document introduces a classification of automated NM A&C systems, defines requirements to information access security features depending on the class of the NM A&C system and, finally, specifies certification and qualification requirements to information security features.
Classification of NM A&C systems
Classification of NM A&C systems is introduced for the purpose of developing and employing valid measures to achieve the required level of information security. The security class is determined by the NM A&C system user and developer with involvement of information security experts. The following system features are used as criteria in establishing the class of security:
∙presence in the NM A&C system of information of different secrecy levels;
∙level of the user authority for access to classified information;
∙procedures and conditions for the deployment and operation, and the physical security status the NM A&C system computers.
Based on the estimates for these factors, the requirements establish three security classes for automated NM A&C systems. The highest of these is Class 1.
Class 3 includes NM A&C systems which are characterized by:
∙the presence of information of strictly one secrecy level;
∙all access subjects (except the administrator) having equal rights (powers) of access to the NM A&C system information;
∙all NM A&C computes installed within a controlled area and having no external physical information communications (leading to beyond the controlled area).
Class 2 includes NM A&C systems which are characterized by:
∙the presence of information of several secrecy levels;
∙subjects of access having different rights of access to the NM A&C system information;
∙all NM A&C system computers installed within one or more controlled areas and having no open external physical information communications.
Class 1 includes NM A&C systems which are characterized by:
∙the presence of information of several secrecy levels;
∙subjects of access having different rights of access to the NM A&C system information;