<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en"><front><journal-meta><journal-id journal-id-type="publisher-id">Infokommunikacionnye tehnologii</journal-id><journal-title-group><journal-title xml:lang="en">Infokommunikacionnye tehnologii</journal-title><trans-title-group xml:lang="ru"><trans-title>Инфокоммуникационные технологии</trans-title></trans-title-group></journal-title-group><issn publication-format="print">2073-3909</issn><publisher><publisher-name xml:lang="en">Povolzhskiy State University of Telecommunications and Informatics</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">55895</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>Articles</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>Статьи</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">MODERN TECHNIQUES ARE USED TO EVALUATE THREATE AND VULNERABILITIES INFORMATION SYSTEMS</article-title><trans-title-group xml:lang="ru"><trans-title>СОВРЕМЕННЫЕ МЕТОДИКИ, ПРИМЕНЯЕМЫЕ ДЛЯ ОЦЕНКИ УГРОЗ И УЯЗВИМОСТЕЙ ИНФОРМАЦИОННЫХ СИСТЕМ</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Gubareva</surname><given-names>O. Yu</given-names></name><name xml:lang="ru"><surname>Губарева</surname><given-names>Ольга Юрьевна</given-names></name></name-alternatives><bio xml:lang="ru"><p>аспирант Кафедры мультисервисных сетей и информационной безопасности (МСИБ)</p></bio><email>olgagubareva@inbox.ru</email><xref ref-type="aff" rid="aff1"/></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Pugin</surname><given-names>V. V</given-names></name><name xml:lang="ru"><surname>Пугин</surname><given-names>Владимир Владимирович</given-names></name></name-alternatives><bio xml:lang="ru"><p>к.т.н., доцент Кафедры МСИБ</p></bio><email>pugin@psati.ru</email><xref ref-type="aff" rid="aff1"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="en"></institution></aff><aff><institution xml:lang="ru">Поволжский государственный университет телекоммуникаций и информатики (ПГУТИ)</institution></aff></aff-alternatives><pub-date date-type="pub" iso-8601-date="2013-03-15" publication-format="electronic"><day>15</day><month>03</month><year>2013</year></pub-date><volume>11</volume><issue>1</issue><issue-title xml:lang="en">VOL 11, NO1 (2013)</issue-title><issue-title xml:lang="ru">ТОМ 11, №1 (2013)</issue-title><fpage>100</fpage><lpage>105</lpage><history><date date-type="received" iso-8601-date="2020-12-20"><day>20</day><month>12</month><year>2020</year></date></history><permissions><copyright-statement xml:lang="en">Copyright ©; 2013, Gubareva O.Y., Pugin V.V.</copyright-statement><copyright-statement xml:lang="ru">Copyright ©; 2013, Губарева О.Ю., Пугин В.В.</copyright-statement><copyright-year>2013</copyright-year><copyright-holder xml:lang="en">Gubareva O.Y., Pugin V.V.</copyright-holder><copyright-holder xml:lang="ru">Губарева О.Ю., Пугин В.В.</copyright-holder><ali:free_to_read xmlns:ali="http://www.niso.org/schemas/ali/1.0/"/><license><ali:license_ref xmlns:ali="http://www.niso.org/schemas/ali/1.0/">https://creativecommons.org/licenses/by-nc-nd/4.0</ali:license_ref></license></permissions><self-uri xlink:href="https://journals.eco-vector.com/2073-3909/article/view/55895">https://journals.eco-vector.com/2073-3909/article/view/55895</self-uri><abstract xml:lang="en"><p>Modern information systems trust the solution of the most diverse and important tasks: automatic control of technological processes and industrial enterprises, the automation of activities of banks, financial markets, insurance and trading companies, and so on. Grow the size and complexity of corporate systems. The importance of the task of ensuring the security of corporate information resources is understood as the management of companies, and customers. And already insufficient condition is the organization of the protection of individual segments of the information system. Proceeding from this, the requirements of information security should be aimed at ensuring an optimal regime of functioning of the information system as a whole.</p></abstract><trans-abstract xml:lang="ru"><p>Современным информационным системам доверяют решение самых разнообразных и важных задач: автоматизированное управление технологическими процессами и промышленными предприятиями, автоматизацию деятельности банков, финансовых бирж, страховых и торговых компаний и так далее. Растут масштабы и сложность корпоративных систем. Важность задачи обеспечения безопасности корпоративных информационных ресурсов осознана как руководством компаний, так и их клиентами. И уже недостаточным условием является организация защиты отдельных сегментов информационной системы. Исходя из этого требования информационной безопасности должны быть направлены на обеспечение оптимального режима функционирования информационной системы в целом.</p></trans-abstract><kwd-group xml:lang="en"><kwd>information security</kwd><kwd>information system</kwd><kwd>risk</kwd><kwd>analysis</kwd><kwd>technique</kwd><kwd>counter-measure</kwd><kwd>security</kwd><kwd>model</kwd><kwd>audit</kwd><kwd>threat</kwd><kwd>vulnerability</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>информационная безопасность</kwd><kwd>информационная система</kwd><kwd>риск</kwd><kwd>анализ</kwd><kwd>методика</kwd><kwd>контрмера</kwd><kwd>защищенность</kwd><kwd>модель</kwd><kwd>аудит</kwd><kwd>угроза</kwd><kwd>уязвимость</kwd></kwd-group></article-meta></front><body></body><back><ref-list><ref id="B1"><label>1.</label><mixed-citation>Анализ методов оценки рисков информационной безопасности / http://igorosa.com/analiz-metodov-ocenki-riskov-informacionnoj-bezopasnosti/</mixed-citation></ref><ref id="B2"><label>2.</label><mixed-citation>Сердюк В. Аудит информационной безопасности. BYTE Россия. №4 (92), 2006 / http://www. bytemag.ru/articles/detail.php?ID=6781</mixed-citation></ref><ref id="B3"><label>3.</label><mixed-citation>Петренко С.А. Возможная методика построения системы информационной безопасности предприятия. security.meganet.md / http://bre.ru/security/13985.html</mixed-citation></ref><ref id="B4"><label>4.</label><mixed-citation>Галатенко В.А. Основы информационной безопасности. / http://www.intuit.ru/ department/ security/secbasics/</mixed-citation></ref><ref id="B5"><label>5.</label><mixed-citation>http://www.peltierassociates.com</mixed-citation></ref><ref id="B6"><label>6.</label><mixed-citation>Software Engineering Institute Carnegie Mellon. OCTAVE // www.cert.org/octave</mixed-citation></ref><ref id="B7"><label>7.</label><mixed-citation>Siemens. The total information security toolkit / http://www.cramm.com</mixed-citation></ref><ref id="B8"><label>8.</label><mixed-citation>Пугин В.В., Губарева О.Ю. Методика Risk Watch для анализа рисков в сфере информационной безопасности // Материалы XIX РНТК ПГУТИ. Самара: 2012. - С. 52.</mixed-citation></ref><ref id="B9"><label>9.</label><mixed-citation>Пугин В.В., Губарева О.Ю. Методика FRAP для анализа рисков в сфере информационной безопасности // Материалы XIX РНТК ПГУТИ. Самара: 2012. - С. 50.</mixed-citation></ref></ref-list></back></article>
