<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en"><front><journal-meta><journal-id journal-id-type="publisher-id">Computational nanotechnology</journal-id><journal-title-group><journal-title xml:lang="en">Computational nanotechnology</journal-title><trans-title-group xml:lang="kk"><trans-title>Computational nanotechnology</trans-title></trans-title-group><trans-title-group xml:lang="pt"><trans-title>Computational nanotechnology</trans-title></trans-title-group><trans-title-group xml:lang="ru"><trans-title>Computational nanotechnology</trans-title></trans-title-group><trans-title-group xml:lang="zh"><trans-title>Computational nanotechnology</trans-title></trans-title-group></journal-title-group><issn publication-format="print">2313-223X</issn><issn publication-format="electronic">2587-9693</issn><publisher><publisher-name xml:lang="en">YUR-VAK</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">529853</article-id><article-id pub-id-type="doi">10.33693/2313-223X-2022-9-2-45-55</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>Articles</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>Статьи</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">The Modeling of Processes of Design of Information Protection Systems in Critical Information Infrastructures</article-title><trans-title-group xml:lang="ru"><trans-title>Моделирование процессов проектирования систем защиты информации в критических информационных инфраструктурах</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Prokushev</surname><given-names>Yaroslav E.</given-names></name><name xml:lang="ru"><surname>Прокушев</surname><given-names>Ярослав Евгеньевич</given-names></name></name-alternatives><bio xml:lang="en"><p>Cand. Sci. (Econ.), Associate Professor; associate professor at the Department of Applied Information Technology and Information Security</p></bio><bio xml:lang="ru"><p>кандидат экономических наук, доцент; доцент кафедры прикладной информатики и информационной безопасности</p></bio><email>prokye@list.ru</email><xref ref-type="aff" rid="aff1"/></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Ponomarenko</surname><given-names>Sergei V.</given-names></name><name xml:lang="ru"><surname>Пономаренко</surname><given-names>Сергей Владимирович</given-names></name></name-alternatives><bio xml:lang="en"><p>Cand. Sci. (Eng.), Associate Professor; Professor at the Department of Information Security</p></bio><bio xml:lang="ru"><p>кандидат технических наук, доцент; профессор кафедры информационной безопасности</p></bio><email>kaf-otzi-spec@bukep.ru</email><xref ref-type="aff" rid="aff2"/></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Shishov</surname><given-names>Nikita V.</given-names></name><name xml:lang="ru"><surname>Шишов</surname><given-names>Никита Владимирович</given-names></name></name-alternatives><bio xml:lang="en"><p>postgraduatestudent at the Department of Information Security</p></bio><bio xml:lang="ru"><p>аспирант кафедры информационной безопасности</p></bio><email>asda.n@bk.ru</email><xref ref-type="aff" rid="aff2"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="en">Plekhanov Russian University of Economics</institution></aff><aff><institution xml:lang="ru">Российский экономический университет имени Г.В. Плеханова</institution></aff></aff-alternatives><aff-alternatives id="aff2"><aff><institution xml:lang="en">Belgorod University of Cooperation, Economics and Law</institution></aff><aff><institution xml:lang="ru">Белгородский университет кооперации, экономики и права</institution></aff></aff-alternatives><pub-date date-type="pub" iso-8601-date="2022-06-15" publication-format="electronic"><day>15</day><month>06</month><year>2022</year></pub-date><volume>9</volume><issue>2</issue><issue-title xml:lang="en">VOL 9, NO2 (2022)</issue-title><issue-title xml:lang="ru">ТОМ 9, №2 (2022)</issue-title><fpage>45</fpage><lpage>55</lpage><history><date date-type="received" iso-8601-date="2023-07-05"><day>05</day><month>07</month><year>2023</year></date></history><permissions><copyright-statement xml:lang="en">Copyright ©; 2022, Yur-VAK</copyright-statement><copyright-statement xml:lang="ru">Copyright ©; 2022, Юр-ВАК</copyright-statement><copyright-year>2022</copyright-year><copyright-holder xml:lang="en">Yur-VAK</copyright-holder><copyright-holder xml:lang="ru">Юр-ВАК</copyright-holder><ali:free_to_read xmlns:ali="http://www.niso.org/schemas/ali/1.0/"/><license><ali:license_ref xmlns:ali="http://www.niso.org/schemas/ali/1.0/">https://journals.eco-vector.com/2313-223X/about/editorialPolicies</ali:license_ref></license></permissions><self-uri xlink:href="https://journals.eco-vector.com/2313-223X/article/view/529853">https://journals.eco-vector.com/2313-223X/article/view/529853</self-uri><abstract xml:lang="en"><p>The relevance and necessity of implementations of measures of information security in CII (critical information infrastructures) is explained by several reasons. Firstly, these are the requirements of Russian legislation. Note that some CII objects, because of the nature of the information being processed, can also be attributed to GIS (state information systems) or ISPDn (personal data information systems). There are also requirements for information security measures [4; 5] for systems of this type, which largely correlate with the measures described for CII objects in [6]. Secondly, it is the objective presence of threats of various kinds that require neutralization and exist in almost all modern information systems. In order to ensure information security, the protective mechanisms used at CII facilities should take into account such factors as a significant amount of processed information, the need to ensure correct, stable and trouble-free operation, the multi-user nature of access to information resources, and ensuring the security of managed equipment. The fact that failures and errors in the operation of information systems in a number of CII of industrial enterprises can entail not only economic damage or negative social consequences, but also create a direct threat to the lives of a significant number of people, that live not so far to the place of work of these objects [11]. Modeling of the work performed at the design stage of information security systems of CII facilities is due to the complexity of this process. In present, ensuring the information security of CII facilities is one of the most important tasks currently being solved at the state level. These circumstances determine the relevance of writing the article. The purpose of writing this work is the developing of the set of models describing the features of organizational, legal and technical processes that arise at the stages of formation of requirements for ensuring information security of CII facilities. The normative legal acts of the FSTEC of Russia, which are in the public domain, are used as the methodological basis for writing the work. The methodology of functional graphical modeling IDEF0 was used to describe the ongoing work performed at the design stage of the information security system of the CII. The result of the research presented in this paper is a set of graphical and symbolic models describing the processes performed at the design stage of the information security system in critical information infrastructures.</p></abstract><trans-abstract xml:lang="ru"><p>Актуальность и необходимость выполнения мер по защите информации в КИИ (критических информационных инфраструктурах) обусловлена несколькими причинами. Во-первых, это требования законодательства России. Отметим, что некоторые объекты КИИ в силу характера обрабатываемых сведений могут быть также отнесены к ГИС (государственным информационным системам) или ИСПДн (информационным системам персональных данных). Для систем такого типа также существуют требования к мерам информационной безопасности [4; 5], которые во многом коррелируют с мерами, изложенными для объектов КИИ в [6]. Во-вторых, это объективное наличие угроз различного характера, требующих обязательной нейтрализации и существующих практически во всех современных информационных системах. С целью обеспечения информационной безопасности защитные механизмы, используемые на объектах КИИ, должны учитывать такие факторы, как значительный объем обрабатываемой информации, необходимость обеспечения корректной, стабильной и безотказной работы, многопользовательский характер доступа к информационным ресурсам, обеспечение безопасности управляемого оборудования. Особенно следует выделить тот факт, что отказы и ошибки в работе информационных систем в ряде объектов КИИ могут повлечь за собой не только экономический ущерб или негативные социальные последствия, но и создать прямую угрозу жизни значительного числа людей, проживающих близко от места функционирования этих объектов [11]. Моделирование работ, выполняемых на этапе проектирования систем информационной безопасности объектов КИИ, обусловлено сложность выполнения данного процесса. В настоящее время обеспечение информационной безопасности объектов КИИ является одной из важнейших задач, решаемых на уровне государства. Данные обстоятельства обуславливается актуальность написания статьи. Целью написания данной работы является разработка комплекса моделей, описывающих особенности организационно-правовых и технических процессов, возникающих на этапах формирования требований к обеспечению информационной безопасности объектов КИИ. В качестве методической базой для написания работы использованы нормативно-правовые акты ФСТЭК России, находящиеся в открытом доступе. Для описания происходящих работ, выполняемых на этапе проектирования системы защиты информации КИИ, была использована методология функционального графического моделирования IDEF0. Результатом представленных в работе исследований является комплекс графических и символьных моделей, описывающих процессы, выполняемые на этапе проектирования системы защиты информации критических информационных инфраструктур.</p></trans-abstract><kwd-group xml:lang="en"><kwd>modeling of information security processes</kwd><kwd>information security</kwd><kwd>information security management</kwd><kwd>graphical modeling</kwd><kwd>methodology of functional graphical modeling</kwd><kwd>critical information systems</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>моделирование процессов обеспечения информационной безопасности</kwd><kwd>управление информационной безопасностью</kwd><kwd>графическое моделирование</kwd><kwd>защита информации</kwd><kwd>методология функционального графического моделирования</kwd><kwd>критические информационные системы</kwd></kwd-group></article-meta></front><body></body><back><ref-list><ref id="B1"><label>1.</label><citation-alternatives><mixed-citation xml:lang="en">Federal Law No. 149-FZ of July 27, 2006 “On information, information technologies and information protection”.</mixed-citation><mixed-citation xml:lang="ru">Федеральный закон № 149-ФЗ от 27 июля 2006 года «Об информации, информационных технологиях и защите информации».</mixed-citation></citation-alternatives></ref><ref id="B2"><label>2.</label><citation-alternatives><mixed-citation xml:lang="en">Federal Law No. 187-FZ of July 27, 2006 “On the security of the critical information infrastructure of the Russian Federation”.</mixed-citation><mixed-citation xml:lang="ru">Федеральный закон № 187-ФЗ от 27 июля 2017 года «О безопасности критической информационной инфраструктуры Российской Федерации».</mixed-citation></citation-alternatives></ref><ref id="B3"><label>3.</label><citation-alternatives><mixed-citation xml:lang="en">Decree of the Government of the Russian Federation of February 8, 2018 No. 127 “On approval of the Rules for categorizing objects of critical information infrastructure of the Russian Federation and the list of indicators of criteria for the significance of objects of critical information infrastructure of the Russian Federation and their values”.</mixed-citation><mixed-citation xml:lang="ru">Постановление правительства Российской Федерации от 8 февраля 2018 г. № 127 «Об утверждении Правил категорирования объектов критической информационной инфраструктуры Российской Федерации, а также перечня показателей критериев значимости объектов критической информационной инфраструктуры Российской Федерации и их значений».</mixed-citation></citation-alternatives></ref><ref id="B4"><label>4.</label><citation-alternatives><mixed-citation xml:lang="en">Order No. 17 “On approval of requirements for the protection of information that does not constitute a state secret contained in state information systems”. Approved by FSTEC of Russia of 11.02.2013.</mixed-citation><mixed-citation xml:lang="ru">Приказ ФСТЭК России от 11 февраля 2013 г. № 17 «Об утверждении требований о защите информации, не составляющей государственную тайну, содержащейся в государственных информационных системах».</mixed-citation></citation-alternatives></ref><ref id="B5"><label>5.</label><citation-alternatives><mixed-citation xml:lang="en">Order No. 21 “On approval of the composition and content of organizational and technical measures to ensure the security of personal data during their processing in personal data information systems”. Approved by FSTEC of Russia of 18.02.2013.</mixed-citation><mixed-citation xml:lang="ru">Приказ ФСТЭК России от 18 февраля 2013 г. № 21 «Об утверждении состава и содержания организационных и технических мер по обеспечению безопасности персональных данных при их обработке в информационных системах персональных данных».</mixed-citation></citation-alternatives></ref><ref id="B6"><label>6.</label><citation-alternatives><mixed-citation xml:lang="en">Order No. 239 “On approval of the Requirements for ensuring the security of significant objects of critical information infrastructure of the Russian Federation”. Approved by FSTEC of Russia of 25.12.2017.</mixed-citation><mixed-citation xml:lang="ru">Приказ ФСТЭК России от 25 декабря 2017 г. № 239 «Об утверждении Требований по обеспечению безопасности значимых объектов критической информационной инфраструктуры Российской Федерации».</mixed-citation></citation-alternatives></ref><ref id="B7"><label>7.</label><citation-alternatives><mixed-citation xml:lang="en">Order No. 31 “On approval of requirements for providing information protection in automated management systems for industrial and technological processes on critical objects, potentially dangerous facilities, as well as objects representing increased danger to people's lives and health and environmental environment”. Approved by FSTEC of Russia of 14.03.2014.</mixed-citation><mixed-citation xml:lang="ru">Приказ ФСТЭК России от 14 марта 2014 г. № 31 «Об утверждении требований к обеспечению защиты информации в автоматизированных системах управления производственными и технологическими процессами на критически важных объектах, потенциально опасных объектах, а также объектах, представляющих повышенную опасность для жизни и здоровья людей и для окружающей природной среды».</mixed-citation></citation-alternatives></ref><ref id="B8"><label>8.</label><citation-alternatives><mixed-citation xml:lang="en">Methodological document “Methodology for assessing information security threats”. Approved by FSTEC of Russia of 05.02.2021.</mixed-citation><mixed-citation xml:lang="ru">Методический документ ФСТЭК России «Методика оценки угроз безопасности информации». Утвержден ФСТЭК России 5 февраля 2021 г.</mixed-citation></citation-alternatives></ref><ref id="B9"><label>9.</label><citation-alternatives><mixed-citation xml:lang="en">Order No. 77 “The procedure for organizing and carrying out work on certification of informatization objects for compliance with the requirements for the protection of information of limited access that is not a state secret”. Approved by FSTEC of Russia of 29.04.2021.</mixed-citation><mixed-citation xml:lang="ru">Приказ ФСТЭК России от 29 апреля 2021 г. № 77 «Порядок организации и проведения работ по аттестации объектов информатизации на соответствие требованиям о защите информации ограниченного доступа, не составляющей государственную тайну».</mixed-citation></citation-alternatives></ref><ref id="B10"><label>10.</label><citation-alternatives><mixed-citation xml:lang="en">Goldobina A.S., Isaeva Yu.A., Selifanov V.V. et al. Construction of an adaptive three-level model of control processes of the information protection system of critical information infrastructure objects. Reports of the Tomsk State University of Control Systems and Radioelectronics. 2018. Vol. 21. No. 4. Pp. 51-58. (In Rus.)</mixed-citation><mixed-citation xml:lang="ru">Голдобина А.С., Исаева Ю.А., Селифанов В.В. и др. Построение адаптивной трехуровневой модели процессов управления системой защиты информации объектов критической информационной инфраструктуры // Доклады Томского государственного университета систем управления и радиоэлектроники. 2018. Т. 21. № 4. С. 51-58.</mixed-citation></citation-alternatives></ref><ref id="B11"><label>11.</label><citation-alternatives><mixed-citation xml:lang="en">Ponomarenko S.V., Ponomarenko S.A., Prokushev Ya.E. Information security of critical information infrastructure systems: Monograph. Belgorod: BUKEP Publishing House, 2021. 133 p.</mixed-citation><mixed-citation xml:lang="ru">Пономаренко С.В., Пономаренко С.А., Прокушев Я.Е. Информационная безопасность критических систем информационной инфраструктуры: монография. Белгород: Изд-во БУКЭП, 2021. 133 с.</mixed-citation></citation-alternatives></ref><ref id="B12"><label>12.</label><citation-alternatives><mixed-citation xml:lang="en">Ponomarenko S.V., Ponomarenko S.A., Alexandrov V.V. Modeling of unauthorized access to information resources of key information infrastructure systems: Monograph. Belgorod: BUKEP Publishing House, 2017. 180 p.</mixed-citation><mixed-citation xml:lang="ru">Пономаренко С.В., Пономаренко С.А., Александров В.В. Моделирование несанкционированного доступа к информационным ресурсам ключевых систем информационной инфраструктуры: монография. Белгород: Изд-во БУКЭП, 2017. 180 с.</mixed-citation></citation-alternatives></ref><ref id="B13"><label>13.</label><citation-alternatives><mixed-citation xml:lang="en">Prokushev Ya.E., Ponomarenko S.V., Ponomarenko S.A. Modeling of information security systems design processes in state information systems. Computational Nanotechnology. 2021. Vol. 8. No. 1. Pp. 26-37. (In Rus.)</mixed-citation><mixed-citation xml:lang="ru">Прокушев Я.Е., Пономаренко С.В., Пономаренко С.А. Моделирование процессов проектирования систем защиты информации в государственных информационных системах // Computational Nanotechnology. 2021. Т. 8. № 1. С. 26-37.</mixed-citation></citation-alternatives></ref><ref id="B14"><label>14.</label><citation-alternatives><mixed-citation xml:lang="en">The Data bank of information security threats [Electronic resource]. URL: https://bdu.fstec.ru/threat</mixed-citation><mixed-citation xml:lang="ru">Банк данных угроз безопасности информации [Электронный ресурс]. URL: https://bdu.fstec.ru/threat</mixed-citation></citation-alternatives></ref></ref-list></back></article>
