Development of an individual profile of enterprise protection.

Authors

  • Samoilenko H.T. https://orcid.org/0000-0002-9374-2833 , State University of Trade and Economics, Kyiv, Ukraine
  • Yurchenko Yu.Yu. https://orcid.org/0000-0002-8047-7647 , State University of Trade and Economics, Kyiv, Ukraine

DOI:

https://doi.org/10.34121/1028-9763-2022-3-91-96

Keywords:

security models, implementation of security policy, requirements, vulnerabilities, individual protection profile, моделі безпеки, реалізація політики безпеки, вимоги, вразливості, індивідуальний профіль захисту

Abstract

The article considers the existing models of information security, which are the basis for the development of an individual protection profile, and determines the features of their application. Ensuring information security at the enterprise is to develop a comprehensive system for protecting information and controlling the sources of potential threats, the need to protect information in accordance with existing standards for the security of information technology. Preparation and development of normative documentation of individual protection profile are necessary components in accordance with the type of activity and needs of the enterprise. The article substantiates the need to develop and further apply the company's protection profile in accordance with modern standards in the field of information security. The number of profiles may not be limited, they are developed for various applications. The task of implementing the company’s security policy includes the development of one or more security profiles. The security profile is the basis for creating a security task that can be considered as a technical project. The article considers the components of the concept of security and defines the connections and interactions between them. Identified requirements, risks (i.e. events or situations that indicate the possibility of harm), assets and measures affecting the vulnerability of the security profile. Safety trust requirements include technology development, testing, vulnerability analysis, supply, maintenance, operational documentation, etc. Actions that pose potential threats to the security of conditional ingestion have been identified. The article proposes the main components for building an individual profile of protection of a conventional enterprise, indicates the links between them. A description of the types of requirements in accordance with the hierarchy «class – family – component – element» was executed. The main classes of functional requirements for individual protection profile are defined.

References

1. Скабцов Н. Аудит безопасности информационных систем. СПб.: Питер, 2018. 272 с.

2. Common Criteria Services – ISO 15408.

3. Диогенес Ю., Озкайя Е. Кибербезопасность: стратегии атак и обороны / пер. с англ. Д.А. Беликова. М.: ДМК Пресс, 2020. 326 с.

4. Олифер В.Г., Олифер Н.А. Компьютерные сети. Принципы, технологии, протоколы. Юбилейное издание. СПб.: Питер, 2020. 1008 с.

Downloads

Views: 54
Downloads: 5

Published

2022-09-01

Issue

Section

INFORMATION AND TELECOMMUNICATION TECHNOLOGY

How to Cite

Development of an individual profile of enterprise protection. (2022). Mathematical Machines and Systems, 3, 91–96. https://doi.org/10.34121/1028-9763-2022-3-91-96