Evolution of Requirements: From KSZI to a Modern Cybersecurity System in Critical Infrastructure
The Ukrainian critical infrastructure sector faces a unique challenge: integrating advanced cloud technologies while simultaneously adhering to strict national cybersecurity standards. Traditionally, the Complex Information Security System (KSZI) was the cornerstone of ensuring the security of state information resources and restricted-access information. KSZI is an interconnected set of organizational and engineering-technical measures, tools, and methods aimed at ensuring the confidentiality, integrity, and availability of information. Its implementation is regulated by the Laws of Ukraine "On Critical Infrastructure," "On Information Protection in Information and Telecommunication Systems," and "On the Basic Principles of Ensuring Cybersecurity of Ukraine."
However, the Cabinet of Ministers of Ukraine recently updated the "Mandatory Requirements for the Creation (Modernization, Modification, Development), Administration, and Functioning of Information Tools," abolishing the KSZI institute as a mandatory element for ensuring the security of information and communication systems. This does not mean a weakening of security requirements, but rather an adaptation to a modern cybersecurity assurance system that may involve a more flexible, risk-oriented approach and integration with international practices. For critical infrastructure operators, this means a need to rethink cybersecurity strategies, focusing on achieving a high level of security in accordance with new or updated regulatory acts that will likely replace or supplement the previous KSZI requirements.
Balancing Global Cloud Capabilities with National Security Standards
Modern international cloud providers offer a wide range of services that comply with global certifications such as ISO 27001, SOC 2, FedRAMP, and others. These certifications are an important indicator of the provider's security system maturity. However, for Ukrainian critical infrastructure, using these platforms requires a thorough analysis of compliance with national requirements, which often include local certification processes and data residency requirements. Although creating security systems using foreign cloud platforms is not prohibited, the State Service of Special Communications and Information Protection (SSSCIP) can only register a certificate of conformity after a positive expert audit of the security profiles of a system that uses cloud services hosted outside Ukraine.
The key task is to find a balance between leveraging the innovative capabilities of global cloud solutions and the necessity of complying with Ukrainian legislation. This involves not only technical integration but also legal and organizational preparation, including a detailed analysis of contracts with providers, risk assessment, and the development of adapted security policies.
Architectural Strategies for Cloud Compliance in Critical Infrastructure
To ensure compliance with national cybersecurity requirements in cloud environments for critical infrastructure, architectural considerations are paramount. Hybrid cloud models often become an optimal solution, allowing the storage of the most sensitive data and critical components in private clouds or local data centers that are under full control and certification, while less sensitive workloads are placed in public clouds.
Key architectural approaches:
- Network Segmentation: Isolating critical systems and data using Virtual Private Clouds (VPC), Firewalls, and other network security tools.
- Data Encryption: Implementing end-to-end encryption for data at rest and in transit, using cryptographic tools certified in Ukraine.
- Access Management: Implementing strict Identity and Access Management (IAM) policies, Multi-Factor Authentication (MFA), and the principle of least privilege.
- Monitoring and Response: Deploying SIEM (Security Information and Event Management) and SOAR (Security Orchestration, Automation and Response) systems for continuous monitoring, threat detection, and automated incident response.
- Backup and Recovery: Ensuring reliable backup mechanisms and Disaster Recovery plans to guarantee business process continuity.
The Role of Ukrainian Providers and Partners in Ensuring National Cybersecurity
Ukrainian cloud providers, such as De Novo and UCloud, are actively developing services that comply with national requirements, including KSZI certification for their cloud infrastructures. This allows critical infrastructure organizations to use cloud solutions that already have the necessary security confirmations. Collaboration with local partners specializing in cybersecurity and system integration is key to successful implementation and ongoing compliance. Companies like Intecracy and Inbase can provide expert consulting and implement comprehensive information security projects in cloud and hybrid environments, helping to adapt international practices to Ukrainian realities.
Checklist of Solutions for Compliance with National Cybersecurity Requirements in the Cloud
| Requirement / Aspect | IaaS (Infrastructure as a Service) | PaaS (Platform as a Service) | SaaS (Software as a Service) | How to Ensure Compliance |
|---|---|---|---|---|
| Data Residency | Full control over data location. | Limited control, depends on the PaaS provider. | Least control, depends on the SaaS provider. | Choosing a Ukrainian cloud provider or a hybrid model; contractual obligations with a foreign provider and audit. |
| Technical Information Protection (TIP) | Operator's responsibility for implementing TIP at the OS and application levels. | PaaS provider ensures platform TIP, operator ensures application TIP. | SaaS provider ensures most TIP. | Using certified TIP tools, cooperating with licensed companies for audit and implementation. |
| Access Management | Full operator control. | Shared responsibility with the PaaS provider. | Depends on SaaS functionality. | Implementing IAM, MFA, regular access rights audit. |
| Monitoring and Auditing | Full operator control. | Access to platform logs, integration with SIEM. | Limited access to logs, depends on SaaS. | Deploying SIEM/SOAR, integrating with cloud service logs. |
| Physical Security | Responsibility of the IaaS provider. | Responsibility of the PaaS provider. | Responsibility of the SaaS provider. | Checking data center certifications (ISO 27001, TIER III/IV), provider audit. |
| Disaster Recovery (DR) | Operator's responsibility for application DR, provider's for infrastructure. | Shared responsibility. | Depends on SaaS provider. | Developing and testing DR plans, using geographically distributed data centers. |
| Risk Assessment and Compliance | Full operator control. | Shared responsibility. | Depends on SaaS provider. | Regular risk assessment, internal and external audits, expert consultations. |
Related solutions: Intecracy solutions and inbase.com.ua solutions.