Download Article (PDF)
Total Page:16
File Type:pdf, Size:1020Kb
Advances in Economics, Business and Management Research, volume 128 International Scientific Conference "Far East Con" (ISCFEC 2020) Information Security Ensuring in the Financial Sector as Part of the Implementation of the National Program “Data Economy Russia 2024” K Horian1, E Gorian2 1HorianSis Studio, Vladivostok, 690014, Russian Federation 2Vladivostok State University of Economics and Service, 41, Gogol str., Vladivostok, 690014, Russian Federation E-mail: [email protected] Abstract. The object of the research is the relations arising from the implementation of the National Program “Data Economy Russia 2024” in the aspect of ensuring information security in the financial sector of Russia. The role of the state financial regulator in the implementation of this program is determined, taking into account the peculiarities of its legal status. The key documents that form the regulatory and legal mechanisms for ensuring the information security of the financial and banking sector of Russia are examined. The content of the activity of the center of competence of the federal project “Information Security” is determined and the need to determine the Bank of Russia as the center of competence is justified. Despite the serious constitutional and legal status and experience of practical management of processes to ensure the security of financial institutions, the potential of the financial regulator is not fully used in the National Program “Data Economy Russia 2024”, although the tasks assigned to the center of competence in information security are of a public nature and accordingly must be performed by the relevant subject. As the confirmation and logical continuation of the main role declared by the legislation in ensuring the stability of the financial system the Bank of Russia should be maintained as the center of competence of the federal project, since the financial regulator has all the organizational and legal powers and material resources (FinCERT) for this words. 1. Introduction In order to implement the Strategy for the Development of the Information Society in the Russian Federation for 2017–2030 [1], the national program “Data Economy Russia 2024” [2] (hereinafter - the Program) was approved in 2017. Its main goal was to create a digital environment that ensures the interaction of all participants in the public and private sectors in all spheres of life in sufficient and necessary institutional and infrastructural conditions for the development of high technologies used in both traditional and new sectors of the economy. The Program’s Roadmap initially envisaged five areas for the development of the digital economy in Russia: 1) legal regulation; 2) human resources and education; 3) the formation of research competencies and technological groundwork; 4) informa- tion infrastructure; 5) information security [2]. However at the end of 2018 the Passport of the Nation- al Program “Data Economy Russia 2024” [3] was approved providing the implementation of six fed- eral projects under the Program (paragraphs 4.1-4.6): a) legal regulation of the digital environment; b) Copyright © 2020 The Authors. Published by Atlantis Press SARL. This is an open access article distributed under the CC BY-NC 4.0 license -http://creativecommons.org/licenses/by-nc/4.0/. 635 Advances in Economics, Business and Management Research, volume 128 information infrastructure; c) frames for the digital economy; d) information security; e) digital tech- nologies; e) digital public administration. To implement the Program a management system was de- veloped, including among other things the so-called “centers of competence” (paragraph 4). Centers of competence are engaged in a) the collection of proposals and the preparation of draft passports for federal projects of the Program, including an explanatory note, a financial and economic justification, and requests for alternations to passports for federal projects of the Program; b) the submission of these projects to the appointed working group and other members of the management system; c) the consideration of final reports on the implementation of the Program and on the implementation of fed- eral projects of the Program; d) the consideration of draft acts and draft amendments to draft laws, which may have an impact on the implementation of the Program and the implementation of federal projects of the Program, as well as draft official comments on such draft laws; e) the implementation of measures of federal projects of the Program within the framework of its competence including the preparation of draft acts (clause 12) [4]. One of the federal projects of the Program is the abovementioned “Information Security”, which is to ensure information security based on domestic developments in the transmission, processing and storage of data, guaranteeing the protection of the interests of the individuals, business and the state (clause 4.4) [3]. The results of this task are follows: 1) the creation of conditions for global competi- tiveness for the domestic developments and information security technologies export; 2) the stability and security of the information infrastructure and data transfer, processing and storage services; 3) the protection of the rights and the legitimate interests of individuals, business and the state from cyber threats in a digital economy; 4) the use of domestic developments and technologies in the transfer, processing and storage of data. However, Sberbank of Russia was designated as the center of compe- tence for this federal project of the Program, and N. Kasperskaya the president of the InfoWatch group of companies was appointed as the head of the working group in the Information Security tier [5]. At the same time, the function of the financial regulator in Russia is performed by the Central Bank of the Russian Federation (Bank of Russia), which has a special constitutional legal status and corresponding powers. The management of the Bank of Russia has repeatedly appealed to the Government of the Russian Federation with a request to reconsider the decision on the definition of Sberbank of Russia as a center of competence in favor of the Bank of Russia or at least to transfer some of its powers to it, but to no avail [6]. Their arguments were follows: firstly, the Bank of Russia successfully operates a center for monitoring and responding to computer attacks in the credit and financial sector (FinCERT); secondly, its participation “harmonizes the program with the strategic goals of financial market devel- opment and reduces the risks of a conflict of interest in the envisaging and execution of the program ... these functions are “exclusively state-owned and are not characteristic of commercial banks” [6]. After all, the financial regulator is responsible for the stable functioning of the financial market and the banking system of Russia (Art. 2) [7], it plays a coordinating role setting the rules for the implementa- tion of financial institutions, including in the field of ensuring the safety of their operations [8, p. 26]. Therefore, a theoretical study and substantiation of the role of the Bank of Russia as a center of com- petence for the federal Information Security project of the National Program “Data Economy Russia 2024” is necessary. All of the above indicates the relevance of the research topic. 2. Methodology and literature review The methodology for this study comprises of two groups of methods: the general scientific ones (sys- tem-structural, formal-logical and hermeneutical methods) and the special legal methods of cognition (comparative legal analyses and formal-legal method). In order to obtain the most reliable scientific results they were used in complex. The subject of the research is the main regulatory and legal acts defining the content of the Program and the powers of the Bank of Russia to ensure information secu- rity, as well as a number of scientific studies on the topic. The topic chosen by us for research is poorly represented in the Russian scientific literature. Among domestic scientific research, one can single out works on the role of the Russian financial reg- ulator in ensuring the information security of the banking and financial systems [9; 10], as well as 636 Advances in Economics, Business and Management Research, volume 128 work on approaches to the development of the information-regulatory system of financial infrastruc- ture [11]. 3. Hypothesis Ensuring the information security of the state is carried out by interacting institutions of the public and private sectors. In such a situation, representatives of the public sector are responsible for coordinating actions within a particular segment of the economy. The financial regulator performs the functions of coordinating and managing relations within the financial and banking sectors (Art. 3, 4) [7], therefore, determining its role in ensuring information security in the framework of the state program to create a digital environment that ensures the interaction of all participants in public and private sectors in all spheres of life, is scientifically and practically justified. 4. Results and discussion Before determining the legal status of the Bank of Russia, it is necessary to dwell on the issue of the specifics of an object to which the powers of the financial regulator apply. We are talking about in- formation systems of the banking and financial sectors that have the status of objects of critical infor- mation infrastructures (CII). Along with the information systems of the energy and transport sectors, they are the primary target of computer attacks from both the criminal community and the specialized public services of foreign countries. CII objects constitute a zone of responsibility of primarily specia- lized state institutions that perform functions to ensure national security [12, p. 55-57]. As we indi- cated above, the financial regulator is authorized by the state to establish rules for the activities of all financial institutions, including in the sphere of the safety of their operations [8, p. 26]. The special legal status of the Bank of Russia is established by the Constitution of the Russian Fed- eration (Art.