Автоматизація процесів побудови та супроводу комплексних систем захисту інформації
Вантажиться...
Файли
Дата
Автори
Назва журналу
Номер ISSN
Назва тому
DOI
Анотація
The abstract discusses the issues of creating and implementing comprehensive information protection systems (CIPS)
in modern information and telecommunications systems (ITS). The relevance of the study is due to the rapid growth in
the volume of data subject to protection in accordance with the requirements of ND TZI (regulatory documents of the
technical information protection system) and the inadequacy of traditional ‘manual’ methods of building protection
systems to the dynamics of modern cyber threats. The main shortcomings of the classical approach to creating CIS are
analysed, including: the high labour intensity of developing project documentation, the significant influence of the human
factor in configuring protection measures, the static nature of the security policies implemented, and the complexity of
maintaining the current state of security after system certification. Particular attention is paid to the problem of ‘paper
security,’ when the system formally meets the requirements but remains technically vulnerable due to configuration
errors. A methodology for automating the stages of the ISMS life cycle by implementing Infrastructure as Code (IaC) and
Security as Code (SaC) approaches is proposed. The possibility of using configuration management systems (e.g., Ansible,
Chef, Puppet) for automated deployment of security policies is considered, which guarantees the identity of settings on
all network nodes and eliminates administrator errors. The effectiveness of using the Security Content Automation
Protocol (SCAP) for continuous monitoring of system compliance with established requirements was also investigated.
It was substantiated that the transition from periodic manual control to automated monitoring allows maintaining the
ISMS up to date in real time, significantly reduces the time required for preparation for state examination, and reduces
the cost of operating the protection system.
Опис
Ключові слова
Security as Code , безперервний моніторинг , політики безпеки , comprehensive information security system , automation of security processes , regulatory framework for information security , human factor , configuration management , Security as Code , SCAP , continuous monitoring , security policies
Тип документа
Мова
ISSN
Бібліографічний опис
Бондаренко І. О., Магденко А. Р. Аналіз соціальних джерел для виявлення прихованих спільнот і трендів // Матеріали LV Всеукраїнської науково-технічної конференції підрозділів ВНТУ, Вінниця, 24-27 березня 2026 р. Електрон. текст. дані. 2026. URI: https://conferences.vntu.edu.ua/index.php/all-fm/all-fm-2026/paper/view/27853.
Схвалення
Рецензія
Доповнено
Цитується в
Список використаної літератури (5)
- NIST (National Institute of Standards and Technology). URL: https://www.nist.gov/ (дата звернення: 13.02.2026).
- 2024 ETFA – IEEE 29th International Conference on Emerging Technologies and Factory Automation. URL: https://bibliographie.ub.rub.de/work/396934 (дата звернення: 16.02.2026).
- Morris, K. (2016). Infrastructure as Code: Managing Servers in the Cloud. O'Reilly Media. URL: https://dl.ebooksworld.ir/books/Infrastructure.as.Code.2nd.Edition.Kief.Morris.OReilly.9781098114671.EBooksWorld.ir.pdf (дата звернення: 19.02.2026).
- Scarfone, K., & Souppaya, M. (2018). The Technical Specification for the Security Content Automation Protocol (SCAP). NIST Special Publication 800-126 Revision 3. URL: https://csrc.nist.gov/pubs/sp/800/126/r3/final (дата звернення: 19.02.2026).
- Wazuh. URL: https://documentation.wazuh.com/current/compliance/nist/configuration-assessment.html (дата звернення: 20.02.2026)