Popel V. Information technology for increasing the survivability of critical energy infrastructure objects by the factor of managing the information security system.

Українська версія

Thesis for the degree of Doctor of Philosophy (PhD)

State registration number

0824U000096

Applicant for

Specialization

  • 151 - Автоматизація та приладобудування. Автоматизація та комп’ютерно-інтегровані технології

Specialized Academic Board

4518

National university of food technologies

Essay

The aim of the dissertation is the scientific justification of increasing the level of information security of the management system of a complex of critical energy infrastructure objects due to the improvement of the information security subsystem. In the first chapter of the dissertation, the methods of increasing the level of information security at critical infrastructure facilities, including those united in territorial or sectoral complexes, are considered, and a conclusion is drawn about the possibility of obtaining a comprehensive effect of optimizing resource costs to ensure the appropriate level of information security and obtaining its increase at costs of a similar amount of resources under the condition of improving the information security management system. A number of factors, including the complexity of the infrastructure, the threat environment, regulations and compliance requirements, human resources, technology, and the need for knowledge and training, affects ensuring the required level of information security at a critical infrastructure facility. However, the cost of unprotected critical infrastructure can be even higher, including financial loss, reputational damage, and even loss of life in some cases. It is unacceptable to save resources on elements of information security, at the same time the available resources are limited and the sources of their receipt have certain capabilities. Thus, in the field of cyber security, there is an urgent need to obtain additional resources to ensure information security, which can be met by improving the information security management system. Therefore, the development of better rules for building an information security management system, the application of which allows you to increase the level of information security without spending additional resources, is an urgent task. The second chapter of the thesis presents the justification of the mathematical model used to assess risks specific to critical infrastructure objects. The third chapter of the dissertation provides an analysis of the methods of determining the performance indicators of the critical infrastructure protection management system, with an emphasis on critical energy infrastructure facilities. Reasoned opportunities for optimization of resource management processes while ensuring the proper level of safety of objects, a calculation model for determining the optimal costs for ensuring the safety parameters of a critical energy infrastructure object are presented. A typical structure of the automated management system is proposed, the task of which is to monitor and assess the current state of risks of the critical infrastructure system, support decision-making in the management of the security system. The fourth chapter of the dissertation contains the results of the risk analysis of the critical infrastructure of the Kyiv region, which is based on computer modeling using the selected mathematical apparatus and real data on threats and the state of critical infrastructure objects. Based on the conducted research and calculations, the Critical Infrastructure Risk Assessment Methodology was developed, which was used in the development of a regulatory act of the State Special Communications Administration, which must be registered with the Ministry of Justice of Ukraine and accepted for implementation by the end of 2023. The methodology contains a list of requirements and a description of practices, the application of which will ensure the fulfillment of current security requirements for the system of protection of critical infrastructure of Ukraine. The conducted dissertation research made it possible to obtain the following new scientific results: - for the first time, a methodology for evaluating the effectiveness of the information security system of a complex of critical energy infrastructure facilities was developed, which differs from the existing system of criteria indicators and a calculation algorithm that allow to increase the level of security in the conditions of missile and drone strikes on critical energy infrastructure facilities. - the mathematical model for calculating threats for a complex of critical energy infrastructure objects in conditions of armed conflict has been improved, which differs from the existing ones by using the apparatus of fuzzy sets, which allows obtaining threat estimates in conditions of a priori uncertainty of the means of damage to critical energy infrastructure objects. - the scientific-methodical and scientific-organizational recommendations regarding the formation of an information security subsystem optimal in terms of the composition of the information resource received further development due to the use of modern information technologies, which allow to achieve an increase in the level of information security for the system of automated management of the complex of objects of the country's critical energy infrastructure.

Research papers

Попель В.А. , Мацько П.І. Методика визначення чинників, що впливають на забезпечення ТБ об'єктів критичної інфраструктури Сил Оборони під час відсічі збройної агресії. Труди університету. 2023, №7(182), С.203-217.

Чумаченко, С., Попель, В. Системний підхід до автоматизації процесів забезпечення компетентності персоналу на об’єктах критичної інфраструктури сил оборони України. Вісник Черкаського державного технологічного університету. 2023, (3), С.141–155.

Чумаченко С.М., Кутовий О.П., Гуйда О.Г., Попель В.А., Заїка Н.В. Комплексний підхід до визначення рівня безпеки критичної енергетичної інфраструктури на основі інтегральної системи захисту її об'єктів від БПЛА та крилатих і балістичних ракет. Вчені записки ТНУ імені В.І. Вернадського. Серія: Технічні науки. 2023, Т. 34(73), № 2, Ч.2, С. 261-267.

Files

Similar theses