Vol. 1 No. 1 (2024)
FORMS, METHODS AND MEANS OF DETECTING, EVALUATING AND FORECASTING THREATS TO THE INFORMATION SECURITY OF UKRAINE

ISSUES OF IMPROVING THE PROCESSES OF DETECTION AND PROCESSING OF INFORMATION SECURITY EVENTS AND INCIDENTS

Information Security of the Person, Society and State

Published 05/14/2025

Keywords

  • a threat source,
  • IS events and incidents,
  • IS incident response process,
  • event monitoring system,
  • IS incident management system,
  • event processing and correlation systems
  • ...More
    Less

Abstract

Timely detection of events and processing of possible information security (IS) incidents is the most urgent issue in the conditions of information warfare and military aggression.

The article notes the special relevance of creating IS monitoring systems to solve tasks in the work process of companies that are actively expanding their arsenal of security tools to ensure information security at critical infrastructure facilities.

The essence of methods of responding to IS events and incidents and their processing, improving the processes of detection and processing of information security events and incidents, supporting the effective functioning of IS event monitoring systems is revealed.

The sequence of IS event and incident processing operations implemented at the stage of the IS incident management process using the algorithm of the first assessment and preliminary decision on events and the second assessment with confirmation of a possible information security incident is considered.

Particular attention is drawn to the fact that in the process of analyzing the potential or actual negative impact, it is necessary to confirm what consequences occurred for the organization's business as a result of the IS incident.

Practical recommendations are provided for improving the processes of identifying events and processing IS incidents, supporting the effective functioning of IS event monitoring systems, in particular, carrying out the following measures: ensuring the proper organization of the IS incident management process, which involves the development and implementation of IS incident management policies and procedures, training of personnel who will be responsible for identifying and responding to IS incidents; implementation of IS monitoring systems capable of detecting a wide range of IS events and incidents and ensuring effective processing of detected IS events and incidents; creation of an effective algorithm for responding to IS incidents, which will determine the order of actions that must be performed to eliminate detected IS events and incidents; holding regular exercises and trainings on detection and response to IS incidents, which will help staff acquire the necessary knowledge and skills to effectively detect and respond to IS incidents.

References

  1. Бурячок В. Л., Толубко В. Б., Хорошко В. О., Толюпа С. В. Інформаційна та кібербезпека: соціотехнічний аспект: підручник. Київ: ДУТ, 2015. 288 с.
  2. Богуш В. М., Бровко В. Д., Гордієнко С. Б., Козюра В. Д., Кудін А. М. Управління інформаційною безпекою та кібербезпекою організації: навчальний посібник: в 2 ч. Ч. 1: Основи менеджменту інформаційної безпеки та кібербезпеки. Київ : НА СБУ, 2023. 168 с.
  3. Богуш В. М., Бровко В. Д., Гордієнко С. Б., Козюра В. Д., Кудін А. М. Управління інформаційною безпекою та кібербезпекою організації: навчальний посібник: в 2 ч. Ч. 2: Основи побудови системи і основних підсистем управління інформаційною безпекою та кібербезпекою організації. Київ: НА СБУ, 2023. 208 с.
  4. Гарасим Ю. Р., Ромака В.А., Рибій М. М. Аналіз процесу управління ризиками інформаційної безпеки в процесі забезпечення властивості живучості систем. Вісник Національного університету «Львівська політехніка» «Автоматика, вимірювання та керування». 2013. № 756. С. 105–123.
  5. ДСТУ EN ISO/IEC 27001:2022 Інформаційні технології. Методи захисту. Системи управління інформаційною безпекою. Вимоги (EN ISO/IEC 27001:2017, IDT; ISO/IEC 27001:2013 including Cor 1:2014 and Cor 2:2015, IDT).
  6. ДСТУ ISO/IEC 27000:2019 Інформаційні технології. Методи захисту. Системи керування інформаційною безпекою. Огляд і словник термінів (ISO/IEC 27000:2018, IDT).
  7. ДСТУ ISO/IEC TR 19791:2015 Інформаційні технології. Методи захисту. Оцінювання безпеки операційних систем (ISO/IEC TR 19791:2010, IDT).
  8. Про затвердження Загальних вимог до кіберзахисту об’єктів критичної інфраструктури: Постанова Кабінету Міністрів України від 19.06.2019 № 518. Базаданих «Законодавство України»/ Верховна Рада України. URL: https://zakon.rada.gov.ua/go/518-2019-%D0%BF (дата звернення: 24.01.2024).
  9. Bruce Schneier. Harvard Kennedy School. URL: https://www.hks.harvard.edu/faculty/bruce-schneier (дата звернення: 05.02.2024).
  10. General Data Protection Regulation (GDPR). Legal Text. URL: https://gdpr-info.eu/ (дата звернення: 11.01.2024).
  11. Dan Geer. Harvard Kennedy School. Harvard Kennedy School. URL: https://www.hks.harvard.edu/about/dan-geer (дата звернення: 19.01.2024).
  12. Data Mining Approaches for Intrusion Detection. The Advanced Computing Systems Association. URL: https://www.usenix.org/conference/7th-usenix-security-symposium/data-mining-approaches-intrusion-detection (дата звернення: 15.02.2024).
  13. HIPAA Home. HHS.gov. URL: https://www.hhs.gov/hipaa/index.html (дата звернення: 05.01.2024).
  14. Mihai Christodorescu. Google Scholar. URL: https://scholar.google.com/citations?user=jRnIqvkAAAAJ&hl=en (дата звернення: 03.02.2024).
  15. Ross J. Anderson 1956–2024. The University of Edinburg. URL: https://informatics.ed.ac.uk/news-events/news/latest-news/ross-j-anderson-1956-2024 (дата звернення: 12.02.2024).
  16. Spafford E. H., Zamboni D. Intrusion detection using autonomous agents. Computer Netwoks. 2000. T. 34. № 4. C. 547–570. URL: https://doi.org/10.1016/s1389-1286(00)00136-5 (дата звернення: 12.02.2024).
  17. What is a Computer Security Incident Response Center (CSIRC)? Group-IB. URL: https://www.group-ib.com/resources/knowledge-hub/csirc/ (дата звернення: 12.02.2024).