Asymptotic Information Security Management Formal Description for Critical Information Infrastructure
Sergey Erokhin, Andrey Petukhov, Pavel Pilyugin, Sergey Litvinyuk · 2024
The article discusses a formal description of a theoretical method (management model) that can be used to implement process asymptotic management of information security (IS). In particular, it can be noted that such a model is typical for managing critical information infrastructure (CII) IS. The article discusses the general principles of information security management when using security level for asymptotic non-metric qualitative scales and risk assessment for metric (quantitative and ordinal) scales as a target value. The proposed formal description can act as a framework of different methods or their modifications.