Evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilities

Today in Russia the active work is going on the implementation of a relatively new mechanism of state regulation in the field of information security, which is legally defined as ensuring the security of significant objects of critical information infrastructure (CII). The subjects of this legislati...

Full description

Bibliographic Details
Main Authors: Roman V. Natalichev, Viktor S. Gorbatov, Grigory P. Gavdan, Anatoly P. Durakovskiy
Format: Article
Language:English
Published: Joint Stock Company "Experimental Scientific and Production Association SPELS 2021-09-01
Series:Безопасность информационных технологий
Subjects:
Online Access:https://bit.mephi.ru/index.php/bit/article/view/1359
_version_ 1797724360158478336
author Roman V. Natalichev
Viktor S. Gorbatov
Grigory P. Gavdan
Anatoly P. Durakovskiy
author_facet Roman V. Natalichev
Viktor S. Gorbatov
Grigory P. Gavdan
Anatoly P. Durakovskiy
author_sort Roman V. Natalichev
collection DOAJ
description Today in Russia the active work is going on the implementation of a relatively new mechanism of state regulation in the field of information security, which is legally defined as ensuring the security of significant objects of critical information infrastructure (CII). The subjects of this legislation have carried out a fairly large amount of organizational measures supported by scientific research of domestic and foreign specialists. The paper is devoted to the study of the issues of ensuring the safety of significant CII objects based on a critical system analysis of the regulatory framework and indicating the ambiguity of interpretation and possible options for the practical implementation of the requirements related to a specific field. The high level of tension of discussions in this area at various forums demonstrates that the formation of a new system at the level of individual subjects causes many difficulties and even sometimes leads to rejection of some aspects of regulatory requirements. As a rule, this always happens at the initial stages of the formation of any new system due to ambiguity of the wordings and the presence of significant internal contradictions in certain regulatory acts. One of the significant problems, in our opinion, is a certain misunderstanding, especially in the real sector of the economy, of the need to introduce and the role of a new security mechanism within the overall set of information security measures that have already been implemented in Russia for more than a quarter of a century. Conducting a system analysis of such a problematic situation is especially relevant for the educational community that has already started implementing new training programs of various levels of training, retraining and advanced training of specialists in the field of information security. Based on the description of the evolution of domestic legislation in the field of information security, for the need for a new mechanism of state regulation is justified. Examples of ambiguity and internal contradictions (paradoxes) of some provisions of regulatory legal acts on the safety of CII facilities are given, showing the urgent need for their improvement as well as for additional efforts to interpret the main provisions, based on the principle of a creative approach to explaining complex issues.
first_indexed 2024-03-12T10:16:11Z
format Article
id doaj.art-d0fdab2c5bc24b9d8b1582fd1ae3d9e6
institution Directory Open Access Journal
issn 2074-7128
2074-7136
language English
last_indexed 2024-03-12T10:16:11Z
publishDate 2021-09-01
publisher Joint Stock Company "Experimental Scientific and Production Association SPELS
record_format Article
series Безопасность информационных технологий
spelling doaj.art-d0fdab2c5bc24b9d8b1582fd1ae3d9e62023-09-02T10:31:33ZengJoint Stock Company "Experimental Scientific and Production Association SPELSБезопасность информационных технологий2074-71282074-71362021-09-0128362710.26583/bit.2021.3.011231Evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilitiesRoman V. Natalichev0Viktor S. Gorbatov1Grigory P. Gavdan2Anatoly P. Durakovskiy3National Research Nuclear University MEPhI (Moscow Engineering Physics Institute)National Research Nuclear University MEPhI (Moscow Engineering Physics Institute)National Research Nuclear University MEPhI (Moscow Engineering Physics Institute)National Research Nuclear University MEPhI (Moscow Engineering Physics Institute)Today in Russia the active work is going on the implementation of a relatively new mechanism of state regulation in the field of information security, which is legally defined as ensuring the security of significant objects of critical information infrastructure (CII). The subjects of this legislation have carried out a fairly large amount of organizational measures supported by scientific research of domestic and foreign specialists. The paper is devoted to the study of the issues of ensuring the safety of significant CII objects based on a critical system analysis of the regulatory framework and indicating the ambiguity of interpretation and possible options for the practical implementation of the requirements related to a specific field. The high level of tension of discussions in this area at various forums demonstrates that the formation of a new system at the level of individual subjects causes many difficulties and even sometimes leads to rejection of some aspects of regulatory requirements. As a rule, this always happens at the initial stages of the formation of any new system due to ambiguity of the wordings and the presence of significant internal contradictions in certain regulatory acts. One of the significant problems, in our opinion, is a certain misunderstanding, especially in the real sector of the economy, of the need to introduce and the role of a new security mechanism within the overall set of information security measures that have already been implemented in Russia for more than a quarter of a century. Conducting a system analysis of such a problematic situation is especially relevant for the educational community that has already started implementing new training programs of various levels of training, retraining and advanced training of specialists in the field of information security. Based on the description of the evolution of domestic legislation in the field of information security, for the need for a new mechanism of state regulation is justified. Examples of ambiguity and internal contradictions (paradoxes) of some provisions of regulatory legal acts on the safety of CII facilities are given, showing the urgent need for their improvement as well as for additional efforts to interpret the main provisions, based on the principle of a creative approach to explaining complex issues.https://bit.mephi.ru/index.php/bit/article/view/1359information security, critical information infrastructure, significant object, significant consequences, significance indicator, regulatory legal acts, system analysis, threats to security, training of specialists.
spellingShingle Roman V. Natalichev
Viktor S. Gorbatov
Grigory P. Gavdan
Anatoly P. Durakovskiy
Evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilities
Безопасность информационных технологий
information security, critical information infrastructure, significant object, significant consequences, significance indicator, regulatory legal acts, system analysis, threats to security, training of specialists.
title Evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilities
title_full Evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilities
title_fullStr Evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilities
title_full_unstemmed Evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilities
title_short Evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilities
title_sort evolution and paradoxes of the regulatory framework for ensuring the security of critical information infrastructure facilities
topic information security, critical information infrastructure, significant object, significant consequences, significance indicator, regulatory legal acts, system analysis, threats to security, training of specialists.
url https://bit.mephi.ru/index.php/bit/article/view/1359
work_keys_str_mv AT romanvnatalichev evolutionandparadoxesoftheregulatoryframeworkforensuringthesecurityofcriticalinformationinfrastructurefacilities
AT viktorsgorbatov evolutionandparadoxesoftheregulatoryframeworkforensuringthesecurityofcriticalinformationinfrastructurefacilities
AT grigorypgavdan evolutionandparadoxesoftheregulatoryframeworkforensuringthesecurityofcriticalinformationinfrastructurefacilities
AT anatolypdurakovskiy evolutionandparadoxesoftheregulatoryframeworkforensuringthesecurityofcriticalinformationinfrastructurefacilities