<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">mireabulletin</journal-id><journal-title-group><journal-title xml:lang="ru">Russian Technological Journal</journal-title><trans-title-group xml:lang="en"><trans-title>Russian Technological Journal</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2782-3210</issn><issn pub-type="epub">2500-316X</issn><publisher><publisher-name>RTU MIREA</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.32362/2500-316X-2024-12-6-39-47</article-id><article-id custom-type="edn" pub-id-type="custom">IYBIZH</article-id><article-id custom-type="elpub" pub-id-type="custom">mireabulletin-1029</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>ИНФОРМАЦИОННЫЕ СИСТЕМЫ. ИНФОРМАТИКА. ПРОБЛЕМЫ ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>INFORMATION SYSTEMS. COMPUTER SCIENCES. ISSUES OF INFORMATION SECURITY</subject></subj-group></article-categories><title-group><article-title>Моделирование процессов управления инцидентами информационной безопасности на предприятии</article-title><trans-title-group xml:lang="en"><trans-title>Modeling incident management processes in information security at an enterprise</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-6579-0988</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Митяков</surname><given-names>Е. С.</given-names></name><name name-style="western" xml:lang="en"><surname>Mityakov</surname><given-names>E. S.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Митяков Евгений Сергеевич, д.э.н., профессор, и.о. заведующего кафедрой КБ-9 «Предметно-ориентированные информационные системы», Институт кибербезопасности и цифровых технологий</p><p>119454, Москва, пр-т Вернадского, д. 78</p><p>Scopus Author ID 55960540500</p></bio><bio xml:lang="en"><p>Evgeny S. Mityakov, Dr. Sci. (Econ.), Professor, Acting Head of the «Subject-Oriented Information Systems»Department, Institute of Cybersecurity and Digital Technologies</p><p>78, Vernadskogo pr., Moscow, 119454</p><p>Scopus Author ID 55960540500</p></bio><email xlink:type="simple">mityakov@mirea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-8788-4256</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Максимова</surname><given-names>Е. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Maksimova</surname><given-names>E. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Максимова Елена Александровна, д.т.н., доцент, заведующий кафедрой КБ-4 «Интеллектуальные системы информационной безопасности», Институт кибербезопасности и цифровых технологий</p><p>119454, Москва, пр-т Вернадского, д. 78</p><p>Scopus Author ID 57219701980</p></bio><bio xml:lang="en"><p>Elena A. Maksimova, Dr. Sci. (Eng.), Associate Professor, Head of the «Intelligent Information SecuritySystems» Department, Institute of Cybersecurity and Digital Technologies</p><p>78, Vernadskogo pr., Moscow, 119454</p><p>Scopus Author ID 57219701980</p></bio><email xlink:type="simple">maksimova@mirea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0006-8374-8197</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Артемова</surname><given-names>С. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Artemova</surname><given-names>S. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Артемова Светлана Валерьевна, д.т.н., доцент, заведующий кафедрой КБ-1 «Защита информации»,Институт кибербезопасности и цифровых технологий</p><p>119454, Москва, пр-т Вернадского, д. 78</p><p>Scopus Author ID 6508256085</p></bio><bio xml:lang="en"><p>Svetlana V. Artemova, Dr. Sci. (Eng.), Associate Professor, Head of the «Information Protection» Department, Institute of Cybersecurity and Digital Technologies</p><p>78, Vernadskogo pr., Moscow, 119454</p><p>Scopus Author ID 6508256085</p></bio><email xlink:type="simple">artemova_s@mirea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-9526-0117</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Бакаев</surname><given-names>А. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Bakaev</surname><given-names>A. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Бакаев Анатолий Александрович, д.и.н., к.ю.н., доцент, директор Института кибербезопасности и цифровых технологий</p><p>119454, Москва, пр-т Вернадского, д. 78</p><p>Scopus Author ID 57297341000</p></bio><bio xml:lang="en"><p>Anatoly A. Bakaev, Dr. Sci. (Hist.), Cand. Sci. (Juri.), Associate Professor, Director of the Institute of Cybersecurity and Digital Technologies</p><p>78, Vernadskogo pr., Moscow, 119454</p><p>Scopus Author ID 57297341000</p></bio><email xlink:type="simple">bakaev@mirea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0001-7312-3341</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Вегера</surname><given-names>Ж. Г.</given-names></name><name name-style="western" xml:lang="en"><surname>Vegera</surname><given-names>Zh. G.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Вегера Жанна Геннадьевна, к.ф.-м.н., доцент, заведующий кафедрой высшей математики, Институт кибербезопасности и цифровых технологий</p><p>119454, Москва, пр-т Вернадского, д. 78</p><p>Scopus Author ID 57212931836</p></bio><bio xml:lang="en"><p>Zhanna G. Vegera, Cand. Sci. (Phys.-Math.), Associate Professor, Head of the Department of Higher Mathematics, Institute of Cybersecurity and Digital Technologies</p><p>78, Vernadskogo pr., Moscow, 119454</p><p>Scopus Author ID 57212931836</p></bio><email xlink:type="simple">vegera@mirea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>МИРЭА – Российский технологический университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>MIREA – Russian Technological University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2024</year></pub-date><pub-date pub-type="epub"><day>05</day><month>12</month><year>2024</year></pub-date><volume>12</volume><issue>6</issue><fpage>39</fpage><lpage>47</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Митяков Е.С., Максимова Е.А., Артемова С.В., Бакаев А.А., Вегера Ж.Г., 2024</copyright-statement><copyright-year>2024</copyright-year><copyright-holder xml:lang="ru">Митяков Е.С., Максимова Е.А., Артемова С.В., Бакаев А.А., Вегера Ж.Г.</copyright-holder><copyright-holder xml:lang="en">Mityakov E.S., Maksimova E.A., Artemova S.V., Bakaev A.A., Vegera Z.G.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://www.rtj-mirea.ru/jour/article/view/1029">https://www.rtj-mirea.ru/jour/article/view/1029</self-uri><abstract><sec><title>Цели</title><p>Цели. Основной целью исследования является разработка модели управления инцидентами информационной безопасности на предприятии, минимизирующей ущерб и затраты на устранение инцидентов в условиях ограниченных ресурсов и времени.</p></sec><sec><title>Методы</title><p>Методы. В работе проведен анализ существующих подходов к управлению инцидентами информационной безопасности, включая математические и имитационные модели, стохастические дифференциальные уравнения, цепи Маркова и другие методы. Основанием для работы послужил системный подход, который включает в себя всесторонний анализ параметров инцидентов, действий по их устранению, времени реакции, а также ущерба от реализации инцидентов и вероятности успешного их устранения. Для проверки работоспособности разработанной модели использовались синтетические данные, которые отражают разнообразные типы инцидентов и возможные пути их ликвидации.</p></sec><sec><title>Результаты</title><p>Результаты. Предложенная модель управления инцидентами позволяет оптимизировать управление инцидентами за счет минимизации ущерба и затрат. В рамках модели учитываются такие параметры, как критичность инцидентов, доступные ресурсы, время реакции и вероятность успешного устранения инцидентов. Апробация модели на синтетических данных показала, что предложенный подход существенно улучшает выбор оптимальных действий для реагирования на инциденты в ситуациях ограничений бюджета и времени, что в свою очередь повышает общую эффективность управления инцидентами.</p></sec><sec><title>Выводы</title><p>Выводы. Внедрение предложенной модели на предприятиях позволит повысить общий уровень информационной безопасности, эффективность реагирования на инциденты и улучшить процессы защиты информации. Это обеспечит минимизацию рисков, связанных с утечками данных и другими инцидентами, и поможет предприятиям принимать обоснованные и оперативные решения в условиях ограниченных ресурсов и времени.</p></sec></abstract><trans-abstract xml:lang="en"><sec><title>Objectives</title><p>Objectives. The primary aim of the study is to develop a model for managing information security incidents within an enterprise that minimizes damage and costs associated with incident resolution under limited resources and time constraints.</p></sec><sec><title>Methods</title><p>Methods. The paper analyzes existing approaches to managing information security incidents, including mathematical and simulation models, stochastic differential equations, Markov chains, and other methods. The study is based on a systems approach, incorporating analysis of incident parameters, actions for their resolution, response times, damages due to incident occurrence, and the probability of incident elimination. To validate the developed model, synthetic data reflecting various types of incidents and possible actions were used.</p></sec><sec><title>Results</title><p>Results. The proposed model optimizes incident management by minimizing damage and costs. It considers parameters such as incident criticality, available resources, response time, and the likelihood of successful incident resolution. Testing of the model on synthetic data showed that the proposed approach significantly improves the selection of optimal actions for responding to incidents in situations constrained by budget and time limitations, thereby enhancing the overall effectiveness of incident management.</p></sec><sec><title>Conclusions</title><p>Conclusions. Implementing the proposed model in enterprises will improve the overall level of information security, enhance incident response efficiency, and strengthen information protection processes. This will ensure the minimization of risks associated with data leaks and other incidents, thus helping enterprises to make informed and timely decisions under conditions of limited resources and time.</p></sec></trans-abstract><kwd-group xml:lang="ru"><kwd>управление инцидентами</kwd><kwd>информационная безопасность</kwd><kwd>моделирование инцидентов</kwd><kwd>минимизация ущерба</kwd><kwd>ограниченные ресурсы</kwd><kwd>математическое моделирование</kwd><kwd>оптимизация</kwd></kwd-group><kwd-group xml:lang="en"><kwd>incident management</kwd><kwd>information security</kwd><kwd>incident modeling</kwd><kwd>damage minimization</kwd><kwd>limited resources</kwd><kwd>mathematical modeling</kwd><kwd>optimization</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Żywiolek J., di Taranto A. Creating value added for an enterprise by managing information security incidents. System Safety: Human – Technical Facility – Environment. 2019;1(1):156–162. https://doi.org/10.2478/CZOTO-2019-0020</mixed-citation><mixed-citation xml:lang="en">Żywiolek J., di Taranto A. Creating value added for an enterprise by managing information security incidents. System Safety: Human – Technical Facility – Environment. 2019;1(1):156–162. https://doi.org/10.2478/CZOTO-2019-0020</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Zidan K., Alam A., Allison J., Al-sherbaz A. Assessing the challenges faced by Security Operations Centers (SOC). In: Arai K. (Ed.). Advances in Information and Communication. FICC 2024. Lecture Notes in Networks and Systems. Springer; 2024. V. 920. P. 256–271. https://doi.org/10.1007/978-3-031-53963-3_18</mixed-citation><mixed-citation xml:lang="en">Zidan K., Alam A., Allison J., Al-sherbaz A. Assessing the challenges faced by Security Operations Centers (SOC). In: Arai K. (Ed.). Advances in Information and Communication. FICC 2024. Lecture Notes in Networks and Systems. Springer; 2024. V. 920. P. 256–271. https://doi.org/10.1007/978-3-031-53963-3_18</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Sackey A. Information Security Incident Handling in the Cloud. In: Book Chapter Series on Research Nexus in IT, Law, Cyber Security &amp; Forensics. 2022. P. 103–108. https://doi.org/10.22624/AIMS/CRP-BK3-P17</mixed-citation><mixed-citation xml:lang="en">Sackey A. Information Security Incident Handling in the Cloud. In: Book Chapter Series on Research Nexus in IT, Law, Cyber Security &amp; Forensics. 2022. P. 103–108. https://doi.org/10.22624/AIMS/CRP-BK3-P17</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">Дёмина А.К. Управление инцидентами информационной безопасности. Международный журнал гуманитарных и естественных наук. 2024;5–1(92):227–231. https://doi.org/10.24412/2500-1000-2024-5-1-227-231, URL: https://elibrary.ru/aizkwa</mixed-citation><mixed-citation xml:lang="en">Demina A.K. Information security incident management. Mezhdunarodnyi zhurnal gumanitarnykh i estestvennykh nauk = International Journal of Humanities and Natural Sciences. 2024;5–1(92):227–231 (in Russ.). https://doi.org/10.24412/2500-1000-2024-5-1-227-231, available from URL: https://elibrary.ru/aizkwa</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Khorev P.B., Karpeeva V.A. Software tools for analyzing information security incidents based on monitoring of information resources. In: 2022 6th International Conference on Information Technologies in Engineering Education (Inforino). IEEE; 2022. https://doi.org/10.1109/Inforino53888.2022.9782979, URL: https://elibrary.ru/qjfmzi</mixed-citation><mixed-citation xml:lang="en">Khorev P.B., Karpeeva V.A. Software tools for analyzing information security incidents based on monitoring of information resources. In: 2022 6th International Conference on Information Technologies in Engineering Education (Inforino). IEEE; 2022. https://doi.org/10.1109/Inforino53888.2022.9782979, available from URL: https://elibrary.ru/qjfmzi</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Максимова Е.А. Когнитивное моделирование деструктивных злоумышленных воздействий на объектах критической информационной инфраструктуры. Труды учебных заведений связи. 2020;6(4):91–103. https://doi.org/10.31854/1813-324X-2020-6-4-91-103, URL: https://elibrary.ru/lirtxz</mixed-citation><mixed-citation xml:lang="en">Maksimova E.A. Cognitive modeling of destructive malicious impacts on critical information infrastructure objects. Trudy uchebnykh zavedenii svyazi = Proceedings of Telecommunication Universities. 2020;6(4):91–103 (in Russ). https://doi.org/10.31854/1813-324X-2020-6-4-91-103, available from URL: https://elibrary.ru/lirtxz</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Котенко И.В., Паращук И.Б. Модель системы управления информацией и событиями безопасности. Вестник Астраханского государственного технического университета. Серия: Управление, вычислительная техника и информатика. 2020;2:84–94. https://doi.org/10.24143/2072-9502-2020-2-84-94, URL: https://elibrary.ru/owaldx</mixed-citation><mixed-citation xml:lang="en">Kotenko I.V., Parashchuk I.B. Model of security information and event management system. Vestnik Astrakhanskogo gosudarstvennogo tekhnicheskogo universiteta. Seriya: Upravlenie, vychislitel’naya tekhnika i informatika = Vestnik of Astrakhan State Technical University. Series: Management, Computer Science and Informatics. 2020;2:84–94 (in Russ). https://doi.org/10.24143/2072-9502-2020-2-84-94, available from URL: https://elibrary.ru/owaldx</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Kotenko I., Parashchuk I. An approach to modeling the decision support process of the security event and incident management based on Markov chains. IFAC-PapersOnLine. 2019;52(13):934–939. https://doi.org/10.1016/j.ifacol.2019.11.314, URL: https://elibrary.ru/eqccxc</mixed-citation><mixed-citation xml:lang="en">Kotenko I., Parashchuk I. An approach to modeling the decision support process of the security event and incident management based on Markov chains. IFAC-PapersOnLine. 2019;52(13):934–939. https://doi.org/10.1016/j.ifacol.2019.11.314, available from URL: https://elibrary.ru/eqccxc</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Dohtieva I., Shyian A. Simulation of the work of the information security incident response team during cyberattacks. Herald of Khmelnytskyi National University. 2021;303(6):115–123.</mixed-citation><mixed-citation xml:lang="en">Dohtieva I., Shyian A. Simulation of the work of the information security incident response team during cyberattacks. Herald of Khmelnytskyi National University. 2021;303(6):115–123.</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Микрюков А.А., Куулар А.В. Разработка модели управления инцидентами в информационной системе предприятия на основе трехуровневой архитектуры с использованием ключевых (релевантных) метрик. Открытое образование. 2020;24(3):78–86. https://doi.org/10.21686/1818-4243-2020-3-78-86, URL: https://elibrary.ru/fcqjjr</mixed-citation><mixed-citation xml:lang="en">Mikryukov A.A., Kuular A.V. Development of an incident management model in an enterprise information system based on a three-tier architecture using key (relevant) metrics. Otkrytoe obrazovanie = Open Education. 2020;24(3):78–86 (in Russ.). https://doi.org/10.21686/1818-4243-2020-3-78-86, available from URL: https://elibrary.ru/fcqjjr</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Mouratidis H., Islam S., Santos-Olmo A., Sanchez L.E., Ismail U.M. Modelling language for cyber security incident handling for critical infrastructures. Comput. Secur. 2023;128(8):103139. https://doi.org/10.1016/j.cose.2023.103139</mixed-citation><mixed-citation xml:lang="en">Mouratidis H., Islam S., Santos-Olmo A., Sanchez L.E., Ismail U.M. Modelling language for cyber security incident handling for critical infrastructures. Comput. Secur. 2023;128(8):103139. https://doi.org/10.1016/j.cose.2023.103139</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Renners L., Heine F., Kleiner C., Rodosek G. Design and evaluation of an approach for feedback-based adaptation of incident prioritization. In: 2019 2nd International Conference on Data Intelligence and Security (ICDIS). IEEE: 2019. P. 28–35. https://doi.org/10.1109/ICDIS.2019.00012</mixed-citation><mixed-citation xml:lang="en">Renners L., Heine F., Kleiner C., Rodosek G. Design and evaluation of an approach for feedback-based adaptation of incident prioritization. In: 2019 2nd International Conference on Data Intelligence and Security (ICDIS). IEEE: 2019. P. 28–35. https://doi.org/10.1109/ICDIS.2019.00012</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Maksimova E., Sadovnikova N. Proactive modeling in the assessment of the structural functionality of the subject of critical information infrastructure. In: Kravets A.G., Shcherbakov M., Parygin D., Groumpos P.P. (Eds.). Creativity in Intelligent Technologies and Data Science (CIT&amp;DS 2021). Communications in Computer and Information Science. Springer; 2021. V. 1448. P. 436–448. https://doi.org/10.1007/978-3-030-87034-8_31</mixed-citation><mixed-citation xml:lang="en">Maksimova E., Sadovnikova N. Proactive modeling in the assessment of the structural functionality of the subject of critical information infrastructure. In: Kravets A.G., Shcherbakov M., Parygin D., Groumpos P.P. (Eds.). Creativity in Intelligent Technologies and Data Science (CIT&amp;DS 2021). Communications in Computer and Information Science. Springer; 2021. V. 1448. P. 436–448. https://doi.org/10.1007/978-3-030-87034-8_31</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Alin Z., Sharma R. Cybersecurity management for incident response. Romanian Cyber Security Journal. 2022;4(1):69–75. URL: https://elibrary.ru/ihxntg</mixed-citation><mixed-citation xml:lang="en">Alin Z., Sharma R. Cybersecurity management for incident response. Romanian Cyber Security Journal. 2022;4(1):69–75. Available from URL: https://elibrary.ru/ihxntg</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
