The paper proposes a method for strategic planning of cybersecurity measures for critical infrastructure objects, developed on the basis of a formalized SWOT model that integrates qualitative analysis of strengths, weaknesses, opportunities, and threats with quantitative assessment of risks, costs, and the effectiveness of protective actions. Unlike the classical descriptive SWOT analysis, which lacks analytical consistency, the proposed approach involves constructing a mathematical model of strategic planning in which each factor is represented by a weighted set, and the relationships between internal and external factors are defined through a strategic influence matrix. An integrated risk coefficient is introduced, taking into account the probability of threat realization, the level of its impact on critical functions, and the residual vulnerability of the system. This enables a transition from qualitative expert assessment to an optimization problem of maximizing cybersecurity effectiveness under resource constraints. The mathematical model implements multicriteria optimization, where the objective function describes the difference between the expected efficiency of measures and
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً