ANALYSIS OF CYBER SECURITY MANAGEMENT CONCEPTS FOR DISTRIBUTED IT INFRASTRUCTURES
Yuriy Ponochovniy · Systems and Technologies · 2019
The paper summarizes the current issues of security management of organi-zationally complex systems. Massive introduction of cloud technologies, the In-ternet of things (IoT), intelligent data processing systems, block chain technolo-gies is not only a fashionable trend, but also dictates the conditions for the deve- lopment of the information and communication systems industry. Organization, definition and classification of safety and cybersecurity ma- nagement concepts in organizationally complex systems are disclosed in the work of researchers in various industries: aviation, economic, information (cybersecu-rity), administrative, environmental and the like. The article summarizes basic principles of conceptual approaches to safety and cybersecurity management in scientific works and regulatory documents for various spheres of human life.The purpose of this article is to summarize basic principles for presenting conceptual approaches to managing the cybersecurity of IT-systems and infra-structures in scientific and regulatory documents. To solve the problem, it is ne- cessary to consider the concepts of security management in various spheres of human life, to determine the concept and components of cybersecurity for IT-systems and infrastructures, to consider the basic principles for various concep-tual approaches to security management.Attention is paid both to the components of IT-systems security (functional-, informational-, cybersecurity), and the qualities of complex systems that include security (dependability, functional reliability). Among the main provisions of se-curity management concepts, an important place is given to security policy, both the general and the whole (often as security strategies), and the separation of po- licies into global and local.A comparative list of principles for various concepts of managing IT-systems and infrastructures security is given. The security management concepts of distributed IT-systems are analyzed on the example of critical infrastructures, information and telecommunication systems, industrial automation systems, cy-berphysical systems and continuous business systems. It is determined that vari-ous concepts can use general principles, such as risk management, improvement/adaptation of the security management system.