PECULIARITIES OF THE IMPLEMENTATION OF THE INFORMATION SECURITY MANAGEMENT SYSTEM UNDER MARTIAL LAW CONDITIONS
Published 09/30/2025
Keywords
- military aggression,
- cyber security measures,
- banking system of Ukraine, information security, critical infrastructure security,
- information and psychological operations,
- cyber security
- critical information infrastructure,
- security policy,
- ISMS policies and procedures,
- risk-oriented approach,
- information security management system,
- modern information and communication systems and technologies,
- management decision ...More
Copyright (c) 2025 Сергій Гордієнко (Автор)

This work is licensed under a Creative Commons Attribution 4.0 International License.
Abstract
Due to the active conduct of information-psychological operations (IPSO) and the spread of destructive informational impacts by the aggressor state, rf, against our country, the issue of ensuring information security is becoming increasingly urgent. Ensuring the information system operates under optimal conditions for the functioning of information exchange processes in state and military management solely with a set of technical means is, at present, practically impossible.
Moreover, the challenge extends to ensuring the resilience of management processes related to actively countering military aggression by rf, as well as fully understanding the process of cybernetic-hybrid impact, where special IPSO are used against Ukraine, its military forces, and its civilian population.
These issues can be addressed through the implementation of an adaptive approach to the use of an effective Information Security Management System (ISMS) for critical information infrastructure objects in state and military-political administration.
This article identifies the key features of ISMS implementation and modern approaches to its development stages at critical information infrastructure objects, in state and military-political administration, and during the processing of information, the dissemination of which has a destructive impact on the country’s state system and citizens’ information security. Given the current realities in countering active military aggression and the need to build an effective information security management system, approaches based on DSTU ISO/IEC 27001:2015 "Information Technology. Protection Methods. Information Security Management Systems. Requirements" are discussed. The analysis reveals the interconnection of information security processes and subsystems, which are responsible for them, and the political, financial, and military resources required for their effective operation under martial law.
One of the most crucial and urgent areas of conflict in the military sphere is active information-psychological operations and various destructive strategies aimed at Ukraine's military-political infrastructure, including in cyberspace.
It is concluded that the creation and implementation of an effective ISMS will allow for a new level of quality in managing military-political processes under conditions of military aggression and counteracting IPSO by rf. This will reduce information and organisational threats, improve the controllability of operational management processes, and demonstrate the effectiveness and reliability of decision-making, enabling successful resistance to the aggressor's plans alongside leading NATO countries at the global international level.
References
- Богуш В. М., Бровко В. Д., Гордієнко С. Б., Козюра В. Д., Кудін А. М. Управління інформаційною безпекою та кібербезпекою організації : навчальний посібник : в 2 ч. Ч. 1: Основи менеджменту інформаційної безпеки та кібербезпеки. Київ : НА СБУ, 2023. 168 с.
- Богуш В. М., Бровко В. Д., Гордієнко С. Б., Козюра В. Д., Кудін А. М. Управління інформаційною безпекою та кібербезпекою організації : навчальний посібник : в 2 ч. Ч. 2: Основи побудови системи і основних підсистем управління інформаційною безпекою та кібербезпекою організації. Київ : НА СБУ, 2023. 208 с.
- Домарєв В. В., Домарєв Д. В. Управління інформаційною безпекою в банківських установах (Теорія і практика впровадження стандартів серії ISO 27k). Донецьк : Велстар, 2012, 146 с.
- Гордієнко С. Б. Актуальні питання управління ІТ ризиками на об’єктах критичної інформаційної інфраструктури. Вісник Державного університету телекомунікацій «Телекомунікаційні та інформаційні технології». 2022. № 1 (74). С. 29–35.
- ДСТУ ISO/IEC 27000:2015. Інформаційні технології. Методи захисту. Система управління інформаційною безпекою. Огляд і словник (ISO/IEC 27000: 2014, IDT).
- ДСТУ ISO/IEC 27001:2015. Інформаційні технології. Методи захисту. Системи управління інформаційною безпекою. Вимоги (ISO/IEC 27001:2013; Cor 1:2014, IDT).
- ДСТУ ISO/IEC 27002:2015. Інформаційні технології. Методи захисту. Звід практик щодо заходів інформаційної безпеки (ISO/IEC 27002:2013; Cor 1:2014, IDT).
- ДСТУ ISO/IEC 27005:2015. Інформаційні технології. Методи захисту. Управління ризиками інформаційної безпеки (ISO/IEC 27005:2011, IDT).
- ДСТУ ISO/IEC 27006:2015. Інформаційні технології. Методи захисту. Вимоги до організацій, які надають послуги з аудиту і сертифікації систем управління інформаційною безпекою (ISO/IEC 27006:2011, IDT).
- Гладиш С. В., Кононович В. Г., Тардаскін М. Ф. Розподіл відповідальності щодо реагування та обробки інцидентів безпеки в інформаційно-телекомунікаційній мережі загального користування. Зв’язок. 2007. № 8. С. 28–31.
- Гладиш С. В. Інтелектуальна система керування інцидентами інформаційної безпеки телекомунікаційних мереж. Інформаційні технології та інформаційна безпека в науці, техніці та освіті ІНФОТЕХ-2007 : матеріали міжнародної науково-практичної конференції. Севастополь : СевНТУ, 2007. С. 53–57.
- Арбузов С. Г., Колобов Ю. В., Міщенко В. І., Науменкова С. В. Безперервність бізнесу. Банківська енциклопедія. Київ : Центр наукових досліджень Національного банку України : Знання, 2011. 504 с.
- ISO/IEC 27031:2011 року (Інформаційні технології. Методи забезпечення безпеки. Керівництво по створенню готовності інформаційно-комунікаційних технологій до забезпечення безперервності бізнесу).
