<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Information Technology of Information Security Audit of Objects of Critical Infrastructure</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Igor Kozubtsov</string-name>
          <email>kozubtsov@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Nataliya Lishchyna</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Lesia Kozubtsova</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Igor Trush</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii Yashchuk</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>01011</institution>
          ,
          <addr-line>Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Emerging Technology Trends on the Smart Industry and the Internet of Things</institution>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Legistation Institute of the Verkhovna Rada of Ukraine</institution>
          ,
          <addr-line>4 Nestorivsky prov., 04053, Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Lutsk National Technical University</institution>
          ,
          <addr-line>75 Lvivska str., 43000, Lutsk</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff4">
          <label>4</label>
          <institution>Military Institute of Telecommunications and Informatization named after Heroes of Kruty</institution>
          ,
          <addr-line>45/1 Moscow str.</addr-line>
        </aff>
      </contrib-group>
      <fpage>97</fpage>
      <lpage>106</lpage>
      <abstract>
        <p>Context. The scientific and practical task to substantiate the mathematical apparatus on the basis of which the information technology of information security audit of critical infrastructure is developed, which provides verification of compliance of critical infrastructure with the general requirements approved by the Cabinet of Ministers of Ukraine dated 2019-0619, No.518. A security audit is one of the most effective measures to increase the level of information security of the critical infrastructure. Objective. The purpose of the work is to create information security audit of critical information infrastructure on the basis of separate partial solutions of information technology. Method. On the basis of the general requirements defined by the Resolution of the Cabinet of Ministers of Ukraine dated 2019-06-19, No.18 “On approval of the General requirements for cyber protection of critical infrastructure objects” a set of indicators and evaluation criteria was proposed. The structure of future information technology was offered. In accordance with the structure of information technology, the stages of the methodology of information security audit of critical infrastructure were built. The technique contains a simple mathematical apparatus that simplifies calculations even in Microsoft Excel spreadsheets. In this paper, in contrast to the known methods and techniques, it is proposed to take into account the weight of the importance of information security requirements. As a result, the method has become sensitive to the most critical requirements for cybersecurity of critical infrastructure. Results. Information technology of information security audit of critical information infrastructure objects has been developed. Conclusions. The experiments in Microsoft Excel spreadsheets confirm the efficiency of the proposed method. It is advisable to recommend the development of software that would in practice automate the process of information security audit of critical information infrastructure. The scientific novelty of the obtained result is that for the first time the information technology of information security audit of critical infrastructure facilities was developed, which provides verification of compliance of critical infrastructure facilities with the general requirements approved by the Cabinet of Ministers of Ukraine dated 19 June 2019, No.518. The practical significance of the work lies in the possibility of developing information technology software. Prospects for further research in this area. The presented study does not cover all aspects of this problem. Theoretical and practical results obtained in the process of scientific research are the basis for further study in such areas as the development of information technology software. Information technology, audit, information security, critical infrastructure facility.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>EMAIL:
(I. Kozubtsov);</p>
      <p>2022 Copyright for this paper by its authors.</p>
    </sec>
    <sec id="sec-2">
      <title>1. Introduction</title>
      <p>Cybersecurity is a state of protection of critical objects of national infrastructure and its individual
components, which ensures their sustainable functioning and development, timely detection, prevention
and neutralization of cyber threats in the interests of man, society and state.</p>
      <p>According to current practice, cybersecurity of objects of critical infrastructure (OCI) is not a
constant value over time. The cybersecurity of the OCI is a function of a number of random parameters,
namely the availability of a cybersecurity system, staffing, and the frequency of new cyber threats.
There is a constant cyber confrontation between the security system and the stakeholder “Threat
Agents” [1].</p>
      <p>Security audit of the information security is a systematic process of obtaining objective qualitative
and quantitative assessments of the current state of information system security, a comprehensive
assessment of the level of information security of the client, taking into account three main factors:
personnel, processes and technologies.</p>
      <p>Independent information security audit at critical infrastructure facilities (hereinafter - independent
audit) is a systematic, independent and documented process of assessing the state of information
security at critical infrastructure facilities, based on legal requirements, national standards and
recommendations of international information security standards.</p>
      <p>A regular information security audit is needed in order to assess the real state of security of OCI
resources and its ability to withstand external and internal threats to information security, which are
constantly changing and adapting.</p>
    </sec>
    <sec id="sec-3">
      <title>2. Problem Statement</title>
      <p>In order to ensure compliance with the Law of Ukraine “On Basic Principles of Cyber Security of
Ukraine”, it is recommended to conduct a scheduled and unscheduled independent audit of information
security of OCI on the effectiveness of cybersecurity. In accordance with the second part of Article 6
of the Law of Ukraine “On Basic Principles of Cyber Security of Ukraine”, the Cabinet of Ministers of
Ukraine resolves: paragraph 7. If the critical information infrastructure does not process state
information resources or information with limited access, the protection requirement of which is
established by law, the provisions of these General Requirements are taken into account during the
creation (modernization) of the information security system of the critical infrastructure object.
Compliance with the General Requirements is verified during an independent information security audit
of the critical infrastructure.</p>
      <p>Thus, the owner and/or manager of a critical infrastructure facility is obliged to organize and conduct
an independent information security audit at the critical infrastructure facility in accordance with the
requirements of the legislation in the field of information protection and cybersecurity.</p>
      <p>According to the provisions of the National Security Strategy of Ukraine, the Concept of
Development of the Security and Defense Sector of Ukraine [2, 33], the Law of Ukraine “On Basic
Principles of Cyber Security of Ukraine” [3];</p>
      <p>Cybersecurity Strategies of Ukraine [4];</p>
      <p>Decision of the National Security and Defense Council of Ukraine dated 2017-07-10 “On the status
of implementation of the decision of the National Security and Defense Council of Ukraine dated
201612-29”, “On threats to cybersecurity and urgent measures to neutralize them” [5].</p>
      <p>Therefore, solving the scientific problem of the demand to conduct an audit of OCI in compliance
with the general requirements of the Cabinet of Ministers of Ukraine dated 2019-06-19, No.518 “On
approval of the General requirements for cyber protection of critical infrastructure” [6] is currently
considered relevant.</p>
    </sec>
    <sec id="sec-4">
      <title>3. Review of the Literature</title>
      <p>This work is also aimed at implementing urgent public policy measures to neutralize object of critical
information infrastructure (OCII) threats [5], which could lead to negative consequences, as predicted
in the description “Future Security Environment 2030” [7].</p>
      <p>In general, research and publications on the problem of information security audit are devoted to a
relatively large number of works, among which, in our opinion, the following deserve attention.</p>
      <p>In [8] the peculiarities of building the methodology of information security audit in modern
conditions are presented.</p>
      <p>In [9] the method of information security audit is described.</p>
      <p>In [10] the methods of information security audit of information systems that process personal data
in non-state military pension funds are revealed.</p>
      <p>In [11], the authors proposed a method for assessing the stability of the OCII, which operates in
cyberspace.</p>
      <p>In [12] the problem of developing a methodology for assessing the cyber security of the
communication system of the organization was solved.</p>
      <p>In [13] the authors developed a method of auditing information objects for information security
requirements. The methodology is based on a combination of techniques that use quantitative and
qualitative criteria as parameters for assessing security.</p>
      <p>The monograph [14] describes the procedure for conducting security audits of information systems.</p>
      <p>The monograph [15] considers the audit of critical infrastructure security by special information
influences.</p>
      <p>The monograph [16] describes the types of internal control, security and integrity procedures that
management should incorporate into its automated systems. This book provides auditors with the
guidance they need to keep their systems safe from both internal and external threats.</p>
      <p>The monograph [17] outlines a systematic process of creating a virtual environment for the practice
of penetration testing. The author gives examples of creating a network architecture that allows you to
test almost any environment.</p>
      <p>There is no doubt that the implementation of the requirements presented in the documents [6]
requires a method of independent information security audit, which takes into account the main aspects
of OCI information security, and in these works there is no mathematical apparatus of calculation. In
addition, the practical result of solving the scientific problem should be information technology audit
of information security of critical information infrastructure.</p>
      <p>The purpose of the article is to develop information technology of audit of information security of
objects of critical information infrastructure on the basis of separate partial decisions.</p>
    </sec>
    <sec id="sec-5">
      <title>4. Materials and Methods</title>
      <p>According to the State standard of Ukraine DSTU 2392-94 [18] “information system” is a
communication system that provides collection, retrieval, processing and transmission of information.</p>
      <p>The Law of Ukraine “On Information Protection in Information and Telecommunication Systems”
defines an information (automated) system as an organizational and technical system in which
information processing technology is implemented using technical and software tools [19].</p>
      <p>According to ISO / IEC 2382: 2015 [20] “information system – a system designed for storage,
retrieval and processing of information, as well as relevant organizational resources (human, technical,
financial, etc.) that ensure the dissemination of information”.</p>
      <p>Information technology is a set of methods, tools, techniques that provide search, collection, storage,
processing, presentation, transmission of information between people.</p>
      <p>Information technology is a process that can be implemented by means of computer technology,
which will ensure compliance with the requirements for the search, presentation, conversion and
transmission of information, ie processes that implement human information activities. Schematically,
the components of information technology are presented in Figure 1.</p>
      <p>The main components of the proposed information technology are hardware (personal computer,
multimedia, etc.), software and organizational and methodological support.</p>
      <p>Information technology provides the implementation of the following interconnected processes in
the form of algorithm stages:
 Stage 1 search, collection and storage of information
 Stage 2 information processing</p>
      <p>Stage 3 displaying information
impact is absent: DII = 0.
operation and information security.
of critical infrastructure [6].</p>
      <sec id="sec-5-1">
        <title>Stage 2 Information processing.</title>
        <p>The information security audit of OCI is performed by questioning the persons responsible for the
Questionnaire questions are developed on the basis of current general requirements for cybersecurity
Evaluation criteria must be specified before processing. The criterion for evaluating the results of an
independent information security audit of OII is the effectiveness of the implementation of measures at
the inspection sites, which should perform the target function under the conditions of destructive
information impacts KIS(OCII), see table.1.
verification КISN.</p>
        <p>OCII;</p>
      </sec>
      <sec id="sec-5-2">
        <title>Calculation of the effectiveness of information security on the component of the object of</title>
        <p>1) the requirements V1… VN are distributed for each component of the object of inspection (Kj)
2) the implementation of the requirements (V1… VN) on each component of the object of
verification (Kj) OCII OCI is checked;
implemented measures defined in the requirements (V1… VN)
3) the audit committee carries out the audit as on each component of the object of audit (Kj) OCII OCI
The value of information security efficiency on each component of the object of verification (Kj)
OCII OCI takes the value of KISN [0; 1] under the following conditions, if:</p>
        <p>partial requirements are implemented on each component of the OCII test object (Kj), then
(V1) = “1”, otherwise (V1) = “0” requirements are not implemented.</p>
        <p>Quantity (VN) for different components of the test object (Kj) OCII OCI has a different number.</p>
        <p>The results of the calculations are listed in table 2
where VN – the number of general information security requirements; VN1 – the number of general
requirements VN that take the value “1”; VN0 – the number of general requirements VN that take the
value “0” for the component of the test object of OCII.</p>
        <p>The results of the calculations are listed in table 3.
..
number of general information security requirements (VN);
the number of VN1, which takes the value “1”;
the number of requirements VN0, which takes the value “0”.</p>
        <p>Conditions and procedure for conducting an independent information security audit. The algorithm
of information activities of the audit committee is presented in Table 4 (abbreviations:</p>
        <p>ROCII OCI is responsible for the object of critical information infrastructure of an object of critical
infrastructure;
5. Experiments
1 includes:









calculated:</p>
      </sec>
      <sec id="sec-5-3">
        <title>Calculation of the overall effectiveness of information security at the object of verification</title>
      </sec>
      <sec id="sec-5-4">
        <title>KIS(OCII) at time t0.</title>
        <p>will operate normally.</p>
        <p>The quantitative indicator for assessing the information security of a complex system is KIS(OCII) –
the probability that in a complex system, all components will be protected from cyber interference and</p>
        <p>The Information Security Performance Indicator КIS(OCII) is generally calculated according to
formula (2) as a weighted and standardized assessment of the cyber security performance of all
components of a complex system.</p>
        <p>(    ) =

 =1(    ×    ).</p>
        <p>,
(2)
where m – the number of components (Kj) of the object of inspection of OCII;</p>
      </sec>
      <sec id="sec-5-5">
        <title>Step 3 Displaying information.</title>
        <p>The results of the independent OCI information security audit are recorded in the protocols, which
record the results of tests for compliance with current legislation of Ukraine and draw a conclusion on
the effectiveness of information security at the OCI. The generalized results of the protocols are
formalized by the act of compliance with information security on the OCI and the effectiveness of</p>
        <p>The general scheme of the experimental setup, which implements the information technology of
information security audit of critical information infrastructure objects according to the ideology in Fig.
computer (laptop);
Microsoft Excel software, version higher than 2000;
programmed calculation file.</p>
        <p>The initial data are:
the list of general requirements for cyber protection of critical infrastructure is formed on the
basis of the Resolution of the Cabinet of Ministers dated 2019-06-19, No.518 “On approval of
the General requirements for cyber protection of critical infrastructure” [6];
weighting factors of information security requirements (WVi);
m is the number of components (Kj) in the OCII OCI object.</p>
        <p>As a result of the verification of compliance with the requirements, the following values are
SAOCII OCI is a system administrator of the object of critical information infrastructure of an object
of critical infrastructure;</p>
        <p>CIISAC is a chairman of the Independent Information Security Audit Commission;
MC1-CN are members of the independent information security audit commission;
P1-P9 are audit protocols;</p>
        <p>V1-V9 are general requirements for cybersecurity of critical infrastructure.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>6. Results</title>
      <p>The paper presents a structured methodology for information security audit with a description of
each of the stages.</p>
      <p>The result of an independent OCI information security audit is considered positive if the objects of
the inspection comply with the requirements of the Law of Ukraine “On Basic Principles of Cyber
Security of Ukraine” and ensure effective use of the information security system within certain
standards. Based on the results of the evaluation, a general conclusion is made on the effectiveness of
the information security measures implemented at the inspection facilities of OCI.
12 Calculating
13 Drawing up an act
14 Signing the act</p>
      <p>MC1-CN
SAOCII OCI
CIISAC
MC1-CN
SAOCII OCI
CIISAC
ROCII OCI
calculation of the coefficient of efficiency of information
security on OCII. The result is a numerical value of the
total efficiency factor of information security on the OCII
draft act of compliance of information security on OCII
and efficiency of information security
signing of the audit report by all parties</p>
      <p>To increase the information security of OCII OCI, it is recommended to use information technology
audit of information security of critical infrastructure objects according to the PDCA scheme (Plan, Do,
Chek, Act). The influence of the frequency of the audit on the level of compliance is shown in (Fig. 2).
Important factors for successful evaluation of audit results are:
 awareness and motivation of the management (owner) of the OCII OCI;
 confidentiality;
 trust.</p>
    </sec>
    <sec id="sec-7">
      <title>7. Discussion</title>
      <p>A debatable issue in the development of information technology audit of information security of
critical information infrastructure, which provides verification of compliance of critical information
infrastructure with the general requirements approved by the Cabinet of Ministers of Ukraine dated
2019-06-19, No.518, is the choice of weighting of information security requirements WVi.</p>
      <p>It should be noted that in the review of the scientific literature on the problem of developing methods
of information security audit [8 – 13] in similar decisions, when the generalized indicator is calculated,
it is not taken into account the weight of the importance of information security requirements. In
contrast to these works, in the actual work for the first time it is proposed to take into account the
weighting significance of the information security requirement WVi.</p>
      <p>In this version of information technology, it is proposed to assign a weighting factor by expert
method, which requires prior approval of this value before the audit.</p>
    </sec>
    <sec id="sec-8">
      <title>8. Conclusions</title>
      <p>Therefore, security audit is one of the most effective measures to increase the level of information
security of critical infrastructure.</p>
      <p>The scientific and practical problem of substantiation of the mathematical apparatus is solved in the
work and on its basis the information technology of audit of information security of objects of critical
infrastructure is created. This information technology allows to check the compliance of critical
infrastructure facilities with the general requirements approved by the Resolution of the Cabinet of
Ministers of Ukraine dated 2019-06-19, No.518.</p>
      <p>The scientific novelty of the result is that for the first time the information technology of information
security audit of critical infrastructure facilities was developed, which provides verification of compliance
of critical infrastructure facilities with the general requirements approved by the Cabinet of Ministers dated
2019-06-19, No.518.</p>
      <p>The practical significance of the work lies in the possibility on the basis of the proposed
mathematical apparatus to develop special information technology software.</p>
      <p>Prospects for further research in this area. The presented study does not cover all aspects of this
problem. Theoretical and practical results obtained in the process of scientific research are the basis for its
further study in such areas as the development of information technology software.</p>
    </sec>
    <sec id="sec-9">
      <title>9. Acknowledgements</title>
      <p>The study was conducted by the authors on their own initiative. Funding was provided at their own
expense.
10.References
[1] V.I. Slipchenko, Wars of the sixth generation weapons and military art of the future, Moscow,</p>
      <p>Veche, 2002.
[2] A. G. Petrenko, Action Plan for the implementation of defense reform in 2016-2020 (roadmap for
defense reform), Kiev, DVPSP and MS of the Ministry of defense of Ukraine, 2016.
[3] Law of Ukraine “On basic principles of ensuring cybersecurity of Ukraine”. URL:
https://zakon.rada.gov.ua/laws/show/2163-19.
[4] On the decision of the national security and Defense Council of Ukraine of January 27, 2016 “On
the cybersecurity strategy of Ukraine”, approved by Presidential Decree No. 96/2016 of 15.03.16.</p>
      <p>URL: https://zakon5.rada.gov.ua/laws/show/96/2016.
[5] Decision of the national security and Defense Council of Ukraine of 10.07.17 “On the status of
implementation of the decision of the national security and Defense Council of Ukraine of
December 29, 2016” “On threats to state cybersecurity and urgent measures to neutralize them”,
put into effect by Presidential Decree No.254/2017 of 13.02.17. URL:
https://zakon.rada.gov.ua/laws/show/n0006525-17.
[6] Resolution of the Cabinet of Ministers of Ukraine No. 518 of 19.06.19 “On approval of general
requirements for cyber protection of critical infrastructure facilities”. URL:
https://zakon.rada.gov.ua/laws/show/518-2019-п.
[7] I. M. Kozubtsov, L. M. Kozubtsova, Forecast of possible consequences of the onset of “collapse
of special purpose information systems”, Actual problems of information security management of
the state: sat. abstracts of scientific documents, Nauk. - prakt. conf. (Kiev, March 26, 2021), Kiev,
on the SBU, 2021, pp. 50-53.
[8] M.A. Egorov, Methods of information security audit in modern conditions, Bulletin of Science and</p>
      <p>Education, 2019, 11(65), 2, pp. 34-37.
[9] A. A. Zamula, K. I. Ivanov, V. I. Chernysh, B.V. Volobuev, Methodology of information security
audit, Radio Engineering, 2012, 168, pp. 83-86.
[10] E. V. Ermakova, Methodology of information security audit of personal data information systems
in non-state pension funds, International Scientific Journal “Young Scientist”, 2016, 3(107).
pp. 92-95.
[11] R. I. Zakharchenko, I. D. Korolev, Methodology for assessing the stability of the functioning of
objects of critical information infrastructure functioning in cyberspace, Vol. 10. High-tech
technologies in space research of the Earth, 2018, 2, pp. 52-61.
[12] I. M. Kozubtsov, L. M. Kozubtsova, V. V. Kutsaev, T. P. Tereshchenko, Metodika otseniya
cybernetic Zahi-schist sistemy Svyaznoy organizatsii [methodology for evaluating the cybernetic
security of the organization's communication system], 2018, 1 (31), pp. 43-46.
[13] A. P. Nyrkov, S. A. Rudakova, Methodology of audit of informatization objects according to
information security requirements, Bulletin of the Admiral S. O. Makarov State University of the
Sea and River Fleet, 2012, 3 (15), pp. 146-149.
[14] N. Skobtsov, Information systems security audit. St. Petersburg, Petersburg, 2018.
[15] S. I. Makarenko, Security audit of critical infrastructure by special information impacts.</p>
      <p>Monograph, St. Petersburg, Science-intensive technologies, 2018.
[16] R. Moeller, IT Audit, Control, and Security. Hoboken, John Wile &amp; Sons Inc., 2010.
[17] К. Cardwell, Building Virtual Pentesting Labs for Advanced Penetration Testing, Packt</p>
      <p>Publishing, 2014.
[18] DSTU 2392-94 “Information and documentation. Basic concepts”, Kiev, UkrNDISSI, 1994.
[19] Law of Ukraine “On information protection in information and telecommunications systems” of
05.07.1994, No. 80/94-BP, Verkhovna Rada of Ukraine. URL: https://zakon.rada.gov.ua/
laws/show/80/94-вр.
[20] GOST 33707-2016 (ISO/IEC 2382:2015) Information Technologies (ICS).</p>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>