5.1. When processing PD, the Operator takes all necessary legal, organizational and technical measures to protect them from unauthorized or accidental access, destruction, modification, blocking, copying, provision, distribution, as well as from other illegal actions in relation to them. Ensuring the safety of PD is achieved, in particular, in the following ways (taking into account their applicability, depending on the method and characteristics of PD processing):
5.1.1. appointment of a responsible person for the organization of PD processing;
5.1.2. by issuing documents defining the Operator's policy regarding PD processing, local acts on PD processing, defining for each purpose of PD processing the categories and list of PD being processed, the categories of subjects whose PD is being processed, methods, terms of their processing and storage, the procedure for destroying PD when achieving the goals of their processing or upon the occurrence of other legitimate grounds, as well as local acts establishing procedures aimed at preventing and detecting violations of the legislation of the RF, eliminating the consequences of such violations;
5.1.3. implementation of internal control and (or) audit of compliance of PD processing with the requirements of 152-FZ and regulatory legal acts adopted in accordance with it, requirements for PD protection, local acts of the Operator;
5.1.4. assessment of the harm that may be caused to PD subjects in case of violation of 152-FZ, the ratio of the specified harm and the measures taken by the Operator aimed at ensuring the fulfillment of obligations provided for by 152-FZ;
5.1.5. familiarization of persons directly engaged in PD processing for the purposes provided by the Operator with the provisions of the legislation of the RF on PD, including requirements for PD protection, local acts of the Operator regarding PD processing and (or) training of these persons;
5.1.6. identification of security threats to PD that may arise during their processing in the PDIS;
5.1.7. the application of organizational and (or) technical measures to ensure the safety of PD during their processing, including in PDIS, necessary to ensure the constant confidentiality, integrity, accessibility and stability of processes and (or) systems related to PD processing;
5.1.8. the use of information security tools that have passed the compliance assessment procedure in accordance with the established procedure, when the use of such tools is necessary to neutralize current threats to the security of PD and information technologies used in PDIS;
5.1.9. assessment of the effectiveness of the measures taken to ensure the safety of PD before commissioning of the PDIS;
5.1.10. determining the storage locations of PD material media, as well as ensuring the accounting and safety of PD material media;
5.1.11. by detecting the facts of unauthorized access to PD and taking appropriate measures, including measures to detect, prevent and eliminate the consequences of computer attacks on PDIS related to PD processing, and to respond to computer incidents in them;
5.1.12. restoration of PD modified or destroyed due to unauthorized access to them;
5.1.13. control over the measures taken to ensure the safety of PD and the level of protection of PDIS;
5.1.14. by establishing a list of persons involved in the processing of PD, including in the PDIS, and restricting access to PDIS for other persons;
5.1.15. the organization of the security regime of the premises in which PD processing is carried out and (or) the software and hardware used for PD processing are located;
5.1.16. establishing rules for access to PD processed in PDIS, as well as ensuring registration and accounting of all actions performed with PD in PDIS.
5.2. In case of establishing the fact of illegal or accidental transfer (provision, distribution, access) of PD, which resulted in violation of the rights of PD subjects, the Operator, in accordance with the procedure provided for by law and within the appropriate time frame, notifies the authorized body for the protection of the rights of PD subjects about this fact.
5.3. The Operator may ensure connection to the GosSOPKA and inform the federal executive authority authorized in the field of security, represented by the NCICC, about computer incidents that led to the illegal transfer (provision, distribution, access) of PD.