<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Multisociometrical Readiness Characteristics in Information Security Management</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Anastasiya Arkhipova</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Novosibirsk State Technical University, 20 Prospekt K. Marksa</institution>
          ,
          <addr-line>Novosibirsk, 630073</addr-line>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <fpage>25</fpage>
      <lpage>34</lpage>
      <abstract>
        <p>The article discusses the characteristics of Information security management. Information security management system represents as a part of a general management system in organizations. The main tasks that are solved during the information security management and audit of information objects, information security management are formulated. The article considers information security risks from personnel constitute as a separate group of information security risks of the organization with a specific set of causes and conditions for their implementation. The article describes the hypothesis of multisociometrical readiness characteristics construct in Information Security Management as a specific educational component. Thus component, firstly, is an indicator of the readiness of applicants as the most important factor affecting the formation of the competence of a student at the university, secondly, is an indicator of the readiness of a graduate of the university for professional activities, and thirdly, is an indicator of the professionalism of an information security specialist, which is the resulting component of educational activities.</p>
      </abstract>
      <kwd-group>
        <kwd>1 education</kwd>
        <kwd>information security management</kwd>
        <kwd>information security</kwd>
        <kwd>cybersecurity level</kwd>
        <kwd>readiness indicator</kwd>
        <kwd>social engineering</kwd>
        <kwd>cybergaming</kwd>
        <kwd>education characteristics</kwd>
        <kwd>multisociometrical readiness characteristics</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Ensuring the high quality of education on the basis of preserving its fundamentality and meeting the
current and promising needs of the individual, society and the state is one of the main tasks of Russian
educational policy. The current state of the educational process, including in the field of information
security, is characterized by the mastery of a competent approach to the training of specialists, which
consists in the development of key competencies among students that determine their successful
adaptation to professional activity.</p>
      <p>Analysis of standards, various methodological documents in the field of information security shows
the existence of a formal approach to the assessment of specialists in the field of information security
(education, seniority, advanced training). The methods lack indicators of the level of professional
fitness, competence of employees, criteria for the level of education in the context of theoretical
knowledge and practical skills and skills. The set of the above indicators and evaluation criteria, which
together represent the educational component, has a direct impact on the employer's activities. Thus, it
is now necessary to develop a multisociometrical educational component (multisociometrical readiness
characteristics) based on a certain complex qualitative and quantitative indicator in the form of a
specialist readiness indicator. The latter will allow the management of enterprises and organizations to
make the right decisions on working with personnel and will contribute to improving the level of
training of specialists in information security as the most important organizational and technical task of
providing information security of the Russian Federation.</p>
      <p>Today, in the framework of employment, applicants are not only required to comply with the
professional model of the specialist in the context of professional skills (hard skills), but also a certain
complex of psychophysiological characteristics (soft skills). Thus, the optimal combination of soft skills
and hard skills presents some model of a graduate of an educational institution to the context of a
continuous education model [7]. This article attempts to focus on the field of information security [3,
12]. However, it can be extended to other spectra and interdisciplinary areas of research.</p>
      <p>The purpose of this article is to describe the technology of generating the multisociometrical
readiness characteristics in information security management.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Information security management</title>
      <p>Information security management system is a part of general management system in organizations.
It is based in the group of business risks approach. Its primary objective is to found, implement, exploit,
supervise, maintain and improve information security of organizations. Information security
management is a systematic approach for managing sensitive information in order to protect it.
Information and security is the something beyond of installing a simple fire wall or tying of a contract
with a company in the field of information security. In such an approach, it is important that we balance
various security activities with a common strategy in order to provide an optimal protection level.</p>
      <p>The main purpose of the information security management is to objectively assess the current state
of the information security of the organization, for counteracting possible external and internal threats.</p>
      <p>Today, conducting an audit of information security management systems is a necessary and required
activity. A number of organizations whose business is closely connected with the use of information
technologies, such as banks, oil, gas, energy and telecommunications companies, have recently become
more active in conducting audits of information security management systems.</p>
      <p>The main tasks that are solved during the information security management and audit of information
objects, information security management are:
 analysis of structure, functions, used technologies of automated processing and transfer of
information to the information objects, analysis of business processes, regulatory and
administrative and some technical documents;
 identification of significant information security threats and ways of their implementation;
identification and ranking of existing technological and organizational vulnerabilities at the
information objects by the danger level;
 development of models of violators, application of active audit techniques to check the
possibility of violators implementation of identified information security threats;
 analysis and assessment of risks associated with threats to the security of information
resources;
 assessment of the information security management system for compliance with the
requirements of the existing information security standards, and development of
recommendations for improving the information security management system;
 assessment of the current level of information objects protection and localization of
bottlenecks in the protection system;
 development of proposals and recommendations to introduce new and improve the
effectiveness of the existing mechanisms for the provision of information security.</p>
      <p>Information security risks from personnel constitute a separate group of information security risks
of the organization with a specific set of causes and conditions for their implementation.</p>
      <p>A set of risk factors represents a single network with causal relationships. Risk factors of the first
and second levels are identified. Second-level risk factors mean relatively small phenomena that an
organization can work out separately. The group of risk factors of the first level are phenomena that
directly and most strongly affect the possibility of implementing threats to information security from
personnel. A special place in the organization's personnel system is occupied by information security
specialists. They are directly involved in the creation of the Information security management system,
its audit and monitoring.</p>
      <p>A review of the literature on the development and exploring information security management
systems indicates that such systems depend on the human factor [1-2, 5, 7, 11-16].</p>
      <p>In order to optimize the processes of information security audit and applicant diagnostics, there is a
need to develop an educational component as a multisociometric characteristic, firstly, an indicator of
the readiness of applicants as the most important factor affecting the formation of the competence of a
student at the university, secondly, an indicator of the readiness of a graduate of the university for
professional activities, and thirdly, an indicator of the professionalism of an information security
specialist, which is the resulting component of educational activities [7].
3. Technology of multisociometrical readiness characteristics generation in
information security management</p>
      <p>The specialist readiness indicator is directly related to the subject area, therefore, the specialist
readiness technology is logical to build from these positions. Let's take a look at information security.
The effective solution of problems in this area requires highly organized, highly qualified personnel
support, ranging from the employment procedure to continuous processes of advanced training,
retraining taking into account program and technological, organizational changes in the information
security of the open state. Moreover, the procedure of employing a specialist from the position of a
readiness indicator involves an analysis of its characteristics, while the working process is accompanied
by the effect of accumulative frequencies of the factors included in it, as well as the formation of
additional links [7].</p>
      <p>Therefore, in order to generate a readiness index, it is necessary to enter a group of cumulative
factors for the assessment of soft skills and hard skills, as well as nominal characteristics with branching
by categories and types/forms of education.</p>
      <p>Within the project supported by Charity Foundation of Potanin in 2021 in FGBOOU WAUGH
"Novosibirsk State Technical University" is developed in the scientific purposes the automated system
of assessment of an indicator of readiness of experts of the direction 10.03.01 "Information security"
and 10.05.03 "Information security of the automated systems". This system is a tool for monitoring and
analyzing training results. The impact of gamblers in the implementation of programs for the education
of an enlarged group of specialties 10.00.00 "Information Security" [7, 15] is also evaluated.</p>
      <p>Implementation of the automated system for the readiness indicator modelling can be one of useful
methods. Algorithm or the comprehensive approach to the estimation of specialists readiness, based on
the results of the expert questioning, accumulated frequencies (fuzzy model with linguistic and point
scales). It consists of next blocks:</p>
      <p>To create and operate the above-mentioned system, a generalized algorithm for estimating of the
multisociometrical readiness characteristics in Information Security Management is implemented as the
result of the following units (fig. 1)</p>
      <p>Unit 1 is one of the most complex, since it involves the analysis and formalization of criteria and
the selection of readiness indicator indicators. Every indicator contains both quantitative and qualitative
indicators. Quantitative indicators include specialty/direction data resulting from the competency model
in the section of the blocks of disciplines of the curriculum. Qualitative indicators represent a complex
of psychophysiological characteristics within the framework of the given direction. Quantitative criteria
for choosing indicators should be valid, effective, systemic and measurable (the quantitative and quality
aspect).</p>
      <p>The technology for generating the specialist readiness indicator is presented in the form of a
multilevel structure and involves a consistent solution at all stages: stage 1, stage 2, stage 3.
Unit 1. Modelling
the definition of
readiness indicator.</p>
      <p>Unit 2. Generation
of readiness
indicators
benchmarks.</p>
      <p>Unit 3. Procedure
for assessment of
readiness indicator.</p>
      <p>Unit 4.</p>
      <p>Generalization and
interpretation of
the results.</p>
      <p>Unit 5. Forming of
conclusions and
adjustment of
model.
the graduate in the field of information security.</p>
      <p>1. The level of readiness of a student to study at a university ( 011) is an expression of the following</p>
      <p>
        011 = ∑   ⋅ (∑ (   ⋅ 
 =1
 =1
⋅ (1 −   )+   ⋅ (1 − 
)⋅    )),
(
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
where j – result of curriculum training (1&lt;jn, n – disciplines curriculum);  - coefficient of significance
of disciplines j (0 &lt;   &lt; 1);   
- total result Хi by discipline j (25 ≤   
≤ 100);  – summary
coefficient of significance (0 &lt;  &lt; 1); weight wi={0, 1},   
- total graduated result Хi of discipline j
(25 ≤
      </p>
      <p>≤ 100);  – number of disciplines in curriculum training part j.</p>
      <p>2. The indicator of psychological suitability ( 021) is a complex three-component qualitative
indicator that combines data on the attentive, accuracy of a graduate when working with service
documentation, etc. Evaluation is carried out on 5 levels: A - high, B - above average, C - medium, D
below average, E - low.
interest of a graduate of an educational institution based on comprehensive methods.
3. The level of interest in the field of information security ( 031,%) is an assessment of the level of
Unit 2 includes professional selection of applicants based on the set of obtained indicators &lt;  011,
 021,  031&gt;.
characteristics.</p>
      <p>Unit 3 involves the formation of a readiness indicator based on the entire period of study at the
university by specialty (X1, fig. 2). The indicator takes into account the set of nominal and calculated</p>
      <p>Elements No. 2- No. 3 (X2-3, fig. 2) - 'Theoretical knowledge (Practical skills)' - are composed of the
level of theoretical knowledge (practical skills) (%) and the corresponding standard deviations (%).</p>
      <p>An integral evaluation in a theoretical and practical context is a weighted average estimate. As
weights, we take normalized importance factors calculated from the results of an expert survey:
indicator are formed.
elements (mnemonic code):
security is shown in fig. 2.
where    – normalized coefficient of significance of discipline i;     ,    - normalized coefficient
of significance competency (discipline group C and discipline group O); α - coefficient of significance
of competency O; n, m – number of competencies C and O accordingly;    and  
– total result of competency j cycle of disciplines C and O accordingly; k1 and k2 – number of disciplines

С

  (  С and  

 
 )
by realized C and O competencies; k – total number of disciplines.</p>
      <p>Element No. 4 (X4, fig. 2) - Indicator «Adequacy. Discipline».</p>
      <p>
        The adequacy indicator (X4(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ),%) determines the degree of compliance of the student with his own
strength and knowledge based on the results of the state attestation exam. The discipline rate (X4(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ),%)
is a comprehensive indicator that combines the level of attendance by students in professional
disciplines.
      </p>
      <p>Element No. 5 (X5, fig. 2) - Indicator of psychological suitability (pays attention to details in
information security, mentally capable of handling complexity, continuously improving, honest,
hardworking, stress resistance) when working with the data of a graduate of a university. Evaluation is
carried out on 5 levels: A - high, B - above average, C - medium, D - below average, E - low.</p>
      <p>The last stage of the formation of the multisociometric educational component (readiness indicator)
of the information security is Stage «Employment». Based on the calculated indicators, the employer
draws appropriate conclusions and makes decisions on employment or refusal of employment of a
graduate of the university. Then elements (Performance data, X6) and (Additional education, X7) of
Thus, the multisociometrical readiness characteristic represents a 7-component symbolic set of</p>
      <p>X = &lt; X1, X2, X3, X4, X5, X6, X7&gt;.</p>
      <p>The type of parameters of the common educational component (readiness indicator) of information
The type of additional parameters of the common educational component (readiness indicator) of


 =1
 =1


 =1
 =1
  = 
∑    ⋅ ∑     ⋅    + (1 −  )⋅

К
  = 
∑   С ⋅ ∑  
 ⋅    + (1 −  )⋅
∑   
 +
 +
 = +1</p>
      <p>
        ∑   
 = +1
⋅ ∑   
 =1


⋅ ∑  
 =1
  ⋅   
  ⋅   

(
        <xref ref-type="bibr" rid="ref2">2</xref>
        )
(
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
information security is shown in fig. 3.
      </p>
      <p>7. Additional education
7.1 Additional educations last year
7.2 Number of additional educations
7.3 Additional specialty codes
7.4 Numbers of professional educations
7.5 Scientistic degree
7.6 Numbers of scientistic degrees
7.7 Academic rank
7.8 Numbers of academic rank
00009999
0099
‘0’-‘9’
0099
Yes/No/Range
09
09
Yes/No/Range
information security specialists
1. Specialty
1.2 Year of graduation
2. Theoretical base</p>
      <p>2.1 Theoretical knowledge
3. Practical base</p>
      <p>3.1 Practical skills
4. Adequacy. Discipline
4.1 Indicator of adequacy
2.2 Root mean square deviation
3.2 Root mean square deviation
5. Psychological
professional suitability
6. Performance Data
6.1 Record of service
4.2 Indicator of discipline level
5.1 Psychological professional indicator 1
5.2 Psychological professional indicator2
5.3 Psychological professional indicator3
….
5.n Psychological professional indicator n
6.2 record of service as a specialist in the field of
information security
6.3 Skill level
6.4 Rating in skill level
00009999
0100
0100
0100
0100
0100
0100
‘A’-‘Е’
‘A’-‘Е’
‘A’-‘Е’
‘A’-‘Е’
0099
0099
09
‘A’-‘Е’</p>
      <p>Different information security initiatives are being carried out to improve the educational component
(readiness indicator) of information security specialists. An example of quest is a game held at
Novosibirsk Technical University for students of the direction of information security.</p>
      <p>Using role-playing games for information security awareness tasks has many benefits. In addition
to the clear task of simulating a real situation, we can also note the removal of psychological barriers in
the interaction of players, and gaining access to practical cases that are difficult to integrate into other
types of games. In recent years, there are a lot of various types of games based on the use of roles that
are widely represented in information security training tasks [3-6, 9, 15]. It is important that tasks used
in this types of games are usually connected in logical chains or performed in quest’s form, and also
contain keys or a fixed execution scheme.</p>
      <p>It should be noted that a large number of ethical hacking competitions are organized as Capture The
Flag (CTF) in Novosibirsk Technical University. The game takes place in the digital world, while each
team must protect and attack vulnerable systems and collect the flags which are alphanumeric strings.
Each challenge has a description, related files or website links, 2 featuring potential hints and the
amount of reward points which each participant or team collects after a successful flag submission
[36]. Groups or individual participants are trying to collect as many reward points as possible within a
certain time. The winner is the individual or the team with the most collected reward points [6].</p>
      <p>Unit 4 is oriented to forming of standardization of every readiness indicator. If estimation of the
quantitative readiness indicators does not cause the special problems because of the presence of a large
number of mathematical models, then the readiness indicators require the special attention, because the
object of estimation is characterized by the large degree of uncertainties.</p>
      <p>The aim of this block are formalization and integration of the basic data formed in the process of
quality evaluation. The choice of method of construction of member functions depends on the type of
the decided task, complication of receipt of the checked-up information for decision, authenticity of
this information, and also from labour intensiveness of algorithm of treatment of information at the
construction of member functions.</p>
      <p>Unit 5 of the readiness index estimation algorithm assumes a standard procedure for quantitative
evaluation of quantitative indicators and a fuzzy evaluation of qualitative indicators.</p>
      <p>Example. In case of additional education (undergraduate, master's degree, higher education),
reference is made in indicator 7 with indication of the cipher of the specialty (direction), after which an
additional readiness indicator is formed, similar to presented before.</p>
      <p>Note that the element "Year of the last advanced training" of component No. 7 is variable and reflects
either the year of advanced training, or receiving a second education, or the assignment of a degree
(title).</p>
      <p>
        For example, in the case of the indicator "educational component of the IB audit" of type
"090104.2005-90.10-70.15-40.95-ABAAA-4 (
        <xref ref-type="bibr" rid="ref4">4</xref>
        ) .B-2011.090900 (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) .K (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) .D (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )," one additional
code is formed: "100401.2021-75.15-80.25-80.75-ABAAA" upon completion of training in the
direction 100401 "Information security".
      </p>
      <p>
        Let us first consider the first indicator:
090104.2005-90.10-70.15-40.95-ABAAA–4(
        <xref ref-type="bibr" rid="ref4">4</xref>
        ).B-2021.100401(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ).К(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ).D(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ).
      </p>
      <p>
        According to the described technique, component-by-component decryption yields the following
results:
1. specialty - 090104.2005 ';
a. specialty code - 090104;
b. year of completion - 2005;
2. theoretical knowledge - '90.10';
a. the level of theoretical knowledge - 90%;
b. standard deviation of theoretical knowledge - 10%;
3. practical skills - 70.15 ';
a. the level of practical skills - 70%;
b. standard deviation of practical skills - 15%;
4. adequacy. discipline – '40.95';
a. adequacy - 40%;
b. discipline - 95%;
5. indicator of psychological professional suitability - "ABAAA";
a. The level of purpose is' A ';
b. Attention level - 'B';
c. Stress tolerance level - 'A';
d. Decency level - 'A';
e. The level of accuracy when working with data is'A '.
6. operation data - "4 (
        <xref ref-type="bibr" rid="ref4">4</xref>
        ) .B";
a. Work experience - 4 years;
b. Work experience in the specialty - 4 years;
c. Assessment of the manager - "B";
7. advanced training - "2021.100401 (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) .K (
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) .D (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )";
a. Year of last advanced training - 2021;
b. The code of the specialty of second education is 100401;
c. The number of additional formations is 1;
d. Degree - K (candidate);
e. The number of degrees is 1;
f. Academic title - D (Associate Professor);
g. The number of scientific ranks is 1.
      </p>
      <p>Next, consider a component by component additional measure of the fitness of the species:
“100401.2021-75.15-80.25-80.75-ABAAA”.</p>
      <p>According to the described technique, component-by-component decryption yields the following
results:
1. specialty - 100401.2021';
a. specialty code - 100401;
b. year of completion - 2021;
2. theoretical knowledge - '75.15';
a. the level of theoretical knowledge - 75%;
b. standard deviation of theoretical knowledge - 15%;
3. practical skills - 80.25 ';
a. the level of practical skills - 80%;
b. standard deviation of practical skills - 25%;
4. adequacy. discipline – '80.75';
a. adequacy - 80%;
b. discipline - 75%;
5. indicator of psychological professional suitability - 'ABAAA';
a. The level of purpose is' A ';
b. Attention level - 'B';
c. Stress tolerance level - 'A';
d. Decency level - 'A';
e. The level of accuracy when working with data is 'A '.</p>
      <p>The formed indicator indicates the high educational achievements of the employee in the first
specialty "Comprehensive protection of informatization objects" in the context of 90% theoretical
knowledge and 70% practical skills with a small spread of 10-15% during the entire training period, as
well as a high level of professional fitness (dominance of the results of the 'A' level).</p>
      <p>Moreover, the specialist has 4 years of experience in the professional field.</p>
      <p>The presence of an additional indicator indicates the presence of a second education in the field of
information security (magistracy 100401 "Information Security"). The component composition
indicates high levels of theoretical knowledge (75%) and practical skills (80%), adequacy (80%) and
discipline (75%), as well as professional fitness (dominance of "A" level results).</p>
      <p>In the end, based on a comprehensive measure of preparedness, it can be concluded that this
employee is of interest to employers in the future.</p>
    </sec>
    <sec id="sec-3">
      <title>4. Experimental part</title>
      <p>The technology of formation of qualitative and quantitative indicators in the form of the information
security specialist readiness as an element of a trusted environment figure has been tested in
Novosibirsk technical university. Students of different specialty (10.03.01 Information security,
10.05.03 Information security of automized systems) took part in this experiment (department
information security). Thus, experimental work on the formation of indicators of readiness of specialists
in the field of information security was carried out in the period 2020-2021.</p>
      <p>The formation of readiness indicator of information security specialists, interaction with employers
contributed to increasing the responsibility of all participants in the educational process for the total
results. The results of pedagogical monitoring were: a clearer organization of practices, improved
educational programs of a number of disciplines, modified educational and methodological complexes,
modernized laboratory installations.</p>
      <p>Teachers noted the increased interest of students in the learning process. From these positions, the
motivational factor for learning was investigated throughout the training period according to the
modified methodology.</p>
      <p>Dynamics of structural elements of the readiness indicator on average (levels of theoretical
knowledge, practical skills) is positive. Individual psychological qualities were assessed by specialists
of the professional psychological selection group using a set of psychodiagnostical methods and tests
taking into account modern requirements for an information protection specialist.</p>
      <p>The experts of the commission, when assessing the psychological qualities of specialists in the field
of information security, made a conclusion on the professional suitability of graduates on the basis of
levels of determination, mindfulness, stress resistance and others.</p>
    </sec>
    <sec id="sec-4">
      <title>5. Conclusion</title>
      <p>The article discusses the characteristics of Information security management. Today, conducting an
audit of information security management systems is a necessary and required activity. A number of
organizations whose business is closely connected with the use of information technologies, such as
banks, oil, gas, energy and telecommunications companies, have recently become more active in
conducting audits of information security management systems. Information security risks from
personnel constitute a separate group of information security risks of the organization with a specific
set of causes and conditions for their implementation. Thus in order to optimize the processes of
information security audit and applicant diagnostics, there is a need to develop an educational
component as a multisociometric characteristic, firstly, an indicator of the readiness of applicants as the
most important factor affecting the formation of the competence of a student at the university, secondly,
an indicator of the readiness of a graduate of the university for professional activities, and thirdly, an
indicator of the professionalism of an information security specialist, which is the resulting component
of educational activities.</p>
      <p>The multisociometrical readiness characteristic represents a 7-component symbolic set of elements
(mnemonic code): specialty, theoretical base, practical base, indicators of adequacy and discipline,
psychological professional suitability indicators, performance data indicators, additional indicators.</p>
    </sec>
    <sec id="sec-5">
      <title>6. Acknowledgement</title>
      <p>This work was supported by the Vladimir Potanin Foundation for Basic Research project No
GK21001229</p>
    </sec>
    <sec id="sec-6">
      <title>7. References</title>
      <p>[9] Official website of Positive Technologies, 2021. - URL: https://www.ptsecurity.com/ru-ru/.
[10] Rajasekar A. Sociometric Methods for Relevancy Analysis of Long Tail Science Data / A.</p>
      <p>
        Rajasekar et al. // International Conference on Social Computing, 2013, pp. 1-6, doi:
10.1109/SocialCom.2013.6.
[11] Sahar Al-Dhahri. Information Security Management System / Sahar Al-Dhahri, Manar Al-Sarti,
Azrilah Abdaziz // International Journal of Computer Applications, 2017. vol. 158 – No 7. pp.
2933. DOI: 10.5120/ijca2017912851.
[12] Somepalli S. H. Information Security Management / Somepalli, S. H. et. al // HOLISTICA –
Journal of Business and Public Administration, vol. 11, iss. 2, 2020. pp. 1-16. DOI:
10.2478/hjbpa2020-0015.
[13] Tolani M. G. Use of artificial intelligence in cyber defense / M. G. Tolani, H. G. Tolani //
International Research Journal of Engineering and Technology (IRJET), 2019. 6(
        <xref ref-type="bibr" rid="ref7">7</xref>
        ), pp.
30843087. URL: https://www.irjet.net/archives/V6/i7/IRJET-V6I7468.pdf.
[14] Zaydi M. A New Approach of Information System Security Governance: A Proposition of the
Continuous Improvement Process Model of Information System Security Risk Management:
4DISS / M. Zaydi, N. Bouchaib // 27th IEEE International Conference on Enabling Technologies:
Infrastructure for Collaborative Enterprises (WETICE-2018) At: PSB PARIS-FRANCE, 2018, pp.
112-118. IEEE. https://doi.org/10.1109/WETICE.2018.00028.
[15] Zolotarev V. V. Strategies of social engineering attacks on information resources of gamified
online education projects / V. V. Zolotarev, A. B. Arkhipova, N. Y. Parotkin, A. P. Lvova. – Text
: electronic // CEUR Workshop Proceedings. – 2021. – Vol. 2861 : International Scientific
Conference on Innovative Approaches to the Application of Digital Technologies in Education
(SLET–2020), Stavropol, 12–13 Nov. 2020. – P. 386–391. – URL: http://ceur-ws.org/Vol-2861/.
– Publication date: 13.05.2021.
[16] Zolotareva G. New approach to risk controlling in information security / G. Zolotareva, V.
      </p>
      <p>
        Zolotarev, S. Filko // Journal of Physics Conference. 2019. Series 1210(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ):012170. DOI:
10.1088/1742-6596/1210/1/012170.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>Bilbao</surname>
            <given-names>A</given-names>
          </string-name>
          . Measuring security / A. Bilbao, E. Bilbao // 47th International Carnahan Conference on Security
          <source>Technology (ICCST)</source>
          ,
          <year>2013</year>
          . pp.
          <fpage>1</fpage>
          -
          <lpage>5</lpage>
          . https://doi.org/10.1109/CCST.
          <year>2013</year>
          .
          <volume>6922054</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Fernandez</surname>
            <given-names>E. B. Measuring</given-names>
          </string-name>
          <article-title>the Level of Security Introduced by Security Patterns / Fernandez E. B</article-title>
          . et al // International Conference on Availability,
          <source>Reliability and Security</source>
          ,
          <year>2010</year>
          , pp.
          <fpage>565</fpage>
          -
          <lpage>568</lpage>
          , doi: 10.1109/ARES.
          <year>2010</year>
          .
          <volume>111</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Hamari</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Koivisto</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Sarsa</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          (
          <year>2014</year>
          ). Does Gamification Work?
          <article-title>- A Literature Review of Empirical Studies on Gamification</article-title>
          .
          <source>Proceedings of the Annual Hawaii International Conference on System Sciences. 10</source>
          .1109/HICSS.
          <year>2014</year>
          .
          <volume>377</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Hendrix</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Al-Sherbaz</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Victoria</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Game based cyber security training: are serious games suitable for cyber security training?</article-title>
          .
          <source>International Journal of Serious Games</source>
          ,
          <volume>3</volume>
          (
          <issue>1</issue>
          ),
          <fpage>53</fpage>
          -
          <lpage>61</lpage>
          (
          <year>2016</year>
          ). https://doi.org/10.17083/ijsg.v3i1.
          <fpage>107</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>Hironori</given-names>
            <surname>Washizaki</surname>
          </string-name>
          ,
          <article-title>Security patterns: Research direction metamodel application and verification, Big Data and Information Security</article-title>
          (IWBIS) 2017 International Workshop on, pp.
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Karagiannis</surname>
            <given-names>S.</given-names>
          </string-name>
          <article-title>An Analysis and Evaluation of Open Source Capture the Flag Platforms as Cybersecurity e-Learning Tools / Stylianos Karagiannis</article-title>
          , Elpidoforos Maragkos,
          <source>Emmanouil Magkos // IFIP World Conference on Information Security Education</source>
          ,
          <year>2020</year>
          . DOI:
          <volume>10</volume>
          .1007/978- 3-
          <fpage>030</fpage>
          -59291-
          <issue>2</issue>
          _
          <fpage>5</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Krokhaleva</surname>
            <given-names>A. B.</given-names>
          </string-name>
          <article-title>The human factor in the system of socially significant activity (article of the Higher Attestation Commission )/A</article-title>
          . B.
          <string-name>
            <surname>Krokhaleva</surname>
          </string-name>
          , V. M. Belov//Mathematical structures and modeling. -
          <source>2017</source>
          . - №
          <volume>4</volume>
          (
          <issue>44</issue>
          ). - p.
          <fpage>85</fpage>
          -
          <lpage>99</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Monica</surname>
            <given-names>G.</given-names>
          </string-name>
          <string-name>
            <surname>Tolani</surname>
          </string-name>
          .
          <article-title>Use of artificial intelligence in cyber defence / Monica G</article-title>
          . Tolani, Harsha G. Tolani // International Research Journal of Engineering and Technology (IRJET),
          <year>2019</year>
          . pp.
          <fpage>3084</fpage>
          -
          <lpage>3087</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>