Topic
FSTEC

FSTEC Publishes 35-Point Network Perimeter Recommendations, Most Require No Spending
Policy & Regulation
NIST Bans Periodic Password Rotation While Russia's FSTEC Mandates 90-Day Changes for Government Systems
Policy & Regulation
2.2 Million Line Vulnerability Report: What Happens After Discovery and How to Turn Findings Into Action
Vulnerabilities & ExploitsBank of Russia Publishes Methodological Recommendations No. 3-MR on AI Security for Financial Market Participants
The Bank of Russia has released methodological recommendations No. 3-MR dated 16 June 2026, providing detailed guidance on ensuring information security during the development and use of artificial intelligence systems in the financial sector. The document builds on the earlier Code of Ethics for AI in finance and integrates with existing risk management, operational resilience, and data protection frameworks already familiar to credit institutions and other market participants. It introduces standardized terminology for AI-specific threats such as hallucinations, data drift, and poisoned datasets while outlining six risk categories and a four-stage AI system lifecycle model. Organizations are advised to apply threat modeling based on FSTEC methodology, implement proportional controls across data preparation, development, training, and operation phases, and maintain human oversight for high-risk automated processes. Special attention is given to supply chain risks involving third-party vendors and open-source components, requiring due diligence, provenance tracking, and contractual safeguards aligned with existing outsourcing standards. The recommendations remain non-binding yet signal clear regulatory expectations that are likely to influence future compliance checks and audits.
Understanding SCA: How Software Composition Analysis Helps Manage Software Supply Chain Risks
Software Composition Analysis (SCA) has emerged as a critical tool for organizations seeking to understand and control the risks hidden within modern applications built from third-party components, open-source libraries, container images, and transitive dependencies. SCA tools scan projects to identify components, versions, dependency chains, known vulnerabilities, and license issues, providing visibility that traditional security methods often miss. The approach supports SBOM generation and integrates with standards such as SPDX, CycloneDX, and VEX to improve transparency across the software supply chain. Organizations use SCA throughout the development lifecycle—from dependency selection and build-time gating to post-release monitoring—to reduce reaction time when new vulnerabilities appear and to manage technical debt, licensing conflicts, and abandoned packages. In regulated environments, including compliance with Russian standards like GOST R 56939-2024 and FSTEC requirements, SCA helps teams demonstrate control over software composition and prepare evidence for certification. While powerful, SCA is not a silver bullet: it relies on accurate data, cannot detect zero-days, and requires careful policy tuning to avoid alert fatigue or developer workarounds.
RZD Trunk Quantum Network Obtains FSTEC Attestation and Enters External Commercial Market
Russia’s state-owned railway operator RZD has successfully passed certification by the Federal Service for Technical and Export Control (FSTEC), confirming that its trunk quantum network meets the requirements for information systems of the second protection class. The attestation enables RZD to begin offering quantum-secured communication services to external organizations, including banks, industrial enterprises, medical institutions, and transport companies. Quantum key distribution technology allows any interception attempt to be detected because interference with the quantum channel alters the state of transmitted particles, providing a level of security far beyond conventional encryption methods. The network is already being tested by the Bank of Russia, the Federal Treasury, the Financial University, and several major banks, with potential clients also identified in the oil-and-gas, industrial, healthcare, and transportation sectors. The Ministry of Digital Development considers the technology sufficiently mature and has included further expansion of the quantum network through 2030 in the national “Data Economy” project roadmap. As a result, RZD is gradually transforming from a traditional carrier of passengers and cargo into an operator of protected digital highways.