Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Security Deck
    • Overview
    • Security Deck workspaces
    • Alerts in Security Deck
      • Overview
      • Yandex Cloud basic security rules
      • Cloud infrastructure security standard Yandex Cloud
      • CIS Benchmark™ requirements for Kubernetes
      • Personal data protection standard for Yandex Cloud users
      • PCI DSS standard in Yandex Cloud
      • Requirements of the GOST R 57580 standard
    • Data Security Posture Management (DSPM)
    • Kubernetes® Security Posture Management (KSPM)
    • Cloud Infrastructure Entitlement Management (CIEM)
    • Cloud Security Posture Management (CSPM)
    • Threat Detector (TD)
    • Vulnerability Management (VM)
    • Access Transparency
    • AI assistant
    • Quotas and limits
  • Pricing policy
  • Audit Trails events
  • Release notes
  1. Concepts
  2. Compliance UI
  3. Requirements of the GOST R 57580 standard

GOST R 57580 requirements

Written by
Yandex Cloud
Updated at May 28, 2026

Note

This feature is at the Preview stage.

GOST R 57580 is the national security standard for banking and financial operations. This standard defines information protection levels and establishes baseline administrative and technical safeguards for each tier.

The standard aligns implemented controls with the active threat landscape and accepted operational risks associated with financial and banking services, including money transfers.

These rules help ensure compliance with GOST R 57580:

Security standard requirement

Check IDs in the CSPM module

7.2.1. Subprocess Managing accounts and permissions of logical access subjects

УЗП.10; УЗП.17–УЗП.21

cspm.access.min-privileges

УЗП.22–УЗП.27

cspm.access.check-privileged-roles

УЗП.22–УЗП.25; УЗП.28

cspm.access.kms-keys-access

УЗП.8–УЗП.13; УЗП.17–УЗП.20

cspm.access.check-bindings

УЗП.10; УЗП.17–УЗП.21

cspm.access.min-privileges

РД.14–РД.15

cspm.cookie-timeout.organization

УЗП.22–УЗП.25

cspm.access.user-groups-access

РД.31; УЗП.17–УЗП.20

cspm.access.user-groups-mapping

7.2.2. Subprocess Identification, authentication, and authorization (access control) associated with logical access

РД.30-РД.31; РД.39-РД.44

cspm.access.idp
cspm.k8s.access

РД.14–РД.15; РД.30–РД.31

cspm.access.serial-console

РД.17–РД.18

cspm.crypto.secrets-lockbox
cspm.crypto.secrets-serverless
cspm.appsec.cdn-https

РЗИ.14

cspm.appsec.cdn-https

РД.30–РД.31

cspm.access.db-console-access
cspm.access.os-login-onto-hosts.vm

РД.31; УЗП.17–УЗП.20

cspm.access.user-groups-mapping

РД.30–РД.31; ИУ.7–ИУ.8

cspm.access.bucket-access-policy

РД.31

cspm.k8s.kspm

7.2.4. Subprocess Identifying and registering resources and access objects

УЗП.10; УЗП.17–УЗП.20

cspm.access.sa-privileges-org-roles
cspm.access.sa-privileges-service-roles

УЗП.22–УЗП.25

cspm.access.privileged-sa-access

РД.29; РД.43–РД.44

cspm.crypto.sa-key-rotation

РД.30–РД.31

cspm.access.defined-key-scopes

СМЭ.16–СМЭ.19; ИУ.7–ИУ.8

cspm.access.bucket-public-access

ИУ.1–ИУ.4

cspm.o11y.labeled-resources

РД.30–РД.31; ИУ.7–ИУ.8

cspm.access.bucket-access-policy

7.3.1. Subprocess Network segmentation and firewalling

СМЭ.3; СМЭ.9; СМЭ.16; СМЭ.21

cspm.network.network-firewall

СМЭ.3; СМЭ.16

cspm.network.firewall

СМЭ.16–СМЭ.19; СМЭ.21

cspm.access.public-access
cspm.network.network-firewall-scope
cspm.k8s.network-firewall-scope
cspm.trusted-ip
cspm.trusted-ip-k8s

СМЭ.16–СМЭ.19

cspm.network.db-security-group
cspm.network.ydb-public
cspm.network.serverless-uses-vpc
cspm.k8s.api-security

СМЭ.1

cspm.network.serverless-uses-vpc

СМЭ.17

cspm.access.db-datalens-access

СМЭ.19

cspm.access.acl-container-registry

СМЭ.16–СМЭ.19; ИУ.7–ИУ.8

cspm.access.bucket-public-access

7.3.2. Subprocess Detecting intrusions and network attacks

ВСА.8; ВСА.9

cspm.appsec.ddos-protection.l3

ВСА.1–ВСА.7; BCA.11–BCA.13

cspm.appsec.use-sws
cspm.appsec.use-waf

ВСА.1–ВСА.7

cspm.appsec.use-arl

7.3.3. Subprocess Protecting information transmitted over computer networks

3ВС.1–3ВС.2

cspm.crypto.certificate-validity

3ВС.2

cspm.data.storage-https
cspm.appsec.alb-https
cspm.appsec.api-gateway-https
cspm.appsec.cdn-https

7.4.2. Subprocess Vulnerability management

ЦЗИ.4–ЦЗИ.6

cspm.aws-token

ЦЗИ.1–ЦЗИ.11; ЦЗИ.20–ЦЗИ.26

cspm.k8s.secure-configuration

ЦЗИ.1–ЦЗИ.11; ЦЗИ.20–ЦЗИ.26

cspm.o11y.gitlab-audited

7.4.3. Subprocess Software placement, storage, and update governance

ЦЗИ.16

cspm.db.db-deletion-protection

ЦЗИ.1–ЦЗИ.11; ЦЗИ.20–ЦЗИ.26

cspm.k8s.secure-configuration

ЦЗИ.1–ЦЗИ.11; ЦЗИ.20–ЦЗИ.26

cspm.o11y.gitlab-audited

7.4.4. Subprocess Software inventory management and integrity control across the IT infractructure

ЦЗИ.1–ЦЗИ.11; ЦЗИ.20–ЦЗИ.26

cspm.k8s.secure-configuration
cspm.o11y.gitlab-audited

7.5. Process 4 Protection against malicious code

ЗВК.8–ЗВК.12

cspm.appsec.secure-registry

ЗВК.11–ЗВК.12

cspm.appsec.periodic-scan

ЗВК.20; ЗВК.12

cspm.appsec.registry-recently-scan

ЗВК.20; ЗВК.11–ЗВК.12

cspm.appsec.secure-registry

7.7.1. Subprocess Information security event monitoring and analysis

МАС.1–МАС.9

cspm.o11y.audit-trails
cspm.appsec.use-smartcaptcha

МАС.1–МАС.7

cspm.o11y.data-plane-events

МАС.22

cspm.s3.used-object-lock

6.12. General provisions for the use of cryptographic information protection tools

РЗИ.14

cspm.crypto.keys-hsm
cspm.data.object-storage-encryption
cspm.crypto.managed-vm-kms
cspm.appsec.cdn-https

РД.17–РД.18

cspm.appsec.cdn-https

УЗП.28

cspm.crypto.keys-rotation
cspm.crypto.keys-deletion-protection

Was the article helpful?

Previous
PCI DSS standard in Yandex Cloud
Next
Data Security Posture Management (DSPM)
© 2026 Direct Cursus Technology L.L.C.