Analysis of current regulations in the field of cybersecurity of critical information infrastructure of the Russian Federation

Andrey V. Bondarenko, Konstantin V. Mushovets, Sergey V. Porshnev, Olga K. Rogova
{"title":"Analysis of current regulations in the field of cybersecurity of critical information infrastructure of the Russian Federation","authors":"Andrey V. Bondarenko, Konstantin V. Mushovets, Sergey V. Porshnev, Olga K. Rogova","doi":"10.26583/bit.2023.3.09","DOIUrl":null,"url":null,"abstract":"The paper is devoted to a complex analysis of the current system of regulations in the field of security of critical information infrastructure (CII) facilities of the Russian Federation from the point of view of the logic of formation of the legal basis and the chronology of their creation, the results of which have provided a systematic regulatory framework for the security of CII facilities. The main directions of legislative activity in the field of security CII of the Russian Federation have been highlighted and a classification of the current legal acts in terms of it’s requirements has been proposed..The evolution of the content of the regulatory system to ensure the security of significant CII facilities has been described. The results of the analysis led to the conclusion that the state and regulators in the field of IS has developed a sufficient regulatory framework that defines the basic rules, procedures and requirements for the process of categorization, monitoring of its results, as well as providing information security of significant CII facilities. At the same time, on the basis of the experience of categorization of significant objects of the gas industry by the heat and power complex of the Russian Federation, a hypothesis has been made that the establishment of the information security system at specific significant CII sites (e.g., a variety of types of CII objects and areas of activity of CII entities) will require not only the application of existing legal instruments, but also the development of existing sectoral methodical documents in the field of categorization of objects of CII and in the field of construction of the information security system, taking into account their sectoral characteristics.","PeriodicalId":53106,"journal":{"name":"Bezopasnost'' Informacionnyh Tehnologij","volume":"15 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Bezopasnost'' Informacionnyh Tehnologij","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.26583/bit.2023.3.09","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The paper is devoted to a complex analysis of the current system of regulations in the field of security of critical information infrastructure (CII) facilities of the Russian Federation from the point of view of the logic of formation of the legal basis and the chronology of their creation, the results of which have provided a systematic regulatory framework for the security of CII facilities. The main directions of legislative activity in the field of security CII of the Russian Federation have been highlighted and a classification of the current legal acts in terms of it’s requirements has been proposed..The evolution of the content of the regulatory system to ensure the security of significant CII facilities has been described. The results of the analysis led to the conclusion that the state and regulators in the field of IS has developed a sufficient regulatory framework that defines the basic rules, procedures and requirements for the process of categorization, monitoring of its results, as well as providing information security of significant CII facilities. At the same time, on the basis of the experience of categorization of significant objects of the gas industry by the heat and power complex of the Russian Federation, a hypothesis has been made that the establishment of the information security system at specific significant CII sites (e.g., a variety of types of CII objects and areas of activity of CII entities) will require not only the application of existing legal instruments, but also the development of existing sectoral methodical documents in the field of categorization of objects of CII and in the field of construction of the information security system, taking into account their sectoral characteristics.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
分析俄罗斯联邦关键信息基础设施网络安全领域的现行法规
本文致力于对俄罗斯联邦关键信息基础设施(CII)设施安全领域的现行法规体系进行复杂分析,从法律基础形成的逻辑和其创建的时间顺序的角度出发,其结果为CII设施的安全提供了系统的监管框架。强调了俄罗斯联邦安全CII领域立法活动的主要方向,并根据其要求提出了现行法律行为的分类……描述了确保重要CII设施安全的监管体系内容的演变。分析的结果得出的结论是,国家和IS领域的监管机构已经制定了一个足够的监管框架,定义了分类过程的基本规则、程序和要求,监测其结果,以及提供重要CII设施的信息安全。同时,根据俄罗斯联邦热力和电力综合体对天然气工业的重要目标进行分类的经验,提出了一项假设,即在特定的重要工业工业场址(例如,各种类型的工业工业目标和工业工业实体的活动领域)建立信息安全系统不仅需要适用现有的法律文书,还要在考虑到其部门特点的情况下,在CII对象分类领域和信息安全系统建设领域制定现有的部门系统文件。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
29
期刊最新文献
Analysis of current regulations in the field of cybersecurity of critical information infrastructure of the Russian Federation Study of the applicability of the hierarchy analysis method for choosing a SIEM system The Specialized RF Elements Library for Trusted Transceiver VLSI Design Physically unclonable functions based on a controlled ring oscillator Search for malicious powershell scripts using syntax trees
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1