VAC 05.13.01 Системный анализ, управление и обработка информации (по отраслям)
VAC 05.13.06 Автоматизация и управление технологическими процессами и производствами (по отраслям)
VAC 05.13.10 Управление в социальных и экономических системах
VAC 05.13.18 Математическое моделирование, численные методы и комплексы программ
VAC 05.13.19 Методы и системы защиты информации, информационная безопасность
UDK 004.942
GRNTI 20.01 Общие вопросы информатики
GRNTI 28.01 Общие вопросы кибернетики
GRNTI 49.01 Общие вопросы связи
GRNTI 50.01 Общие вопросы автоматики и вычислительной техники
GRNTI 82.01 Общие вопросы организации и управления
The article highlights the aspects of risk management in the information system. According to the analysis of the work of Russian and foreign scientists and world practices in the field of risk management, it is stated that there is a need to improve the effectiveness of risk management of information system and to develop a method for managing the risks of the information system. As a solution to the problem of effective risk management of the information system, there has been proposed a formalized procedure for managing the risks of the information system. The scientific novelty of this solution is the use of decision space and optimization space to reduce risks. This procedure allows to assess the damage, risk and effectiveness of risk management of the information system. The risks of the information system are determined and analyzed; a pyramidal risk diagram is developed. This diagram allows you to describe the relationship of risks with the components of the information system. The negative consequences to which these risks can lead are given. The analysis of methods and approaches to risk management has been carried out. Based on the results of the analysis, the methods GRAMM, CORAS, GOST R ISO / IEC scored to the maximum. The weak points of these methods and the difficulty of applying these methods in practice are described. The developed formalized risk management procedure to control the risks of information system can be used as management system’s element of the information security quality that complies with the recommendations of GOST R ISO / IEC 27003-2012. The prospect of further development of the research results is the development of management systems of risk of information system.
information system, risk, damage, evaluation, management effectiveness, optimization
1. Mikov D. A. Analiz metodov i sredstv, ispol'zuemyh na razlichnyh etapah ocenki riskov informacionnoy bezopasnosti // Vopr. kiberbezopasnosti. 2014. № 4 (7). S. 49-54.
2. Vybornova O. N., Azhmuhamedov I. M. Sintez upravlencheskih resheniy po snizheniyu riskov v nechetkih usloviyah pri ogranichennyh resursah // Fundamental'nye issledovaniya. 2016. № 5. Ch. 1. S. 18-22.
3. Popov G. A., Popov A. G. Rezul'tiruyuschaya ocenka pri nalichii neskol'kih variantov ocenivaniya na primere zadach informacionnoy bezopasnosti // Vestn. Astrahan. gos. tehn. un-ta. Ser.: Upravlenie, vychislitel'naya tehnika i informatika. 2017. № 1. S. 48-61.
4. Kravets A. The Risk Management Model of Design Department’s PDM Information System // Creativity in Intelligent Technologies and Data Science. Second Conference, CIT&DS 2017 (Volgograd, Russia, September 12-14, 2017): Proceedings (Ser. Communications in Computer and Information Science. Vol. 754) / ed. by A. Kravets, M. Shcherbakov, M. Kultsova, Peter Groumpos. Volgograd State Technical University [et al.]; [Germany]: Springer International Publishing AG, 2017. P. 490-500.
5. Finogeev A. A., Finogeev A. G., Nefedova I. S., Finogeev E. A., Kamaev V. A. Analiz informacionnyh riskov v sistemah obrabotki dannyh na osnove «tumannyh» vychisleniy // Vestn. Astrahan. gos. tehn. un-ta. Ser.: Upravlenie, vychislitel'naya tehnika i informatika. 2015. № 4. S. 38-46.
6. Atkina V. S., Vorob'ev A. E. Podhod k ocenke riskov narusheniya informacionnoy bezopasnosti s ispol'zovaniem ierarhicheskogo podhoda k ranzhirovaniyu resursov predpriyatiya // Informacionnye sistemy i tehnologii. 2015. № 1 (87). S. 125-131.
7. Kiseleva I. A., Iskadzhyan S. O. Informacionnye riski: metody ocenki i analiza. URL: http://itportal.ru/science/economy/informatsionnye-riski-metody-otsenk/ (data obrascheniya: 03.12.2017).
8. Belozerova A. A., Olad'ko V. S., Mikova S. Yu., Nesterenko M. A. Arhitektura programmy ocenki riskov informacionnoy bezopasnosti v ERP-sistemah // Vestn. nauki i obrazovaniya. 2016. № 9 (21). S. 31-33.
9. Gneushev V. A., Kravec A. G., Kozunova S. S., Babenko A. A. Modelirovanie setevyh atak zloumyshlennikov v korporativnoy informacionnoy sisteme // Promyshlennye ASU i kontrollery. 2017. № 6. S. 51-60.
10. Vahrameev Ya. M., Bogatenkov D. S. Upravleniya riskami i problemami na proektah po vnedreniyu otechestvennyh ERP-sistem // Nauch.-metod. elektron. zhurn. «Koncept». 2016. T. 17. S. 103-108. URL: http://e-koncept.ru/2016/46184.htm (data obrascheniya: 03.12.2017).
11. Ob informacii, informacionnyh tehnologiyah i o zaschite informacii: Federal'nyy Zakon ot 27 iyulya 2006 g. № 149-FZ. URL: http://fstec.ru/component/attachments/download/277 (data obrascheniya 03.12.2017).
12. Ob utverzhdenii Trebovaniy o zaschite informacii, soderzhascheysya v informacionnyh sistemah obschego pol'zovaniya»: Prikaz FSB RF № 416, FSTEK RF № 489 ot 31 avgusta 2010 g. URL: http://fstec.ru/component/attachments/download/283 (data obrascheniya: 03.12.2017).
13. Ob utverzhdenii Trebovaniy o zaschite informacii, ne sostavlyayuschey gosudarstvennuyu taynu, soderzhascheysya v gosudarstvennyh informacionnyh sistemah: Prikaz FSTEK Rossii ot 11 fevralya 2013 g. № 17 (red. ot 15.02.2017). URL: http://fstec.ru/component/attachments/download/567 (data obrascheniya: 03.12.2017).
14. Ob utverzhdenii Doktriny informacionnoy bezopasnosti Rossiyskoy Federacii: Ukaz Prezidenta RF ot 05 dekabrya 2016 g. № 646. URL: http://base.garant.ru/71556224/ (data obrascheniya: 11.04.2017).
15. GOST R ISO/MEK 27005-2010. Informacionnaya tehnologiya. Metody i sredstva obespecheniya bezopasnosti. Menedzhment riska informacionnoy bezopasnosti. M.: Standartinform, 2011. URL: http://docs.cntd.ru/document/gost-r-iso-mek-27005-2010 (data obrascheniya: 03.12.2017).
16. Baranova E., Mal'ceva A. Analiz riskov informacionnoy bezopasnosti dlya malogo i srednego biznesa // Direktor po bezopasnosti. 2015. Vyp. 9. S. 58-63.
17. Surkova N. E., Ostrouh A. V. Metodologiya strukturnogo proektirovaniya informacionnyh sistem: monogr. Krasnoyarsk: Nauch.-innovac. centr. 2014. 190 s. URL: http://lib.madi.ru/fel/fel1/fel16S061.pdf (data obrascheniya: 06.12.2017).
18. Kozunova S. S., Babenko A. A. Model' postroeniya zaschischennoy informacionnoy sistemy korporativnogo tipa // Informacionnye sistemy i tehnologii. 2016. № 3 (95). S. 112-120.
19. Azhmuhamedov I. M., Knyazeva O. M. Kompleksnaya ocenka kachestva informacionnyh sistem na osnove nechetkogo kognitivnogo modelirovaniya // Nauchnye tendencii: Voprosy tochnyh i tehnicheskih nauk: sb. nauch. tr. po materialam X Mezhdunar. nauch. konf. (Sankt-Peterburg, 12 oktyabrya 2017 g.). SPb.: Izd-vo CNK MNIF «Obschestv. nauka». S. 10-12.
20. Pomorcev A. S. Metodika ocenki riskov narusheniya informacionnoy bezopasnosti organizacii s uchetom kvalifikacii ekspertov // Dokl. TUSURa. 2014. № 2 (32). S. 167-169.
21. Azhmuhamedov I. M., Vybornova O. N. Formalizaciya ponyatiy priemlemogo i tolerantnogo riska // Inzhenernyy vestnik Dona. 2015. T. 37. № 3. S. 63.
22. BS 7799-3. Information security management systems. Guidelines for information security risk management.
23. COSO 2004. Enterprise Risk Management - Integrated Framework.
24. ISO 31000:2009. Risk management - Principles and guidelines.
25. Azhmuhamedov I. M., Knyazeva O. M. Ocenka sostoyaniya zaschischennosti dannyh organizacii v usloviyah vozmozhnosti realizacii ugroz informacionnoy bezopasnosti // Prikaspiyskiy zhurnal: upravlenie i vysokie tehnologii. 2015. № 3 (31). S. 24-39.
26. Campbell T. The Information Security Manager // Practical Information Security Management. 2016. P. 31-42.
27. Anikin I. V., Emaletdinova L. Yu., Kirpichnikov A. P. Metody ocenki i upravleniya riskami informacionnoy bezopasnosti v korporativnyh informacionnyh setyah // Vestn. Kazan. tehnolog. un-ta. 2015. T. 18. № 6. S. 195-197.
28. Anikin I. V. Metody ocenki i upravleniya riskami informacionnoy bezopasnosti v korporativnyh informacionnyh setyah: monogr. Kazan': Redakc.-izdat. centr «Shkola», 2015. 224 s.
29. Bazovaya model' ugroz bezopasnosti personal'nyh dannyh pri ih obrabotke v informacionnyh sistemah personal'nyh dannyh (vypiska) (utv. zam. direktora FSTEK Rossii 15 fevralya 2008 g.). URL: https://fstec.ru/component/attachments/download/289 (data obrascheniya: 06.02.2018).
30. Metodika opredeleniya aktual'nyh ugroz bezopasnosti personal'nyh dannyh pri ih obrabotke v informacionnyh sistemah personal'nyh dannyh (utv. zam. direktora FSTEK Rossii 14 fevralya 2008 g.). URL: https://fstec.ru/component/attachments/download/290 (data obrascheniya: 06.02.2018).
31. Kozunova S. S., Kravec A. G. Upravlenie riskoustoychivost'yu informacionnoy sistemy konstruktorskogo byuro // Upravlenie informacionnoy bezopasnost'yu v sovremennom obschestve: materialy Vseros. molodezhnoy nauch. shkoly-konf. po problemam informac. bezopasnosti (Volgograd, 26-28 aprelya 2017 g.). Volgograd: Volgogr. gos. un-t, 2017. C. 203-207.
32. GOST R ISO/MEK 27003-2012. Informacionnaya tehnologiya (IT). Metody i sredstva obespecheniya bezopasnosti. Sistemy menedzhmenta informacionnoy bezopasnosti. Rukovodstvo po realizacii sistemy menedzhmenta informacionnoy bezopasnosti. M.: Standartinform, 2014. URL: http://docs.cntd.ru/document/1200103165 (data obrascheniya: 06.12.2017).