RuCloud
FZ-187 Compliant Cloud
"Cloud 187" (RuCloud) simplifies compliance with Federal Law 187 for Critical Information Infrastructure (CII) operators, helping them avoid violations related to CII operations.
Cloud infrastructure is built on hardware and software listed in the Russian Software Registry.
Cloud constructor
Price
Price
What security level do you need?
Data can be non-critical or critical. Critical data is categorized based on:
Social Impact
Political Impact
Economic Impact
Environmental Impact
The required security level depends not only on data category but other factors. Submit a request, and Cloud4Y experts will help determine the right protection level for you.
Our Services
Depending on data category, FZ-187 compliance may involve multiple tasks. Cloud4Y’s experts offer:
- Compliance documentation audit
- Threat modeling per FSTEC & FSB guidelines
- Secure information system architecture design
- Documentation package (threat models, technical designs, organizational policies, etc.)
- Deployment of information security tools
- Security effectiveness assessment programs per FSTEC Order 239
Our Licenses
How CII Cloud Security Works
FZ-187 compliance involves security at two levels: data center and CII client.
Data Center Level
CII Client Level
Includes internal policies, data handling procedures, assigning roles, and defining security requirements
Includes firewalls, Dr.Web antivirus, vulnerability scans, logging tools, data encryption, etc.

FAQ
- Form a categorization committee
- Compile a CII inventory
- CII inventory approval (optional)
- Submit inventory to FSTEC
- Data collection for categorization
- Threat analysis
- CII object categorization
- Submit categorization results to FSTEC
