SOT

SOT

SOAR
Security Orchestration, Automation and Response

Automation of response to information security incidents using dynamic playbooks and information security tools, building an attack chain and with an object-oriented approach

NG SOAR
Next Generation SOAR

Automation of response to information security incidents with built-in basic correlation (SIEM), vulnerability Scanner (VS), collection of raw events directly from information security tools, dynamic playbooks, building an attack chain and an object-oriented approach. AM and VM are included

AM
Asset Management

Description of the IT landscape, detection of new objects on the network, categorization of assets, inventory, life cycle management of equipment and software on automated workstations and servers of organizations

VS
Vulnerability Scanner

Scanning information assets with enrichment from any external services (additional scanners, The Data Security Threats Database and other analytical databases) to analyze the security of the infrastructure.

VM
Vulnerability Management

Building a process for detecting and eliminating technical vulnerabilities, collecting information from existing security scanners, update management platforms, expert external services and other solutions

FinCERT
Financial Computer Emergency Response Team

Bilateral interaction with the Central Bank, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

GovCERT
Government Computer Emergency Response Team

Bilateral interaction with the state coordination center for computer incidents, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

Mail us to sales@securityvision.ru or get demo presentation

Security Vision presents a new product: Security Vision Personal Data Management

Security Vision presents a new product: Security Vision Personal Data Management
14.05.2026

Security Vision has launched a new product, Security Vision Personal Data Management, designed to control and implement personal data processing and protection requirements in accordance with the following regulatory legal acts:

   -  Federal Law No. 152-FZ of July 27, 2006, "On Personal Data"

   -  Russian Government Resolution No. 1119 of November 1, 2012, "On Approval of Requirements for the Protection of Personal Data When Processed in Personal Data Information Systems"

   -  Order No. 21 of the Federal Service for Technical and Export Control of Russia of February 18, 2013, "On Approval of the Composition and Content of Organizational and Technical Measures to Ensure the Security of Personal Data When Processed in Personal Data Information Systems"

 

This product is suitable for personal data operators, including small companies, medium-sized and large organizations with branches or subsidiaries, and the ability to integrate with various local systems.

 

The product includes the following features:

   -  Formation of processes related to the processing of personal data (PD)

   -  Formation of personal data information systems (PDIS)

   -  Determining the level of security of personal data processed in the information system of personal data

   -  Accounting and monitoring of requests from personal data subjects

   -  Monitoring consents and revocations of consents of personal data subjects

   -  Accounting and control of machine-readable media with personal data

   -  Accounting for personal data protection measures

   -  Accounting and control of computer incidents related to personal data

   -  Modeling threats to personal data security

   -  Formation of basic measures for the protection of personal data with the possibility of adaptation, clarification and supplementation

   -  Conducting an assessment of compliance with personal data security (protection) requirements

   -  Planning measures to protect personal data

   -  Formation of a documentation package based on the requirements of regulatory legal acts

 

Process accounting and ISPDN


Lists of processes and information systems that process personal data are formed on the basis of questionnaires sent to responsible persons in the organization, or by entering existing data into the system.


When creating an ISPD, a full range of information on the processing and protection of personal data is entered, including:

   -  Purposes of processing

   -  Legal basis

   -  Categories, categories of subjects, list of personal data and actions on them


Data is collected and accumulated from all available information systems for personal data, with the ability to generate the necessary notifications to Roskomnadzor.


Determining the level of security and developing protective measures


The level of security for personal data processed in the personal data information system (ISPD) , which is necessary for building further protection, is automatically calculated for each ISPD. Based on the determined security level, a basic set of personal data protection measures is also automatically generated, with the ability to adapt, refine, and supplement them for a specific ISPD.


Threat modeling and compliance assessment


Modeling of threats to the security of personal data can be carried out in accordance with the methodological document of the Federal Service for Technical and Export Control of Russia “Methodology for Assessing Information Security Threats”.


Two modeling approaches have been implemented:

   -  a new section on threats, including threat groups, threats within groups, and the corresponding methods for implementing these threats

   -  a general list of threats, methods of their implementation and scenarios, based on the sequence of tactics and corresponding techniques, to determine the current methods of implementing information security threats


Compliance with personal data security requirements is assessed in accordance with the regulatory legal acts specified above. The assessment is conducted by completing information on the current status of personal data protection in the Personal Data Information System (PDIS), with the option to delegate (in whole or in part) the questionnaires to the appropriate specialists.


Based on the results of the compliance assessment, a list of unimplemented requirements is compiled, followed by the creation of an action plan and necessary tasks.


Monitoring consents, responses, and requests from personal data subjects


We've implemented the ability to store consents from personal data subjects for personal data processing and monitor their revocation after a request. All requests from personal data subjects are recorded in a log of requests and inquiries, with a record of the request completion deadline and the assignment of tasks to performers based on the specific request type. We also monitor the established deadlines for completing requests.


Documentation


Following the completion of the product's core processes, a complete documentation package is generated based on regulatory legal requirements and developed templates. If necessary, the documentation can be adapted to the organization's local requirements.


Key metrics and the current state of processes in the organization are monitored at any given time using a set of dashboards.

Recommended

Threat Intelligence without Myths: What TI Is Not and Why It Is Often Implemented Incorrectly
Threat Intelligence without Myths: What TI Is Not and Why It Is Often Implemented Incorrectly
Next Generation (NG) information security solutions
Next Generation (NG) information security solutions
No - code development and ML assistants are the next generation of SOC analyst tools
No - code development and ML assistants are the next generation of SOC analyst tools
Out of the box: alienable correlation mechanism
Out of the box: alienable correlation mechanism
How AI is changing cybersecurity
How AI is changing cybersecurity
Next Generation Firewall (NGFW) – what is it and what does it protect against
Next Generation Firewall (NGFW) – what is it and what does it protect against
Red Teaming: Simulating a Real Cyber Threat
Red Teaming: Simulating a Real Cyber Threat
Spam - what it is, what it can be and whether it is useful
Spam - what it is, what it can be and whether it is useful
Quantum computers and post-quantum cryptography
Quantum computers and post-quantum cryptography
When the database becomes an open book
When the database becomes an open book
Compliance in information security
Compliance in information security
AI Cybersecurity. P. 3: AI Regulation, Standardization and Cybersecurity
AI Cybersecurity. P. 3: AI Regulation, Standardization and Cybersecurity

Recommended

Threat Intelligence without Myths: What TI Is Not and Why It Is Often Implemented Incorrectly
Threat Intelligence without Myths: What TI Is Not and Why It Is Often Implemented Incorrectly
Next Generation (NG) information security solutions
Next Generation (NG) information security solutions
No - code development and ML assistants are the next generation of SOC analyst tools
No - code development and ML assistants are the next generation of SOC analyst tools
Out of the box: alienable correlation mechanism
Out of the box: alienable correlation mechanism
How AI is changing cybersecurity
How AI is changing cybersecurity
Next Generation Firewall (NGFW) – what is it and what does it protect against
Next Generation Firewall (NGFW) – what is it and what does it protect against
Red Teaming: Simulating a Real Cyber Threat
Red Teaming: Simulating a Real Cyber Threat
Spam - what it is, what it can be and whether it is useful
Spam - what it is, what it can be and whether it is useful
Quantum computers and post-quantum cryptography
Quantum computers and post-quantum cryptography
When the database becomes an open book
When the database becomes an open book
Compliance in information security
Compliance in information security
AI Cybersecurity. P. 3: AI Regulation, Standardization and Cybersecurity
AI Cybersecurity. P. 3: AI Regulation, Standardization and Cybersecurity