ІNTERNATIONAL STANDARDS IN THE SECURITY OF CRITICAL INFORMATION INFRASTRUCTURE

M.V. Sokiran · Actual problems of native jurisprudence · 2024

У статті проаналізовано міжнародні та європейські документи, що встановлюють стандарти щодо захисту та стійкості критичної інфраструктури загалом та інформаційної -зокрема.Визначено, що кібербезпека -це важлива складова всієї системи забезпечення безпеки країни і є стабілізуючим елементом стійкості суспільства.Тому країни світу почали розробляти правові стандарти та політики у сфері забезпечення безпеки критичної інформаційної інфраструктури.З'ясовано, що термін «інформаційна безпека» є частиною загального поняття безпека і формує тип безпеки, для якого, як і для самої безпеки, існує багато визначень.Однак існує відносний консенсус у безпековій спільноті щодо основних характеристик терміну інформаційна безпека.Зазначено, що термін «інформаційна безпека» є ширшим, тоді як термін «кібербезпека» означає захист інформації в «кіберпросторі», який широко розуміється як Інтернет, однак для цілей цієї статті ці два терміни розглянуто як еквівалентні.Досліджено Міжнародний стандарт з інформаційної безпеки (ISO 27001) та зроблено висновок про необхідність інтеграції управлінських і технічних компетенцій у системи управління інформаційною безпекою.Підкреслено, що ефективне управління нею має враховувати та включати технічні, кадрові та організаційні аспекти.Аналіз юридичної літератури дозволив підтвердити висновок про необхідність інтеграційного підходу до забезпечення захисту критичної інформаційної інфраструктури.Оскільки контрзаходи безпеки часто приймають форму складних процедур, а в деяких випадках відсутність знань про прийнятті правила безпеки та відповідну поведінку не є основною причиною недотримання процедур безпеки.Скоріше це результат недостатньої організаційної культури безпеки, яка може наражати організацію на небезпеку в наслідок потенційної вразливості людини.Ключові слова: критична інформаційна інфраструктура, міжнародні стандарти, безпека, захист, інформаційна безпека, кібербезпека, система управління безпекою.The article analyzes international and European documents that set standards for the protection and stability of critical infrastructure in general and information infrastructure in particular.It was determined that cyber security is an important component of the entire system of ensuring the security of the country and is a stabilizing element of the stability of the world society, the countries of the world began to develop legal standards and policies in the field of ensuring the security of critical information infrastructure.It was found that the term "information security" is part of the general concept of security and forms a type of security for which, like security itself, there are many definitions.However, there is a relative consensus in the security community regarding the basic characteristics of the term information security.It is noted that the term "information security" is broader, while the term "cybersecurity" refers to the protection of information in "cyberspace", which is broadly understood as the Internet, but for the purposes of this article, the two terms are considered equivalent.The International Standard for Information Security (ISO 27001) was studied, and a conclusion was drawn about the need to integrate managerial and technical competencies into information security management systems, and it was emphasized that its effective management should take into account and include technical, personnel and organizational aspects.The analysis of legal literature allowed to confirm the conclusion about the need for an integration approach to ensure the protection of critical information infrastructure.Since security countermeasures often take the form of complex procedures, and in some cases, lack of knowledge about the adoption of security rules and appropriate behavior is not the main reason for non-compliance with security procedures.Rather, it is the result of an insufficient organizational security culture, which can expose the organization to danger as a result of potential human vulnerability.

Read the paper · More papers on PaperTik