<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Method of Assessing the Influence of Personnel Competence on Institutional Information Security</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Ihor Pilkevych</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleg Boychenko</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nadiia Lobanchykova</string-name>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tetiana Vakaliuk</string-name>
          <email>tetianavakaliuk@gmail.com</email>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Serhiy Semerikov</string-name>
          <email>semerikov@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Institute of Information Technologies and Learning Tools of the NAES of Ukraine</institution>
          ,
          <addr-line>M. Berlynskoho str., 9, Kyiv, 04060</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Korolov Zhytomyr Military Institute</institution>
          ,
          <addr-line>22, Prospect Myru, Zhytomyr, 10004</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Kryvyi Rih National University</institution>
          ,
          <addr-line>Vitalii Matusevych str., 27, Kryvyi Rih, 50027</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Kryvyi Rih State Pedagogical University</institution>
          ,
          <addr-line>54 Gagarin av., Kryvyi Rih, 50086</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff4">
          <label>4</label>
          <institution>Zhytomyr Polytechnic State University</institution>
          ,
          <addr-line>Chudnivska str., 103, Zhytomyr, 10005</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>Modern types of internal threats and methods of counteracting these threats are analyzed. It is established that increasing the competence of the staff of the institution through training (education) is the most effective method of counteracting internal threats to information. A method for assessing the influence of personnel competence on institutional information security is proposed. This method takes into account violator models and information threat models that are designed for a specific institution. The method proposes to assess the competence of the staff of the institution by three components: the level of knowledge, skills, and character traits (personal qualities). It is proposed to assess the level of knowledge based on the results of test tasks of different levels of complexity. Not only the number of correct answers is taken into account, but also the complexity of test tasks. It is proposed to assess the assessment of the level of skills as the ratio of the number of correctly performed practical tasks to the total number of practical tasks. It is assumed that the number of practical tasks, their complexity is determined for each institution by the direction of activity. It is proposed to use a list of character traits for each position to assess the character traits (personal qualities) that a person must have to effectively perform the tasks assigned to him. This list should be developed in each institution. It is proposed to establish a quantitative assessment of the state of information security, defining it as restoring the amount of probability of occurrence of a threat from the relevant employee to the product of the general threat and employees of the institution. An experiment was conducted, the results of which form a particular institution show different values of the level of information security of the institution for different values of the competence of the staff of the institution. It is shown that with the increase of the level of competence of the staff of the institution the state of information security in the institution increases.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Assessment of the level of knowledge</kwd>
        <kwd>competence</kwd>
        <kwd>information threats</kwd>
        <kwd>a model of the internal violator</kwd>
        <kwd>model threats</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>The development of information technology provides society with a great variety of electronic
services. However, at the same time, there are threats to confidentiality, integrity, and availability of
information. Therefore, in recent years, more attention has been paid to the protection of information
in institutions (enterprises): measures are organized and carried out to prevent the loss, modification,
unauthorized access (acquaintance), leakage, recovery of damaged or lost information. Information
security services are also being set up to ensure constant monitoring of the technical condition and
software of the information security system, information security, and actions of the institution's
personnel who are users of the institution's information and telecommunication system (ITS).</p>
      <p>Modern information security systems can effectively counter threats from the outside through the
use of antivirus, firewalls, and other specialized software (SS). However, the disadvantage of such an
SS is the lack of effective solutions to counter internal threats. To protect against internal threats, a
separate SS is used, the effective use of which requires the staff of the Information Security Service
(ISS) to have the appropriate knowledge and skills to operate this type of software.</p>
      <p>The results of the analysis of internal threats for 2019, presented in the annual report of
Cybersecurity Insiders and Gurucul [1], show that the number of insider attacks in 12 months
increased by 68% and only 48% of surveyed institutions are confident in protecting their information
from internal threats. The same report states that to counter internal threats, 49% of institutions have
chosen the tactics of training (education) of ITS users of the institution and the person.</p>
      <p>Therefore, this study is aimed at solving the scientific and practical problem of assessing the
impact of staff competence on the state of information security of the institution.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related works</title>
      <p>The human factor in ensuring the information security of institutions (enterprises) is often ignored.
Thus, the report [2] provides an analysis of information security (IS) risks that arise due to
irresponsibility and low competence of the staff of the institution (enterprise). The author emphasizes
the relevance of the culture of information security, which consists of the observance of the rules of
"digital hygiene" by the staff of the institution.</p>
      <p>In the article [3], the authors investigated cyber hygiene and its role in information security. They
found that those individuals with good cyber hygiene follow best practices for security and protect
their personal information.</p>
      <p>The authors in the scientific work [4] emphasized the need to consider the level of professional
training of employees responsible for IS, as a separate factor influencing the state of IS institution. It
was also suggested to improve the selection of employees at the hiring stage and to take appropriate
measures to improve their professional level (competence) to prevent or minimize unintentional
mistakes.</p>
      <p>In the report [5] the author provides a list of methods for detecting insider attacks. The results of
the analysis of these methods allow us to conclude that to successfully counter insider attacks, ISS
staff must have a high level of professional training and constantly improve it through training in
thematic courses and training on IS.</p>
      <p>In [6], the authors examined the threat management programs used by firms that provide financial
services. These programs began to take into account threats from trusted employees, contractors, and
business partners. One such program is the Guide to Insider Threats [7]. This threat management
program provides a tool for assessing the trust of employees and the organization of information
security in the enterprise.</p>
      <p>Several approaches are used to counter insider attacks. The authors [8] suggest using models that
are using linguistic analysis to determine an employee's risk level of computer-mediated
communication, particularly emails. In [9], the authors suggest using advanced deep learning
techniques, which provide a new paradigm to learn end-to-end models from complex data.</p>
      <p>Another area of countering insider is information security management. According to research
[10], the authors found that numerous activities of management, particularly development and
execution of information security policy, awareness, compliance training, development of effective
enterprise information architecture, IT infrastructure management, business, and IT alignment, and
human resources management, had a significant impact on the quality of management of information
security.</p>
      <p>Institutional IS depends on the competence of the institution's staff. In the article [11] the authors
proposed Competency Model and Instrument for Competency Measurement.</p>
      <p>The report [12] presents the views of the international community on the prospects for the
development of education for cybersecurity professionals. The authors propose to consider the
discipline of cybersecurity as multidisciplinary and provide ways to improve the training of
cybersecurity professionals. A modern view on the construction of a model of competence of a
specialist in the field of information technology is given in [13]. The authors propose to use the
following components of the competency model: personal characteristics, the ability of a person to
perform certain functions, a set of types of behavior, and social roles. The authors in the article [14]
introduce the concept of mathematical competence of future IS specialists. Mathematical competence
is the acquisition of mathematical knowledge and its implementation in the form of professionally
significant skills and abilities. The competence approach with the separation of general and special
competencies is considered in scientific research [15-18]. These studies propose two approaches to
describe competencies: generalization - providing a list of competencies with comments on each
component; structural and functional - a description of the stages, functions of activities with access to
the generalization of information. In [19-20] techniques concerning cyberattacks detection presented
for information security assessment are presented.</p>
      <p>Thus, a large number of scientific papers are devoted to the study of competencies, but the issue of
the impact of staff competence on the information security of the institution (organization) is not
sufficiently studied. The purpose of the article is to develop a method for assessing the impact of staff
competence on the information security of the institution using a structural and functional approach to
the description of staff competencies.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Method of assessing the influence</title>
      <p>institutional information security
of
personnel competence
on</p>
      <p>Competence in this scientific and practical research should be understood as a set of knowledge
and skills, as well as personality traits, the use of which allows the individual to solve a specific
problem. Assessment of the level of knowledge is based on the methods and techniques of modern
Item Response Theory, which provides tools for determining the level of knowledge tested by the
results of test tasks, which are evaluated by some continuous value that takes values from [0… 1].
The relationship between the level of knowledge and the performance of test tasks is determined by
some nonlinear dependence [21 - 24]. It is the assessment of the level of knowledge is a quantitative
indicator of the totality of knowledge and skills of the individual.</p>
      <p>In our opinion, (we think that), the competence of the individual functionally depends on the
knowledge, skills, and personality traits. If we introduce the coefficients of the importance of
knowledge, skills, and personality traits, the competence of the individual will be as follows:</p>
      <p>
        Comp = α1Sca +α 2Sk +α 3Ch (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
where Sca – assessment of the level of knowledge;
Sk – skills assessment;
Ch – assessment of character traits (personal qualities);
α1, α 2 , α 3 – coefficients of the importance of assessment of knowledge, skills, and character traits. In
this case, the condition must be met: α1 +α 2 + α 3 =1.
      </p>
      <p>Assessment of the level of knowledge is obtained by testing. To assess the level of knowledge
tested by the results of test tasks, a mathematical model was used, which defines the following steps:
1. Calculation of the complexity of the test (complexity of the test). The complexity of the test is
characterized by the number of tasks of different levels of complexity and determines the
maximum score that can be obtained by the test subject, provided all the correct answers to the test
tasks:
m
∑ ni ⋅ tci
Ct = i=1
m
where m – the number of levels of difficulty of tasks; ni – number of tasks i -th level of complexity;
i = 1...m ; tci – task complexity, which is calculated by expression:</p>
      <p>m
2. Calculation of the quality of the answer. The quality of the answer is a continuous random
variable distributed on the interval [0… 1], which characterizes the completeness of the correct
answer:</p>
      <p>k −1
where k – the number of options for answers to the test task; i = 1...k .</p>
      <p>3. Calculation of the probability of the correct answer. The probability of the correct answer
depends on m – the number of levels of complexity of the tasks, it is determined by this ratio:
i (5)
m
where m – the number of levels of complexity of the tasks; i = 1...m .</p>
      <p>tci =
m + 1 − i</p>
      <p>.
qai =
k − i</p>
      <p>
        ,
pcai =
(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
(
        <xref ref-type="bibr" rid="ref4">4</xref>
        )
(6)
(9)
4. Calculation of the answer level. The level of the answer Al is a continuous random variable
distributed on the interval [0… 1], which characterizes the completeness of the correct answer
obtained for the problem with the corresponding level of complexity. The level of response does
not take into account the probability of the correct answer to the task and the complexity of the
task. Then the level of the answer Al is calculated by the following expression:
b c
∑ ∑ zi, j
IS = i=1 j=1
b ⋅ c
Ali
      </p>
      <p>=qai,l ⋅ tci, j ,
where i = 1...n ; l = 1...k ; j = 1...m ; n – number of test tasks.</p>
      <p>5. Calculation of the share of correct answers. The share of correct answers Sca is a continuous
random variable distributed on the interval [0… 1], which characterizes the level of knowledge
based on the quality of answers obtained to tasks of different levels of complexity:
n (7)
∑ Ali
Sca = i=1 .</p>
      <p>n</p>
      <p>Assessment of the level of skills is based on the results of a specially developed set of practical
tasks. Assessment of the level of skills is calculated as the number of correctly performed practical
tasks to the total number of practical tasks.</p>
      <p>Assessment of character traits (personal qualities) is based on the results of special psychological
tests. The list of character traits that a person must have to effectively perform the tasks assigned to
him, is developed separately for each position. For each position in the institution, the required list of
character traits Fch consist x s of elements. The importance of each character trait is determined by
x
the weighting factor β i . With ∑ β i = 1. Then the following ratio should be used to calculate the
i=1
assessment of personality traits:</p>
      <p>x (8)
Сh =∑Fchi ⋅ β i .</p>
      <p>i=1</p>
      <p>Under the IS of the institution in this study, we will understand the state of protection of
information of the institution from many threats of information, which is determined by the model of
threats to information of the institution. Dependence of IS on information threats is presented as an
expression:
where zi, j – the probability of occurrence of the i -th threat of information from the set of threats of
information Z from the j -th employee of the institution; b – the number of information threats Z ,
which is determined by the model of information threats of the institution; c – number of employees
of the institution.</p>
      <p>The probability of occurrence of the i -th threat of information from the set of threats of
information from the j -th employee of the institution is influenced by his competence. To find the
quantitative value zi, j , the method of calculating the probability of realization of information threats
from an internal violator was used [25]. This method takes into account the motive of illegal actions
by the internal violator and the assessment of his knowledge about the possibility of realizing the
threats of information of the institution. When using the method of calculating the probability of
realization of information threats from an internal violator in this study, the competence of the internal
violator was used instead of assessing his knowledge. According to the method [25] and taking into
account the above, the expression for calculating the probability of occurrence of the i -th threat of
information from the set of threats to information Z from the j -th employee of the institution:
(10)
zi, j = M j + Ri, j + Comp j − M j ⋅ Ri, j − M j ⋅ Comp j − Ri, j ⋅ Comp j + M j ⋅ Ri, j ⋅ Comp j ,
where M j – the probability of the motive of illegal behavior of the employee of the institution; Ri, j –
the probability of realization of threats by an employee of the institution on the grounds given in the
model of the violator.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Experiment</title>
      <p>Examples are considered to verify the method of assessing the impact of staff competence on the
IS of the institution.</p>
      <p>Example 1. The institution has a list of positions. The results of the assessment of the level of
competence of the staff following the list of positions are shown in table 1.
• r1 – the launch of a fixed set of tasks (programs) that implement pre-provided information
processing functions - reading (viewing);
• r2 – creation, and launch of own programs with new functions of information processing (draft
documents) - modification, deletion, and copying;
• r3 – creation, and launch of own programs with new functions of information processing (valid
documents) - modification, deletion, and copying;
• a1 – place of action of employees of the institution within the controlled area;
• a2 – a place of action of employees of the institution within the regime premises without access
to ITS hardware and software;
• a3 – the place of action of the employees of the institution within the regime premises with
access to ITS hardware and software;
• s1 – the employee has access to the settings of the data transmission channels;
• s2 – the employee uses standard ITS hardware or software;
• s3 – the employee uses additional ITS hardware or software;
• s4 – the employee uses disguise as a registered ITS user.</p>
      <p>Methods and</p>
      <p>The probability of occurrence of a motive for the illegal behavior of an employee of the institution
for all staff of the institution is equal to 0.25.</p>
      <p>Substituting the data from tables 1-4 to expression (9) we obtain a quantitative value of
information security, which is equal to 0.658.</p>
      <p>Example 2. The institution has a list of positions. The results of the assessment of the level of
competence of the staff by the list of positions are shown in table 5.</p>
      <p>The model of the internal violator, the model of information threats, the probability of information
threats from the staff of the institution, and the probability of the motive of misconduct of the
employee of the institution used from example 1. Then obtained a quantitative value of information
security, equal to 0.545.</p>
      <p>Example 3. The institution has a list of positions. The results of the assessment of the level of
competence of the staff by the list of positions are shown in table 6.</p>
      <p>The model of the internal violator, the model of information threats, the probability of information
threats from the staff of the institution, and the probability of the motive of misconduct of the
employee of the institution were used from example 1. Then obtained a quantitative value of
information security, equal to 0.734.</p>
    </sec>
    <sec id="sec-5">
      <title>5. Discussions</title>
      <p>The study yielded the following results:
1. Assessment of the level of knowledge of employees of the institution is carried out by testing
them. The mathematical model, which is used to calculate the level of knowledge of employees of the
institution, takes into account the complexity of test tasks. This model provides an expression for
calculating the complexity of the test in general. The complexity of the test has a direct functional
dependence on the sum of the product of the complexity of the tasks and their number. It is also
proposed to use a mathematical dependence to assess the quality of the answer, which characterizes
the completeness of the answer. The use of a mathematical model for assessing the level of
knowledge of employees allows the developer of test tasks to obtain tests of different levels of
complexity for different positions of the institution.</p>
      <p>2. In each institution to ensure information security, a model of threats to the information of the
institution and a model of the violator (internal and external) are developed. The threat can be realized
with the appropriate probability. To find the quantitative value of the possibility of realizing the threat
of information, the method of calculating the probability of realizing information threats from an
internal violator was used. In this study, using the method of calculating the probability of realization
of information threats from an internal violator, instead of assessing the knowledge of the internal
violator, the competence of employees of the institution was used. To take into account the mutual
influence of the probability of occurrence of events (realization of information threat, acquisition of
appropriate access rights) to calculate the probability of realization of information threat from the set
of information threats from an employee, the theorem on the addition of arbitrary events was applied.</p>
      <p>3. The results of the experiment indicate that with the increase in the level of competence of
employees of the institution, the state of information security in the institution increases. In example
3, where the competence of employees of the institution is the highest, the quantitative value of
information security is equal to 0.734. In example 2, where the competence of employees of the
institution is the lowest, the quantitative value of information security is equal to 0.545. In example 1,
where the competence of employees of the institution is average, the quantitative value of information
security is equal to 0.658. In these examples, only the quantitative values of competence of employees
of the institution were changed. The model of the internal violator, the model of information threats,
the probability of information threats from the employees of the institution, and the probability of the
motive for the illegal behavior of the employee of the institution were the same for all examples. The
conducted experiments confirm that the information security of the institution has a nonlinear
functional dependence on the competence of the employees of the institution.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Conclusions</title>
      <p>The method of assessing the influence of personnel competence on institutional information
security allows obtaining a quantitative value of information security. The proposed method makes it
possible to automate the process of assessing personnel competence through the use of the
mathematical apparatus of modern test theory, systems analysis, and probability theory. The practical
orientation of the study is to use the developed method in the information security service of the
institution to assess the possibility of implementing the appropriate type of threat from the staff of the
institution, taking into account the level of personnel competence. The method of assessing the
influence of personnel competence on institutional information security allows assessing the
information security taking into account the model of the violator, the model of information threats,
which are designed for a particular institution.
7. References</p>
      <p>Vol. 4, Iss. 2 (7) (2016) 262-268.
[5] S. Kovalenko. Insajderska zahroza jak odna z aktualnyx problem kiberbezpeky. Osnovni metody
vyjavlennja Aktualʹni problemy kiberbezpeky : zb. tez dop. Vseukrajinsʹkoji nauk. konf. (Kyjiv,
24 žovtnja 2019 Kyjiv : DUT) 28–32.
[6] J. Eggenschwiler, I. Agrafiotis, J. RC Nurse, Insider threat response and recovery strategies in
financial services firms. Computer Fraud &amp; Security. Vol. 2016, Iss. 11 (2016) 12-19.
[7] W. F. Gross, Insider Threat. Computer and Information Security Handbook. (2017) 529-536.
[8] Faisal Janjua, Asif Masood, Haider Abbas, Imran Rashid, Handling Insider Threat Through</p>
      <p>Supervised Machine Learning Technique. Vol. 177 (2020) 64-71.
[9] Shuhan Yuan, Xintao Wu, Deep Learning for Insider Threat Detection: Review, Challenges and</p>
      <p>Opportunities. Computers &amp; Security (2021) 102221.
[10] Z. A. Soomro, M. H. Shah, J. Ahmed, Information security management needs more holistic
approach: A literature review. Vol. 36, Iss. 2 (2016) 215-225.
[11] J. Funke, A. Fischer &amp; D. V. Holt, Competencies for complexity: problem solving in the twenty-first
century. In Assessment and teaching of 21st century skills, pp. 41-53. Springer, Cham (2018).
[12] A. Parrish, J. Impagliazzo, R. K. Raj, H. Santos, M. R. Asghar, A. Jøsang, T. Pereira, E. Stavrou,
Global perspectives on cybersecurity education for 2030: a case for a meta-discipline. In
Proceedings Companion of the 23rd Annual ACM Conference on Innovation and Technology in
Computer Science Education (ITiCSE 2018 Companion). Association for Computing Machinery,
New York, NY, USA, (2018) 36–54. doi: https://doi.org/10.1145/3293881.3295778.
[13] E. Kashtanova, A. Lobacheva, S. Makushkin, T. Ridho, A Competency Model in the Field of
Information Technology. In: Bogoviz A.V., Suglobov A.E., Maloletko A.N., Kaurova O.V.,
Lobova S.V. (eds) Frontier Information Technology and Systems Research in Cooperative
Economics. Studies in Systems, Decision and Control, vol 316. Springer, Cham (2021)
https://doi.org/10.1007/978-3-030-57831-2_58.
[14] S. Shevchenko, Yu. Zhdanova, Mathematical competencies of future specialists information
security. Suchasniy zahist informatsii. 4 (2016) 90-96.
[15] O. Mandzuk, Qualification requirements to the competence of information analytics-lawyers.</p>
      <p>Scientific notes of Taurida National V. Vernadsky University. Juridical Sciences. 26(68) (2018) 64-72.
[16] V.Buryachok, I.Parhomey, M.Stepanov, V.Tolubko. Problemni pytannja ta aktualʹni zavdannja
pidhotovky faxivciv z kibernetyčnoji bezpeky haluzi znanʹ «Informacijni texnolohiji». Suchasniy
zahist informatsii. 2(2016) 4-9.
[17] M. Bohlouli, N. Mittas, G. Kakarontzas, T. Theodosiou, L. Angelis, M. Fathi, Competence
assessment as an expert system for human resource management: A mathematical approach. Expert
Systems with Applications, vol. 70 (2017) 83-102.
[18] V. Belevitin, S. Bogatenkov, V. Rudnev, M. Khasanova, A. Tyunin, Integrated approach to modeling</p>
      <p>
        IC Competence in students. International Journal of Engineering &amp; Technology, 7(
        <xref ref-type="bibr" rid="ref4">4</xref>
        ) (2018) 60-62.
[19] S. Lysenko, K. Bobrovnikova &amp; O. Savenko, A botnet detection approach based on the clonal
selection algorithm. In 2018 IEEE 9th International Conference on Dependable Systems,
Services and Technologies (DESSERT). IEEE (2018) 424-428.
[20] S. Lysenko, K. Bobrovnikova, S. Matiukh, I. Hurman &amp; O. Savenko, Detection of the botnets'
low-rate DDoS attacks based on self-similarity. International Journal of Electrical &amp; Computer
Engineering, 2020, 10, 2088-8708.
[21] D. Magis, J. R. Barrada, Computerized adaptive testing with R: Recent updates of the package
catR. Journal of Statistical Software, 76(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) (2017) 1-19.
[22] G. Ling, Y. Attali, B. Finn, E. A. Stone, Is a Computerized Adaptive Test More Motivating Than
a Fixed-Item Test? Applied Psychological Measurement, 41(7) (2017) 495–511.
[23] E. D. Heggestad, D. J. Scheaf, G. C. Banks, M. Monroe Hausfeld, S. Tonidandel, E. B. Williams,
Scale Adaptation in Organizational Science Research: A Review and Best-Practice
Recommendations. Journal of Management, 45(6) (2019) 2596–2627.
[24] Van der Linden, W. J. (Ed.), Handbook of item response theory, three volume set. CRC Press (2018).
[25] O.Boychenko, R.Ziubina. The method of calculation of probability of realization of threats of
information with the limited access from an internal user violator. Information systems and
technologies security. 1 (2019) 19–26.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>2020</given-names>
            <surname>Insider Threat</surname>
          </string-name>
          <article-title>Report</article-title>
          . Cybersecurity Insiders, URL: https://www.cybersecurityinsiders.com/wp-content/uploads/2019/11/2020-
          <article-title>Insider-</article-title>
          <string-name>
            <surname>Threat-</surname>
          </string-name>
          Report-Gurucul.pdf
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>N.</given-names>
            <surname>Kuharska</surname>
          </string-name>
          ,
          <article-title>Informacijna bezpeka jak element korporatyvnoji struktury Aktualʹni problemy upravlinnja informacijnoju bezpekoju deržavy: zb. tez nauk</article-title>
          .
          <source>dop. nauk.-prakt. konf. (Kyjiv</source>
          ,
          <article-title>4 kvitnja 2019</article-title>
          .
          <article-title>Kyjiv : Nac. akad</article-title>
          . SBU)
          <fpage>70</fpage>
          -
          <lpage>73</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A. A.</given-names>
            <surname>Cain</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. E.</given-names>
            <surname>Edwards</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. D.</given-names>
            <surname>Still</surname>
          </string-name>
          ,
          <article-title>An exploratory study of cyber hygiene behaviors and knowledge</article-title>
          .
          <source>Journal of Information Security and Applications</source>
          . Vol.
          <volume>42</volume>
          (
          <year>2018</year>
          )
          <fpage>36</fpage>
          -
          <lpage>45</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>S.</given-names>
            <surname>Honchar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Leonenko</surname>
          </string-name>
          ,
          <article-title>Analysis of the factors influencing condition cybersecurity of information system of object of the critical infrastructure</article-title>
          .
          <source>Information Technology and Security.</source>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>