HabrSeptember 23, 2026🇷🇺Translated from Russian

Why Vulnerability Management Specialists Must Master Compliance: Closing All CVEs but Leaving admin:admin

Compliance has become a core component of vulnerability management rather than a separate bureaucratic task. Russian organizations now face real financial and criminal consequences for failing to meet regulatory requirements on vulnerability handling and system configuration.

Over the past years regulators have significantly raised the stakes. FSTEC Order 117, effective from 1 March 2026, makes vulnerability management mandatory for state systems with strict deadlines: 24 hours for critical vulnerabilities and 7 days for high-severity issues. Turnover fines for personal-data leaks introduced in May 2025 range from 3 to 15 million rubles for the first incident and up to 1–3 % of annual revenue for repeat violations. Presidential Decree No. 250 assigns personal responsibility to deputy heads of organizations for information security and bans the use of protective equipment from unfriendly countries starting 1 January 2025.

Three main approaches to building compliance exist. The first is to rely on historical practices only, which is now considered high-risk. The second follows regulator requirements from FSTEC and the Central Bank of Russia, creating internal standards and checking systems against them. The third uses international benchmarks such as CIS Benchmarks, although full compliance across thousands of hosts is practically impossible and organizations realistically achieve around 70 % coverage.

The recommended path is to develop an organization-specific standard that reflects its threat model. CISO and compliance specialists jointly define requirements, document change procedures, run continuous checks, and agree on SLAs for remediation. Automated tools such as MaxPatrol HCC, RedCheck, ScanOVAL, and modules in R-Vision and Security Vision perform configuration scanning and generate reports.

A more mature approach shifts compliance left by embedding controls into golden images built with Packer, Ansible or similar tools. These pre-hardened images are then deployed through CI/CD pipelines, reducing configuration drift. Regular scanning remains necessary because systems still deviate over time.

The article concludes with a practical warning: even a fully patched firewall offers no protection if it retains the password admin:admin. Configuration errors such as weak credentials and exposed management interfaces constitute exploitable vulnerabilities and must be treated as part of the vulnerability management process alongside CVE remediation.

Related articles

安全客Policy & Regulation

China Public Security Ministry Warns IoT Operators: Default Passwords on Devices Like Bus Stop Displays Violate Cybersecurity Law Even Without Major Incidents

A bus electronic display router in Wuhu, Anhui, was compromised in April 2026 because the device retained factory-default credentials and exposed multiple management ports. The Ministry of Public Security highlighted the case in its Hu Wang 2026 report, stressing that failing to change default passwords and leaving ports open constitutes a violation of the Cybersecurity Law regardless of whether serious harm occurred. The RCtea botnet actively targeted similar routers and cameras across China, infecting 9,827 devices in just six days in January 2026 through Telnet brute-force attacks. Experts from the Chinese Academy of Social Sciences clarified that penalties do not require actual damage and that operators must implement technical measures, retain logs for at least six months, and maintain internal security procedures. Additional cases in Qinghai and Nanchong demonstrated repeated enforcement actions against entities that ignored weak-password remediation orders. The report calls on operators, regulators, and manufacturers to enforce password changes at installation, close unnecessary ports, and apply network segmentation to prevent low-hanging IoT devices from becoming botnet recruits.

HabrPolicy & Regulation

Alfa-Bank Balances Cloud Trust and Zero Trust Models During Migration to Yandex Cloud

Alfa-Bank's head of container and cloud security, Sasha Chertok, detailed how the bank migrated regulated workloads to Yandex Cloud while preserving existing Zero Trust controls. The organization mapped on-premises network segmentation, Active Directory authentication, and firewall policies directly onto Yandex Cloud resources using interconnect links secured with GOST encryption. Responsibility for managed services is shared under a Cloud Trust model, yet the bank retains oversight through Terraform-managed Security Groups, custom CSPM checks, and internal CI/CD gates. User access continues to authenticate via on-premises Active Directory and KeyCloak federations, while authorization leverages granular Yandex Cloud IAM roles. Logging and detection rely on a combination of Yandex Cloud Audit Trail, Cloud Logging, and the YCDR service to compensate for incomplete control-plane visibility. The resulting hybrid architecture now supports 1,500 virtual machines, 100 managed services, and 1,000 identities across multiple environments without disrupting established security processes.

HabrPolicy & Regulation

EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure

The EnvSpec Naming 1.0.0 standard proposes replacing ad-hoc hostnames with a strict hierarchical naming system based on environment, perimeter, system, slot and node. It defines exactly six environments—dev, test, stage, prod, infrastructure and workplace—and treats any test or pilot system processing real data as prod. The model projects names into SPIFFE IDs, Kubernetes namespaces, cloud projects and mandatory tags for automated policy enforcement. Rules prohibit direct communication between different linear environments and require all access from workplace devices through dedicated gateways. The standard is published under CC BY-SA 4.0 and includes machine-checkable criteria for compliance.

AntiMalwarePolicy & Regulation

Russian Woman Fined 30,000 Rubles and Loses iPhone 11 for Posting AI-Generated Bear Photo

A resident of Duldurga village in Zabaykalsky Krai was fined 30,000 rubles under part 9 of article 13.15 of the Russian Code of Administrative Offenses for publishing an AI-generated image of a bear presented as authentic. The court also ordered confiscation of her iPhone 11 as the instrument of the administrative violation. The woman knew the photograph was fake before posting it, yet the image spread widely online and was even shared by a local Ministry of Natural Resources channel on 10 September. Local authorities used the case to warn residents that publishing neural-network-generated fake images carries real legal consequences. The incident highlights ongoing enforcement of Russian legislation against the distribution of knowingly false socially significant information under the guise of credible reports. Meanwhile, wildlife specialists continue to investigate separate reports of actual bears near populated areas in the region.