In today's world, where the number and complexity of cyber threats, especially those targeting strategic state assets, are growing rapidly, there is an urgent need to develop effective, flexible, and adaptive mechanisms for assessing the current level of cyber security. In view of this need, an analysis of existing approaches to assessing the level of cyber security was conducted. Among them are models based on maturity, risk, and compliance. The results of the analysis showed that none of these approaches is completely universal or sufficient for a comprehensive assessment of critical information infrastructure objects in the context of the national legislative field. In particular, approaches based solely on compliance may not take into account real risks, while approaches based on maturity are often too subjective. To address these systemic shortcomings, a hybrid approach was proposed. This approach integrates the best features of previous models, combining the objectivity of compliance testing, the flexibility and process orientation of maturity assessment, and risk-based prioritization. Based on the hybrid approach, a method for calculating the level of cyber protection of cri
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً