An information security solution for compliance with Amendment 13 must provide three core capabilities: information access control, data leak prevention, and auditing that proves compliance with the requirements. Amendment 13 to the Privacy Protection Law and the Information Security Regulations of 2017 together define the controls that every organization must implement. The right choice is a solution that maps each regulatory requirement to a concrete technological capability, so that compliance with the standard is measurable rather than declarative.
What do the information security regulations require alongside Amendment 13?
The 2017 Privacy Protection Regulations define security levels for databases—basic, medium, and high—with each level having its own requirements. Amendment 13 adds teeth of enforcement and fines. Together, they require access controls, event monitoring, and orderly documentation, with the scope of the requirements increasing as the database becomes larger and more sensitive.
Among the key requirements appearing in the regulations and the amendment, several can be listed that every organization must examine against its own situation:
- Access control: Role-based access control and the principle of least privilege
- Monitoring and documentation: Full logging of information access and security events
- Risk Assessment and Penetration Testing: At a high security level, periodically required
- Periodic review: Re-examination of the security status at intervals stipulated by regulations
- Leak prevention and encryption: Protection of data in transit and at rest from unauthorized exfiltration
An important point is that the requirements are not one-time. Compliance with Amendment 13 and the regulations is not a task that ends on implementation day, but rather an ongoing commitment to monitoring, documentation, and incident review over time. Therefore, a solution is required that provides ongoing and continuous control, rather than just a one-time setup that loses its validity over time.
How do access control and permission management meet the requirements?
Access control is the ability to know who is accessing what information, and to ensure that each user receives only the permissions necessary for their role. A monitoring and permissions system identifies excessive permissions, dormant accounts of former employees, and unusual access attempts, and allows them to be corrected. This capability directly addresses the access control and monitoring requirements in information security regulations.
Beyond identification, documentation is also required. A system that generates compliance reports and logs every permission change enables the organization to prove to the Privacy Protection Authority that it complies with the requirements, and this is a critical point in a world where enforcement is already active.
Another advantage is the ability to send real-time alerts. Instead of discovering after the fact that someone received unauthorized permissions or accessed sensitive information at an unusual hour, a good monitoring system sends an immediate alert and makes it possible to stop the incident while it is still happening. This way, the organization shifts from a reactive approach to a preventive one, which is exactly what regulators expect from an organization that responsibly manages a database.
How does data leak prevention complete the picture?
Access control controls who is authorized to access information, but it does not prevent those who are authorized from taking it outside. This is where a DLP solution comes in, preventing the leakage of sensitive information via email, USB devices, cloud services, and AI tools. The combination of access control and data loss prevention covers both sides of the equation: who enters the information and what leaves it.
Forced encryption of files exported to removable devices completes the protection, so that even if a device is lost, the data on it remains inaccessible. This also ensures the organization meets the requirement for protecting data in transit.
An additional layer is data aggregation. Event logs from the DLP solution and monitoring system are fed into a centralized security event management system, known as SIEM, which centralizes all the information and makes it possible to identify suspicious patterns and respond to them quickly. Such aggregation is important for both operational and regulatory purposes, because it creates the complete audit trail that the Privacy Protection Authority expects to see during an audit.
Which solution combines all these capabilities?
An information security solution for Amendment 13 compliance must unify access control, data loss prevention, and auditing under one roof. ofek dist distributes Netwrix solutions in Israel, combining Netwrix Auditor for access control, excessive permission identification, and compliance reporting with Netwrix Endpoint Protector for data loss prevention and endpoint-level encryption. Together, they cover most of the controls required by regulations and Amendment 13.
The advantage of ofek dist is not just in the product. As an information security company, ofek dist conducts risk assessments and penetration testing, thoroughly understands Israeli regulations, and accompanies the client in Hebrew and according to Israeli time zones from the initial assessment all the way to certification. This turns compliance from a daunting project into a managed process.
What does the implementation process of the solution look like?
Implementing an information security solution for compliance with Amendment 13 begins with a survey and mapping of the organization's information and systems, which reveals the gap analysis against the requirements. Based on the mapping, a work plan is built that prioritizes the controls and connects each regulatory requirement to the technological capability that addresses it.
Next comes the pilot and phased implementation stage, duringซึ่ง the controls are installed, connected to Active Directory and a central monitoring system, and their actual impact is tested before full rollout. This process concludes with organized documentation and compliance reports that enable the organization to prove its compliance with requirements in any future audit.
Mapping regulatory requirements to the solution
According to the 2017 Information Security Regulations, a database with a high security level requires a risk assessment and penetration test every 18 months, and an audit every 24 months. The table maps each key requirement to the technological capability that addresses it.
|
Requirement |
The ability that answers it |
|
Access control and excessive permission identification |
Netwrix Auditor |
|
Data loss prevention |
Netwrix Endpoint Protector |
|
Removable media encryption |
Enforced Encryption |
|
Discovery and Classification of Sensitive Information |
eDiscovery |
|
Documentation and compliance reports |
Netwrix Auditor reports |
Summary
Compliance with Amendment 13 and the information security regulations requires a solution that maps every requirement to a technological capability, access control, leak prevention, encryption, and logging. The combination of Netwrix Auditor with Netwrix Endpoint Protector, accompanied by professional guidance, provides a comprehensive response to the requirements. For a regulatory compliance assessment and full support, contact the ofek dist team today.
Frequently Asked Questions
What is the connection between Amendment 13 and the 2017 Information Security Regulations?
The Information Security Regulations 2017 define the technical controls required according to the database level, and Amendment 13 adds enforcement powers and fines to them. Together, they create the framework of obligations that the organization must comply with.
Do you need both an access control system and a DLP solution?
Yes, the two capabilities complement each other. Access control manages who is authorized to reach the information, and a DLP solution prevents it from being taken out by those who are authorized to access it.
How do you prove to the Privacy Protection Authority that the organization complies with the requirements?
Through documentation and compliance reports generated by the monitoring system. They show who accessed the information, what permissions exist, and which security events were logged and handled.
How often are a risk assessment and penetration test required?
At a high security level, information security regulations require periodic risk assessments and penetration testing. ofek dist, as an information security company, performs these assessments and tests and accompanies the organization in remediating the findings.
Is one solution enough for all the requirements of Amendment 13?
Combining access control with data loss prevention covers a significant portion of the technological controls required by regulations and Amendment 13. However, full compliance also requires procedures, appointments, and periodic surveys, which is why it is important to accompany the solution with appropriate regulatory consulting.