确保信息安全的途径

Yu.M. Lysetskyi, D.Y. Kalbazov
{"title":"确保信息安全的途径","authors":"Yu.M. Lysetskyi, D.Y. Kalbazov","doi":"10.34121/1028-9763-2023-4-26-32","DOIUrl":null,"url":null,"abstract":"The article analyzes situational, integration, and integration and innovation approaches that have emerged among domestic enterprises in today's market to ensure information security. The following differences between them have been identified: the situational approach involves the point implementation of information security systems, decentralized management, the lack of a unified approach to system design, and inertia in system implementation; the integration ap-proach involves the presence of planning and information security provisioning services, the formulation of unified requirements for information security, analysis of the criticality of in-formation assets, risk and threat management, and the design of information security from business processes of the enterprise; the integration and innovation approach includes the pres-ence of security operation centers, operational response centers, centralized information securi-ty monitoring systems, the creation of Business Continuity Plans and Disaster Recovery Plans, and the formation of fault-tolerant protection systems. Some existing problems in choosing methods and information protection technologies are presented in the paper. The ways and means for ensuring effective information security in an enterprise are discussed. These are next-generation network firewalls, SIEM systems, DLP systems, as well as a cloud access security broker – CASB. Using CASB to ensure information security in the cloud allows for addressing the following tasks: access control; data protection; detection and response to threats; compli-ance with regulatory requirements; monitoring and auditing; and security policy management. Analyzing the approaches to ensuring information security in domestic enterprises, we can con-clude that it should be based on a comprehensive approach and effective integration of all ele-ments of IT infrastructure at different levels of their interaction.","PeriodicalId":473328,"journal":{"name":"Matematičeskie mašiny i sistemy","volume":"44 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Approaches to ensuring information security\",\"authors\":\"Yu.M. Lysetskyi, D.Y. Kalbazov\",\"doi\":\"10.34121/1028-9763-2023-4-26-32\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The article analyzes situational, integration, and integration and innovation approaches that have emerged among domestic enterprises in today's market to ensure information security. The following differences between them have been identified: the situational approach involves the point implementation of information security systems, decentralized management, the lack of a unified approach to system design, and inertia in system implementation; the integration ap-proach involves the presence of planning and information security provisioning services, the formulation of unified requirements for information security, analysis of the criticality of in-formation assets, risk and threat management, and the design of information security from business processes of the enterprise; the integration and innovation approach includes the pres-ence of security operation centers, operational response centers, centralized information securi-ty monitoring systems, the creation of Business Continuity Plans and Disaster Recovery Plans, and the formation of fault-tolerant protection systems. Some existing problems in choosing methods and information protection technologies are presented in the paper. The ways and means for ensuring effective information security in an enterprise are discussed. These are next-generation network firewalls, SIEM systems, DLP systems, as well as a cloud access security broker – CASB. Using CASB to ensure information security in the cloud allows for addressing the following tasks: access control; data protection; detection and response to threats; compli-ance with regulatory requirements; monitoring and auditing; and security policy management. Analyzing the approaches to ensuring information security in domestic enterprises, we can con-clude that it should be based on a comprehensive approach and effective integration of all ele-ments of IT infrastructure at different levels of their interaction.\",\"PeriodicalId\":473328,\"journal\":{\"name\":\"Matematičeskie mašiny i sistemy\",\"volume\":\"44 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Matematičeskie mašiny i sistemy\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.34121/1028-9763-2023-4-26-32\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Matematičeskie mašiny i sistemy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.34121/1028-9763-2023-4-26-32","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

文章分析了当今市场上国内企业为保障信息安全而出现的态势化、集成化、集成创新等途径。它们之间的区别如下:情景方法涉及信息安全系统的点实施,分散管理,缺乏统一的系统设计方法,系统实施惯性;集成方法包括提供规划和信息安全提供服务,制定统一的信息安全需求,分析信息资产的重要性,进行风险和威胁管理,并从企业的业务流程进行信息安全设计;整合创新方法包括建立安全运营中心、运营响应中心、集中信息安全监控系统、创建业务连续性计划和灾难恢复计划,以及形成容错保护系统。本文指出了在选择方法和信息保护技术方面存在的一些问题。讨论了确保企业有效信息安全的途径和手段。这些是下一代网络防火墙、SIEM系统、DLP系统,以及云访问安全代理——CASB。使用CASB来确保云中的信息安全,可以解决以下任务:访问控制;数据保护;发现和应对威胁;遵守法规要求;监测和审计;以及安全策略管理。通过对国内企业信息安全保障途径的分析,我们可以得出结论:信息安全保障应建立在信息基础设施各要素在不同层次上相互作用的综合方法和有效集成的基础上。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Approaches to ensuring information security
The article analyzes situational, integration, and integration and innovation approaches that have emerged among domestic enterprises in today's market to ensure information security. The following differences between them have been identified: the situational approach involves the point implementation of information security systems, decentralized management, the lack of a unified approach to system design, and inertia in system implementation; the integration ap-proach involves the presence of planning and information security provisioning services, the formulation of unified requirements for information security, analysis of the criticality of in-formation assets, risk and threat management, and the design of information security from business processes of the enterprise; the integration and innovation approach includes the pres-ence of security operation centers, operational response centers, centralized information securi-ty monitoring systems, the creation of Business Continuity Plans and Disaster Recovery Plans, and the formation of fault-tolerant protection systems. Some existing problems in choosing methods and information protection technologies are presented in the paper. The ways and means for ensuring effective information security in an enterprise are discussed. These are next-generation network firewalls, SIEM systems, DLP systems, as well as a cloud access security broker – CASB. Using CASB to ensure information security in the cloud allows for addressing the following tasks: access control; data protection; detection and response to threats; compli-ance with regulatory requirements; monitoring and auditing; and security policy management. Analyzing the approaches to ensuring information security in domestic enterprises, we can con-clude that it should be based on a comprehensive approach and effective integration of all ele-ments of IT infrastructure at different levels of their interaction.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信