Review of national and international standards for categorizing of critical information infrastructure objects
Ensuring the security of critical information infrastructure facilities is an actual developing area of information security both at the national and global level. Categorization of critical infrastructure objects is an integral part of the common and holistic security process. With a dynamically...
Main Author: | |
---|---|
Format: | Article |
Language: | English |
Published: |
Saint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University)
2023-06-01
|
Series: | Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki |
Subjects: | |
Online Access: | https://ntv.ifmo.ru/file/article/22051.pdf |
_version_ | 1797798446848016384 |
---|---|
author | Ilya I. Livshitz |
author_facet | Ilya I. Livshitz |
author_sort | Ilya I. Livshitz |
collection | DOAJ |
description | Ensuring the security of critical information infrastructure facilities is an actual developing area of information security
both at the national and global level. Categorization of critical infrastructure objects is an integral part of the common
and holistic security process. With a dynamically changing threats level, the process of determining the category of an
object is still not optimal enough. Based on the existing requirements both of Russian and International standards, the
assessment of critical infrastructure facilities not always be carried out promptly and correctly, in addition, numerical estimates are not formed, the objectivity of the assessment and subsequent reassessment by independent experts is not
ensured. This article presents an analysis of the current requirements in the field of categorization of critical infrastructure
objects used in the Russian Federation. A comparative analysis of the national regulatory legal acts of the Russian
Federation and the system of International standards in the field of IT-security is presented. Regulation of categorization
processes of critical infrastructure objects is considered. The necessity of forming numerical values of significance
criteria for the correct determination and subsequent independent evaluation (reassessment) of the category of critical
infrastructure objects is substantiated. Recommendations for improving the process of categorizing critical infrastructure
objects and the formation of numerical estimates are presented. The implementation of the recommendations made
will improve the accuracy, objectivity and reliability of the process of creating modern information security systems. |
first_indexed | 2024-03-13T04:03:50Z |
format | Article |
id | doaj.art-0f6302a39f9b484dbc7c523e6c7e4ab5 |
institution | Directory Open Access Journal |
issn | 2226-1494 2500-0373 |
language | English |
last_indexed | 2024-03-13T04:03:50Z |
publishDate | 2023-06-01 |
publisher | Saint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University) |
record_format | Article |
series | Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki |
spelling | doaj.art-0f6302a39f9b484dbc7c523e6c7e4ab52023-06-21T09:10:31ZengSaint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University)Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki2226-14942500-03732023-06-0123351952910.17586/2226-1494-2023-23-3-519-529Review of national and international standards for categorizing of critical information infrastructure objectsIlya I. Livshitz0https://orcid.org/0000-0003-0651-8591D.Sc., Professor of Practice, ITMO University, Saint Petersburg, 197101, Russian Federation, sc 57191569306Ensuring the security of critical information infrastructure facilities is an actual developing area of information security both at the national and global level. Categorization of critical infrastructure objects is an integral part of the common and holistic security process. With a dynamically changing threats level, the process of determining the category of an object is still not optimal enough. Based on the existing requirements both of Russian and International standards, the assessment of critical infrastructure facilities not always be carried out promptly and correctly, in addition, numerical estimates are not formed, the objectivity of the assessment and subsequent reassessment by independent experts is not ensured. This article presents an analysis of the current requirements in the field of categorization of critical infrastructure objects used in the Russian Federation. A comparative analysis of the national regulatory legal acts of the Russian Federation and the system of International standards in the field of IT-security is presented. Regulation of categorization processes of critical infrastructure objects is considered. The necessity of forming numerical values of significance criteria for the correct determination and subsequent independent evaluation (reassessment) of the category of critical infrastructure objects is substantiated. Recommendations for improving the process of categorizing critical infrastructure objects and the formation of numerical estimates are presented. The implementation of the recommendations made will improve the accuracy, objectivity and reliability of the process of creating modern information security systems.https://ntv.ifmo.ru/file/article/22051.pdfcritical information infrastructurecategorization of critical information infrastructure objectssignificance criteriainformation securityinformation security management systemrisksresidual risks |
spellingShingle | Ilya I. Livshitz Review of national and international standards for categorizing of critical information infrastructure objects Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki critical information infrastructure categorization of critical information infrastructure objects significance criteria information security information security management system risks residual risks |
title | Review of national and international standards for categorizing of critical information infrastructure objects |
title_full | Review of national and international standards for categorizing of critical information infrastructure objects |
title_fullStr | Review of national and international standards for categorizing of critical information infrastructure objects |
title_full_unstemmed | Review of national and international standards for categorizing of critical information infrastructure objects |
title_short | Review of national and international standards for categorizing of critical information infrastructure objects |
title_sort | review of national and international standards for categorizing of critical information infrastructure objects |
topic | critical information infrastructure categorization of critical information infrastructure objects significance criteria information security information security management system risks residual risks |
url | https://ntv.ifmo.ru/file/article/22051.pdf |
work_keys_str_mv | AT ilyailivshitz reviewofnationalandinternationalstandardsforcategorizingofcriticalinformationinfrastructureobjects |