Измерение, мониторинг, управление, контроль (Jan 2022)
PROBLEMS OF EFFECTIVE ASSESSMENT OF INFORMATION SECURITY EVENTS IN THE ROCKET AND SPACE INDUSTRY
Abstract
Background. The organization of the information security incident management process is a very important aspect of the information security system design. The objective of the research was to analyze problems of effective assessment of information security events. Materials and methods. In the theoretical part of the article analyzed international and Russian standarts in the field of information security event management. For example, Russian GOST or international ISO/IEC. The article described such incident management models as PDCA and PICERL. The study proved the importance of using SIEM-solutions in information systems and methods for setting up event correlation. Results. The key thesis of this article are: there is no generally accepted method of incident management; models for building information security event management processes don’t describe the nuances of configuring technical solutions and don’t provide a quick response, analysis and resolution of information security incidents. The results of the study show the main problems of effective assessment of information security events.
Keywords