<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>model of guarantee capacity and cyber security management in the critical automated systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Hennadii</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Hulak</string-name>
          <email>h.hulak@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Skladannyi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sokolov</string-name>
          <email>v.sokolov@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yevhen</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Academician Glushkov ave. 42</institution>
          ,
          <addr-line>Kyiv, 03187</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Borys Grinchenko Kyiv University</institution>
          ,
          <addr-line>Bulvarno-Kudriavska str. 18/2, Kyiv, 04053</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Institute of Mathematical Machines and Systems Problems National Academy of Science of Ukraine</institution>
        </aff>
      </contrib-group>
      <abstract>
        <p>The paper examines the methods of increasing the effectiveness of guarantee capacity management and cyber security of automated systems in critical infrastructure. The use of Anthony's business management model is proposed to build a management system. A binary relation of partial order on a set of functional security profiles of computer systems is proposed to arrange the levels of security. The dynamic model of the provision of capacity and cyber security and critical performance indicators proposed in the paper can be used to model the behavior of critical infrastructure objects and form balanced management decisions in the relevant industries. cybersecurity culture, critical infrastructure management CMiGIN 2022: 2nd International Conference on Conflict Management in Global Information Networks, November 30, 2022, Kyiv, Ukraine ORCID: 0000-0001-9131-9233 (H. Hulak); 0000-0002-7775-6039 (P. Skladannyi); 0000-0002-9349-7946 (V. Sokolov); 0000-0003-4984686X (Y. Hulak); 0000-0002-4967-8395 (V. Korniiets)</p>
      </abstract>
      <kwd-group>
        <kwd>model</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Scientific and practical interest in constructing protected, guarantee-capable automated systems
(AS) is constantly growing. This is due to high requirements for information services to critical
infrastructure objects. The task of rational management of such systems is greatly facilitated by the use
of effective platforms such as SIEM [2], Threat Intelligence [3], the MITRE ATT&amp;CK knowledge base
[4], cyber attack attribution technology [5], and many other tools. Let us note that the system's guarantee
capacity is an integral characteristic of its ability to provide services, defined in its use regulations and
conditions [1].</p>
      <p>At the same time, comprehensive support of dynamic rational management of guarantee capacity
and cyber security (G&amp;C) in AS is a relatively expensive and complex process, for which proposing a
practical methodology is a non-trivial task. Many scientific publications are devoted to solving such
problems, but searching for new solutions continues. The main difficulty of the task lies in the fact that
protection functions in computer systems are primarily discrete by definition, which entirely or partially
makes it impossible to apply known mathematical methods of management optimization.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related Works</title>
      <p>In particular, in [6], the issue of applying situational management methods based on signature
models was considered to make the best decision regarding the management of information protection
EMAIL:
p.skladannyi@kubg.edu.ua
(P.</p>
      <p>Skladannyi);</p>
      <p>2022 Copyright for this paper by its authors.
objects. At the same time, it was noted that the features of these systems influence the possibility of
applying traditional methods of optimal management.</p>
      <p>It is necessary to clarify the essence of these differences a little, agreeing in principle with this thesis.
Namely, it concerns the implementation of system management (in our case, the management of G&amp;C)
in conditions of uncertainty and negative influence on it both from the side of cyberspace and as a result
of intentional or accidental actions of its legal users; management goals and objectives can be
formulated both qualitatively and quantitatively; the description of the object is very difficult to
formalize.</p>
      <p>In [7,8], the methodology of formalization of the states of the controlled system underwent further
development, but, in our opinion, a particular shortcoming of these works, as well as of the previous
study [6] by these authors, is the lack of criteria for achieving a defined goal, which would determine
the state of information security. As a result, in [6], the conclusion announces only the possibility of
applying an algorithmic approach to determining the complete set of situations, creating a knowledge
base, the use of which will contribute to increasing the validity of management decisions in the case of
applying the proposed method of using the signature model of the management of objects of the
information protection system.</p>
      <p>In [9], it is proposed how to build a mathematical model of comprehensive security of computer
systems (CS) based on expert judgments. The research uses indicators of the level of security according
to some undefined criteria. It is shown that the application of the modified method of loose ranking
allows determining the Fishburn weights for one level of the hierarchy. In [10], the author continued
the study of the comprehensive security of CS by assessing the probabilities of the realization of some
threats without reference to specific security criteria.</p>
      <p>In [11], the conceptual provisions of several research initiatives related to innovative technologies
for cloud computing in environmental security, quality assurance, service composition, and system
management are considered. Also, intrusion detection technologies, customer security issues,
experimental evaluation of routing for grid and cloud, and improving the simulator for validating an
approach to environmental cloud computing are presented without formalization. In general, the
problems of the top management of an enterprise are considered.</p>
      <p>In [12], the critical organizational tasks of a cyber security center are defined in terms of security
management, including the implementation of the components of the organizational and technical
model of cyber protection; monitoring of the global state of cyber security of nuclear energy facilities;
combating cyber threats by increasing general situational awareness of incidents and vulnerabilities of
information systems and systems for protecting critical infrastructure objects; reduction of
vulnerabilities, prevention of threats and their effective localization; conducting training and increasing
the level of awareness in terms of cyber security among managers of critical infrastructure [13].</p>
      <p>Scientific and practical interest in security management is the generally unsolved problem of
dynamically linking the states of an automated system to the established criteria of its security. This
work is dedicated to the steps to its solution.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Problem Statement</title>
      <p>To begin with, according to the canons of philosophical science, the protection of information, in
general, should be characterized by the same categories as other types of productive human activity
[14]. This provides logical grounds for the use of the best scientific and practical developments in the
field of effective management of entrepreneurial (business) activity for the formation of general
approaches to the rational management of the system of G&amp;C provision, which should be supplemented
with methods and models specific to the field under investigation.</p>
      <p>In the classic work of Robert Anthony [15], to describe the structure of effective management of a
company (organization), an organizational model called the Anthony triangle (Fig. 1) was proposed,
which was later used to define the tasks of information systems [16].</p>
      <p>In [15], it is proposed to distinguish the following categories (levels) of management:
 Strategic planning is a decision-making process regarding the goals of the enterprise
(organization), changes in these goals, resources used to achieve these goals, and the policy that
should guide the acquisition, use, and disposal of these resources. This category corresponds to the
strategic level of management.
 Management control is a process by which managers ensure that resources are used efficiently
and effectively to achieve the organization’s goals. This category corresponds to the so-called
tactical level of management.
 Operational control is the process of ensuring the effective and efficient performance of
specific tasks. This process is implemented at the operational level of management.</p>
      <p>For a better understanding of the term “operational control” (English), please note that this concept
in German corresponds to the term “Betriebskontrolle” (production control). Therefore, in the
Ukrainian translation of the English term, we prefer the term “operations control” (the adjective is
related to the subject of control operations) instead of “operational” control (the adjective is associated
with the time of control execution).</p>
      <p>The main difference between management control and operational control is due [15] to the
difference between the set of activities called management and the actions related to the performance
of defined tasks.</p>
      <p>In particular, operational control is concerned with technology and procedures, while managerial
control is primarily concerned with personnel. In addition, operational control only requires the
adoption of a small number of decisions since the tasks, goals, and resources required for the effective
functioning of the organization must be defined in detail during strategic planning and management
control.</p>
      <p>
        The Anthony triangle model shown in Fig. 1 differs from its widespread depictions by the presence
of an essential, in our opinion, addition. Each task at the strategic management level   ,  =
1,   generates a set of tasks at the tactical and operational levels associated with it
{  1, … ,   } and {  11, … ,   }. (
        <xref ref-type="bibr" rid="ref1">1</xref>
        )
      </p>
      <p>Taking into account the multi-year comprehensive approbation of the Anthony triangle model, it is
proposed to consider the mechanism of its application in the case of managing measures to ensure the
safety and security of G&amp;C of information systems of critical infrastructure.</p>
      <p>Namely, by analogy with the Anthony triangle to increase the efficiency of management activities,
it seems appropriate to divide measures to support, develop, improve or restore the level of G&amp;C of
information systems into several levels (Table 1) based on characteristics of the tasks to be solved,
categories and competencies of personnel, which is directly responsible for and takes care of solving
the problems of G&amp;C as well as the amount of financial, material and time costs for their
implementation.</p>
    </sec>
    <sec id="sec-4">
      <title>4. Ranking of Systems by Management Levels</title>
      <p>The primary tasks of different levels of management in Table 1 are defined based on NATO
approaches to cyber defense [17] and developments in [13].</p>
      <p>In the general case, without focusing on a specific area of the organization’s work, to assess the
effectiveness of management actions according to [18], key performance indicators (KPI) should be
ІС owner</p>
      <sec id="sec-4-1">
        <title>Tactical</title>
        <p>1. Approval of security policy,
determination of its goals and
objectives, and financial, material, and
human resources.
2. Normative regulation of aspects of
cyber security.
3. Allocation of additional resources to
eliminate the consequences of cyber
incidents.
4. Making decisions regarding the work
order in an emergency.
5. Organization of training and
education of personnel and their
motivation.
6. Ensuring physical security.
1. Monitoring and assessment of the
current state of threats to the system.
2. Organization of system security
assessment and audit.
3. Determination of authority and
management of the access control
system.
4. Monitoring the level of training and
education of security operators and
system users.
5. Planning work in emergency
conditions.
6. Management of restoration
measures.
1. Management of hardware and
software protection, including
installation, adjustment, and
maintenance.</p>
      </sec>
      <sec id="sec-4-2">
        <title>2. Carrying out recovery works after incidents.</title>
        <p>formed, the use of which allows for the analysis and measurement of the success of selected measures
on the way to achieving the expected result. Having reliable KPIs is critical for companies implementing
performance management systems. It is proposed to choose ordered functional security profiles as KPIs
that will be dynamically changing.</p>
        <p>From the beginning, to formalize some procedures, we will introduce the relation operator on the set
of security criteria of CS against unauthorized access { 1 , … ,   } [19].</p>
        <p>Note that we further consider that if some criterion   is not applied to describe the security of a
particular CS, its current value is equal to ∅ an “empty” element, and this is the lowest level of security
compared to any other value of this criterion.</p>
      </sec>
      <sec id="sec-4-3">
        <title>Costs</title>
      </sec>
      <sec id="sec-4-4">
        <title>Significant (purchase</title>
        <p>of fixed assets +</p>
        <p>training and
maintenance of
personnel + work of
external contractors)</p>
      </sec>
      <sec id="sec-4-5">
        <title>Term</title>
      </sec>
      <sec id="sec-4-6">
        <title>Long</title>
      </sec>
      <sec id="sec-4-7">
        <title>Average (maintenance)</title>
      </sec>
      <sec id="sec-4-8">
        <title>Medium</title>
      </sec>
      <sec id="sec-4-9">
        <title>Average (maintenance + supplies)</title>
      </sec>
      <sec id="sec-4-10">
        <title>Short (2) (4) (5)</title>
        <p>
          The two values   (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) and   (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) of the quantitative or qualitative criterion     ∀  = 1, 
will
be called those connected by the “majority” ratio:   (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ≺   (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) if the second value of the criterion
corresponds to the highest level of security. For instance, in the case of the examples of security profiles
given in [20]:
        </p>
        <p>
          1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) = {КА = 1},  1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) = {КА = 3} and  1(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) = {∅},
we have
        </p>
        <p>
          1(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) ≺  1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ),  1(
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) ≺  1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ),  1(
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ≺  1(
          <xref ref-type="bibr" rid="ref2">2</xref>
          ). (
          <xref ref-type="bibr" rid="ref3">3</xref>
          )
        </p>
        <p>Next, we consider that the available security profile of the CS is a tuple  ( ) =
〈 1( 1), … ,   (  )〉, which includes all criteria of CS security against unauthorized access from their
set { 1 , … ,   } [21].</p>
        <p>
          We will assume that two security profiles are connected by the ratio  (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ≺  (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) if the inequality
holds:
|{( 1, … ,   ):   (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ≺   (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ∀ = 1,  }| &lt; |{( 1, … ,   ):   (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ≺   (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ∀ = 1,  }|.
        </p>
        <p>
          We will call two profiles practically indistinguishable  (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ≅  (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) if it has:
|{( 1, … ,   ):   (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ≺   (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ∀ = 1,  }| = |{( 1, … ,   ):   (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ≺   (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) ∀ = 1,  }|.
        </p>
        <p>
          The binary relation constructed in this way is not an equivalence relation [22]. It is reflexive and
symmetrical but not transitive. Regarding non-fulfillment of the transitivity property, it is enough to
consider the following example: let  (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) = 〈1,2,1,2〉,  (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) = 〈2,1,2,1〉,  (
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) = 〈1,3,2,1〉.
According to (
          <xref ref-type="bibr" rid="ref5">5</xref>
          ), we have  (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) =  (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ),  (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ) =  (
          <xref ref-type="bibr" rid="ref3">3</xref>
          ), while according to (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ), we have  (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) ≺
 (
          <xref ref-type="bibr" rid="ref3">3</xref>
          ). Intuitively, in the proposed trio, the last hypothetical profile is, in a certain sense, correct.
        </p>
        <p>
          Let us pay attention to that from (
          <xref ref-type="bibr" rid="ref4">4</xref>
          ) and (
          <xref ref-type="bibr" rid="ref5">5</xref>
          ) follows that  =  and
        </p>
        <p>
          +  = 2 ∙  =  −  , (
          <xref ref-type="bibr" rid="ref6">6</xref>
          )
where  is the number of criteria not used simultaneously in the security profiles  (
          <xref ref-type="bibr" rid="ref1">1</xref>
          ) and  (
          <xref ref-type="bibr" rid="ref2">2</xref>
          ).
        </p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Method of Decision-Making</title>
      <p>To build security management, conducting an analysis of the output data for implementing the cyber
protection system project and decision-making regarding current actions in various conditions is
considered appropriate. First, let’s consider that according to the definition of regulatory documents of
the technical information protection system [23], a computer system is a set of hardware and software
that is a target of evaluation. A security profile characterizes this object of evaluation after testing.</p>
      <p>At the same time, information services necessary for organizations (enterprises) are provided by
various automated systems—AS (information, telecommunications, etc.), which all include the
personnel for these systems. The execution of the primary tasks of G&amp;C at all levels of management
(Table 1) requires the person to possess specific knowledge, abilities, skills, and qualities [24].</p>
      <p>In [25], the corresponding set of characteristics is defined as the Cyber Security Culture (CSC) of
the organization, which refers to the knowledge, beliefs, ideas, attitudes, assumptions, norms, and
values of people regarding cyber security and how they manifest in people while handling information
technologies. Note that the high level of CS security specified by the protection profile only guarantees
the security of the accurate AS if the CSC level is low [26].</p>
      <p>Thus, within the framework of an integrated approach to ensuring the G&amp;C of the AS, the
implementation of effective management requires consideration at the strategic and tactical levels of
the current state and dynamics of changes in the CSC level.</p>
      <p>It is generally challenging to formulate an integral characteristic of CSC, so a heuristic approach to
assess the achievement of the required level of CSC based on the Turing test [27] has been proposed,
which is theoretically applicable for distinguishing artificial intelligence from natural intelligence.</p>
      <p>The test mentioned above can be interpreted as follows: the expert interacts with a computer and a
person. Using the answers to the questions, the expert must establish with whom or what he is in contact.
The task of artificial intelligence is to give the expert the impression of communication with natural
intelligence.</p>
      <p>In the situation under study, we have the opposite case: a person's activity (security operator, user)
in typical situations must fully meet the requirements of the approved instructions. The risk of erroneous</p>
      <sec id="sec-5-1">
        <title>Categories of criticality of CIO</title>
      </sec>
      <sec id="sec-5-2">
        <title>IV necessary objects</title>
      </sec>
      <sec id="sec-5-3">
        <title>III important objects</title>
      </sec>
      <sec id="sec-5-4">
        <title>II vitally important objects</title>
      </sec>
      <sec id="sec-5-5">
        <title>I especially important objects</title>
        <p>E/D
D/C
C/B</p>
        <p>B/A
actions must be minimal. Based on this, the critical task of the operational and tactical levels of
management is to increase and maintain CSC in the organization at a level that is adequate to the degree
of reliability of the applied information technologies and to exclude the possibility of such a negative
phenomenon as the “human factor” [28] in the AC.</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>6. Cyber Security Culture Level Sufficiency Model</title>
      <p>Raising the level of CSC should be facilitated by conducting exercises, training, and ongoing
monitoring of acquired skills at the tactical level [29, 30]. At the same time, the European Credit
Transfer System (ECTS) scale [30] should be an effective tool for rating the control of knowledge and
skills of a student.</p>
      <p>Let us take into account that this evaluation scale includes five positive levels of the quality of
training of a future specialist, namely, the highest—A (negligible number of errors), medium levels B,
C, satisfactory level D, and the lowest—E (satisfies the minimum criteria) as well as negative
evaluations of F and Fx.</p>
      <p>On the example of the model of the required level of CSC in the organization (Table 2), it is possible
to find out how the security of the organization's personnel can be managed using the definition of the
criticality category of the critical infrastructure object (CIO) [27]—the indicator that characterizes the
probability of the implementation of cyber attacks and the average assessment of the level of cyber
security culture in the organization.
of critical infrastructure objects</p>
      <p>In Table 2, the following designations are used:  
is an indicator that characterizes the probability
of implementing cyber attacks against the object of information activity, which should be called the
state of aggressiveness of the external environment. In [11], as part of analyzing the motives, goals, and
tasks of invasions from different positions, it was noted that knowledge of these factors improves the
situation by preventing possible consequences.</p>
      <p>In our case, from the point of view of implementing preventive measures, the emphasis of the
managerial response is somewhat different. Namely, the question arises of how the current situation in
cyberspace differs from the typical situation and how to use human potential to increase the resistance
of the AS.</p>
      <p>Clearly, the relevant states’ definition requires a global analysis [15] of the political, military,
economic, and other goals and aspirations of individual states and their alliances or criminal groups.
This issue is of separate scientific interest and requires individual processing. Within the framework of
this study, we highlight the following situations:




 
 
 
 
= 0 normal state of the external environment.
= 1 increased level of danger.
= 2 high level of danger.</p>
      <p>= 3 a very high level of danger.</p>
      <p>Note that the  
characteristic related to the value ex is the  
trend of the number of cyberattacks
observed in cyberspace over a certain period: if the number of cyberattacks increases, then we have


&gt; 0, in the case of no increase in the number of cyberattacks  
≤ 0. At the same time |  | is the
the average score of the CSC level for the state
of aggressiveness of the external environment  
 
= 0/ 
 
= 1/ 
 
= 2/</p>
      <p>= 3/ 
D/C
C/B
B/A</p>
      <p>A</p>
      <p>C/B
B/A</p>
      <p>A
А</p>
      <p>B
A
А
А
absolute value of the trend is the difference in the number of cyber attacks in the external environment
for two consecutive periods (week, decade, or month).</p>
      <p>Significant growth of this trend (  ) over a certain period may indicate the need to recognize the
environment's new state of aggressiveness. Conversely, a significant drop in the number of observed
cyberattacks may be a reason to return to the previous state of determining the CSC characteristics   .</p>
      <p>Adopting a decision at the strategic level of management to establish a higher state of aggressiveness
of the environment   should immediately activate the mechanisms for increasing the level of system
security with the help of organizational measures and additional software and technical
means (Table 1).</p>
      <p>In particular, organizational measures can provide for the work of reinforced regular shifts, the early
change of keys and passwords, the limitation of the powers of users in the access control system, and
most importantly—targeted work with personnel that affects the level of the system’s GIS, to increase
its professionalism and discipline (indicators:   is the average current rating,  ℎ is the trend of the
CSC indicator, which reflects changes in the level of professional training and compliance with the
norms (discipline) of cyber security).</p>
      <p>It should be noted that even under normal conditions,   and  ℎ indicators can considerably
deteriorate as a result [14] of significant changes in the organizational structure of the enterprise,
ineffective management motivation policy, miscalculations in personnel work, staff turnover, and the
influence of external factors. Therefore, an essential task of the tactical level of management (Table 1)
is to monitor the level of training and education of personnel.</p>
      <p>In the proposed model, the characterization of the criticality of a specific object of information
activity, if it does not fall under the legally established classification [27], should be determined a priori
taking into account the importance of the sphere of public production, possible damage in the event of
a decrease or loss of the guarantee capacity of the system (inaccessibility of its services), destruction of
information resources and software systems, lost profits and costs of restoration work.</p>
    </sec>
    <sec id="sec-7">
      <title>7. Functional Security Profile of Computer Systems</title>
      <p>at that</p>
      <p>Based on what has been stated regarding the connection of CSC indicators with the level of G&amp;C of
an AS, it seems appropriate to supplement the functional profile of the security of the CS, which was
checked during its evaluation and presented in the form of the tuple  ( ) = 〈 1( ), … ,   ( )〉, by
another mandatory criterion   +1( ) expressing the level of cyber security culture of CSC personnel,
which takes values from the set { .  ,  ,  ,  } based on the model of the given Table 2 and explanations
to it.</p>
      <p>Thus, the additional criterion can acquire the following meanings:</p>
      <p>
        +1(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) = { =  }, (
        <xref ref-type="bibr" rid="ref7">7</xref>
        )
  +1(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ) = { =  }, … ,   +1(
        <xref ref-type="bibr" rid="ref5">5</xref>
        ) = { =  },
  +1(
        <xref ref-type="bibr" rid="ref1">1</xref>
        ) ≺   +1(
        <xref ref-type="bibr" rid="ref2">2</xref>
        ) ≺   +1(
        <xref ref-type="bibr" rid="ref3">3</xref>
        ) ≺   +1(
        <xref ref-type="bibr" rid="ref4">4</xref>
        ) ≺   +1(
        <xref ref-type="bibr" rid="ref5">5</xref>
        ).
      </p>
      <p>
        A critical condition in the security profile for the AS is this criterion can never be “empty:”
(
        <xref ref-type="bibr" rid="ref8">8</xref>
        )
  +1 ≠ {∅}. (
        <xref ref-type="bibr" rid="ref9">9</xref>
        )
      </p>
      <p>This means that the formation of the organization’s AC security profile should begin with an answer
to the question: What level of CSC should security personnel and system users meet?</p>
      <p>
        Next, using the partial ordering given by conditions (
        <xref ref-type="bibr" rid="ref4">4</xref>
        ) and (
        <xref ref-type="bibr" rid="ref5">5</xref>
        ) on a set of different operational
security profiles and the lexicographic order, we renumber all possible security profiles in the direction
of increasing protection requirements from 0 (for an empty profile) to    , which corresponds to the
highest level of security with the maximum level of guarantees [20].
      </p>
      <p>Before the organization or modernization of the computer security system, the parameters of the
criticality category (CC) of the object, the trend   , the state of aggressiveness of the environment   ,
the required level of CSC in the organization, and, based on the available financial and material
resources, the initial security profile must be determined (in Table 3 the profile is defined conditionally).</p>
      <p>Based on the defined parameters, measures are taken in the management process to adjust the
protection profile and increase the level of CSC.
СС
 
 1( )
 2( )
 3( )
 4( )
 5( )
=
0
IV
E
1
2
1
∅
∅</p>
      <sec id="sec-7-1">
        <title>Dynamics of events over time less T0 T0..T1 T1..T2</title>
        <p>T2..T3</p>
      </sec>
      <sec id="sec-7-2">
        <title>Tasks + provision</title>
      </sec>
      <sec id="sec-7-3">
        <title>Management + training</title>
      </sec>
      <sec id="sec-7-4">
        <title>Asset management T3..T4</title>
      </sec>
      <sec id="sec-7-5">
        <title>Recovery of state T4..T5 T5..T6</title>
        <p>T6..T∝</p>
      </sec>
      <sec id="sec-7-6">
        <title>Tasks + provision</title>
      </sec>
      <sec id="sec-7-7">
        <title>Management + training</title>
      </sec>
      <sec id="sec-7-8">
        <title>Asset management ↑ 0 IV</title>
        <p>E
1
2
2
1
∅
↑
0
IV
E
1
2
2
1
∅
↑
1
IV
D
3
2
2
1
∅
↑
1
III
D
3
2
2
1
∅
=
1
IV
D
3
2
2
1
∅
=
1
IV
D
3
2
2
2
1
=
0
IV
D
3
2
2
2
1</p>
        <p>Measures are taken to strengthen security, including instructions and staff training. In the time
  ,  
interval ( 0,  3), based on the constant increase in the number of cyberattacks (  ), the parameters
and the security profile are adjusted on the system. This calculates the current costs of
strengthening the security system, including training and motivating security personnel.</p>
        <p>The time interval ( 3,  4) in Table 3 and on the diagram Fig. 2 corresponds to the restoration of the
system after a cyber attack. This point is characterized by determining the damage caused, comparing
it with previous costs for improving security, and deciding to strengthen security measures further.
Considering that during this period, the system is most vulnerable to new damage, it is advisable to
temporarily increase the organization’s criticality category by one level based on the decision of the
strategic management level.</p>
        <p>The adopted decision regarding further strengthening security measures is implemented in the time
maintain the CSS level within the reached value of the  
parameter.
interval ( 4,  6). Please note that at the tactical management level, security management tries to</p>
        <p>The ratio of damages resulting from attacks and the total cost of improving security indicates the
effectiveness of the selected management decisions. Based on this ratio, based on statistics for a specific
branch of social activity (industry, energy, environmental protection, etc.), the first KPI1 should be
determined—a vital indicator of the effectiveness of the organization's management activities in the
field of providing G&amp;C.</p>
        <p>As the second key indicator of KPI2, it is advisable to choose  ℎ is the trend of changes in the CSC
level of the organization as a result of the training, education, and motivation of personnel implemented
at the operational and tactical levels.</p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>8. Conclusion and Future Work</title>
      <p>The dynamic model of the provision of G&amp;C and critical performance indicators proposed in the
paper can be used to model the behavior of critical infrastructure objects and form balanced
management decisions in the relevant industries.</p>
      <p>The issue of defining and normalizing the parameter is the state of aggressiveness of the
environment, as well as sufficient levels of CSC for different categories of the criticality of critical
infrastructure objects, which require further research.</p>
      <p>In the following studies, it is planned to consider the application of dynamic model of guarantee
capacity and cyber security management in distributed commercial systems.</p>
    </sec>
    <sec id="sec-9">
      <title>9. References</title>
      <p>[13] V. Buriachok, V. Sokolov, P. Skladannyi, Security Rating Metrics for Distributed Wireless
Systems, in: Proceedings of the 8th International Conference on Mathematics. Information
Technologies. Education, 2019, pp. 222–233.
[14] O. Dovgan, et al., Information Protection Methodology, 2012. [in Ukrainian]
[15] R. Anthony, Planning and Control Systems: A Framework for Analysis. Division of Research,</p>
      <p>Graduate School of Business Administration, Harvard University, Boston, 1965.
[16] G. A. Gorry, M. S. S. Morton, A Framework for Management Information Systems, Sloan</p>
      <p>Management Review: Journal 13 (1971) 21–36.
[17] Cybersecurity. A Generic Reference Curriculum, NATO Headquarters Supreme Allied
Commander Transformation, 5000/TTS TTX 0310/TT-161157/Ser. NU0766(INV) (2016). URL:
https://www.nato.int/nato_static_fl2014/assets/pdf/pdf_2016_10/1610-cybersecuritycurriculum.pdf.
[18] D. Parmenter, Key Performance Indicators – Developing, Implementing, and Using Winning KPIs,
4th ed., John Wiley &amp; Sons, 2019.
[19] Criteria for Evaluating the Security of Information in Computer Systems against Unauthorized</p>
      <p>Access, RD TIP 2.5-004-99. [in Ukrainian]
[20] H. Hulak, Mechanisms for Ensuring the Security of Software Information Protection Tools, in:
Problems of Cyber Security of Information and Telecommunication Systems (2017) 66–72. [in
Ukrainian]
[21] Classification of Automated Systems and Standard Functional Profiles of Protection of Processed</p>
      <p>Information from Unauthorized Access, RD TIP 2.5-005-99. [in Ukrainian]
[22] A. G. Akritas, Elements of Computer Algebra With Applications, 1st ed., Wiley-Interscience,
1989.
[23] Terminology in the Field of Information Protection in Computer Systems against Unauthorized</p>
      <p>Access, RD TIP 1.1-003-99 (in Ukrainian).
[24] I. Skiter, Model for Assessing the Level of Cyber Security Culture in the Information System,
Cybersecurity: Education, Science, Technology 1(13) (2021) 158–169.
doi:10.28925/26634023.2021.13.158169. [in Ukrainian]
[25] Cyber Security Culture in Organizations, European Union Agency for Network and Information</p>
      <p>Security (ENISA), 2017. URL: https://www.enisa.europa.eu/.
[26] L. Leenen, J.C. Jansen van Vuuren, Framework for the Cultivation of a Military Cybersecurity
Culture, in: 14th International Conference on Cyber Warfare and Security (ICCWS), 2019, pp.
212–220.
[27] A. Turing, Computing Machinery and Intelligence, Mind LIX (236) (1950) 433–460.
[28] Handbook of Human Factors and Ergonomics, 5th ed., G. Salvendy, W. Karwowski (Eds.), 2021.
[29] P. Patrascu, Promoting Cybersecurity Culture Through Education, in: 15th International Scientific
Conference on eLearning and Software for Education (eLSE) New Technologies and Redesigning
Learning Spaces, New Technologies and Redesigning Learning Spaces II, 2019, pp. 273–279.
[30] B. Stackpole, How to Build a Culture of Cybersecurity, 2022. URL:
https://mitsloan.mit.edu/ideasmade-to-matter/how-to-build-a-culture-cybersecurity.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Hulak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Korshun</surname>
          </string-name>
          ,
          <article-title>Formation of Dependability and Cyber Protection Model in Information Systems of Situational Center</article-title>
          ,
          <source>in: Proceedings of the Workshop on Emerging Technology Trends on the Smart Industry and the Internet of Things</source>
          ,
          <year>2022</year>
          , pp.
          <fpage>107</fpage>
          -
          <lpage>117</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Vielberth</surname>
          </string-name>
          ,
          <article-title>Security Information and Event Management (SIEM)</article-title>
          , in: S. Jajodia,
          <string-name>
            <given-names>P.</given-names>
            <surname>Samarati</surname>
          </string-name>
          , M. Yung (Eds.),
          <source>Encyclopedia of Cryptography, Security and Privacy</source>
          , Springer, Berlin, Heidelberg,
          <year>2021</year>
          . doi:
          <volume>10</volume>
          .1007/978-3-
          <fpage>642</fpage>
          -27739-9_
          <fpage>1681</fpage>
          -
          <lpage>1</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A.</given-names>
            <surname>Zhilin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Nikolayenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Bakalinsky</surname>
          </string-name>
          ,
          <article-title>Increasing the Security of State Information Resources Through the Use of the Threat Intelligence platform</article-title>
          ,
          <source>Information Protection</source>
          <volume>23</volume>
          (
          <issue>3</issue>
          ) (
          <year>2021</year>
          )
          <fpage>136</fpage>
          -
          <lpage>146</lpage>
          . [in Ukrainian]
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Mitre</surname>
            <given-names>ATT</given-names>
          </string-name>
          &amp;CK,
          <year>2021</year>
          . URL: https://attack.mitre.org/.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>T.</given-names>
            <surname>Rid</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Buchanan</surname>
          </string-name>
          , Attributing Cyber Attacks,
          <source>Journal of Strategic Studies</source>
          <volume>38</volume>
          (
          <issue>1-2</issue>
          ) (
          <year>2015</year>
          )
          <fpage>4</fpage>
          -
          <lpage>37</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>S.</given-names>
            <surname>Borzenkova</surname>
          </string-name>
          , et al.,
          <source>Management of Information Security System based on Signature Models</source>
          ,
          <source>Technical Sciences 2</source>
          (
          <issue>2</issue>
          ) (
          <year>2010</year>
          )
          <fpage>200</fpage>
          -
          <lpage>205</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Borzenkova</surname>
          </string-name>
          ,
          <string-name>
            <surname>O. Chechuga,</surname>
          </string-name>
          <article-title>The Concept of using Discrete Situational Models in Information Security Management Systems</article-title>
          , News of TulGU,
          <source>Technical Sciences 6</source>
          (
          <issue>2</issue>
          ) (
          <year>2011</year>
          )
          <fpage>328</fpage>
          -
          <lpage>336</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>S.</given-names>
            <surname>Borzenkova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Chechuga</surname>
          </string-name>
          ,
          <article-title>Decision-Making Model for Managing the Information Security System, News of TulGU</article-title>
          .
          <source>Technical Sciences 3</source>
          (
          <year>2013</year>
          )
          <fpage>471</fpage>
          -
          <lpage>478</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>I. Azhmukhamedov</surname>
          </string-name>
          ,
          <source>Mathematical Model of Complex Security of Computer Systems and Networks based on Expert Judgments, Infocommunication Technologies</source>
          <volume>7</volume>
          (
          <issue>4</issue>
          ) (
          <year>2009</year>
          )
          <fpage>103</fpage>
          -
          <lpage>107</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>I. Azhmukhamedov</surname>
          </string-name>
          ,
          <article-title>Dynamic Fuzzy Cognitive Model for Assessing the Level of</article-title>
          Security of University Information Assets, Management,
          <source>Computer Engineering and Informatics</source>
          <volume>2</volume>
          (
          <year>2012</year>
          )
          <fpage>137</fpage>
          -
          <lpage>141</lpage>
          . [in Russian]
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>C. B. Westphall</surname>
          </string-name>
          , et al.,
          <article-title>Management and Security for Grid, Cloud</article-title>
          and
          <string-name>
            <given-names>Cognitive</given-names>
            <surname>Networks</surname>
          </string-name>
          , Revista de Sistemas de Informação da FSMAn.
          <volume>8</volume>
          (
          <issue>2011</issue>
          )
          <fpage>8</fpage>
          -
          <lpage>21</lpage>
          . URL: http://www.fsma.edu.br/si/sistemas.html.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>H.</given-names>
            <surname>Hulak</surname>
          </string-name>
          , I. Skiter,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Hulak</surname>
          </string-name>
          ,
          <article-title>Methodological Principles of the Creation and Functioning of the Cyber Security Center of the Information Infrastructure of Nuclear Energy Facilities</article-title>
          ,
          <source>Cybersecurity: Education, Science, Technology</source>
          <volume>4</volume>
          (
          <issue>12</issue>
          ) (
          <year>2021</year>
          )
          <fpage>172</fpage>
          -
          <lpage>186</lpage>
          . doi:
          <volume>10</volume>
          .28925/
          <fpage>2663</fpage>
          -
          <lpage>4023</lpage>
          .
          <year>2021</year>
          .
          <volume>12</volume>
          .184186. [in Ukrainian]
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>