THE CONCEPT OF INFORMATION SECURITY MANAGEMENT BASED ON A CYCLE OF INFORMATION SECURITY INCIDENTS CONTINUOUS DETECTION AND RESPONSE

Anna Oleynikova, Vyacheslav Vladimirovich Zolotarev · Известия Южного федерального университета. Технические науки · 2023

For dynamically changing management objects, new tasks arise in the task of informationsecurity management, such as changing approaches to data collection and analysis, developingdynamic scenarios for responding to information security threats. They should be solved throughthe creation of algorithms, models, methods and approaches of security management applicable tothis task, including at the level of organizing processes, working with data and forming the organization'sinformation security architecture. In addition, for the development and formation of continuousdetection and response tools, it is necessary to propose new ways of integrating these algorithmsinto the structure of the control object. At the same time, the creation of response systemsbased on the new concept also involves changing the security management algorithms of suchsystems in special cases, such as decentralized management, stability testing, cloud security servicesand others that require separate research. At the same time, responding to information securityincidents should take into account the continuously changing threat landscape and reconfigurationof the organization's infrastructure. Also, the development of the new concept presented inthe article was influenced by the concept of object-oriented programming in terms of the mainprovisions. This work contains a description of the control concept based on a continuous detectionand response cycle, provides some algorithms and processes that distinguish the implementationof the concept shown, as well as examples of their implementation. The practical examplesgiven in the article relate to issues such as the formation of the incident neighborhood, and allowyou to form the context of information security management. In addition, an approach to automationof information security management processes is shown. The results of the work can be usedboth for simulation models and for implementation as a set of information security managementprocesses in practical tasks. In addition, the results obtained can be integrated into orchestrationtools for information security systems, which increases the effectiveness of responding to informationsecurity incidents.

Read the paper · More papers on PaperTik