<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Cybersecurity Indices: Review and Classification</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Mykola</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Khudyntsev</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Andrii</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Davydiuk</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Lebid</string-name>
          <email>o.g.lebid@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Oleksandr Trofymchuck</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem Zhylin</string-name>
          <email>zhylinartem@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>13</institution>
          ,
          <addr-line>Chokolivs'kyi boulevard, Kyiv, 03186</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>G.E. Pukhov Institute for Modelling in Energy Engineering of the National Academy of Sciences of Ukraine</institution>
          ,
          <addr-line>15</addr-line>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>General Naumov str.</institution>
          ,
          <addr-line>Kyiv, 03164</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>International Cybersecurity University</institution>
          ,
          <addr-line>171, 6, Deputats'ka str., Kyiv, 03115, PO Box 10, Kyiv, 04050</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff4">
          <label>4</label>
          <institution>Ukraine</institution>
          ,
          <addr-line>83B, Yu. Illienko str., Kyiv, 04119</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>117</fpage>
      <lpage>126</lpage>
      <abstract>
        <p>The report is devoted to analyzing and classifying cybersecurity indices developed and implemented by leading global, international, and local organizations as of early 2021. It is proposed to include regular (periodic) information materials, which contain expert, analytical, statistical information on the state of cybersecurity and the level of protection of indexing subjects (rating), as well as on certain indicators regarding the harmful impact of implemented information security and cybersecurity threats, to cybersecurity indices. 65 existing cybersecurity indices and approaches for their formation are described. The definition of the terms necessary for the analysis of indexing (rating) in the field of information security and cybersecurity is offered. Cybersecurity, information security, indices, indexes, ratings Research on cybersecurity indicators is an extremely important and urgent task in the field of global security [1-3]. In Ukraine, this task is solved in the framework of building an organizational and technical model of cybersecurity and cyber protection for the national cybersecurity system [4]. The topics of the research are the current world reports, indices, and ratings in the field of information security and cybersecurity. The aim of the study is the describing, review analysis, and classification of cybersecurity indices (ratings) with the proposition of including all different regular (periodic) information materials, expert, analytical and statistical reports, and data. Systematically for mentioned well and little-known indices (rankings, ratings) in the field of information security and cybersecurity we proposed the classification by types and categories, analyzing the main methods of forming these indices to review and analyze the current state of cybersecurity, cybersecurity indices and ratings, approaches to their formation, as well as to determine the main terms required for indexing (rating) in the field of information security and cybersecurity. The paper schematizes information about known cybersecurity indices (ratings), proposes their classification by types and categories and analyzes the main methods of forming these indices (ratings). ORCID: 0000-0002-9324-6901 (M. Khudyntsev); 0000-0003-1238-2598 (A. Davydiuk); 0000-0002-4003-8068 (O. Lebid); 0000-0003-33586274 (O. Trofymchuck); 0000-0002-4959-612X (A. Zhylin) CEUR Workshop Proceedings (CEUR-WS.org)</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>2022 Copyright for this paper by its authors.</p>
      <p>Use permitted under Creative Commons License Attribution 4.0 International (CC BY 4.0).</p>
      <p>The subjects of indexing (rating), depending on the type of index (rating) are countries, industries
(sectors) of the economy, corporations, and organizations (entities).</p>
      <p>The objects of indexing (rating) are the activities of these entities in the fields of information security
and cybersecurity, the security status and level of protection of these entities from the relevant security
threats, as well as certain indicators of security and safety.</p>
      <p>Cybersecurity indices in the sense of high-level indicators (or cybersecurity indexes in the sense of
quantitative indicators) will include regular (periodic) information materials that contain expert,
analytical, statistical information on the security status and level of protection of indexing entities
(ranking), as well as some indicators regarding the harmful effects of the implemented threats to
information security and cybersecurity. Typically, cybersecurity indices are compiled to assess the state
of information security and cybersecurity, as well as the level of protection from threats.</p>
      <p>The list of cybersecurity indices includes some other indices that are indirectly related to
cybersecurity, namely:
 Artificial Intelligence Index
 Index of Corporate Attractiveness
 Digital Economy and Society Index
 Index of ICT Development
 Network Readiness Index
 Nuclear Safety Index (in terms of cybersecurity)</p>
      <p>Cybersecurity ratings will include cybersecurity indices, which are characterized by lists of indexing
(rating) subjects with the definition of the order place of the subject in the list (rating).</p>
      <p>Cybersecurity indices are proposed to be divided by:
 types (Global, International, Corporate)
 categories (Reports, Expert, Network, Data sets, Financial (Exchange), Combined)
 access methods or other indicators (platform, questionnaires, libraries, applications,
automatic or automated, regulatory, technical, marketing)</p>
      <p>Some indices contain features of different types and categories at the same time, so the proposed
classification of cybersecurity indices is conditional.</p>
      <p>Global cybersecurity indices include cybersecurity indices, which relate to the assessment (indexing,
ranking) of countries on the activities of state institutions. Global cybersecurity indices include, for
example, the Digital Economy and Society Index (DESI), the Global Cybersecurity Index (GCI), the
National Cybersecurity Index (NCSI), the National Cyberpower Index (NCPI). The developers of
global cybersecurity indices are usually global and international organizations, such as the European
Commission (EC), the International Telecommunication Union (ITU), or well-known research centers,
such as the Academy of Electronic Government (EGA), the Robert and Rene Belfer Center for Science
and International Relations (BCH).</p>
      <p>International cybersecurity indices include cybersecurity indices that relate to sectors of the
economy, corporations, and organizations in different jurisdictions. Also, the international
cybersecurity indices include an integrated assessment of countries on individual indicators of
cybersecurity, relating to industries (sectors) of the economy, corporations, and organizations of certain
jurisdictions, including when indexing (ranking) is carried out for a limited number of countries.
International cybersecurity indices include, for example, the Cyber Threat Index (CTI), the Cyber
Exposure Index (CEI). International cybersecurity indices are usually developed by rating agencies or
other expert organizations that specialize in information technology and cybersecurity, such as Imperva
Inc. (IMP), Cyber Intelligence House (CIH).</p>
      <p>Corporate cybersecurity indices include cybersecurity indices that apply to corporations and
organizations. Corporative cybersecurity indices include, for example, the BitSight Security Ratings
Platform (BSSR), the Cyber Risk Index (CRI), the Cyber Attacks Timeline Master Indexes (CATMI).
Corporate cybersecurity indices are typically generated by manufacturers of technology products and
solutions or information technology expert organizations, such as BitSight Technology Company
(BST), Trend Micro Inc. (TMI), HACKMAGEDDON (HMG).</p>
      <p>The cybersecurity indices of the reports category include regular (periodic) materials, which, as a
rule, do not contain statistical information and ratings of indexing subjects (ratings) and relate to issues
of analysis and assessment of threats, risks, events, incidents, negative consequences, and other
specialized issues in the areas of information security and cybersecurity, not directly related to the
subjects of indexing (rating), evaluation of their activities and security. The cybersecurity indices of
this category include, for example, Microsoft Security Intelligence Report (MSIR) from Microsoft
(MSF), Command Control Cybersecurity Index (CCCI) from Command Control (Event) - regular
professional conference (CCE), Cybersecurity Capacity Maturity Model Review Reports (CMMRR)
from Oxford University Global Center for Cybersecurity Capabilities (GCSCC).</p>
      <p>Expert cybersecurity indices include cybersecurity indices, which are formed and/or confirmed by
surveys and/or conclusions of specially involved or self-involved experts. Expert cybersecurity indices
include, for example, global cybersecurity indices, such as the Global Cybersecurity Index (GCI), the
National Cybersecurity Index (NCSI), the National Cyberpower Index (NCPI), the Digital Economy
and Society Index (DESI), the Network Readiness Index (NRI). It should be noted that some methods
of expert evaluation are used to form the most of cybersecurity indices, but at the same time for the
most of indices, the methods of examination and formation of groups of experts have significant
differences and features.</p>
      <p>Cybersecurity indices of the network category include cybersecurity indices, which are formed, as
a rule, for individual organizations through a multilevel analysis of control information contained in
data packets transmitted in packet data networks. Organizations, which usually specialize exclusively
in such activities, take part in the collection, processing, and analysis of management information.
Global cybersecurity indices developers include BitSight Technology (BST), SecurityScorecard (SSC),
UpGuard Inc. (UGI) with, respectively, BitSight Security Ratings Platform (BSSR), SecurityScorecard
Ratings Platform (SSR), UpGuard Ratings (UGR). At a local level (of an individual organization or a
particular sector of the economy) in the collection, processing, and analysis of management information
are involved (if available) industry centers for monitoring and responding to information security
incidents (Security Operation Centers). But, as a rule, the SOCs functionality does not provide for
indexing (rating) of entities that use SOC services.</p>
      <p>Cybersecurity indices of the data sets category include cybersecurity indices, which are formed, as
a rule, by means of automatic visualization of data (other than the data used in the formation of
cybersecurity indices of the network category). If data are directly related to financial (exchange)
information, such cybersecurity indices are classified as financial (exchange). The cybersecurity indices
of the data sets category include, for example, the Index of Cybersecurity (ICS) of the New York
University Tandon School of Engineering (TSE), the Cyber Threat Index (CTI) of Imperva Inc. (IMP),
the IBM X-Force Threat Intelligence Index (XFTII) of IBM Inc. (IBM). Cybersecurity indices in the
financial (exchange) category include, for example, the VP Cyber Index (BVPCI) of Bessemer Venture
Partners (BVP), the Foxberry Tematica Research Cybersecurity &amp; Data Privacy USD PR Index (FXCI)
of Foxberry Ltd (FXB), the Indxx Pure Cyber Index (IPCI) from Indxx (IND).</p>
      <p>The cybersecurity indices of the combined category include cybersecurity indices (indicators,
subindexes, domains) to which several other categories can be assigned simultaneously. The
cybersecurity indices of the combined category include the Cyber Risk Index (CRI) of Trend Micro
Inc. (TMI) and the Local Cyber Security Index (LCSI) of the International Cybersecurity University
(ICU).
2.2.</p>
      <p>Methodology of Forming Cybersecurity Indices: Ratings</p>
      <p>The subject or object of indexing (rating) is determined separately for each cybersecurity index. In
a broad sense, by indexing (rating) we mean any method of evaluation.</p>
      <p>The objects of indexing (rating) include:
 activity of indexing subjects (entities) in the field of information security and cybersecurity
 state of information security or cybersecurity of indexing subjects (entities)
 the level of protection of indexing subjects (entities) from threats (cyberthreats)
 certain indicators of information security and cybersecurity, as well as protection against
relevant threats
 some indicators regarding the harmful effects of implemented threats</p>
      <p>Indicators of indexing (rating) are the certain parameters of the subject of indexing (rating), which
are used to describe and evaluate the index. Different cybersecurity indexes contain from 1 to 50
indicators that belong to the subject or object of indexing (rating) and can be evaluated separately (as a
sub-index) or as part of the main index. The list of indicators of indexing (rating) is determined
separately for each index, which is the basis of the methodology of formation of the corresponding
index or rating.</p>
      <p>Methods of indexing (rating):
 examination - definition and expert assessment of indicators of indexing (rating)
 parameterization - quantitative assessment of indicators of indexing (rating)
 indexing - a method of evaluation, the result of which is a dimensionless numerical indicator
(index, score)
 rating - a method of evaluation, the result of which is a natural numerical indicator (number
in the rating)</p>
      <p>
        The methodology of index (rating) formation is based on the methods of expert evaluations, index
method of mathematical statistics or mathematical rating theory [
        <xref ref-type="bibr" rid="ref7">5</xref>
        ]-[
        <xref ref-type="bibr" rid="ref11">9</xref>
        ]. The problem of choosing
and/or optimizing the methodology for determining and forming indices (ratings) will be considered
separately outside the scope of this study.
      </p>
      <p>Methods of index (ratings) formation, as a rule, consist in the use of expert evaluation methods
(Delphi method). Determining the weight of individual indicators in the composition of indexes and
procedures for calculating index values has significant quantitative differences for different indices
(ratings).</p>
      <p>The formation of indices (ratings), usually takes place according to the following procedure:
 creation of an expert group, analysis of the subject of research or improvement of the
procedure for forming the previous version of the index (rating)
 definition of the objects, subjects, and objectives of indexing (rating)
 data collection
 development or improvement of methods of index (rating) formation
 preparation and publication of the report
3. Global Cybersecurity Indices Data
1st Edition
2016
2021
2016
2016
2011</p>
      <p>Qual.</p>
      <p>4
1
ထ
ထ
ထ</p>
      <p>Country</p>
      <p>SAR
USA
USA
USA
USA</p>
      <p>CAI
CATMI
CCCI
CCI
CEI
CGI
CGI
CHRI
CIGBR
CMAPR
CMMRR</p>
      <p>CNI
CPI
CPP
CRI
CRI
CRI</p>
      <p>Corporate,
Financial
(Exchange)
International,</p>
      <p>Expert
International,</p>
      <p>Data sets
Corporate,</p>
      <p>Reports
Corporate,</p>
      <p>Data sets
International,</p>
      <p>Corporate,
Network
Corporate,
Data sets
Global,
Network</p>
      <p>Corporate
(Individuals),</p>
      <p>Expert
Global,</p>
      <p>Reports
International
(Regional),</p>
      <p>Reports
Global,</p>
      <p>Reports
International,</p>
      <p>Data sets
International,</p>
      <p>Reports
Global,</p>
      <p>Reports
International,</p>
      <p>Reports
International,</p>
      <p>Data sets
Corporate,
Combined
2008 (USA)
1
10
2
2w
9
ထ
ထ
2
1
4
ထ
2
ထ
2
3
3
USA
ITA
DEU
USA
SGP
LXB
USA
USA
UKR
AUS
GBR
USA
USA
CHE
USA
USA
USA</p>
      <p>CSI
CSI
CSPI
CTI
DESI
ECSI
ECSIF
FCRS</p>
      <p>FXCI
GCARC</p>
      <p>GCI
GCSI
GTIR
HXR
ICBI
Corporate,
Financial
(Exchange)
Corporate,</p>
      <p>Reports
Corporate,
Financial
(Exchange)
International,</p>
      <p>Data sets
International,
Expert, Data</p>
      <p>sets
International,</p>
      <p>Data sets
Corporate,
Financial
(Exchange)
Corporate,
Financial
(Exchange)
Corporate,
Financial
(Exchange)
International,</p>
      <p>Reports
Global, Expert
International,</p>
      <p>Reports
International,</p>
      <p>Reports
Corporate,
Financial
(Exchange)
Corporate,</p>
      <p>Reports
1m
1y
n/a
ထ
ထ
6m
2
4
4
ထ
21
USA
USA
DEU
USA
EU
NLD
CAN
USA
GBR
USA
UN
USA
JPN
USA
GBR</p>
      <p>Kaspersky
Cybersecurity</p>
      <p>Index</p>
      <p>S&amp;P Kensho
Cyber Security</p>
      <p>Index</p>
      <p>S&amp;P Kensho
Future Security</p>
      <p>Index</p>
      <p>Local Cyber
Security Index</p>
      <p>Microsoft</p>
      <p>Security
Intelligence</p>
      <p>Report
National Cyber</p>
      <p>Power Index</p>
      <p>National
CyberSecurity</p>
      <p>Index
Nasdaq CTA
Cybersecurity</p>
      <p>Index
Network
Readiness</p>
      <p>Index</p>
      <p>Nuclear
Security Index
Prime Cyber
Defense Index
IDI
IECSI
IPCI
KCI
KCSI
LCSI
MSIR
NCPI
NCSI
NRI
NSI</p>
      <p>PCDI
NQCYBR
PCS GCS
PVTM
RL CIR
RRCR</p>
      <p>Corporate,</p>
      <p>Data sets
Global, Expert
International,</p>
      <p>Financial
(Exchange)
Corporate,
Financial
(Exchange)
International,</p>
      <p>Expert
Corporate,
Financial
(Exchange)
Corporate,
Financial
(Exchange)
Corporate,
Combined</p>
      <p>Global,</p>
      <p>Reports
International,</p>
      <p>Expert
Global, Expert
International,</p>
      <p>Financial
(Exchange)
Global, Expert
Global, Expert</p>
      <p>Corporate,
Financial
(Exchange)</p>
      <p>Corporate,
Expert
Global,</p>
      <p>Network
International,</p>
      <p>Reports
2000
(2019)
2012
2017
~ 2017
2019
&lt;2016
2019
1m
8
6m
1y
n/a
ထ
ထ
1
6m
1
ထ
ထ
3
2y
3m
n/a
ထ
ထ
UN
SNG
USA
RUS
USA
USA
UKR
USA
GBR
EST
USA
USA
USA
USA
USA
FRA</p>
      <p>USA
USAGBR</p>
      <p>CAN
ထ - great number of issues, y - per year, m - per month, w - per week
SGCSI
SSR
TRIC
UGR
USI
XFTII</p>
      <p>International,</p>
      <p>Reports
Corporate,
Financial
(Exchange)</p>
      <p>Global,
Network
Corporate,</p>
      <p>Expert
Global,</p>
      <p>Network
International,</p>
      <p>Expert
International,</p>
      <p>Data sets
BKCRRP</p>
      <p>BSSR
BVPCI</p>
      <p>CAI
CATMI
CCCI
CCI
CEI</p>
      <p>Black Kite Inc.</p>
      <p>BitSight Technology LTD</p>
      <p>Bessemer Venture</p>
      <p>Partners
Institute of Electrical
and Electronics</p>
      <p>Engineers
HACKMAGEDDON
Command Control</p>
      <p>(Event)
Chubb Group Holdings</p>
      <p>Inc.</p>
      <p>Cyber Intelligence</p>
      <p>House
Index</p>
      <p>FXCI
GCARC</p>
      <p>GCI
GCSI
GTIR
HXR
ICBI
ICS
IDI
IECSI
IPCI
USA
USA
USA
USA</p>
      <p>USA</p>
      <p>Publisher</p>
      <p>Foxberry Ltd
Tenable Network</p>
      <p>Security</p>
      <p>International
Telecommunication</p>
      <p>Union
Center for Strategic
and International</p>
      <p>Studies
NTT Security LTD
Nasdaq Group Inc.</p>
      <p>Neustar, Inc.</p>
      <p>Tandon School of
Engineering (New
York University)</p>
      <p>International
Telecommunication</p>
      <p>Union
Singapore Exchange</p>
      <p>LTD
Indxx
CGI
CHRI
CIGBR</p>
      <p>LCSI
CMAPR
CMMRR</p>
      <p>CNI
CPI
CPP
CRI
CRI
CRI
CRLEI</p>
      <p>CSI
CSI
CSPI
CTI
DESI
ECSI
ECSIF
FCRS</p>
      <p>Cyberhedge EUROPE</p>
      <p>S.a.r.l
CyberGreen Institute
Wakefield Research</p>
      <p>International
Cybersecurity</p>
      <p>University
Australian Strategic</p>
      <p>Policy Institute</p>
      <p>Global Cyber
Security Capacity Centre
(University of Oxford)</p>
      <p>Carnegie Endowment
for International Peace</p>
      <p>EMC Corporation
United Nations Institute
for Disarmament</p>
      <p>Research
Potomac Institute for</p>
      <p>Policy Studies
NordVPN.com &amp;</p>
      <p>Tefincom S.A.</p>
      <p>Trend Micro Inc.&amp;</p>
      <p>Ponemon Institute
Oliver Wyman Forum
Morgan Stanley Capital</p>
      <p>International Inc.</p>
      <p>Dell Secure Works
(Counter Threat Unit)
Vontobel Holding AG</p>
      <p>Imperva Inc.</p>
      <p>European Commission</p>
      <p>VPNoverview
Evolve ETFs</p>
      <p>FICO</p>
      <p>KSECUREP
KCSI
MSIR
NCPI</p>
      <p>NCSI
NQCYBR</p>
      <p>NRI
NSI</p>
      <p>PCDI
PCS GCS
PVTM
RL CIR
RRCR
SCR
SGCSI
SSR
TRIC
UGR
USI
XFTII
S&amp;P Dow Jones</p>
      <p>Indices LLC
S&amp;P Dow Jones</p>
      <p>Indices LLC</p>
      <p>Microsoft
Belfer Centre (Harvard</p>
      <p>University)
e-Governance</p>
      <p>Academy
Nasdaq Group Inc.</p>
      <p>World Economic
Forum (Portulans</p>
      <p>Institute)
Nuclear Threat</p>
      <p>Initiative</p>
      <p>ETF Ventures LLC
Verisk Analytics, Inc.</p>
      <p>Prevalent, Inc.</p>
      <p>ReportLinker.com</p>
      <p>RiskRecon Co.</p>
      <p>Accenture</p>
      <p>Soloactive AG
SecurityScorecard Co.</p>
      <p>Travelers Indemnity</p>
      <p>Co.</p>
      <p>UpGuard Inc.</p>
      <p>Unisys Company</p>
      <p>IBM Inc.
4. Main Results and Conclusion</p>
      <p>The development of high-level indicators to describe the state of information security and
cybersecurity of individual organizations, sectors (industries) of the economy, critical (including
digital) infrastructures, states, regions, and the world as a whole is gradually becoming the main task of
public and global security. A nonlinear increase in the rate of formation of the global hierarchy of safety
indicators can be observed. The problem of defining a system of safety indicators, even at a special
level, remains unsolved and an extremely urgent task.</p>
      <p>For the first time in the frame of a single study 65 existing global, international, and corporate
cybersecurity indices and approaches to their formation are described and analyzed. The definition of
the terms necessary for the analysis of indexing (rating) in the field of information security and
cybersecurity is offered.</p>
      <p>The materials of the report could be used for making a national contribution to the global
cybersecurity reports of the world and international organizations in the field of information and
communication technologies, telecommunications, and cybersecurity (ITU, FIRST, GFCE).
5. Acknowledgements</p>
      <p>The research within the project "Development of a Methodology for the Formation of Cybersecurity
Indices and Implementation of the Original Integrated Cybersecurity Index (national, regional, sectoral,
entity level)" is organized by the International University of Cybersecurity and supported by the
Administration of the State Service of Special Communication and Information Protection of Ukraine,
Ministry of Internal Affairs of Ukraine, Ministry of Energy of Ukraine.</p>
      <p>The authors are grateful for supporting the research and for discussions in the field of cybersecurity
with colleagues from the Office of the National Security and Defense Council of Ukraine, the State
Service of Special Communications and Information Protection and the Institute of
Telecommunications and Global Information Space.</p>
    </sec>
    <sec id="sec-2">
      <title>6. References</title>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          2.
          <string-name>
            <given-names>Cybersecurity</given-names>
            <surname>Indices</surname>
          </string-name>
          : Rankings, Ratings
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>2.1. Cybersecurity Indices: Definitions, Types, Categories</mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>J.</given-names>
            <surname>Lewis</surname>
          </string-name>
          , G. Neuneck, “
          <article-title>The Cyber Index International Security Trends and Realities”, UNIDIR United Nations Institute for Disarmament Research Geneva</article-title>
          , Switzerland,
          <year>2013</year>
          , no.
          <issue>3</issue>
          , URL: https://www.files.ethz.ch/isn/165142/the-cyber
          <article-title>-index- international-security-trends-and-realitiesen-463</article-title>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <source>[2] Global Cybersecurity Index</source>
          <year>2018</year>
          , v.4, ISBN 978-92-61-28201-1, International Telecommunication Union, CH-
          <volume>1211</volume>
          , Geneva, Switzerland,
          <year>2019</year>
          , 90 p., URL: https://www.itu.int/en/ITU-D/Cybersecurity/Pages/global-cybersecurity-index.aspx
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [3]
          <string-name>
            <surname>S. Gnatyuk</surname>
          </string-name>
          <article-title>and oth</article-title>
          .., “
          <article-title>Method of Cybersecurity Level Determining for the Critical Information Infrastructure of the State”</article-title>
          , [COAPSN-2020: International Workshop on Control,
          <source>Optimisation and Analytical Processing of Social Networks]</source>
          ,
          <year>2020</year>
          , URL: http://ceur-ws.org/Vol2616/paper28.pdf
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>R.</given-names>
            <surname>Boyarchuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Khudyntsev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Lebid</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Trofymchuk</surname>
          </string-name>
          , “
          <article-title>Organizational and Technical Model of National Cybersecurity and Cyber Protection”</article-title>
          ,
          <source>[CPITS'2021, Workshop on Cybersecurity Providing in Information and Telecommunication Systems CEUR Workshop Proceedings ISSN 1613-0073, January</source>
          <volume>28</volume>
          ,
          <year>2021</year>
          , NURE, Kyiv, Ukraine], URL: http://ceur-ws.org/Vol2746/frontmatter.pdf
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>I.</given-names>
            <surname>Gormley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Frühwirth-Schnatter</surname>
          </string-name>
          , “Mixtures of Experts` Models”, arXiv:
          <year>1806</year>
          .
          <article-title>08200v1 [stat</article-title>
          .ME],
          <volume>21</volume>
          June,
          <year>2018</year>
          , Preprint,
          <volume>38</volume>
          p., URL: https://www.researchgate.net/profile/ Sylvia_Fruehwirth-Schnatter/publication/325922320_Mixtures_ofdEfelin -Experts-Models.pdf
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [6]
          <string-name>
            <surname>P. Lutereau</surname>
          </string-name>
          <article-title>and oth</article-title>
          ., “General Criteria: Group Rating Methodology”, Standard&amp;
          <string-name>
            <surname>Poor's Financial Services</surname>
            <given-names>LLC</given-names>
          </string-name>
          ,
          <year>2013</year>
          , 51 p., URL: https://www.maalot.co.il/Publications/MT20180219160103.pdf
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>L.</given-names>
            <surname>Davidson</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Ling</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Sargis</surname>
          </string-name>
          , T. Strauts, “Morningstar Quantitative Rating for funds”,
          <source>19 March</source>
          ,
          <year>2018</year>
          , 37 p.,
          <string-name>
            <surname>Morningstar</surname>
          </string-name>
          , URL: https://s21.q4cdn.com/198919461/files/doc_downloads/
          <year>2019</year>
          /11/Morningstar-Quantitative-
          <article-title>Rating-for-funds-Methodology-v14</article-title>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>A.</given-names>
            <surname>Solodov</surname>
          </string-name>
          ,
          <article-title>Mathematical principles of building rating systems</article-title>
          , Economics, Statistics, and
          <string-name>
            <surname>Informatics</surname>
          </string-name>
          ,
          <year>2016</year>
          , №
          <volume>1</volume>
          , p.
          <fpage>75</fpage>
          -
          <lpage>82</lpage>
          (in Russ.), URL: https://cyberleninka.ru/article/n/ matematicheskie- printsipy
          <article-title>-postroeniya-reytingovyh-sistem</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>M.</given-names>
            <surname>Lyndina</surname>
          </string-name>
          ,
          <string-name>
            <surname>A</surname>
          </string-name>
          . Orlov,
          <source>Mathematical theory of ratings. Nauchnyy zhurnal KubGAU [Scientific Journal of KubSAU]</source>
          ,
          <year>2015</year>
          , no.
          <issue>114</issue>
          , p.
          <fpage>1</fpage>
          -
          <lpage>26</lpage>
          (in Russ.). URL: http://sj.kubsau.ru/
          <year>2015</year>
          /10/pdf/01.pdf
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>