of FSTEC and actual operation.
There are ISPD, GIS, CII, personal data, integrations and document requirements.
It is necessary to combine information security requirements with networks, servers, DevOps, ERP and application systems.
It is necessary to correctly formulate the scope of work, artifacts, acceptance criteria and procurement documentation.
An information security project often fails when requirements are described separately from the actual infrastructure, users, data and operations.
| Pain | What happens without preparation |
|---|---|
| There are no clear system boundaries | It is impossible to provably determine the composition of assets, data, owners and protection measures. |
| Documents are not related to implementation | The threat model and set of documents exist separately from networks, servers, information security and processes. |
| Purchasing information security does not solve the risk | Products are purchased without a proven architecture, compatibility and operational model. |
| Checking becomes stressful | The team is not ready to explain what measures have been taken, where the evidence is and who is responsible for the operation. |
We record systems, data, classes, owners, integrations, current documents and technical limitations.
Result: boundaries and survey map.We analyze threats, current violators, channels, vulnerabilities and protection measures.
Result: threat model and list of measures.We select architecture, segmentation, access rights, logs, information security/cryptographic information security and operational processes.
Result: design solutions.We help implement measures, prepare documents, check settings and collect evidence.
Result: roadmap and acceptance package.Systems, owners, data types, integrations, areas of responsibility.
Current threats, violators, scenarios and applicable protection measures.
Architectural and detailed design solutions for information security.
Priorities, quick actions, procurement, implementation, documents and operation.
For CII/Federal Law No. 152-FZ, a reasonable start is diagnostics within 10-15 working days. It provides a manageable picture of the current state and a plan of action without prematurely purchasing unnecessary protective equipment.
| Role | Area of responsibility |
|---|---|
| Information Security Architect | Requirements, threat model, protection measures, HLD/LLD. |
| Information security implementation engineer | Compatibility, settings, pilot, production operations. |
| System Analyst | Outlines, processes, documents, owners, acceptance artifacts. |
| Project manager | Work plan, risks, communications, control of deadlines and artifacts. |
Systems, data, networks, roles, documents, integrations and operations.
Applicability of Federal Law No. 152-FZ, CII, GIS, threat model and list of measures.
HLD/LLD, information security, access, segmentation, logs, maintenance processes.
Priorities, procurement, implementation, documents, milestones and acceptance.
Public cases do not reveal confidential details of customers, but show RESTART’s experience in related enterprise landscapes.
Yes, information about licenses and statuses is published on the website in the “Licenses and statuses” section.
Yes. This is the safest format: first understand the outline, risks and applicable requirements, then plan the implementation.
RESTART closes the full cycle: inspection, design, selection of solutions, implementation, documents and operation support.
Fill out a short application or send an email to info@restart.re. For the first conversation, it is enough to describe the outline, the role of the organization, current systems, limitations and the desired outcome.
Describe the task, current systems, constraints, and expected results. We will offer a practical first step: diagnostics, pilot, audit, roadmap or project team.
