Topic

FSTEC

🇷🇺Jul 19

Understanding SCA: How Software Composition Analysis Helps Manage Software Supply Chain Risks

Software Composition Analysis (SCA) has emerged as a critical tool for organizations seeking to understand and control the risks hidden within modern applications built from third-party components, open-source libraries, container images, and transitive dependencies. SCA tools scan projects to identify components, versions, dependency chains, known vulnerabilities, and license issues, providing visibility that traditional security methods often miss. The approach supports SBOM generation and integrates with standards such as SPDX, CycloneDX, and VEX to improve transparency across the software supply chain. Organizations use SCA throughout the development lifecycle—from dependency selection and build-time gating to post-release monitoring—to reduce reaction time when new vulnerabilities appear and to manage technical debt, licensing conflicts, and abandoned packages. In regulated environments, including compliance with Russian standards like GOST R 56939-2024 and FSTEC requirements, SCA helps teams demonstrate control over software composition and prepare evidence for certification. While powerful, SCA is not a silver bullet: it relies on accurate data, cannot detect zero-days, and requires careful policy tuning to avoid alert fatigue or developer workarounds.

SecuritylabSupply Chain & Open Source
🇷🇺Jul 14

RZD Trunk Quantum Network Obtains FSTEC Attestation and Enters External Commercial Market

Russia’s state-owned railway operator RZD has successfully passed certification by the Federal Service for Technical and Export Control (FSTEC), confirming that its trunk quantum network meets the requirements for information systems of the second protection class. The attestation enables RZD to begin offering quantum-secured communication services to external organizations, including banks, industrial enterprises, medical institutions, and transport companies. Quantum key distribution technology allows any interception attempt to be detected because interference with the quantum channel alters the state of transmitted particles, providing a level of security far beyond conventional encryption methods. The network is already being tested by the Bank of Russia, the Federal Treasury, the Financial University, and several major banks, with potential clients also identified in the oil-and-gas, industrial, healthcare, and transportation sectors. The Ministry of Digital Development considers the technology sufficiently mature and has included further expansion of the quantum network through 2030 in the national “Data Economy” project roadmap. As a result, RZD is gradually transforming from a traditional carrier of passengers and cargo into an operator of protected digital highways.

AntiMalwarePolicy & Regulation