<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>ORCID:</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Determining Key Risks for Modern Distributed Information Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Dmytro Palko</string-name>
          <email>palko.dmytro@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Hrygorii Hnatienko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Tetiana Babenko</string-name>
          <email>babenkot@ua.fm</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii Bigdan</string-name>
          <email>abigdan@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Taras Shevchenko National University of Kyiv 64/13</institution>
          ,
          <addr-line>Volodymyrska Street, Kyiv, 01601</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>1975</year>
      </pub-date>
      <volume>000</volume>
      <fpage>0</fpage>
      <lpage>0002</lpage>
      <abstract>
        <p>This work aims to study the problem of identifying and assessing information security risks in complex, distributed, and scalable information systems, as well as building a profile of key risk factors that can cause potential information security incidents in the physical and functional allocation of resources. As part of this work, a study was carried out of the main information security risks that can be identified at the time of creating and operating a typical distributed information system designed to support information processes and provide information services. The result of the study is the ranking of major risk factors according to their importance and frequency in practice, as well as highlighting the most significant security controls. The data for analysis was compiled based on the results of interviews and questionnaires of information security specialists with different training levels and different focuses in their activities within this knowledge area. The paper presents summarized information on classical approaches to information security risks quantitative, qualitative, and hybrid analysis, as well as the latest methodologies based on solving the problems of intelligent classification and analysis of data on risk factors in the system distribution, and in operation with large data sets.</p>
      </abstract>
      <kwd-group>
        <kwd>Keywords1</kwd>
        <kwd>assessment models</kwd>
        <kwd>Information security risk</kwd>
        <kwd>distributed information systems</kwd>
        <kwd>risk factors</kwd>
        <kwd>security controls</kwd>
        <kwd>risk</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Today, information security management plays a key role in the life processes of almost any
organization that uses modern technologies for collecting, processing, and storing information. This
process is based on the regular assessment of information risks, which allows you to timely identify
new threats and vulnerabilities, implement appropriate measures to neutralize them, and continuously
monitor the state of information security of the system, considering the previous experience and new
factors.</p>
      <p>To prepare for potential attacks and possible problems of this nature, as well as to prevent disruptions
to business processes and operations, damage to reputation, or loss of data, organizations must
constantly assess their risk profile, make recommended corrections, and actively improve their security
system. Threat analysis and risk management are the cornerstones of any security policy. Cybersecurity
risks should be considered as a key factor in the strategic planning of business processes. That is why
it is the responsibility of each company to develop a risk assessment methodology that best suits the
organization's priorities and business goals.</p>
      <p>The importance of risk management as a process in modern reality is undeniable. The modeling and
forecasting information security risks task has been and remains a significant and priority. This issue is
especially relevant in the context of the widespread of complex multi-component information systems</p>
      <p>2020 Copyright for this paper by its authors.
that have a distributed nature and contain a large number of nodes. The total number of computer
systems, active network equipment, and peripherals installed in any infrastructure is growing at a
phenomenal rate. The relative simplicity of networking is a compelling reason to interconnect computer
systems, share functions, and share resources. This approach allows better use of a computing power
vast set that is currently available, but on the other hand, raises some issues primarily related to the
complexity of security and potential risk management. The transition to complex, large-scale, and
structurally complex information systems increases the likelihood of unforeseen and unplanned events
affecting the performance and operability of the system as a whole.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Literature Review and Problem Statement</title>
    </sec>
    <sec id="sec-3">
      <title>2.1. Distributed Information Systems overview</title>
      <p>The widespread introduction of distributed information systems (DIS) today is representative of
almost all areas of human activity, where they are entrusted with solving more and more important
tasks. The efficiency of decision-making and the efficiency of the functioning of many economic,
social, political, and military structures depend on the quality of DIS functioning.</p>
      <p>Distributed information systems are complex technical systems consisting of many structural
elements, functionally combined to provide one or more types of information processes and the
provision of information services. Such systems typically operate under random factors, the presence
of negative influences of various natures, active interaction with the external environment, and the high
cost of impacts of possible violations or malfunctions. All this causes many problems related primarily
to information security. Managing the cybersecurity risk assessment in distributed systems involves
solving a set of problems related to functional distribution and hierarchy, a high degree of resources
parallelization, and a near-complete lack of centralized management.</p>
      <p>
        On the way, there are difficulties to the analysis of heterogeneous data, the need to reconcile
information obtained from different sources, the variability of distributed metrics, which requires a wide
arsenal of tools for analytical processing and intelligent data processing of different nature, the problem
of incomplete information about the components of a distributed system and the complexity of
integrated multifactor analysis in general. There is a need, on the one hand, for a set of methods and
tools that can eliminate these obstacles, and on the other hand, for a new approach to organizing research
on information security risks in a distributed environment and performing comprehensive analytical
processing of distributed data of various natures. Therefore, the implementation of a new approach to
managing risk assessment in DIS involves the introduction of a comprehensive solution that integrates
data obtained from different sources and a wide range of tools for their analysis [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>Several international organizations and leading universities are engaged in research on this issue.
The key standards in this area that need to be relied on are ISO / IEC 27001: 2013, NIST SP 800-30,
and BS 7799-3: 2017. However, despite significant achievements, there is currently no single system
vision of all aspects of the problem, the nature, and features of research tools, and its place in the process
of multifactor risk analysis of a distributed system, considering the entire complex of interrelations and
mutual influence of the processes associated with it. The different degree of depth of elaboration of
certain aspects of this problem has led to the need for effective models and methods of reconciliation
and analytical processing of heterogeneous data for rapid analysis of the current state of information
security of a distributed system.
2.2.</p>
    </sec>
    <sec id="sec-4">
      <title>Risk Management Process in Distributed Information Systems</title>
      <p>Information security risk assessment is an extremely important part of a company's data protection
strategy. It is conducted out to support decision-making and immediate response to identified threats
(risk response).</p>
      <p>
        Information security risk analysis allows you to determine the necessary and sufficient set of
information security tools, regulatory and organizational mechanisms to reduce information security
risks, allowing to ensure the process of building the most effective information security management
system architecture for a given organization [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        Risk management is an iterative process of identifying, quantifying, analyzing, and managing the
risks faced by an organization [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. Risk management is designed to ensure a stable operation of the
information system and minimize possible losses in the event of information security threats. As an
integral part of management practice, risk management should be carried out regularly to support
organizational improvements, improve existing security tools and mechanisms, improve efficiency and
make management decisions [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. The main risks are those risks that have a high likelihood of occurrence
and, if implemented, provide the possibility of a significant impact on operational performance,
achievement of the goals and objectives of the project, or may damage reputation [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>In terms of systemic distribution, risk management should provide for a complex nature, and
consider the risk assessment for each asset or subsystem.</p>
      <p>The specificity of the architecture of distributed information systems involves the analysis of data,
largely differentiated in their structure, and the use of all available tools of assessment methods (both
quantitative and qualitative) that characterize various components of the studied environment. The poor
structure of the tasks of such research resulted from the lack of formal models and obtaining objective
measurements results together with subjective expert assessments.</p>
      <p>Thus, the risk management process in distributed information systems is a sophisticated and rather
integrated task.</p>
      <p>The study of risk factors in a distributed environment deserves special attention.</p>
      <p>
        According to ISACA's annual STATE OF ENTERPRISE RISK MANAGEMENT 2020 survey [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ],
the biggest challenges in corporate risk are factors related to the emergence of new threats,
changes/advances in technology development, as well as weak human resources and lack of necessary
skills and experience of specialists and existing cybersecurity teams (Figure 1).
      </p>
      <p>On the other hand, according to this study, the most frequently used control to prevent/mitigate
potential security concerns is to raise awareness and conduct training on cybersecurity among staff
(Figure 2).</p>
      <p>
        Eighty percent of enterprise respondents provide awareness-raising training, 68 percent use
disaster/incident recovery strategies, and 67 percent use general information security control and
management. Less than half of the responding businesses use insurance as a mitigation control; at the
same time, the largest supporters of this approach are companies in North America and Africa [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
2.3.
      </p>
    </sec>
    <sec id="sec-5">
      <title>Main Approaches to Risk Assessment</title>
      <p>There are many different methods for analyzing information risks for distributed systems. Their
main differences are the approaches and the scales being used for assessing the risk level: quantitative
or qualitative.</p>
      <p>Conventionally, among the methods of risk assessment, the following three groups can be
distinguished:
1. Statistical methods
2. Methods of expert assessments
3. Modeling methods</p>
    </sec>
    <sec id="sec-6">
      <title>2.3.1. Statistical Risk Assessment Methods</title>
      <p>To assess the information security risks, a qualitative, quantitative, or combined approach can be
used.</p>
      <p>In quantitative methods, the risk is assessed in the form of numerical values. Accumulated statistical
information on incidents and violations, as well as meta-information about the current state and
configuration of the node components of the distributed system, are usually used as input data for the
assessment. However, the frequent lack of sufficient statistics leads to a decrease in the adequacy of the
assessment results. Other limitations are complexity, high labor intensity, and long execution time,
especially in the terms of the analysis of distributed systems. The advantages of the quantitative
approach include the accuracy of risk assessment, clarity of results, and the ability to compare the risk
value, expressed in financial equivalent with the investment amount required to respond to this risk.</p>
      <p>
        Qualitative methods are more common, but they use too simplified scales, usually containing three
levels of risk assessment (high, medium, low). The assessment is based on expert surveys, and
promising intellectual methods are still insufficiently applied. Other disadvantages are the lack of
visibility and complexity of using the results of risk analysis for economic justification and assessing
the feasibility of investing in risk response measures. The advantage of a qualitative approach is its
simplicity and minimization of the time and labor costs for conducting a risk assessment [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>The combined approach involves a combination of both methods to apply the benefits of each.</p>
      <p>
        According to "The Marsh Microsoft 2019 Global Cyber Risk Perception Survey" (September 2019),
the popularity of a quantitative approach to assessing information security risks has increased
significantly compared to 2017, but it remains low (Figure 3) [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>Thus, today most companies use a qualitative scale to assess information security risks.</p>
    </sec>
    <sec id="sec-7">
      <title>2.3.2. Statistical Risk Assessment Methods</title>
      <p>If it is impossible to use statistical methods for analyzing the risks of a distributed system (lack of
information on risk factors, insufficient data sampling size, complexity and sophistication of
infrastructure, etc.), you should refer to expert assessment methods. The essence of the method of expert
assessments is to conduct an expert analysis of the problem using qualitative and quantitative
assessment of hypotheses and further processing of the results. This method is simple and accessible
for practical application but requires a significant level of competence and extensive practical
experience from the expert.</p>
      <p>When using expert methods, the risk level is assessed based on the analysis of the probability of an
adverse event occurring by studying and assessing the factors affecting it. Thus, the practical application
of this method is to establish a list of factors that determine a particular type of risk, as well as to
determine the relationship between the nature of the factor and the risk level that this factor causes.</p>
      <p>
        For the objectivity and impartiality of the results, the work on identifying and assessing information
security risks should be carried out by special experts or relevant expert groups who have the necessary
experience and training on this matter issue [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
    </sec>
    <sec id="sec-8">
      <title>2.3.3. Modeling Methods</title>
      <p>
        The most effective methods for analyzing information security risks in distributed systems are
modeling methods [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], among which there are neural networks that can identify and adequately assess
information security risk relying on data mining tools. The need to extract unknown, non-trivial,
practical, and useful knowledge from the "raw" metadata about the operation of a distributed system,
which can be interpreted in a certain way and used to make decisions about the risk level, gives this
problem a non-trivial interpretation.
      </p>
      <p>Artificial Intelligence (AI) is not a new concept, but only in recent years, various companies have
begun to explore and understand its full potential. Intelligent systems play an increasingly important
role in network management. Most research in intrusion detection and risk assessment systems heavily
relies on AI techniques to design, implement, and improve security monitoring systems.</p>
      <p>Recent malware updates and improvements in cyberattacks are difficult to detect with traditional
cybersecurity techniques. An important advantage of neural networks is their ability to "learn" the
characteristics of the input data and identify elements that are not similar to those previously observed
in the system. New AI algorithms use machine learning to quickly adapt and analyze new data, improve
results and identify new vectors of risk implementation.</p>
      <p>Most modern methods of attack detection and risk assessment leverage some form of rule-based
analysis or a statistical approach. The analysis relies on a set of predefined rules created by the
administrator or by the security system itself.</p>
      <p>
        Unlike expert systems, which can give the user a definite answer about the compliance of the
considered characteristics embedded in the knowledge base rules, the neural network analyzes the
information and provides an opportunity to assess, reconcile the data with the characteristics it is trained
to recognize [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>Thus, forecasting and modeling the level of risk, coordination, and intelligent processing of various
nature data about risk factors and creating based on their analysis a comprehensive approach to risk
assessment in distributed information systems is a priority research area today.</p>
    </sec>
    <sec id="sec-9">
      <title>3. The Research Methodology</title>
      <p>The purpose of this study is to highlight the key risk factors inherent in modern distributed
information systems, analyze the most significant security controls for development based on their
recommendations to eliminate potential threats.
3.1.</p>
    </sec>
    <sec id="sec-10">
      <title>The Data Collection Process for Analysis</title>
      <p>A questionnaire method was used to collect a sample of test data for analysis. The respondents were
several dozen information security engineers of various training levels, penetration testing and auditing
specialists, and leading specialists in the field of information security project management. All
interviewees were selected selectively and have experience in providing security for information system
infrastructures of various sizes and scales.</p>
      <p>The study involved two data collection processes for analysis. The first is a pilot survey to test the
research instruments and adjust the questions, the second is a mass survey of the target group using the
final version of the questionnaires.</p>
      <p>The pilot study was performed before the main questionnaire and aimed to test whether the proposed
model of the questionnaire is suitable for the analysis of the final metrics.
23 specialists (Table 1) were involved in the main survey. Age of survey participants from 24 to 47
years, with an average of 34.2.
3.2.</p>
    </sec>
    <sec id="sec-11">
      <title>Questionnaire Development</title>
      <p>The development of questionnaires considers the most common risk factors that are common to most
modern distributed infrastructures. The questionnaire included 40 questions on the main risk factors
and 14 questions on the practice of applying security controls in real projects. These indicators were
identified at the stage of analysis of literature sources in this subject area and during the pilot survey.
The respondents were asked to answer these questions anonymously and subjectively, relying on their
own experience and the real practice of working with distributed information systems.</p>
      <p>IBM SPSS Statistics software toolkit was used for data analysis and modeling as it is widely used
for statistical analysis by market researchers, health researchers, survey companies, government,
education researchers, marketing organizations, data miners, and others. The research findings are
analyzed and discussed in the following sections.</p>
      <p>The share of female respondents among the interviewers is only 26 percent.
3.3.</p>
    </sec>
    <sec id="sec-12">
      <title>Research Criteria and Analysis of the Test Sample</title>
      <p>The respondents were asked various questions that used scales from 1 to 5. To increase efficiency
and narrow the gradation of possible results for assessing risk factors at work, a 5-point scale was
chosen, in which the indicator “does not matter” is equal to one, and “extremely important” is equal to
five. Likewise, there are five categories for assessing security controls so that the “never” indicator is
one and the “always” indicator is five. Thus, all questions about risk factors in distributed systems were
measured on a five-point Likert scale from “nonsignificant” to “most important”, and all security
controls – from "never" to “always”. The Likert scale is quite easy to build, it provides relative reliability
even with a small number of judgments, and the data obtained is easy to process. The selection of
judgments for the scale was carried out based on an analysis of literary sources in a given subject area
and during pilot research by the method of selection from an initial list of judgments with the most
discriminatory ability to the measured attitude. For this purpose, an initial list of statements was created
(Table 2) that were offered to respondents from a group representative of the target audience
(participants in the pilot study).
2 With a background in the field of cybersecurity
№
1.
2.
3.
4.
5.
6.
7.
8.
9.
10.</p>
      <p>11.</p>
      <p>When working with the scale, the respondents rated the degree of their agreement or disagreement
with each of the proposed judgments, from “completely agree” to “completely disagree”.
3.4.</p>
    </sec>
    <sec id="sec-13">
      <title>Key Risk Factors</title>
      <p>The study demonstrates 40 main risk factors in modern distributed information systems (Appendix
1, Table A1), labeled from Factor_1 to Factor_40, which are quite common in the relevant literature,
are often found in practice, and are widely used by researchers and experts in cybersecurity when
studying risk factors and conducting risk management measures. These factors should be identified in
the process of assessing and managing information security risks and monitored in the future.</p>
      <p>Separately, the risks caused by a human factor should be highlighted. They include not only
employee mistakes, but also intentional actions that lead to violating information confidentiality.</p>
      <p>Referring to the NIST SP 800-37 Risk Management Framework, should not forget about such
categories shown in Table 3.</p>
      <p>Category
Financial risks</p>
      <p>Legal risks
Business risks
Political risks</p>
      <p>Software risks
Risks of non-compliance with legislation</p>
      <p>Security and confidentiality risks</p>
      <p>Project risks
Reputational risks</p>
      <p>Risks of life safety</p>
      <p>Risks of strategic planning</p>
      <p>
        They were not considered in this study, however, constitute an important part of any risk
management process [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
3.5.
      </p>
    </sec>
    <sec id="sec-14">
      <title>Key Security Controls and Risk Management Measures</title>
      <p>
        As a result of the analysis of the above statistical data, the expert group proposed possible categories
of actions to minimize information security risks, including organizational and legal protection of
information, engineering, hardware and software protection, cryptographic mechanisms for protecting
information [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], as well as institutional arrangements and physical protection measures.
      </p>
      <p>
        As effective controls to ensure the security of distributed systems by trained full-time specialists or
with the help of information security outsourcing, the following solutions (both separately and in
aggregate) can be implemented, shown in Table 4. The ISO 27001 standard and its Appendix A are
important tools for information security management [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and it was a ground for developing
questionnaires on possible control and risk management measures. It contains a list of security measures
that must be applied to improve information security and consists of 114 security controls, divided into
14 chapters. Not all of these controls are mandatory for implementation – the company can choose on
its own, it considers the controls applicable in the given circumstances and depending on the business
direction, infrastructure state, or the existing profile of external threats, and then implement them
(usually at least 90 % controls). A more detailed description of each control in Appendix A with an
explanation of how it should be applied is presented in the ISO 27002 standard. However, the latter
does not provide any explanations and tips on how to choose control in a given situation, which controls
to implement, how to measure them and how to distribute duties [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>
        Separately, it should be noted the international standard ISO/IEC 27005: 2018 “Information
technology – Security techniques – Information security risk management”, which contains
recommendations for information security risk management. This document supports the general
concepts defined in ISO/IEC 27001 and is intended to guide the implementation of information security
measures based on a risk-based approach [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. In the study, it was proposed to evaluate 14 main groups
(Appendix 1, Table 6) of information security controls of modern distributed information systems in
terms of frequency and effectiveness of their use, labeled from Control_1 to Control_14.
      </p>
      <p>Thus, the proposed options cover the entire range of the most common risk management mechanisms
and measures used in modern distributed systems.</p>
    </sec>
    <sec id="sec-15">
      <title>4. Results and Discussion</title>
    </sec>
    <sec id="sec-16">
      <title>4.1. The Importance of Risk Factors in Lifecycle of Modern Distributed</title>
    </sec>
    <sec id="sec-17">
      <title>Information Systems</title>
      <p>Table 7 (Appendix 1) shows that nearly all respondents ranked factors related to lack of
cybersecurity policy, lack of protection mechanisms against network attacks, violations of
authentication and session management, violations of access control, and use of components with
known vulnerabilities as the most important.</p>
      <p>The uncorrected sample standard deviation S is calculated (1) for four groups of factors, each of
which contains 10 of them
where {x1, x2, …, xn} are the mean values of the sample items, n = 10 – the size of the sample (number
of factors in each group: Factor_1 – Factor_10, Factor_11 – Factor_20, Factor_21 – Factor_30,
Factor_31 – Factor40), and  ̃ – the mean value of this assessment (2)
 = √ ∑
and summarization of the survey responses gave the following rating of the importance of the listed
risks (in order of importance): Factor_20, Factor_6, Factor_10, Factor_11, Factor_12, Factor_14,
Factor_8, Factor_9, Factor_4, Factor_3, Factor_13, Factor_17, Factor_18, Factor_1, Factor_15,
Factor_15 , Factor_5, Factor_7, Factor_16.</p>
      <p>Among organizational factors, the risks associated with the lack of cybersecurity and anti-virus
protection policies are the most important. The ranking of the importance of risks in this category (in
order of importance): Factor_21, Factor_27, Factor_30, Factor_28, Factor_29, Factor_25, Factor_23,
Factor_24, Factor_22, Factor_26.</p>
      <p>In addition, all respondents noted that the risk of abuse of privileges is the highest risk factor and
very important among the factors associated with the human factor. Risk severity rating for this category
(in order of importance): Factor_33, Factor_40, Factor_35, Factor_37, Factor_38, Factor_36,
Factor_34, Factor_31, Factor_32, Factor_39.</p>
      <p>In summary, the categories of risk factors can be ranked in order of importance and criticality as
follows: logical, physical, human factors, and organizational factors.
survey of experienced cybersecurity managers and engineers.
(2)</p>
    </sec>
    <sec id="sec-18">
      <title>Frequency of Controls Occurrence</title>
      <p>this study show that most security controls are used frequently and are important mechanisms to prevent
and minimize potential risks.</p>
    </sec>
    <sec id="sec-19">
      <title>Construct Validity (Risk Factors Correlation)</title>
      <p>The next step was to test the hypothesis about relationships between key risk factors using
correlation coefficients.</p>
      <p>The correlation coefficient is a statistical indicator of the probability of a relationship between two
variables, measured on a quantitative scale, which allows you to answer the question of the degree and
direction of the relationship between the values of these variables.</p>
      <p>To choose the right method of correlation research, it is necessary to answer the question of whether
the studied factors are normally distributed. Frequency histograms for key risk factors are presented in
Appendix 2. An example of a histogram for factor Fact_21 is shown in the Figure 4.
That is,
 0: 
=  0,  1: 
≠  0,
(3)
where P is the distribution of our sample and P0 is a normal distribution.</p>
      <p>Even though the plotted frequency histograms at first glance are quite symmetric and are well
described by the parabolic curve for both tests, significance values less than .05 which means that the
data do not have a normal distribution (Figure 5). So, the null hypothesis that the data is normally
distributed was rejected.
 .01 &lt; p ≤ .05 – low statistical significance (one star – *),
 .001 &lt; p ≤ .01 – the average strength of statistical significance (two stars – **),
 p ≤ .001 – high statistical significance (three stars – ***).</p>
      <p>Table 10 (Appendix 1) illustrates the relationship between key factors.</p>
      <p>The correlation analysis revealed a moderate negative relationship of medium statistical significance
between factors Factor_20 and Factor_8 – r-Spearman =-0.528 at p ≤ .01, as well as a moderate
negative relationship of low statistical significance between factors Factor_14 and Factor_8 –
r-Spearman =-0.415 at p ≤ .05.</p>
      <p>Analyzing the results of correlation analysis, we can conclude that among the studied risk factors
there is a moderate positive relationship of low statistical significance for the correlation of variables
Factor_10 and Factor_11 – r-Spearman = 0.423 at p ≤ .05.</p>
      <p>Thus, the obtained results indicate that risk factors are often interrelated and have complex impacts,
and therefore require a comprehensive and multidisciplinary analysis, considering all possible factors
and conditions.</p>
    </sec>
    <sec id="sec-20">
      <title>5. Conclusions</title>
      <p>Thus, this paper investigates the problem of identifying and assessing information security risks in
complex, distributed, and large-scale information systems, and also builds a profile of key risk factors
that can cause potential information security incidents in the physical and functional allocation of
resources. The study examines the main risks of information security that can be identified during the
construction and operation of a typical distributed information system designed to provide one or more
types of information processes and provisioning information services. The result was a ranking of the
main risk factors according to their importance and frequency in practice, as well as highlighting the
most significant security controls.</p>
      <p>Thus, the results of the study show that all risk factors in the life cycle of a modern distributed system
are very important and require detailed analysis and consideration when building a profile of potential
threats and assessing information security risks. The importance rating of the risk factors categories by
nature can be given as follows (in order of importance): technological factors (logical and physical),
human factors, organizational factors.</p>
      <p>In particular, the study identified ten main risk factors for distributed information systems, which
can be displayed as follows (in order of importance and criticality of potential consequences):
Factor_21, Factor_20, Factor_6, Factor_10, Factor_11, Factor_12, Factor_33, Factor_27, Factor_14,
Factor_8. Nearly all respondents ranked factors related to lack of cybersecurity policy, lack of
protection mechanisms against network attacks, violations of authentication and session management,
violations of access control, and use of components with known vulnerabilities as the most important.
These factors should be identified in the process of assessing and managing information security risks
and monitored in the future.</p>
      <p>Analysis of the most common categories of risk management mechanisms and measures used in
modern distributed systems has shown that most protection controls are used frequently and are
important mechanisms for preventing and minimizing potential risks. The generalization of the survey
responses, according to the main groups of information security controls of modern distributed
information systems in terms of frequency and effectiveness of their use, showed that most of the
respondents identified controls responsible for the proper and effective use of cryptography and public
key infrastructure, logical and physical access control, operational security and compliance with
information security policies as important and most common in practice.</p>
      <p>The results of the study can be used by managers and information security engineers to assess the
importance and probability of potential risks and further prevent and minimize their consequences, as
well as build tools for identifying and analyzing the risks of distributed systems based on qualitative,
quantitative and intelligent methods.</p>
    </sec>
    <sec id="sec-21">
      <title>6. References</title>
    </sec>
    <sec id="sec-22">
      <title>7. Appendix</title>
    </sec>
    <sec id="sec-23">
      <title>Appendix 1. Tables data</title>
      <p>Table A1
Top Security Risks Factors of Modern Distributed Information Systems Based on Researchers
1 2 3
Category № Risk factors</p>
      <p>Factor_1
Factor_2</p>
      <p>Factor_3
)re Factor_4
aw Factor_5
fto Factor_6
l(s Factor_7
ica Factor_8
g
o
L</p>
      <p>Insecure applications use
Inadequate patch management
API vulnerabilities and breaches
Technical flaws and errors during system design
Insufficient logging and monitoring
Broken authentication and session management
Unapproved third-party software use
Use of unlicensed software solutions with undeclared
capabilities
0-day vulnerabilities and errors associated with the
development of information technology
Broken access control3
Using outdated hardware and components with known
vulnerabilities
Servers and network appliances security misconfiguration
Low reliability of the set of hardware and software
components, lack of a recovery plan, and periodic backups
Weak endpoints and network perimeter protection
Unmanaged IoT and mobile devices
The imperfection of the organizational structure of the
information security, the need for frequent reconfiguration of
the information security or its individual parts
The possibility of information leakage and sensitive data
exposure using technical channels
Insufficient physical access control
Unauthorized use of the organization's assets
Lack of protection mechanisms against external network
attacks
Lack of a cybersecurity policy
Non-compliance with the requirements of standards at the
stage of design of the system
Non-compliance with information security requirements
during system exploitation
Lack of control over information security incidents
Lack of top management commitment support and
involvement</p>
      <p>Lack of security audits
)
re Factor_14
a
w Factor_15
d
ra Factor_16
h
(
l
a
c
i
s
yh Factor_17
P</p>
      <p>Factor_18
Factor_19
Factor_20
Factor_21
Factor_22
Factor_23
Factor_24
Factor_25</p>
      <p>Factor_26
3 Lack of differentiation of user rights and controlled area access
Factor_31
Factor_32
Factor_33
Factor_34
Factor_35
Factor_36
Factor_37
Factor_38
Factor_39
Factor_40
3
Lack of antivirus protection policy
Weak potential to apply existing protection technologies
Inconsistencies between the infrastructure and the adopted
security measures
The inability to provide the proper level of support and
comprehensive development of security systems
Actions of unreliable employees
Unintentional mistakes of service personnel
Privilege abuse
The essential list of persons with access to protected
information
Lack of personnel awareness (especially about phishing/social
engineering)
Lack of information security training
A severe shortage of cybersecurity professionals
Insufficient passwords hygiene
Personnel access to potentially dangerous objects in the
external network</p>
      <p>Data loss or theft controls lack
3</p>
      <p>Description
controls responsible for implementing and verifying
compliance with information security policies
controls responsible for the organizational component
of information security measures and the distribution
of responsibilities; creation of a management system
for initiating and monitoring the implementation and
operation of information security in the organization
Personnel and controls designed to regulate the work of personnel
human resources and contractors, identifying their responsibilities for
security information security both at the stage of the working
process and upon dismissal
Asset management controls related to the inventory of company assets,
classification of processed information, and media
management
Logical access controls responsible for restricting access to
control information and information processing facilities,
access control policy, rights management for
authorized users to systems and applications
Table A2 (continued)
1 2 3
Control_6 Cryptography controls responsible for the proper and effective use of
cryptography and public key infrastructure (PKI) to
protect the confidentiality, reliability, and integrity of
information
Control_7 Physical and controls related to the management and prevention of
environmental unauthorized physical access, loss, damage, theft or
security compromise of assets and interruption of the
organization's activities, as well as the definition of
safe zones, entry controls, equipment security, “clear
desk” and “clear screen” policies
Control_8 Operational a set of controls for ensuring the correct and secure
security work of processing information means that combines
such activity as change management, backup,
monitoring, logging and activity logs management,
tracking the installed software and detecting malicious
software, monitoring and eliminating identified
vulnerabilities
Control_9 Communications controls related to network security, network services,
security information transmission, and messaging
Control_10 System acquisition, controls that define security requirements and
development, and protection mechanisms in development and support
maintenance processes
Control_11 Supplier controls regarding relationships with third parties and
relationships contractors, protecting the organization's valuable
assets that are available to them and ensuring an
agreed level of information security and service
delivery under agreements with suppliers
Control_12 Information controls related to incident management, events, and
security incident information security vulnerabilities, reporting on
management identified violations, defining responsibilities, response
procedures, and collecting evidence
Control_13 Information controls that are necessary to ensure business
security aspects of continuity planning, verification and ongoing audit
business continuity procedures, the availability of resources and
management information processing facilities, the use of resiliency
and reliability principles to ensure security
Control_14 Compliance controls that require compliance with legal and
contractual requirements to avoid breaches of
statutory, regulatory, or contractual obligations related
to information security, procedures for protecting
intellectual property, personal data, and assessing
information security at all stages of the life cycle
Table A4
Testing the Hypothesis about the Relationship between Variables Using Spearman's Correlation
Coefficient</p>
    </sec>
    <sec id="sec-24">
      <title>Appendix 2. Frequency histograms for key risk factors</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Andrew</surname>
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Tanenbaum</surname>
          </string-name>
          ,
          <source>Maarten Van Steen Distributed Systems: Principles and Paradigms</source>
          ,
          <source>Prentice Hall of India; 2nd edition (January</source>
          <volume>1</volume>
          ,
          <year>2007</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Henry</surname>
            <given-names>K.</given-names>
          </string-name>
          <article-title>Risk management and analysis</article-title>
          / Kevin Henry // Information Security Management Handbook / Edited by Harold F. Tipton,
          <string-name>
            <given-names>Micki</given-names>
            <surname>Krauze</surname>
          </string-name>
          . - 6th
          <string-name>
            <surname>edition</surname>
          </string-name>
          . - Boca
          <string-name>
            <surname>Raton</surname>
          </string-name>
          : Auerbach Publications,
          <year>2017</year>
          .
          <article-title>- Part 1, Section 1</article-title>
          .4,
          <string-name>
            <surname>Ch</surname>
          </string-name>
          .
          <volume>28</volume>
          . - P.
          <fpage>321</fpage>
          -
          <lpage>329</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Medvedeva</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          <article-title>Organizatsyia integrirovannogo riskmenedzhmenta v organizatsyi // Vestnik nauki i obrazovaniya</article-title>
          .
          <year>2020</year>
          . №
          <fpage>24</fpage>
          -
          <lpage>4</lpage>
          (
          <issue>78</issue>
          ). P.
          <volume>23</volume>
          -
          <fpage>26</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Kanatov</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Expert systems for information security management and audit</article-title>
          . Implementation phase issues / M. Kanatov,
          <string-name>
            <given-names>L.</given-names>
            <surname>Atymtayeva</surname>
          </string-name>
          , B. Yagaliyeva //
          <source>2014 Joint 7th International Conference on Soft Computing and Intelligent Systems (SCIS) and 15th International Symposium on Advanced Intelligent Systems (ISIS)</source>
          .
          <article-title>- 2014</article-title>
          . doi:
          <volume>10</volume>
          .1109/scis-isis.
          <year>2014</year>
          .7044702
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Trofymova</surname>
            <given-names>N.</given-names>
          </string-name>
          <article-title>Sovremennye tendentsyi korporativnogo risk-menedzhmenta v sisteme obespecheniya ekonomicheskoi ustoichivosti promyshlennykh predpriyatiy /</article-title>
          / UPRAVLENIE T.
          <volume>8</volume>
          №
          <issue>2</issue>
          / 2020. Mezhotraslevoi menedzhment. P.
          <volume>30</volume>
          -
          <fpage>38</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6] State of Enterprise Risk Management 2020 Survey // ISACA,
          <string-name>
            <given-names>CMMI</given-names>
            <surname>Institute</surname>
          </string-name>
          .
          <article-title>-</article-title>
          <year>2019</year>
          . - https://www.isaca.org/-/media/info/state
          <article-title>-of-enterprise-risk-management-survey/index</article-title>
          .html
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Rot</surname>
            <given-names>A.</given-names>
          </string-name>
          <string-name>
            <surname>IT Risk</surname>
          </string-name>
          <article-title>Assessment: Quantitative and Qualitative Approach //</article-title>
          <source>Proceedings of the World Congress on Engineering and Computer Science</source>
          ,
          <year>2008</year>
          . - p.
          <fpage>1073</fpage>
          -
          <lpage>1078</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>2019</given-names>
            <surname>Global Cyber Risk</surname>
          </string-name>
          Perception Survey // Marsh, Microsoft. -
          <year>2019</year>
          . - https://www.microsoft.com/security/blog/wp-content/uploads/2019/ 09/
          <string-name>
            <surname>Marsh-Microsoft-</surname>
          </string-name>
          2019
          <string-name>
            <surname>- Global-Cyber-Risk-</surname>
          </string-name>
          Perception-Survey.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Konev</surname>
            <given-names>I.</given-names>
          </string-name>
          <article-title>Informatsyonnaya bezopasnost predpriyatiya</article-title>
          . / I. Konev,
          <string-name>
            <surname>A</surname>
          </string-name>
          . Beliaev - SPb.: BKhVPeterburg,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Chang</surname>
          </string-name>
          , L.-Y.
          <article-title>Applying fuzzy expert system to information security risk Assessment - A case study on an attendance system</article-title>
          [Text] / L.-
          <string-name>
            <given-names>Y.</given-names>
            <surname>Chang</surname>
          </string-name>
          ,
          <string-name>
            <surname>Z.-J</surname>
          </string-name>
          . Lee // 2013 International Conference on
          <source>Fuzzy Theory and Its Applications (iFUZZY)</source>
          .
          <article-title>- 2013</article-title>
          . doi:
          <volume>10</volume>
          .1109/ifuzzy.
          <year>2013</year>
          .6825462
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Xin</surname>
            <given-names>Y.</given-names>
          </string-name>
          et al.
          <article-title>Machine learning and deep learning methods for cybersecurity /</article-title>
          /IEEE access.
          <source>- 2018</source>
          . - Vol.
          <volume>6</volume>
          . - P.
          <fpage>35365</fpage>
          -
          <lpage>35381</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          <source>[12] NIST Special Publication 800-30 Rev A. Risk Management Guide for Information Technology Systems</source>
          , Gary Stoneburner, Alice Goguen, and Alexis Feringa,
          <year>July 2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Palko</surname>
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Myrutenko</surname>
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Babenko</surname>
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bigdan</surname>
            <given-names>A.</given-names>
          </string-name>
          :
          <source>Model of Information Security Critical Incident Risk Assessment</source>
          .
          <source>2020 IEEE International Conference on Problems of Infocommunications Science and Technology, PIC S and T</source>
          <year>2020</year>
          ,
          <year>2021</year>
          , pp.
          <fpage>157</fpage>
          -
          <lpage>161</lpage>
          ,
          <fpage>9468107</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14] ISO/IEC 27001:
          <year>2013</year>
          . Information technology -
          <source>Security techniques - Information security management systems - Requirements</source>
          .
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15] ISO/IEC 27002:
          <year>2013</year>
          .
          <article-title>Information technology - Security techniques - Code of practice for information security controls</article-title>
          .
          <source>2013</source>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16] ISO/IEC 27005:
          <year>2011</year>
          .
          <article-title>Information technology - Security techniques - Information security risk management</article-title>
          .
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>