Review of national and international standards for categorizing of critical information infrastructure objects

Ensuring the security of critical information infrastructure facilities is an actual developing area of information security both at the national and global level. Categorization of critical infrastructure objects is an integral part of the common and holistic security process. With a dynamically...

Full description

Bibliographic Details
Main Author: Ilya I. Livshitz
Format: Article
Language:English
Published: Saint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University) 2023-06-01
Series:Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki
Subjects:
Online Access:https://ntv.ifmo.ru/file/article/22051.pdf
_version_ 1797798446848016384
author Ilya I. Livshitz
author_facet Ilya I. Livshitz
author_sort Ilya I. Livshitz
collection DOAJ
description Ensuring the security of critical information infrastructure facilities is an actual developing area of information security both at the national and global level. Categorization of critical infrastructure objects is an integral part of the common and holistic security process. With a dynamically changing threats level, the process of determining the category of an object is still not optimal enough. Based on the existing requirements both of Russian and International standards, the assessment of critical infrastructure facilities not always be carried out promptly and correctly, in addition, numerical estimates are not formed, the objectivity of the assessment and subsequent reassessment by independent experts is not ensured. This article presents an analysis of the current requirements in the field of categorization of critical infrastructure objects used in the Russian Federation. A comparative analysis of the national regulatory legal acts of the Russian Federation and the system of International standards in the field of IT-security is presented. Regulation of categorization processes of critical infrastructure objects is considered. The necessity of forming numerical values of significance criteria for the correct determination and subsequent independent evaluation (reassessment) of the category of critical infrastructure objects is substantiated. Recommendations for improving the process of categorizing critical infrastructure objects and the formation of numerical estimates are presented. The implementation of the recommendations made will improve the accuracy, objectivity and reliability of the process of creating modern information security systems.
first_indexed 2024-03-13T04:03:50Z
format Article
id doaj.art-0f6302a39f9b484dbc7c523e6c7e4ab5
institution Directory Open Access Journal
issn 2226-1494
2500-0373
language English
last_indexed 2024-03-13T04:03:50Z
publishDate 2023-06-01
publisher Saint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University)
record_format Article
series Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki
spelling doaj.art-0f6302a39f9b484dbc7c523e6c7e4ab52023-06-21T09:10:31ZengSaint Petersburg National Research University of Information Technologies, Mechanics and Optics (ITMO University)Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki2226-14942500-03732023-06-0123351952910.17586/2226-1494-2023-23-3-519-529Review of national and international standards for categorizing of critical information infrastructure objectsIlya I. Livshitz0https://orcid.org/0000-0003-0651-8591D.Sc., Professor of Practice, ITMO University, Saint Petersburg, 197101, Russian Federation, sc 57191569306Ensuring the security of critical information infrastructure facilities is an actual developing area of information security both at the national and global level. Categorization of critical infrastructure objects is an integral part of the common and holistic security process. With a dynamically changing threats level, the process of determining the category of an object is still not optimal enough. Based on the existing requirements both of Russian and International standards, the assessment of critical infrastructure facilities not always be carried out promptly and correctly, in addition, numerical estimates are not formed, the objectivity of the assessment and subsequent reassessment by independent experts is not ensured. This article presents an analysis of the current requirements in the field of categorization of critical infrastructure objects used in the Russian Federation. A comparative analysis of the national regulatory legal acts of the Russian Federation and the system of International standards in the field of IT-security is presented. Regulation of categorization processes of critical infrastructure objects is considered. The necessity of forming numerical values of significance criteria for the correct determination and subsequent independent evaluation (reassessment) of the category of critical infrastructure objects is substantiated. Recommendations for improving the process of categorizing critical infrastructure objects and the formation of numerical estimates are presented. The implementation of the recommendations made will improve the accuracy, objectivity and reliability of the process of creating modern information security systems.https://ntv.ifmo.ru/file/article/22051.pdfcritical information infrastructurecategorization of critical information infrastructure objectssignificance criteriainformation securityinformation security management systemrisksresidual risks
spellingShingle Ilya I. Livshitz
Review of national and international standards for categorizing of critical information infrastructure objects
Naučno-tehničeskij Vestnik Informacionnyh Tehnologij, Mehaniki i Optiki
critical information infrastructure
categorization of critical information infrastructure objects
significance criteria
information security
information security management system
risks
residual risks
title Review of national and international standards for categorizing of critical information infrastructure objects
title_full Review of national and international standards for categorizing of critical information infrastructure objects
title_fullStr Review of national and international standards for categorizing of critical information infrastructure objects
title_full_unstemmed Review of national and international standards for categorizing of critical information infrastructure objects
title_short Review of national and international standards for categorizing of critical information infrastructure objects
title_sort review of national and international standards for categorizing of critical information infrastructure objects
topic critical information infrastructure
categorization of critical information infrastructure objects
significance criteria
information security
information security management system
risks
residual risks
url https://ntv.ifmo.ru/file/article/22051.pdf
work_keys_str_mv AT ilyailivshitz reviewofnationalandinternationalstandardsforcategorizingofcriticalinformationinfrastructureobjects