This work highlights the problem of developing a comprehensive information protection system (CIPS) for a typical information activity object in the context of increasing cyber threats and increasing requirements for information security. It presents an analysis of current trends in cyber incidents in Ukraine and the world, examines the regulatory framework governing the creation of CIPS, and also considers international standards ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27005 and NIST recommendations. The methodology for building CIPS is disclosed, in particular, the classification of information activity objects, stages of threat analysis, modeling of the intruder and the formation of a security policy. The results of developing a CIPS model for a typical enterprise are presented: analysis of information flows, threat and intruder models, assessment of the level of security, formation of a security profile and selection of technical, cryptographic and organizational measures. The effectiveness of the implementation was assessed, and the expected benefits were identified, including reduced risk of leakage, increased business process resilience, and compliance with international stand
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً