RISK PROCESS APPROACH IN PLANNING CYBER SECURITY MEASURES OF CRITICAL INFRASTRUCTURE FACILITIES

Lesya Kozubtsova · Collection of scientific works of the Military Institute of Kyiv National Taras Shevchenko University · 2021

Cybersecurity as a state of security of critical objects of the national information infrastructure and its individual components, which ensures their sustainable functioning and development, timely detection, prevention, neutralization of cyber threats is an urgent task of modern society. Ensuring cybersecurity and its management in an organization is a continuous cyclical process. It is based on the creative approach recommended in NIST Special Publication 800-53 and in the introduction of the process approach, presented in the ISO 9001: 2000 standard. The purpose of the study is to justify an approach to planning cybersecurity activities of critical information infrastructure objects based on the analysis of global solutions and approaches to planning cybersecurity activities of organizations. The article analyzes the key experience in solving and the approach to planning cybersecurity activities of organizations. It is established that the provision of cybersecurity and its management in the organization is a continuous cyclical process. Therefore, preference is given to the use of a process approach according to the PDCA scheme (Plan, Do, Chek, Akt). Based on the analysis, it is proposed to choose a basic approach to planning cybersecurity activities of organizations. Thus, the scientific novelty is obtained, which consists in the fact that for the first time it is proposed to supplement the "protection measures" block to the improved ontology of cybersecurity with a model of processes according to the PDCA scheme. The practical significance is to supplement the improved 67 cybersecurity ontology, namely the "protection measures" block with a model of processes according to the PDCA scheme, which allows us to obtain a methodology for planning measures to ensure cybersecurity of critical information infrastructure objects. It is advisable to focus the prospects for further research in this direction on the justification of the formulation of the problem of the expediency of development: 1) methods of planning cybersecurity measures for critical information infrastructure facilities; 2) methods for evaluating the effectiveness of measures aimed at ensuring the cybersecurity of critical information infrastructure facilities.

Read the paper · More papers on PaperTik