组织信息安全文化状态监测系统开发的功能建模

Mariia Voitsekhovska, M. Dorosh, V. F. Grechaninov, O. Verenych
{"title":"组织信息安全文化状态监测系统开发的功能建模","authors":"Mariia Voitsekhovska, M. Dorosh, V. F. Grechaninov, O. Verenych","doi":"10.15276/hait.05.2022.22","DOIUrl":null,"url":null,"abstract":"The mass transition to remote work, which triggered the quarantine and then military actions on the territory of Ukraine, led to new challenges to increase the level of information protection. In addition, permanent information and cyber-attacks create a persistent danger to physical and information systems. This, in turn, requires a clear understanding of the level of information security of various organizations, especially for critical infrastructure. An important component of the organization's information security is the information security culture of all participants in internal information processes. Such kind of influence is usually called the Human Factor.The paper`s aimreveals withtwo goals.The firstgoalis the information processes functional modeling of the information security culture level assessment automation as a part of the overall organization`s security system.The second part consists inthe information security system of project (ISSoP) maturity model developmentto provide the vital level of trust to organization within project activities.The functional model of system development presents a number of separate processes: the formation of questionnaires, data collection, and assessmentof information security culture at the personal, department and organizational levels. Defined input and output data, mechanisms, models, methods and control elements for each process. This model can be included as a component of the system for determining the level of the common organization`s information security system.The maturity stages ofthe information security culture ina project include different Info-Sec activities at various stages of its life cycle. Such kind of activities need to be taken into account while developing organization`s information security systems.","PeriodicalId":375628,"journal":{"name":"Herald of Advanced Information Technology","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-12-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Functional modeling of the organization’s information securityculture state monitoring system development\",\"authors\":\"Mariia Voitsekhovska, M. Dorosh, V. F. Grechaninov, O. Verenych\",\"doi\":\"10.15276/hait.05.2022.22\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The mass transition to remote work, which triggered the quarantine and then military actions on the territory of Ukraine, led to new challenges to increase the level of information protection. In addition, permanent information and cyber-attacks create a persistent danger to physical and information systems. This, in turn, requires a clear understanding of the level of information security of various organizations, especially for critical infrastructure. An important component of the organization's information security is the information security culture of all participants in internal information processes. Such kind of influence is usually called the Human Factor.The paper`s aimreveals withtwo goals.The firstgoalis the information processes functional modeling of the information security culture level assessment automation as a part of the overall organization`s security system.The second part consists inthe information security system of project (ISSoP) maturity model developmentto provide the vital level of trust to organization within project activities.The functional model of system development presents a number of separate processes: the formation of questionnaires, data collection, and assessmentof information security culture at the personal, department and organizational levels. Defined input and output data, mechanisms, models, methods and control elements for each process. This model can be included as a component of the system for determining the level of the common organization`s information security system.The maturity stages ofthe information security culture ina project include different Info-Sec activities at various stages of its life cycle. Such kind of activities need to be taken into account while developing organization`s information security systems.\",\"PeriodicalId\":375628,\"journal\":{\"name\":\"Herald of Advanced Information Technology\",\"volume\":\"7 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-12-28\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Herald of Advanced Information Technology\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.15276/hait.05.2022.22\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Herald of Advanced Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.15276/hait.05.2022.22","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

向远程工作的大规模过渡引发了乌克兰境内的隔离和随后的军事行动,为提高信息保护水平带来了新的挑战。此外,永久性信息和网络攻击对物理和信息系统造成了持续的危险。反过来,这需要清楚地了解各种组织的信息安全级别,特别是对于关键基础设施。组织信息安全的一个重要组成部分是内部信息过程中所有参与者的信息安全文化。这种影响通常被称为人为因素。本文的目的有两个。第一个目标是将信息安全文化水平评估自动化作为整个组织安全系统的一部分进行信息过程功能建模。第二部分是项目信息安全体系(ISSoP)成熟度模型的开发,为项目活动中的组织提供至关重要的信任层次。系统开发的功能模型呈现了许多独立的过程:问卷的形成、数据收集,以及个人、部门和组织层面的信息安全文化评估。为每个过程定义输入和输出数据、机制、模型、方法和控制元素。该模型可以作为系统的一个组成部分,用于确定普通组织的信息安全系统的级别。项目中信息安全文化的成熟阶段包括其生命周期不同阶段的不同信息安全活动。在开发组织的信息安全系统时,需要考虑到此类活动。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Functional modeling of the organization’s information securityculture state monitoring system development
The mass transition to remote work, which triggered the quarantine and then military actions on the territory of Ukraine, led to new challenges to increase the level of information protection. In addition, permanent information and cyber-attacks create a persistent danger to physical and information systems. This, in turn, requires a clear understanding of the level of information security of various organizations, especially for critical infrastructure. An important component of the organization's information security is the information security culture of all participants in internal information processes. Such kind of influence is usually called the Human Factor.The paper`s aimreveals withtwo goals.The firstgoalis the information processes functional modeling of the information security culture level assessment automation as a part of the overall organization`s security system.The second part consists inthe information security system of project (ISSoP) maturity model developmentto provide the vital level of trust to organization within project activities.The functional model of system development presents a number of separate processes: the formation of questionnaires, data collection, and assessmentof information security culture at the personal, department and organizational levels. Defined input and output data, mechanisms, models, methods and control elements for each process. This model can be included as a component of the system for determining the level of the common organization`s information security system.The maturity stages ofthe information security culture ina project include different Info-Sec activities at various stages of its life cycle. Such kind of activities need to be taken into account while developing organization`s information security systems.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信