<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en"><front><journal-meta><journal-id journal-id-type="publisher-id">Computational nanotechnology</journal-id><journal-title-group><journal-title xml:lang="en">Computational nanotechnology</journal-title><trans-title-group xml:lang="kk"><trans-title>Computational nanotechnology</trans-title></trans-title-group><trans-title-group xml:lang="pt"><trans-title>Computational nanotechnology</trans-title></trans-title-group><trans-title-group xml:lang="ru"><trans-title>Computational nanotechnology</trans-title></trans-title-group><trans-title-group xml:lang="zh"><trans-title>Computational nanotechnology</trans-title></trans-title-group></journal-title-group><issn publication-format="print">2313-223X</issn><issn publication-format="electronic">2587-9693</issn><publisher><publisher-name xml:lang="en">YUR-VAK</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">626621</article-id><article-id pub-id-type="doi">10.33693/2313-223X-2023-10-4-23-38</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>METHODS AND SYSTEMS OF INFORMATION PROTECTION, INFORMATION SECURITY</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>МЕТОДЫ И СИСТЕМЫ ЗАЩИТЫ ИНФОРМАЦИИ, ИНФОРМАЦИОННАЯ БЕЗОПАСНОСТЬ</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">The Modeling of Processes of Design of Information Protection Systems in Financial Information Systems</article-title><trans-title-group xml:lang="ru"><trans-title>Моделирование процессов проектирования систем защиты информации в банковских информационных системах</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-7219-7581</contrib-id><name-alternatives><name xml:lang="en"><surname>Prokushev</surname><given-names>Yaroslav E.</given-names></name><name xml:lang="ru"><surname>Прокушев</surname><given-names>Ярослав Евгеньевич</given-names></name></name-alternatives><address><country country="RU">Russian Federation</country></address><bio xml:lang="en"><p>Cand. Sci. (Econ.), Associate Professor; associate professor at the Department of Applied Informatics and Information Security</p></bio><bio xml:lang="ru"><p>кандидат экономических наук, доцент; доцент кафедры прикладной информатики и информационной безопасности</p></bio><email>prokye@list.ru</email><xref ref-type="aff" rid="aff1"/></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Ponomarenko</surname><given-names>Sergei V.</given-names></name><name xml:lang="ru"><surname>Пономаренко</surname><given-names>Сергей Владимирович</given-names></name></name-alternatives><address><country country="RU">Russian Federation</country></address><bio xml:lang="en"><p>Cand. Sci. (Econ.), Associate Professor; Professor at the Department of Information Security Organization and Technology</p></bio><bio xml:lang="ru"><p>кандидат технических наук, доцент; профессор кафедры организации и технологии защиты информации</p></bio><email>kaf-otzi-spec@bukep.ru</email><xref ref-type="aff" rid="aff2"/></contrib><contrib contrib-type="author"><name-alternatives><name xml:lang="en"><surname>Maksimov</surname><given-names>Riyan R.</given-names></name><name xml:lang="ru"><surname>Максимов</surname><given-names>Риян Ренатович</given-names></name></name-alternatives><address><country country="RU">Russian Federation</country></address><bio xml:lang="en"><p>postgraduate student at the Department of Information Security</p></bio><bio xml:lang="ru"><p>аспирант кафедры организации и технологии защиты информации</p></bio><email>maksimov.riyan@mail.ru</email><xref ref-type="aff" rid="aff2"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="en">Plekhanov Russian University of Economics</institution></aff><aff><institution xml:lang="ru">Российский экономический университет имени Г.В. Плеханова</institution></aff></aff-alternatives><aff-alternatives id="aff2"><aff><institution xml:lang="en">Belgorod University of Cooperation, Economics and Law</institution></aff><aff><institution xml:lang="ru">Белгородский университет кооперации, экономики и права</institution></aff></aff-alternatives><pub-date date-type="pub" iso-8601-date="2023-12-12" publication-format="electronic"><day>12</day><month>12</month><year>2023</year></pub-date><volume>10</volume><issue>4</issue><issue-title xml:lang="en"/><issue-title xml:lang="ru"/><fpage>23</fpage><lpage>38</lpage><history><date date-type="received" iso-8601-date="2024-02-07"><day>07</day><month>02</month><year>2024</year></date><date date-type="accepted" iso-8601-date="2024-02-07"><day>07</day><month>02</month><year>2024</year></date></history><permissions><copyright-statement xml:lang="en">Copyright ©; 2023, Yur-VAK</copyright-statement><copyright-statement xml:lang="ru">Copyright ©; 2023, Юр-ВАК</copyright-statement><copyright-year>2023</copyright-year><copyright-holder xml:lang="en">Yur-VAK</copyright-holder><copyright-holder xml:lang="ru">Юр-ВАК</copyright-holder><ali:free_to_read xmlns:ali="http://www.niso.org/schemas/ali/1.0/"/><license><ali:license_ref xmlns:ali="http://www.niso.org/schemas/ali/1.0/">https://journals.eco-vector.com/2313-223X/about/editorialPolicies</ali:license_ref></license></permissions><self-uri xlink:href="https://journals.eco-vector.com/2313-223X/article/view/626621">https://journals.eco-vector.com/2313-223X/article/view/626621</self-uri><abstract xml:lang="en"><p>The relevance and necessity of implementing measures to protect information in banks, as well as in other organizations of the financial and credit sphere of activity is due to a number of reasons. Firstly, these are the requirements of regulators in the field of information security. For systems of this type, there are also requirements for information security measures, which are set out in GOST R 57580.1–2017. Secondly, it is the objective presence of threats of various nature that require mandatory neutralization and exist in many modern information systems. In order to ensure information security, the security mechanisms used in the banking sector should take into account such factors as a significant amount of processed information, the need to ensure correct, stable and trouble-free operation, the multi-user nature of access to information resources, and ensuring the security of managed equipment. It is particularly worth highlighting the fact that failures and errors in the operation of banking information systems can entail not only economic damage or negative social consequences. In general, ensuring the information security of banking facilities is one of the most important tasks currently being solved at the state level, since they directly affect the stability of its economy. These circumstances determine the relevance of writing the article. The purpose of writing this paper is to develop a set of models describing the features of organizational, legal and technical processes that must be performed in banking information systems. As a methodological basis for writing the work, GOST R 57580.1–2017, as well as regulatory legal acts of the FSTEC of Russia, which are in the public domain, were used. To describe the ongoing work that must be performed to ensure the protection of information in banking information systems, the methodology of functional graphical modeling IDEF0 was used. The result of the research presented in this paper is a set of graphical and symbolic models describing the processes performed at the stages of designing and functioning of the information security system in critical information infrastructures.</p></abstract><trans-abstract xml:lang="ru"><p>Актуальность и необходимость выполнения мер по защите информации в банках, как и в других организациях финансово-кредитной сферы деятельности, обусловлена целым рядом причин. Во-первых, это требования регуляторов в области информационной безопасности. Для систем такого типа существуют требования к мерам информационной безопасности, которые изложены в ГОСТ Р 57580.1–2017 и ряде приказов ФСТЭК России. Во-вторых, это объективное наличие угроз различного характера, требующих обязательной нейтрализации и существующих во многих современных информационных системах. С целью обеспечения информационной безопасности защитные механизмы, используемые в банковской сфере, должны учитывать такие факторы, как значительный объем обрабатываемой информации, необходимость обеспечения корректной, стабильной и безотказной работы, многопользовательский характер доступа к информационным ресурсам, обеспечение безопасности управляемого оборудования. Особенно следует выделить тот факт, что отказы и ошибки в работе банковских информационных систем могут повлечь за собой серьезный экономический ущерб или негативные социальные последствия. В целом обеспечение информационной безопасности объектов банковской сферы является одной из важнейших задач, решаемых в настоящее время на уровне государства, поскольку атаки на банковские информационные системы крупных банков могут по влиять на устойчивость экономики. Данные обстоятельства обуславливают актуальность написания статьи. Целью написания данной работы является разработка комплекса моделей, описывающих особенности организационно-правовых и технических процессов, которые должны быть выполнены в банковских информационных системах для обеспечения информационной безопасности. В качестве методической базы для написания работы использованы ГОСТ Р 57580.1–2017, а также нормативно-правовые акты ФСТЭК России, находящиеся в открытом доступе. Для описания происходящих работ, которые должны быть выполнены для обеспечения защиты информации в банковских информационных системах, была использована методология функционального графического моделирования IDEF0. Результатом представленных в работе исследований является комплекс графических и символьных моделей, описывающих процессы, выполняемые на этапах проектирования и функционирования системы защиты информации в критических информационных инфраструктурах.</p></trans-abstract><kwd-group xml:lang="en"><kwd>modeling of information security processes</kwd><kwd>information security</kwd><kwd>information security management</kwd><kwd>graphical modeling</kwd><kwd>methodology of functional graphical modeling</kwd><kwd>financial information systems</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>моделирование процессов обеспечения информационной безопасности</kwd><kwd>защита информации</kwd><kwd>управление информационной безопасностью</kwd><kwd>графическое моделирование</kwd><kwd>методология функционального графического моделирования</kwd><kwd>банковские информационные системы</kwd></kwd-group><funding-group/></article-meta></front><body></body><back><ref-list><ref id="B1"><label>1.</label><citation-alternatives><mixed-citation xml:lang="en">Ponomarenko S.V., Prokushev Ya.Е., Ponomarenko S.A. Information security of critical information infrastructure systems. Monography. Belgorod: BUKEP, 2021. 133 p.</mixed-citation><mixed-citation xml:lang="ru">Пономаренко С.В., Пономаренко С.А., Прокушев Я.Е. Информационная безопасность критических систем информационной инфраструктуры: монография. Белгород: БУКЭП, 2021. 133 с.</mixed-citation></citation-alternatives></ref><ref id="B2"><label>2.</label><citation-alternatives><mixed-citation xml:lang="en">Prokushev Ya.Е., Ponomarenko S.V., Ponomarenko S.A. The modeling of information security system design processes in state information systems. Computational Nanotechnology. 2021. Vol. 8. No. 1. Pp. 26–37. (In Rus.)</mixed-citation><mixed-citation xml:lang="ru">Прокушев Я.Е., Пономаренко С.В., Пономаренко С.А. Моделирование процессов проектирования систем защиты информации в государственных информационных системах // Computational Nanotechnology. 2021. Т. 8. № 1. С. 26–37.</mixed-citation></citation-alternatives></ref><ref id="B3"><label>3.</label><citation-alternatives><mixed-citation xml:lang="en">Prokushev Ya.E., Ponomarenko S.V. Comparative analysis of software and hardware protection of information used in information systems of personal data. Information and Security. 2012. Vol. 15. No. 1. Pp. 31–36. (In Rus.)</mixed-citation><mixed-citation xml:lang="ru">Прокушев Я.Е., Пономаренко С.В. Сравнительный анализ средств программно-аппаратной защиты информации, применяемых в информационных системах персональных данных // Информация и безопасность. 2012. Т. 15. № 1. С. 31–36.</mixed-citation></citation-alternatives></ref><ref id="B4"><label>4.</label><citation-alternatives><mixed-citation xml:lang="en">Prokushev Ya.Е., Ponomarenko S.V., Shishov N.V. The modeling of processes of design of information protection systems in critical information infrastructures. Computational Nanotechnology. 2022. Vol. 9. No. 2. Pp. 45–55. (In Rus.)</mixed-citation><mixed-citation xml:lang="ru">Прокушев Я.Е., Пономаренко С.В., Шишов Н.В. Моделирование процессов проектирования систем защиты информации в критических информационных инфраструктурах // Computational Nanotechnology. 2022. Т. 9. № 2. С. 45–55.</mixed-citation></citation-alternatives></ref><ref id="B5"><label>5.</label><citation-alternatives><mixed-citation xml:lang="en">Prokusheva A.P., Prokushev Ya.E. Modeling and optimization of the choice of software and hardware protection of information from the point of view of economic and technical expediency. Information and Security. 2012. Vol. 15. No. 1. Pp. 55–60. (In Rus.)</mixed-citation><mixed-citation xml:lang="ru">Прокушева А.П., Прокушев Я.Е. Моделирование и оптимизация выбора средств программно-аппаратной защиты информации с точки зрения экономической и технической целесообразности // Информация и безопасность. 2012. Т. 15. № 1. С. 55–60.</mixed-citation></citation-alternatives></ref><ref id="B6"><label>6.</label><mixed-citation>Mattord H., Whitman M. Management of information security. 6th ed. Cengage Learning, 2019. 752 p.</mixed-citation></ref><ref id="B7"><label>7.</label><mixed-citation>Rohit Tanwar. Information security and optimization. CRC Press, 2021. 224 p.</mixed-citation></ref><ref id="B8"><label>8.</label><mixed-citation>Whitman M.E. et al. PRSCIiples of information security. 6th ed. Cengage Learning, 2017. 656 p.</mixed-citation></ref></ref-list></back></article>
