Habr•August 17, 2026ā€¢šŸ‡·šŸ‡ŗTranslated from Russian

Ozon Data Security Team Details Audit Framework to Eliminate Paper-Only Compliance

Ozon’s Data Security team has published a detailed account of its internal audit methodology designed to move beyond formal compliance reports and deliver measurable improvements in data protection.

Alena, who leads the group of 11 analysts, explains that the company handles large volumes of personal data and private data distributed across numerous microservices. These include customer names, addresses, payment details, order contents, and internal business information that must be protected under Federal Law 152-FZ and company requirements. Primary fines for violations range from 150–300 thousand rubles, with repeat offenses reaching 300–500 thousand rubles and potential penalties up to 3 percent of annual turnover or 500 million rubles for data leaks.

How the datasec audit is conducted

The process begins with system familiarization: analysts map microservices, APIs, data flows, and access points, often creating visual diagrams that can take weeks to complete for complex CRM systems. They then review role-based access models to detect excessive permissions. In one audit, broad rights to modify product tags were narrowed because incorrect tagging could lead to storage and display errors causing significant financial damage.

Next, the team examines both employee and service account access. One review covered more than 84,000 user-role combinations, resulting in recommendations to revoke unnecessary privileges that could be exploited if an account were compromised. Logging is another focus area; teams are required to enable human-readable audit logs that support incident investigation, real-time alerts, and playbooks for detecting mass data exports or suspicious UI activity.

Protected access and storage are verified through mandatory use of HTTPS and database encryption so that even direct database access does not expose readable information. Analysts also assess additional architecture elements depending on the specific system under review.

Prioritization model and guiding principles

To decide which systems to audit first, the team applies a scoring framework that evaluates four core parameters: Data (volume and sensitivity), Importance (business criticality), Number (employee count interacting with the system), and Money (potential financial loss from downtime or leakage). Optional factors include incident history, user type, and regulatory obligations such as critical information infrastructure requirements.

The group stresses that audits must produce real changes rather than remain on paper. A notable success involved removing recipient names, phone numbers, and addresses from Ozon delivery boxes. Although the practice was legally permissible, the team argued it created an unnecessary risk of bulk data collection; after implementation, delivery operations continued without disruption.

Key recommendations include setting clear priorities, examining security implications at the business-requirements stage, being willing to redesign long-standing processes, maintaining open dialogue with development and business teams, and assembling analysts who are personally invested in practical outcomes. The ultimate measure of success, according to Alena, is when the first recommendation from an audit report becomes an implemented change in production.

Related articles

Habr•Policy & Regulation

How Russian Companies Can Legally Transfer Personal Data to Contractors Under 152-FZ

The article explains the legal distinction between data processors and independent operators when outsourcing tasks involving personal data. It details that the role of a contractor is determined by who sets the processing purpose, not by the service contract itself. For processors, a detailed data processing instruction under Article 6 of 152-FZ is required, while independent operators need a separate legal basis such as consent or contract performance. Special rules apply to employee data under Article 88 of the Labor Code, mandating written employee consent for transfers to third parties. The guidance also covers sub-processing risks, transparency obligations, and penalties under Article 13.11 of the Code of Administrative Offenses. Practical checklists help organizations classify contractors and prepare the correct documentation.

AntiMalware•Policy & Regulation

Russian Data Centers May Face Temporary State Management Under Decree 604 for Protection Shortfalls

Large Russian data centers could be placed under temporary government administration if they fail to meet security requirements outlined in presidential decree No. 604. The measure targets critical infrastructure operators that neglect physical and cyber protections, create operational risks, or respond slowly to incidents such as drone strikes. Rosimushchestvo would typically assume management duties by default. Market participants note that Tier III and higher facilities generally maintain strong cyber defenses, shifting the main compliance burden to physical safeguards for generators, cooling systems, and network nodes. Operators including RTK-DC and RUVDS have already begun reviewing and upgrading external equipment protection. Additional costs for redundant communications, DDoS mitigation, vulnerability management, and faster recovery are expected to be passed on to clients in government, finance, and telecom sectors. First Deputy Prime Minister Denis Manturov stated that decisions will remain targeted and will not trigger widespread nationalization.

AntiMalware•Policy & Regulation

iMazing 3.6.3 Restores Sideloading of Removed iOS Apps via macOS After Apple Authentication Changes

Developers of iMazing have released version 3.6.3 that restores the ability for users to download and install applications previously removed from the App Store onto iPhone devices. The update currently functions only through macOS, with Windows support still pending further development. The changes address authentication and download errors that appeared in macOS 26 and earlier versions following modifications by Apple to its CommerceKit system. Apple began returning HTTP 403 Forbidden responses to tools including iMazing, ipa_downloader, and 3uTools by deactivating legacy tokens and revoking certificates used for app authentication. The restrictions have particularly affected Russian users who relied on these tools to reinstall banking and other applications removed due to sanctions. Support for macOS 27 Golden Gate and Windows remains unavailable and requires additional engineering work.

Habr•Policy & Regulation

FSTEC Order 60 Expands Attestation Rules to Municipal Systems, Defense Industry and Personal Data Operators

Russia's FSTEC Order No. 60, effective 1 September 2026, rewrites the list of entities subject to information system attestation under the updated Order No. 77. The changes reach far beyond state information systems to cover municipal information systems, industrial control systems at defense enterprises, protected premises for confidential talks, and any commercial personal data operators that voluntarily included attestation in their policies. New clauses introduce mandatory vulnerability analysis and penetration testing as explicit control methods, tighten reporting deadlines to five working days, and require FSTEC-licensed organizations with specific rights for testing. Parallel FSB Order No. 297 obliges every state institution, including schools and hospitals, to report incidents to NKTSKI within 24 hours via a personal cabinet established only after a formal interaction regulation is signed. Government Decree No. 1024 permits cloud services for state systems but keeps full compliance responsibility with the user organization. The combined rules take effect on 1 September 2026, with one provision delayed until March 2027.