Features of mathematical rationale for a complex datа security system of a medical enterprise.
DOI:
https://doi.org/10.34121/1028-9763-2023-4-51-57Keywords:
data protection, security models, access levels, захист даних, моделі безпеки, рівні доступуAbstract
The article is dedicated to the analysis of data protection issues, particularly personal data, in medical institutions of various ownership forms. The necessity of implementing comprehensive data security systems is justified by the Bell-LaPadula model, which is considered a foundation for the development of a complex data security system within the enterprise. The Bell-LaPadula model represents an access control system based on a hierarchical data access structure. However, using a rigid hierarchical approach when building an information infrastructure of an enterprise based on this model, taking into account different levels of information confidentiality, might not account for the possibility of insider intervention at higher levels. The article analyzes the key aspects of this model, including assigning special security levels to all participants in data processing and to documents containing the protected data. To ensure security and access regulation based on an adapted model, individual access levels that correspond to each user’s responsibilities and confidentiality level are proposed for them. After implementing a comprehensive system for protecting confidential data and assigning special security levels to all participants in the processing of protected data and documents, a clear differentiation of ownership rights to information of different values emerged. This facilitates further expansion of the circle of employees with access to this information, reduces access time, and forms informational and analytical reports on access control system performance. The use of the hierarchical Bell-LaPadula access model allows for effective control over access to the information system and ensures overall enterprise security.References
1. Гайворонський М.В. Безпека інформаційно-комунікаційних систем: навч. посіб. К.: Видавнича група BHV, 2014. 608 с.
2. Денісова О.О. Автоматизоване проектування інформаційних систем: навч. посіб. К.: КНЕУ, 2011. 412 с.
3. Plakhotnij S.A., Klyuchko O.M., Krotinova M.V. Information support for automatic industrial environment monitoring systems. Electronics and Control Systems. 2016. Vol. 1, N 47. P. 29–34.
4. Бойченко О.С., Костерев Д.С., Маковський І.Ю., Грищук О.М. Математична модель розрахунку цінності інформації установи. Проблеми створення, випробування, застосування та експлуатації складних інформаційних систем. 2022. Вип. 22. С. 30–40.
5. Мороз Б., Молотков О., Ульяновська Ю. Методи визначення цінності інформації для організації її захисту. Правове, нормативне та метрологічне забезпечення системи захисту інформації в Україні. 2001. Вип. 2. С. 46–53.
6. Гулак Г.М. Методологія захисту інформації. Аспекти кібербезпеки: підручник. Київ: Вид-во НА СБ України, 2020. 256 с.
Published
Issue
Section
License
Copyright (c) 2023 Mathematical Machines and Systems

This work is licensed under a Creative Commons Attribution 4.0 International License.
