<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">vguit</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Воронежского государственного университета инженерных технологий</journal-title><trans-title-group xml:lang="en"><trans-title>Proceedings of the Voronezh State University of Engineering Technologies</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2226-910X</issn><issn pub-type="epub">2310-1202</issn><publisher><publisher-name>VSUET</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.20914/2310-1202-2017-2-107-112</article-id><article-id custom-type="elpub" pub-id-type="custom">vguit-1475</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>Информационные технологии, моделирование и управление</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>Information technologies, modeling and management</subject></subj-group></article-categories><title-group><article-title>Формализация анализа уязвимостей информационной системы при проектировании КСЗИ</article-title><trans-title-group xml:lang="en"><trans-title>Formalization of the analysis of the vulnerabilities of the information system in the design of KSZI</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Грабежов</surname><given-names>И. Е.</given-names></name><name name-style="western" xml:lang="en"><surname>Grabezhov</surname><given-names>I. E.</given-names></name></name-alternatives><bio xml:lang="ru"><p>к.т.н., доцент, кафедра компьютерные технологии и системы, бул. 50-лет Октября, 7, г. Брянск, 241035, Россия</p></bio><bio xml:lang="en"><p>candidate of technical sciences, assistant professor, computer technologies and systems department, Bulvar 50-letiya Oktyabrya, 7, Bryansk, 241035, Russia</p></bio><email xlink:type="simple">noreplay@elpub.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Леонов</surname><given-names>Ю. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Leonov</surname><given-names>Ju. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>к.т.н., доцент, кафедра компьютерные технологии и системы, бул. 50-лет Октября, 7, г. Брянск, 241035, Россия</p></bio><bio xml:lang="en"><p>candidate of technical sciences, assistant professor, computer technologies and systems department, Bulvar 50-letiya Oktyabrya, 7, Bryansk, 241035, Russia</p></bio><email xlink:type="simple">noreplay@elpub.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Брянский государственный технический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Bryansk State Technical University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2017</year></pub-date><pub-date pub-type="epub"><day>27</day><month>07</month><year>2017</year></pub-date><volume>79</volume><issue>2</issue><fpage>107</fpage><lpage>112</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Грабежов И.Е., Леонов Ю.А., 2017</copyright-statement><copyright-year>2017</copyright-year><copyright-holder xml:lang="ru">Грабежов И.Е., Леонов Ю.А.</copyright-holder><copyright-holder xml:lang="en">Grabezhov I.E., Leonov J.A.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://www.vestnik-vsuet.ru/vguit/article/view/1475">https://www.vestnik-vsuet.ru/vguit/article/view/1475</self-uri><abstract><p>Информационные системы и технологии, как компоненты информационной сферы, непосредственно и активно влияют на состояние экономической, экологической, энергетической, транспортной, продовольственной, криминогенной, информационной и других составляющих комплексной безопасности РФ. В статье рассматриваются вопросы формализации параметров информационной системы, от которых зависит значение информационных рисков. Приводится методика проектирования комплексных систем защиты информации путем разделения на соответствующие этапы. С помощью разработанного ПО проектируется КСЗИ на основе объективных параметров информационной системы. Модель представляет собой совокупность объектов информационной системы, описанных при помощи соответствующих программных сущностей. Это позволяет повысить точность расчетов, избежать зависимости от опыта экспертов, что, в конечном итоге, позволит использовать ПО системным администраторам, не имеющим большого опыта в проектировании систем защиты</p></abstract><trans-abstract xml:lang="en"><p>Information systems and technologies, as components of the information sphere, directly and actively influence the state of economic, ecological, energy, transport, food, criminogenic, information and other components of the integrated security of the Russian Federation. The article deals with the formalization of the information system parameters, on which the importance of information risks depends. The technique of designing complex information security systems is described by dividing them into appropriate stages. With the help of the developed software, the KSZI is designed on the basis of the objective parameters of the information system. The model is a set of objects of the information system, described with the help of appropriate software entities. This allows you to improve the accuracy of calculations, avoid dependence on the expertise of experts, which ultimately will allow the software to be used by system administrators who do not have much experience in designing security systems.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>система защиты информации</kwd><kwd>информационный риск</kwd><kwd>угроза информационной безопасности</kwd><kwd>уязвимость информационной системы</kwd></kwd-group><kwd-group xml:lang="en"><kwd>information security system</kwd><kwd>information risk</kwd><kwd>information security threat</kwd><kwd>vulnerability of the information system</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Аверченков В.И., Рытов М.Ю., Кувыклин А.В., РудановскийМ.В. Аудит информационной безопасности органов исполнительной власти. Москва. Флинта, 2011. 100 с.</mixed-citation><mixed-citation xml:lang="en">Averchenkov V.I., Rytov M.Yu., Kuvyklin A.V., Rudanovskii M.V. Audit informatsionnoi bezopasnosti organov ispolnitel'noi vlasti [Information security audit of the Executive bodies]. Moscow. Flinta 2011. 100 p. (in Russian).</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Whitman M. E., Mattord H. J. Principles of information security. Cengage Learning, 2011.</mixed-citation><mixed-citation xml:lang="en">Whitman M. E., Mattord H. J. Principles of information security. Cengage Learning, 2011.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р ИСО 13335-1-2006 Информационные технологии. Методы и средства обеспечения безопасности</mixed-citation><mixed-citation xml:lang="en">GOST no. 13335-1-2006. Informatsionnye tekhnologii. Metody i sredstva obespecheniya bezopasnosti [State standard no. 13335-1-2006. Information technology. Methods and means of security]. (in Russian).</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Ifinedo P. Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory // Computers &amp; Security. 2012. Т. 31. №. 1. С. 83-95.</mixed-citation><mixed-citation xml:lang="en">Ifinedo P. Understanding information systems security policy compliance: An integration of the theory of planned behavior and the protection motivation theory. Computers &amp; Security. 2012. vol. 31. no. 1. pp. 83-95.</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Казаков Ю.М., Леонов Ю.А., Федоров В.Е. Моделирование рациональных схем базирования заготовки при решении задачи синтеза единичных технологических процессов // XI Международная научно-практическая конференция "Михаило-Архангельские чтения". 2016. С. 203–235.</mixed-citation><mixed-citation xml:lang="en">Kazakov Yu.M., Leonov Yu.A., Fedorov V.E. Modeling rational schemes of basing of the workpiece in the solution of the problem of synthesis of individual technological processes. XI Mezhdunarodnaya nauchno-prakticheskaya konferentsiya "Mikhailo-Arkhangel'skie chteniya". 2016.  pp. 203–235. (in Russian).</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Тищенко А.А., Казаков Ю.М. Методика принятия решений о производстве нового изделия на начальных этапах разработки при маркетинговом подходе управления // Вестник Славянских вузов: ежегодный международный научно-практический журнал. 2015. № 4. С. 127–130.</mixed-citation><mixed-citation xml:lang="en">Tishchenko A.A., Kazakov Yu.M. The method of decision-making about the production of a new product in the initial stages of development at the marketing management approach. Vestnik Slavyanskikh vuzov: ezhegodnyi mezhdunarodnyi nauchno-prakticheskii zhurnal [Journal of Slavic universities: the annual international scientific-practical journal]. 2015. no. 4. pp. 127–130. (in Russian).</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Аверченков А.В., Фисун А.П. Модель многоуровневой идентификации персонала в системе контроля и управления доступом на предприятиях строительной индустрии // Строительство и реконструкция. 2016. № 2. С. 56–64.</mixed-citation><mixed-citation xml:lang="en">Averchenkov A.V., Fisun A.P. A multilevel model of personnel identification in the control system and access control at the enterprises of construction industry. Stroitel'stvo i rekonstruktsiya [Construction and reconstruction]. 2016. no. 2. pp. 56–64. (in Russian).</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Tankard C. Advanced persistent threats and how to monitor and deter them // Network security. 2011. Т. 2011. №. 8. С. 16-19.</mixed-citation><mixed-citation xml:lang="en">Tankard C. Advanced persistent threats and how to monitor and deter them. Network security. 2011. vol. 2011. no. 8. pp. 16-19.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
