Assessment of compliance of information security tools with legal requirements

mdtech PROVIDES EXPERT ANALYSIS OF SECURITY LEVELS AND COMPLIANCE ASSESSMENT OF INFORMATION SECURITY TOOLS WITH UZBEKISTAN LEGISLATION AND INDUSTRY STANDARDS

Project Objective: To reduce the probability of IS incidents and minimize the risk of sanctions and fines from Uzbekistan's regulatory bodies by aligning security tools with national and international regulations.

mdtech Conducts Compliance Audits Against:

  • Law of the Republic of Uzbekistan No. ZRU-547 "On Personal Data."

  • Law of the Republic of Uzbekistan No. ZRU-547 "On Cybersecurity" (for Critical Infrastructure).

  • Central Bank of Uzbekistan requirements for information protection in financial institutions.

  • PCI DSS (Payment Card Industry Data Security Standard).

  • ISO/IEC 27001 (International IS management practices).

  • State Cybersecurity Center requirements for the protection of State Information Systems (SIS).

What We Verify:

  1. Personnel: Interviewing employees to assess their security awareness.

  2. Documentation: Analyzing internal regulations, policies, and instructions for compliance with local laws.

  3. Infrastructure: Reviewing settings of software, security tools, firewalls, and encryption of communication channels.

  4. Processes: Verifying the actual implementation of access control and incident monitoring measures.

IP telephony and video conferencing