<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Sergiy Gnatyuk</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Ergonomic Support for Decision-Making Management of the Chief Information Security Officer</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aviation University</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Sumy National Agrarian University</institution>
          ,
          <addr-line>Sumy</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Sumy State University</institution>
          ,
          <addr-line>Sumy</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Yessenov University</institution>
          ,
          <addr-line>Aktau</addr-line>
          ,
          <country country="KZ">Kazakhstan</country>
        </aff>
      </contrib-group>
      <volume>1</volume>
      <issue>2</issue>
      <fpage>0000</fpage>
      <lpage>0003</lpage>
      <abstract>
        <p>The paper considers the actual task of making managerial decisions by the Chief Information Security Officer. The need for the optimal distribution of tasks between department officers is shown. This problem is considered as a linear programming problem. An ergonomic approach is proposed to obtain quantitative estimates of the algorithms of officers' activities. The use of the functional-structural theory of ergotechnical systems made it possible to formalize, describe and evaluate the activities of officers. The obtained probabilistictemporal characteristics of various tasks were used as initial data for solving the optimization problem. To apply this approach in the activities of the leader, an information technology for supporting management decision-making has been developed and described. An example of implementation for two management decision-making strategies is shown in this paper.</p>
      </abstract>
      <kwd-group>
        <kwd>Information Security</kwd>
        <kwd>Management Task</kwd>
        <kwd>Information Technology</kwd>
        <kwd>Decision-Making</kwd>
        <kwd>Chief Information Security Officer</kwd>
        <kwd>Ergonomic Approach</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>The duties of the Chief Information Security Officer (CISO) include not only
informing management about the risks to the company’s activities and direct participation in
risk management, developing information security documents, studying the latest
technologies and security trends, but also implementing other strategic work, such as
responding to incidents and assigning tasks to their prevention, analysis, elimination
of consequences, etc. Naturally, it is not the CISO himself who performs the specified
routine work, but entrusts it to the employees of his service. The reliability of the
company as a whole largely depends on the correct distribution of tasks between its
subordinates. As a rule, CISO makes such decisions more or less intuitively, based on
his knowledge of the health, productivity and reliability of the employees. But such
decisions can lead to non-optimal results.</p>
      <p>
        Related works analysis and problem statement
The final areas of information security management in organizations of various kinds
of activities [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ] include:
1. Asset management of the organization [
        <xref ref-type="bibr" rid="ref1 ref2 ref3">1-3, 18, 19</xref>
        ].
      </p>
      <p>
        2. Resource management of the information security system implemented in the
organization [
        <xref ref-type="bibr" rid="ref1 ref2 ref4">1, 2, 4</xref>
        ].
      </p>
      <p>
        3. Management of risks and threats to information security [
        <xref ref-type="bibr" rid="ref2 ref5 ref6">2, 5, 6</xref>
        ].
      </p>
      <p>
        4. Management of documentation and information help system in the organization
[
        <xref ref-type="bibr" rid="ref1 ref13 ref2 ref7">1, 2, 7, 13</xref>
        ].
      </p>
      <p>
        5. Information security audit management [
        <xref ref-type="bibr" rid="ref6 ref8 ref9">6, 8, 9</xref>
        ].
      </p>
      <p>
        6. Management of the analysis of the effectiveness of the information security
system [
        <xref ref-type="bibr" rid="ref1 ref10 ref4">1, 4, 10</xref>
        ].
      </p>
      <p>
        7. Management of tasks and activities of employees engaged in the processes of
ensuring information security in the organization [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] etc.
      </p>
      <p>
        As one can see, the task of managing the activities of employees involved in
information security processes in the organization has not been completely solved. This
task can be considered as one of the tasks of ergonomics - the distribution of functions
between operators-executors. The use of the ergonomic approach allows the manager
to use scientific and practical developments in this subject area. From the point of
view of the ergonomic approach, the operator-manager has the following tasks:
─ organization of activities of executing operators [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ];
─ creation of optimal psychological working conditions [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ];
─ ensure reliability [14].
      </p>
      <p>In paper [15], the basic principles of the functional-structural theory of
ergotechnical systems (ETS) and its application for various tasks of constructing problems of
ergonomic quality and such systems with a constant functional structure as the
workshop control system are described.</p>
      <p>In paper [16], the problem of the distribution of functions for flexible systems with
a variable functional structure was solved. One can see that the problem of the
distribution of functions can be effectively solved only on the basis of estimates of the
accuracy and timeliness of the functioning algorithms, i.e. human-machine interaction
processes. This approach can be implemented on the basis of the functional-structural
theory of ergotechnical systems [17], which provides tools for modeling
humanmachine interaction:
─ formalized description of functioning algorithms,
─ determination of probability-time indicators of the quality of functioning
algorithms, and
─ optimization.</p>
      <p>This approach can be extended to ensure the reliability of information security
management activities. Untimely and erroneous implementation of information
security management actions can lead to a violation of the integrity, accessibility and
confidentiality of information, which entails material damage.</p>
      <p>Information security officers have different qualifications and work experience,
which leads to different values of faultlessness and execution time of both individual
works and the entire functioning algorithm.</p>
      <p>The unsolved problem is the formation of initial data for evaluating the
functioning algorithms. It is proposed to take data from special directories that are focused on
the average operator. However, there are no such directories for information security
management activities.</p>
      <p>The purpose of the study is to develop information technology to support the
decision-making of the CISO, which ensures the optimal appointment of the security
officers to perform information security management tasks.</p>
      <p>In this case, it is necessary to take into account various strategies:
1) All employees should be allocated to tasks (one employee - one task)
2) Maximum reliability must be ensured (one employee can perform several tasks;
the tasks are not assigned to some employees).</p>
      <p>To achieve this goal, it is necessary to solve the following tasks:
─ developing a mathematical model for solving the problem
─ developing an approach to ensure the evaluation of functioning algorithms with
source data
─ checking the possibility of using the developed models and approaches to build
information technology for decision support of the CISO.
3</p>
      <p>The optimal appointment of CISO to perform tasks
There are n officers and m actual tasks. Any officer can be appointed to accomplish
any task, but with different assumed accuracy of the execution. It is necessary to
allocate officers to carry out tasks in such a way that they complete tasks with maximum
error-freeness within the available time reserve.</p>
      <p>The task can be represented as a following linear programming problem.</p>
      <p>n n
B( X )    bij xij  max ,
The variable xij represents the appointment of officer j for task i and takes the value 1
if the officer is assigned to complete the task, and 0, otherwise bij is the probability of
an error-free operation. Ti is allowable execution time of i task, Mij is the
mathematical expectation of the time to complete the operation.</p>
      <p>The second strategy assumes that one officer may be assigned to complete only
one mission. At the same time, we need the tasks have been completed with
maximum error-freeness within the existing time reserve. The restriction determines the
assignment of one task to one officer:</p>
      <p>i1 j1
n n n
 xij  1 , (i  1, n) ,  xij  1 , ( j  1, n) , 
i1 j1 i1
M ij xij  Ti , xij  1;0.
4</p>
      <p>Application of the ETS theory for quantitative assessment of
the quality of task performance
The generalized structural method that underlies the ETS uses a functional network as
a description of functioning algorithms (FA). To describe the FA used typical
functional unit (TFU) (table 1).
To conduct a quantitative assessment of the quality and reliability of operation in the
FS apparatus, a set of TFS was obtained.</p>
      <p>To build an AF model, it is necessary to prepare a list of work to be performed.
Each work put in line with the TFU. For each TFU, determine the probability-time
characteristics. Using Table 2 to obtain quantitative indicators of the quality of
performance AF [17-19].</p>
    </sec>
    <sec id="sec-2">
      <title>2. Cycle functional</title>
      <p>diagram “Operation
with monitoring the
functioning without
limitation on the
number of cycles”</p>
      <p>TFS
diagram</p>
    </sec>
    <sec id="sec-3">
      <title>Formula</title>
      <p>n
В   Bi
i1
n
M ( X )   M ( X i )</p>
      <p>i1
B
 B1 K 11</p>
      <p>1
1  (B1 K 10  B 0 K 00 )
M ( X )  (M ( X р )  M ( X к ))M (L)</p>
      <p>M (L) </p>
      <p>1
1  (B1K10  B0 K 00 )
The formation of the source data for the task of evaluating the functioning algorithm
Providing the task of evaluating the functioning algorithm (FA) with source data is
one of the main problems of ergonomic modeling. We cannot accept the assumption
of an “average operator” in this study. The proposed approach implements the
technology of intelligent analysis [18, 19] of data accumulated in the database of the
results of activities of the office employees.</p>
      <p>We solve the approximation problem using neuro-fuzzy inference technology [20].
In this technology, a logical conclusion bases on fuzzy logic, and membership
functions are adjusted using neural networks. The parameters of the officer, hardware and
software, time constraints are fed to the input, and at the output, we obtain
probability-time indicators of the quality of the operation.</p>
      <p>Information technology for ergonomic support for management decision-making
of the CISO
Fig. 1 demonstrates the functional structure of the developed system.
Let the CISO have the task to formulate a security office work plan. Every
information security officer should be given a mission. Currently relevant tasks:
─ Task1 - website check
─ Task2 - audit of wireless networks
─ Task3 - prevention of physical intrusion.</p>
      <p>The lead time for the first task is no more than 620; the lead time for the second
task is no more than 500; the lead time for the third task is no more than 160. Tasks
can be assigned to three officers.</p>
      <p>It is necessary to distribute the execution of tasks between officers in such a way as
to ensure maximum reliability of the assignment. In this case, the time limit for each
task should be taken into account.</p>
      <p>To perform each task, the office has developed certain algorithms. So the algorithm
for solving each tasks are:
Task 1 (website verification), the following actions are performed:
1. Examining the existing site code
2. Examining published vulnerabilities
3. Threat analysis
4. Hacking attempts through existing vulnerabilities
5. QA &amp; TA Analysis
6. Data Analysis
7. Elimination of vulnerabilities and the introduction of new technologies based on
the analysis.</p>
      <p>8. Testing applications.</p>
      <p>To solve Task 2 (audit of wireless networks) consists of the following actions:
1. Definition of existing technologies and coverage
2. Studying the configuration of access points and servers
3. Analysis of traffic and existing threats
4. Attempted unauthorized entry
5. Analysis of the data obtained in paragraphs 1-4
6. The introduction of modified technologies.</p>
      <p>Task 3 solution (physical intrusion prevention) involves the following actions:
1. Familiarization with literature
2. Learning from previous invasion techniques
3. Consultation with external sources
4. Independent attempts to penetrate
5. Analysis of all information and conclusions
6. Security penetration
Models of performing tasks in the form of a work graph are presented in Fig. 2.</p>
      <p>The initial data on the quality of the work operations of the activity algorithms for
the implementation of tasks are given in Tables 3-6.
p6
The initial data on the quality of the control operation are given in table 6.
p7
0,998
240
0,943
247
0,975
245
0,98
64
0,998</p>
      <p>61
0,986</p>
      <p>62
0,982</p>
      <p>12
0,991</p>
      <p>15
0,978
13
p6
0,98
56
0,952</p>
      <p>54
0,987
55
Here, B1 is the probability of error-free execution of a work operation; K11 is the
probability of recognition of a work operation performed correctly, when actually
performed correctly; K00 is the probability of recognition of a work operation
performed incorrectly, when actually performed incorrectly; and M are the mathematical
expectation of the operation time [20-23].</p>
      <p>The data in tables 3, 4 and 5 are obtained by the subsystem for the formation of the
source data. The principle of operation is based on the use of expert methods of
assessment and neuro-fuzzy modeling. The source data are loaded automatically. The
manager needs to choose only a list of employees, a list of tasks, and set time limits.</p>
      <p>The results are presented in the form of a job assignment matrix (Fig. 3), in the
form of correlation of employees and tasks for strategy 1.</p>
      <p>Resulting performance indicators (the probability of error-free execution and the
mathematical expectation of the execution time) are presented in Fig. 5.</p>
      <p>Visualization of the resulting quality indicators makes it possible to visually assess
the predicted quality of performance (Fig. 6).</p>
      <p>The results are presented in the form of a job assignment matrix (Fig. 7), in the
form of correlation of employees and tasks for strategy 2.</p>
      <p>Resulting performance indicators (the probability of error-free execution and the
mathematical expectation of the execution time) are presented in Fig. 9.</p>
      <p>Visualization of the resulting quality indicators makes it possible to visually assess
the predicted quality of performance (Fig. 10).
The developed information technology allows the CISO to carry out the optimal
appointment of his officers to perform tasks to ensure information security. Decision
making is based on the obtained quantitative indicators of the quality of the tasks.
Reliability of execution is maximized, taking into account time constraints. The
structure of officers' activities and their individual characteristics of reliability and speed
are taken into account.</p>
      <p>However, it should be noted the high complexity of the method at the stage of
preparation of the initial data. For successful operation of the system, it is necessary,
first, to formalize the algorithms for performing tasks and obtain data on the
probability-time indicators of the quality of operations for each officer [24-26].
6</p>
      <p>Conclusions
The following main results were received in this paper:
─ It is proposed to use the functional-structural theory of ergotechnical systems to
ensure the security of information systems.
─ The approach to the use of the specified method by the CISO for the optimal
selection of specific performers from among the employees of the unit is demonstrated
to perform information security tasks depending on the quality indicators of the
work performed by each employee and the available time limit for the duration of
each task, with the goal of maximizing the accuracy of the execution of the
functioning algorithms, depending on the quality indicators of each employee.
─ The possibility of such an optimal solution has been taken into account when one
performer executes several tasks and tasks will not be given to another potential
performer at all.</p>
      <p>Unlike previously used methods, the use of the theory of ergotechnical systems to
ensure the security of information systems allows us to formalize the process of
decision-making by CISO to a greater extent.</p>
      <p>The practical significance is that since the task is reduced to the linear
programming problem, it can be solved within the framework of a wide class of information
technologies and can be quickly included in the CISO’s decision support system in
companies of various types of activities.</p>
      <p>In the future, studies will be conducted on the use of the functional-structural
theory of ergotechnical systems in the development of CISO’s policies, procedures, and
guidelines, for example, to assess risks, identify and analyze incidents.
Proceedings of 2017 2nd International Conference on Advanced Information and
Communication Technologies, AICT 2017, Lviv, 2017, р. 83-87.
14. F. De Felice, A. Petrillo, Methodological Approach for Performing Human Reliability and
Error Analysis in Railway Transportation System, International Journal of Engineering
and Technology, 2011, vol. 3, issue 5, p. 341-353
15. M.G. Grif, O. Sundui, E.B. Tsoy, Methods of designing and modeling of man-machine
systems, Proceedings of International Summer workshop Computer Science, 2014, р. 38-40.
16. E. Lavrov, N. Pasko, A. Krivodub, N. Barchenko, V. Kontsevich, Ergonomics of IT
outsourcing. Development of a mathematical model to distribute functions among operator,
Eastern-European Journal of Enterprise Technologies, 2016, vol. 2, issue 4 (80), p. 32-40.
doi: 10.15587/1729-4061.2016.66021
17. V. Lyubchak, E. Lavrov, N. Pasko, Ergonomic support of man-machine interaction.
Approach to designing of operators’ group activities, International Journal of Bio-Medical
Soft Computing and Human Sciences, 2011, vol. 17, issue 2, р. 53-58.
18. Zaritskiy O., Pavlenko P., Tolbatov A., Data representing and processing in expert
information system of professional activity analysis, Proceedings of the 13th International
Conference on Modern Problems of Radio Engineering, Telecommunications and Computer
Science, TCSET 2016, Lviv-Slavske, 2016, р. 831-833.
19. Zaritskry O., Pavlenko P., Sudic V., Tolbatov A. et al, Theoretical bases, methods and
technologies of development of the professional activity analytical estimation intellectual
systems, Proceedings of 2017 2nd International Conference on Advanced Information and
Communication Technologies, AICT 2017, Lviv, 2017, р. 101-104.
20. Walia Navneet, Harsukhpreet Singh and Anurag Sharma. ANFIS: Adaptive neuro-fuzzy
inference system-a survey, International Journal of Computer Applications 123.13 (2015).
21. S. Gnatyuk, Critical Aviation Information Systems Cybersecurity, Meeting Security
Challenges Through Data Analytics and Decision Support, NATO Science for Peace and
Security Series, D: Information and Communication Security.  IOS Press Ebooks, Vol.47,
№3, рр. 308-316, 2016.
22. S. Gnatyuk, V. Sydorenko, M. Aleksander, Unified data model for defining state critical
information infrastructure in civil aviation, Proceedings of the 2018 IEEE 9th International
Conference on Dependable Systems, Services and Technologies (DESSERT), Kyiv,
Ukraine, May 24-27, 2018, pp. 37-42.
23. Fedushko S. (2020) Adequacy of Personal Medical Profiles Data in Medical Information
Decision-Making Support System. CEUR Workshop Proceedings. – 2020. Vol 2544:
Proceedings of the International Conference on Rural and Elderly Health.
24. Fedushko S., Michal Gregus ml., Ustyianovych T. Medical card data imputation and
patient psychological and behavioral profile construction. The 9th International Conference
on Current and Future Trends of Information and Communication Technologies in
Healthcare (ICTH 2019) November 4-7, 2019, Coimbra, PortugalProcedia Computer
Science. Volume 160, 2019, pp. 354-361.
25. Fedushko S., Trach O., Kunch Z., Turchyn Y., Yarka U. Modelling the Behavior
Classification of Social News Aggregations Users. CEUR Workshop Proceedings. 2019. Vol
2392: Proceedings of the 1st International Workshop on Control, Optimisation and
Analytical Processing of Social Networks (COAPSN-2019). pp. 95–110.
26. Trach O., Fedushko S. (2020) Determination of Measures of Counteraction to the
SocialOriented Risks of Virtual Community Life Cycle Organization. In: Shakhovska N.,
Medykovskyy M. (eds) Advances in Intelligent Systems and Computing IV. CCSIT 2019.
Advances in Intelligent Systems and Computing, vol. 1080. Springer, Cham. pp. 680-695.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Peltier</surname>
          </string-name>
          , Thomas R. Information Security Policies, Procedures, and
          <article-title>Standards: guidelines for effective information security management</article-title>
          ,
          <source>Auerbach Publications</source>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Nazareth</surname>
          </string-name>
          , Derek L., and Jae Choi,
          <article-title>“A system dynamics model for information security management”</article-title>
          ,
          <source>Information &amp; Management 52.1</source>
          (
          <year>2015</year>
          ): pp.
          <fpage>123</fpage>
          -
          <lpage>134</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Safa</surname>
          </string-name>
          , Nader Sohrabi, Rossouw Von Solms, and Steven Furnell. “
          <article-title>Information security policy compliance model in organizations</article-title>
          .
          <source>” Computers &amp; Security</source>
          <volume>56</volume>
          (
          <year>2016</year>
          ):
          <fpage>70</fpage>
          -
          <lpage>82</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Layton</surname>
          </string-name>
          , Timothy P. Information Security:
          <article-title>Design, implementation, measurement, and compliance</article-title>
          .
          <source>Auerbach Publications</source>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Joshi</surname>
          </string-name>
          , Chanchala, and Umesh Kumar Singh.
          <article-title>“Information security risks management framework-A step towards mitigating security risks in university network”</article-title>
          .
          <source>Journal of Information Security and Applications</source>
          <volume>35</volume>
          (
          <year>2017</year>
          ): pp.
          <fpage>128</fpage>
          -
          <lpage>137</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Soomro</surname>
          </string-name>
          , Zahoor Ahmed, Mahmood Hussain Shah, and Javed Ahmed. “
          <article-title>Information security management needs more holistic approach: A literature review”</article-title>
          .
          <source>International Journal of Information Management 36.2</source>
          (
          <year>2016</year>
          ):
          <fpage>215</fpage>
          -
          <lpage>225</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Grudzień</surname>
          </string-name>
          , Łukasz, and Adam Hamrol. “
          <article-title>Information quality in design process documentation of quality management systems”</article-title>
          .
          <source>International Journal of Information Management 36.4</source>
          (
          <year>2016</year>
          ): pp.
          <fpage>599</fpage>
          -
          <lpage>606</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Livshitz</surname>
            , Ilya,
            <given-names>Pavel</given-names>
          </string-name>
          <string-name>
            <surname>Lontsikh</surname>
          </string-name>
          , and Sergey Eliseev. “
          <article-title>The optimization method of the integrated management system security audit”. 2017 20th Conference of Open Innovations Association (FRUCT)</article-title>
          . IEEE,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Jacobs</surname>
          </string-name>
          , Stuart. Engineering information security:
          <article-title>The application of systems engineering concepts to achieve information assurance</article-title>
          . John Wiley &amp; Sons,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Yoon</surname>
            , Junseob, and
            <given-names>Kyungho</given-names>
          </string-name>
          <string-name>
            <surname>Lee</surname>
          </string-name>
          . “
          <article-title>Advanced assessment model for improving effectiveness of information security measurement”</article-title>
          .
          <source>International Journal of Advanced Media and Communication 6</source>
          .1 (
          <issue>2016</issue>
          ), pp.
          <fpage>4</fpage>
          -
          <lpage>19</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Hsu Jack Shih-Chieh</surname>
          </string-name>
          , et al. “
          <article-title>The role of extra-role behaviors and social controls in information security policy effectiveness”</article-title>
          .
          <source>Information Systems Research 26.2</source>
          (
          <year>2015</year>
          ):
          <fpage>282</fpage>
          -
          <lpage>300</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>A.R. Haji Hosseini</surname>
            ,
            <given-names>M.J.</given-names>
          </string-name>
          <string-name>
            <surname>Jafari</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          <string-name>
            <surname>Mehrabi</surname>
            ,
            <given-names>G.H.</given-names>
          </string-name>
          <string-name>
            <surname>Halwani</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>Ahmadi</surname>
          </string-name>
          ,
          <article-title>Factors influencing human errors during work permit issuance by the electric power transmission network operators</article-title>
          ,
          <source>Indian J. Sci.Technol</source>
          ,
          <year>2012</year>
          , vol.
          <volume>5</volume>
          , issue 8, pp.
          <fpage>3169</fpage>
          -
          <lpage>3242</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Lavrov</surname>
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tolbatov</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Pasko</surname>
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tolbatov</surname>
            <given-names>V</given-names>
          </string-name>
          .
          <article-title>Cybersecurity of distributed information systems. The minimization of damage caused by errors of operators during group activity,</article-title>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>