Polozhentsev A. Methods and means of IT Incident Management at CriticalInformation Infrastructure Facilities.

Thesis for the degree of Doctor of Philosophy (PhD)

  • 122 - Комп’ютерні науки


National Aviation University


Protecting critical infrastructure from IT threats is an urgent need in the modern digital world, as the stability of the state and society depends on it. The development of new IT incident management methods will allow for effective response to threats and ensure the uninterrupted operation of critical systems. The aim of the dissertation is to improve the IT incident management system at critical information infrastructure facilities under threat realization and limited protection resources. The object of research is the processes of IT incident management at critical information infrastructure facilities. The subject of research is the methods and tools for managing incidents at critical information infrastructure facilities under threat realization and limited protection resources. The scientific novelty of the obtained results is as follows: – For the first time, a method for managing IT threats has been developed, which, due to the synthesis of methods of multi-criteria decision-making, threat modeling, and the prospective value function, allows identifying, assessing, and prioritizing IT threats for the optimal allocation of resources for the protection of the state's critical infrastructure. – The method for determining the priorities of IT incidents has been improved, which, due to the presentation of hierarchical structures of elements of potential threats and the calculation of the probability of their implementation, allows for quantitative assessment of IT incident priorities and management thereof to ensure the necessary level of protection of the vital interests of citizens, society, the state, and law and order. – The method of assessing the level of protection has been further developed, which, due to the use of new IT security indicators and the level of digital transformation, as well as the developed recommendations for optimizing protection, allows determining the state of protection of critical infrastructure facilities (sector/subsector or the state as a whole), as well as manage the protection of these facilities in the event of IT incidents.

