The article addresses the problem of the discrepancy between declared information security policies, the requirements of standards and protocols, and the actual functioning of organizational information infrastructures. In practice, components of comprehensive information security systems (CISS) are often developed formally, without considering real risks, characteristics of network protocols, or compliance with international and national security standards. As a result, information security policies are not aligned with technical configuration parameters, leading to fragmentation of protection mechanisms and a decrease in overall system effectiveness. Another critical issue is the continued use of outdated or insecure protocols that remain operational due to the absence of systematic compliance control mechanisms. This study proposes a method for integrating information security policies, standard requirements (ISO/IEC 27001:2022, NIST SP 800-53, Ukrainian ND TZI), and secure network protocols (TLS 1.3, SSHv2, DNSSEC, IPSec) into the process of developing a comprehensive information security system. The method consists of four stages: asset and protocol analysis, development and f
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً