📜 ⬆️ ⬇️

How to adjust the law of Spring to make it lifting for small providers? Cancel it

On June 7, 2019, a vigorous discussion of the situation that developed around the small Internet provider Firma Svyaz from the city of Yeisk, Krasnodar Territory (5,000 customers, annual revenues of 20 million rubles) was launched on Habré. The provider refused to comply with the requirement of Roskomnadzor under the law of Yarovoy - to purchase equipment that has not yet passed certification - and began to challenge the results of the inspection. Roskomnadzor sued . At the same time, the court, having admitted procedural violations, made a decision seven working days after receipt of the application of the RKN, which violates the constitutional right to judicial protection. The Ministry of Communications and Mass Media admitted that there is a gap in the legislation and promised to eliminate the “legislative lacuna”.

We asked Dmitry Galushko, a lawyer representing the interests of Firms Svyaz, the general director of OrderCom, to comment on the situation.

He said that after the law came into force, Spring had a deplorable situation in the market. For small providers, equipment installation costs 50–70% of annual revenue. Many leave the market in black or gray schemes, or are forced to be sold.

On the sale of equipment for SORM, the same supplier companies that have contacts in the structures of power and the opportunity to obtain a state license are “fed”. “This is a closed market, to which not everyone is allowed ... Now in the Krasnodar Territory only three manufacturers are recommended. In some regions, there has recently been one (St. Petersburg for example) in general, ”says Dmitry Galushko.
')
Apparently, in Russia, only five companies have passed certification tests for compliance with the requirements of SORM-2 (carries out selective monitoring of Russian Internet users, is a server that passes all provider traffic through itself, collects and transmits the requested information to security forces):

  1. "MFI Soft"
  2. "Kon Certeza"
  3. "Norse-Trans"
  4. "Ziroudey Technologies"
  5. “Special Technologies” (“Phoenix”)



No one has yet certified equipment for the “Law of Spring”, but Roskomnadzor and the FSB are still pushing providers to enter into contracts with manufacturers. “We are being offered to invest in storage systems, which may be later certified, but we found ourselves in a similar situation with the implementation of SORM-2 and SORM-3 requirements. We spent the money, and the SORM-3 equipment has not yet been certified, ”said Sergey Suboch, Director of Firma Svyaz.

One of the laws of the “Spring Package” obliges telecom operators to store calls and subscriber traffic for a period determined by the government of the Russian Federation (but no more than six months) in accordance with Article 64 of the Federal Law “On Communications”, and information about facts reception, transmission, delivery and processing of messages and calls (metadata) - three years.

On April 12, 2018, the government of the Russian Federation signed a decree that telecom operators are obliged to store text, voice, video and other messages of users for 30 days. Further, the operator is obliged to increase the storage system by 15% per year.

If there is no certified equipment, and the authorities insist on installing non-certified, then the question arises: why buy it? Maybe it is possible to install the equipment yourself? Dmitry Galushko published his correspondence with the authorities at the industry forum of Russian Internet providers, from which such a conclusion can be drawn.

But in practice, the FSB requires providers to agree on a plan for the implementation of SORM and purchase equipment as soon as possible. “Svyaz Firm” filed all the documents on the plan for the implementation of the equipment, but there were disagreements on the timing: “We fulfill all the requirements. Only the UFSB of the Krasnodar Territory requires to sign a Plan for the implementation of 374-FZ Spring with the end of January 2020, but there may be no certificates by that date, the lawyer explains. “Other departments act according to the law, allowing them to be tied to the date of receipt of certificates (see the answers of the Ministry of Communications).

Thus, in January 2019, the FSB Department for the Krasnodar Territory refused to approve the company’s plan for introducing SORM equipment due to the fact that the proposed period exceeded a year. “After that, the local Roskomnadzor administration began an inspection, and on May 27 filed four lawsuits about bringing the company to administrative responsibility, follows from the court file. On June 6, having considered two protocols, the court supported the position of Roskomnadzor, and two more will be considered later, ”said Sergey Suboch, CEO.

A spokesman for the Ministry of Communications and Mass Media said that they were aware of a problem in the legislation, which would be eliminated by an order soon. “I know that we are not talking about a corrective order,” Dmitry Galushko corrects, “but about the second stage of the way to certification, the adoption of a test procedure.” By the way, this order was returned for revision, since the manufacturers did not agree on the test methodology (it is approved by the order of the Ministry of Communications in coordination with the FSB). After three more stages: installation of the stand for SORM in the data center, where test operators will be connected (there should be enough space and time for all manufacturers who want to be certified. Then the tests themselves should be done (this is not a quick procedure, because the SORM technical measures on the equipment must be correctly visible from the SORM control panel.) Then, issuing certificates (three months). And there must also be FSTEC certificates for monitoring database security (so that SORM is not hacked and personal data stolen).

According to Galushko’s forecasts, realistic system implementation times are mid-2020.

But what should small providers do for whom the purchase of equipment is an extremely heavy task? How should I change the package of Spring to make it possible for providers of your size?

Dmitry Galushko categorically answers this question: “Cancel. For earlier it was envisaged 12 hours of storage, and then the norms were simultaneously increased by 60 (!) Times. ”

Minute of care from UFO


This material could cause conflicting feelings, so before writing a comment, refresh something important in your memory:

How to write a comment and survive
  • Do not write offensive comments, do not go to the person.
  • Refrain from using obscene language and toxic behavior (even in a veiled form).
  • To report comments that violate the rules of the site, use the "Report" button (if available) or a feedback form .

What to do if: minus karma | blocked account

→ Code of authors Habra and habraetiket
→ Full site rules

Source: https://habr.com/ru/post/455373/


All Articles