<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Information Security Risk Management using Cognitive Modeling</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Svitlana Shevchenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yuliia Zhdanova</string-name>
          <email>y.zhdanova@kubg.edu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Halina Shevchenko</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Оlena Nehodenko</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>аnd Svitlana Spasiteleva</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Borys Grinchenko Kyiv University</institution>
          ,
          <addr-line>18/2 Bulvarno-Kudriavska str., Kyiv, 04053</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>State University of Telecommunications</institution>
          ,
          <addr-line>7 Solomyanska str., Kyiv, 03110</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>The National University of Ostroh Academy</institution>
          ,
          <addr-line>2 Seminarska str., Ostroh, 35800</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>297</fpage>
      <lpage>305</lpage>
      <abstract>
        <p>Making decisions by an individual is an element of managing any process in society; therefore, theories of cognitive science are applicable in various fields, including information and cyber security systems. This study proposes the development of a cognitive model of “danger-risk” in the process of managing information risks in information and cyber security systems. Based on the analysis of scientific literature, the concepts of “cognitive modeling” and “cognitive map” are defined. The views of scholars on methods for creating cognitive maps and mechanisms for simulating problem situations are presented. The main tasks addressed within cognitive analysis and modeling are outlined, and the advantages and disadvantages of cognitive models are identified. In the second part of the study, the main stages of developing the cognitive model of “danger-risk” in the field of information and cyber security are considered: identification of complex situations and issues, construction of a cognitive map, modeling and verification of model adequacy, and dynamic situation analysis. A theoretical model of “danger-risk” is developed, and its elements are highlighted. A list of risk management concepts in information security is characterized, and cause-andeffect relationships between them are justified using SWOT analysis. As an example, for a specific information asset (a database), threats and vulnerabilities are identified, and the risk level for each connection is calculated as the product of the probability of each threat's realization and the probability of corresponding damages. The model of cognitive risk maps in information security is represented in a static form as an oriented graph, with a subsequent selection of methods for handling these risks.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Information security risks</kwd>
        <kwd>information security system</kwd>
        <kwd>cyber system</kwd>
        <kwd>cyber risks</kwd>
        <kwd>cognitive modeling</kwd>
        <kwd>cognitive danger-risk model</kwd>
        <kwd>SWOT analysis</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        The informational component is one of the
most valuable assets for any organization.
Information can be stolen, distorted, become
inaccessible, and lose its integrity and
confidentiality, all of which result in significant
material and reputational losses for the
enterprise. Every 39 seconds, a new attack
occurs somewhere on the internet, costing
trillions of dollars annually [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Every company
should have experts with practical knowledge
of information confidentiality, availability, and
integrity safeguards [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. Therefore, there is a
constant focus on implementing protective
software and upgrading security technologies
for research in the field of security [
        <xref ref-type="bibr" rid="ref3 ref4">3–4</xref>
        ].
      </p>
      <p>
        As a methodology for managing an
enterprise's information security system, a
risk-oriented approach is chosen. The
formation of the existing spectrum of
information risks during the activities of a
specific organization, the minimization of
these risks, and their transfer or avoidance
while continuously monitoring the risk
situation, is a crucial step in the organization’s
information security system [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>On the other hand, the implementation and
application of the information security risk
management methodology require significant
efforts and resources in constant process
monitoring. This prompts researchers and
information security specialists to seek
optimal and effective risk management
practices.</p>
      <p>
        Information and cyber security is a complex
system with a lack of sufficient analytical data
for uncertainty removal and forecasting.
Therefore, most approaches rely on expert
assessment, fuzzy logic theory, and graph
theory [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>
        Modeling various scenarios in information
and cyber security is the tool that allows risk
analysis for management and future
prediction. This is evident from the extensive
research in this direction. In scientific
development [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ], researchers used stochastic
modeling methods to determine the
possibilities of applying various risk theories
to study the nature and properties of cyber
risks. In research [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ], risk behavior models are
proposed based on the use of the theory of
complex variable function. The risk-oriented
approach in cyber security protection systems
is described in [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], where different cognitive
risk models, methods of their analysis, and
processing are defined. Mathematical models
of reflexive risks, the structure and set of which
are determined by typical “attack/defense”
scenario developments, are developed in [
        <xref ref-type="bibr" rid="ref10 ref11">10,
11</xref>
        ]. Qualitative assessment using SWOT
analysis is conducted in scientific works [
        <xref ref-type="bibr" rid="ref12 ref13">12, 13</xref>
        ].
      </p>
      <p>Information and cyber security are closely
intertwined with human activity, allowing the
integration of cognitive science theories into
information protection-related developments.
Cognitive science, or cognitology, is an
interdisciplinary scientific direction that
combines the theory of cognition, cognitive
psychology, neurophysiology, cognitive
linguistics, and artificial intelligence theory.</p>
      <p>
        As claimed by researchers [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], cognitive
modeling holds significant prospects and
possibilities in the field of cyber security and
can become a powerful tool for exploring
different scenarios and making decisions by
responsible individuals. All of the above allows
for the identification of the research purpose,
which is the development of a cognitive model
of "danger-risk" based on SWOT analysis in
information security risk management.
2.
      </p>
      <p>
        Cognitive Modeling
One of the contemporary trends in scientific
research is the cognitive approach, which is
being implemented in studies across various
fields. “The cognitive approach aims to
understand how people decode information
about reality and organize it to make decisions
or solve pressing tasks” [15, p. 198]. Notable
scientific works in this regard include research
by R. Axelrod [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], B. Kosko [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], F. Roberts
[
        <xref ref-type="bibr" rid="ref18">18</xref>
        ], Y. Milyavsky [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ], and others.
      </p>
      <p>
        Cognitive modeling involves representing a
complex problem situation of a given system in
a simplified form, typically in a graphical
format. Scientific developments in this field
began with the formation of cognitive maps, as
proposed by Robert Axelrod (1976) for the
analysis and decision-making in social
sciences. Axelrod’s cognitive maps are iconic
oriented graphs, with the principle of
operation as follows: the concepts used by the
decision-maker are presented as nodes, and
the cause-and-effect relationships between
these concepts are represented as edges. A
positive connection between node A and node
B means that an increase in A leads to an
increase in B, whereas a negative connection
between A and B implies that an increase in A
results in a decrease in B [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. This depiction is
presented in Fig. 1, and the matrix form in
Fig. 2. The matrix is square, and at the
intersection of the row elements Ci and column
elements Cj, a +1 is placed if there is an edge (Ci,
Cj) with a "+" sign, –1 if there is an edge (Ci, Cj)
with a "–" sign, and 0 if there is no edge (Ci, Cj).
+
      </p>
      <p>C1
C2
+
+</p>
      <p>C3
–
–
+</p>
      <p>
        C4
C5
–
С1 С2 С3 С4 С5
С1 0 +1 +1 0 0
С2 0 0 +1 0 – 1
С3 0 0 0 – 1 +1
С4 0 0 0 0 0
С5 ( 0 0 0 – 1 0 )
Figure 2: Cognitive map in matrix form
Later, researcher Bart Kosko [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] introduced
fuzzy cognitive maps, initially developed as a
means to explain decision-making processes in
politics, and they now form the foundation of
cognitive modeling.
2.1. Fuzzy Cognitive Map
The cognitive Situation Map is a fundamental
representation of the static and dynamic
aspects of a complex system in cognitive
modeling. As evidenced by scientific research
[
        <xref ref-type="bibr" rid="ref16 ref17 ref18 ref19 ref20 ref21 ref22 ref23 ref24 ref25">16–25</xref>
        ], cognitive maps are used for both
statistical and dynamic analysis of systems
(Table 1).
      </p>
      <p>Dynamic</p>
      <p>Generation of
Evaluation of the scenario
influence of one development in
factor on others time</p>
      <p>Analysis of scenario
Overall situation development in
stability time
Search for Consequences of
structural changes influence on system
to obtain stable elements or changes
structures like relationships
A fuzzy cognitive map by Kosko, in addition to
cause-and-effect relationships between
factors, also denotes their weight on the edges,
with values ranging from [–1; 1], thus
determining the level of this influence (Fig. 3).</p>
      <p>
        Today, there are various modifications of
cognitive maps, including iconic cognitive
maps, fuzzy cognitive maps by Kosko, modified
fuzzy cognitive maps by Kosko, fuzzy relational
cognitive maps, and others. They are all
characterized by different interpretations of
edge weights and factor values within the
cognitive map. Deterministic and
nondeterministic cognitive maps are
distinguished, and each of them includes
iconic, quantitative, qualitative, and fuzzy
cognitive maps [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ].
      </p>
      <p>+ 0.3</p>
      <p>
        C1
C2
It’s worth noting that cognitive maps do not
provide an exact description of the entire
system under study but rather reflect the
subjective assessments of experts in a given
situation. They serve as a model for
representing their knowledge. As a drawback,
it should also be mentioned that solving
cognitive modeling tasks can be challenging,
hence the need for software resources,
especially with a library of information assets,
their vulnerabilities, and threats for more
effective monitoring of information security
risks.
2.2. Stages of Cognitive Modeling
In scientific literature, various stages, schemes,
and mechanisms for modeling a problem
situation based on a cognitive approach are
proposed. We favor the process of construction
outlined in the study [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] and presented in
Table 2.
3. Developing a Cognitive Model
of “Danger-Risk” based on
Conducting a SWOT Analysis of
Information Security Risks
The information and cyber security system is a
complex framework with a large amount of
unstructured data. The application of cognitive
analysis allows these data to be presented in a
form that provides a combination of different
scenarios and solutions.
      </p>
      <p>Within
the
"threat-risk"
model, it is
considered that the existence of threats results
in the formation of a set of risks to the object,
each
of
which
is
characterized
by
the
probability of its realization and a certain harm
when the threat exploits the vulnerability of
the object.
graph, where</p>
      <p>Let's denote  1̅ = { ,  ̅,  } an oriented</p>
      <p>= {  } represents the set of factors
(concepts); in this case, it’s the set of possible
threats
to
a
given
information
asset,
vulnerabilities that the threat can exploit, and
possible consequences in case of the threat's
realization.</p>
      <p>̅ = {  } represents the set of edges
reflecting
cause-and-effect
relationships
between factors.</p>
      <p>= {</p>
      <p>} represents the set of weights
on edges (strength of influence); in this case,
  =   =     , 0 ≤   ≤ 1, where  
degree of risk,   is the probability of each
threat's realization, and   is the probability
of corresponding damages, calculated based
on
expert assessment and using SWOT
is the</p>
      <p>Researchers propose scenario modeling in
analysis.
three main directions:
•
•
•</p>
      <p>Development of the situation occurs
independently of the system
(selfcontained).</p>
      <p>Development of the situation occurs
through programmed actions (direct
task).</p>
      <p>Synthesis of a set of influences that
allowed achieving a specific change in
the situation (inverse task).
3.1. Quality Risk Analysis using</p>
      <p>SWOT Analysis
Constructing a cognitive map can be done by a
single individual making decisions based solely
on their experience, or by a group of experts
using information provided by the
organization or through a questionnaire.
Additionally, it is possible to obtain results by
openly conducting surveys and polling
participants in the process.</p>
      <p>In our research, to build a fuzzy cognitive
map, we propose identifying the system and
influence weights using SWOT analysis after
conducting brainstorming.</p>
      <p>
        SWOT analysis is a research procedure
whose idea revolves around a comprehensive
description of strengths, weaknesses,
opportunities, and threats when developing an
organizational strategy. SWOT analysis serves
as the initial stage of organizational strategy
planning, serving as a starting point for a more
in-depth examination of issues related to
information security risks. It is relatively
straightforward to use and does not require
experienced experts to conduct it. A more
detailed procedure for conducting a SWOT
analysis for managing information and cyber
security risks is described in works [
        <xref ref-type="bibr" rid="ref12 ref13">12–13</xref>
        ].
      </p>
      <p>As an example, let's select an information
asset, such as the organization's database, and
conduct the identification of threats and
vulnerabilities for this asset (Table 3).</p>
      <p>We will determine the risk level for each
factor (Table 4) using the probability
multiplication formula for independent
events.</p>
      <sec id="sec-1-1">
        <title>Availability</title>
        <p>Integrity</p>
      </sec>
      <sec id="sec-1-2">
        <title>Confidentiality</title>
      </sec>
      <sec id="sec-1-3">
        <title>Vulnerability</title>
      </sec>
      <sec id="sec-1-4">
        <title>Missing database protection</title>
      </sec>
      <sec id="sec-1-5">
        <title>Weak encryption Threat</title>
      </sec>
      <sec id="sec-1-6">
        <title>Physical</title>
        <p>damage to
databases
(intentional
and
unintentional)
Data theft and
falsification
Lack of Equipment
uninterrupte failure and
d power loss of
sources unsaved data</p>
      </sec>
      <sec id="sec-1-7">
        <title>Missing regular data backup system</title>
      </sec>
      <sec id="sec-1-8">
        <title>Data loss</title>
        <p>Vulnerabilit
y
Lack of
database
protection</p>
      </sec>
      <sec id="sec-1-9">
        <title>Weak passwords for data access</title>
        <p>Absence of
access
rights
segregation</p>
      </sec>
      <sec id="sec-1-10">
        <title>Missing regular data backup system</title>
      </sec>
      <sec id="sec-1-11">
        <title>Threat</title>
      </sec>
      <sec id="sec-1-12">
        <title>Physical</title>
        <p>damage to
databases
(intentional
and
unintentional)
Data theft and
falsification</p>
      </sec>
      <sec id="sec-1-13">
        <title>Data modification (unintentional or intentional)</title>
      </sec>
      <sec id="sec-1-14">
        <title>Data loss</title>
      </sec>
      <sec id="sec-1-15">
        <title>Vulnerability</title>
      </sec>
      <sec id="sec-1-16">
        <title>Threat</title>
      </sec>
      <sec id="sec-1-17">
        <title>Lack of database protection</title>
      </sec>
      <sec id="sec-1-18">
        <title>Weak encryption</title>
      </sec>
      <sec id="sec-1-19">
        <title>Absence of two-factor authenticatio n</title>
      </sec>
      <sec id="sec-1-20">
        <title>Absence of access rights segregation</title>
      </sec>
      <sec id="sec-1-21">
        <title>Unauthorize d access (direct and remote)</title>
      </sec>
      <sec id="sec-1-22">
        <title>Data theft and falsification</title>
      </sec>
      <sec id="sec-1-23">
        <title>Unauthorize d access (direct and remote)</title>
      </sec>
      <sec id="sec-1-24">
        <title>Unauthorize d access (direct and remote)</title>
        <p>Using SWOT analysis, the organization’s
strategy was determined (Table 5) regarding
countering threats, taking into account the
company’s weaknesses (vulnerabilities of the
information asset).</p>
        <p>The priority threat is the one with the most
connections to weaknesses. After the
comparison, the priority threat is “Data Loss.”</p>
        <p>Let’s determine the degree of impact using
cognitive maps. After identifying information
characterizing the database security, we will
construct a matrix of the strength of
relationships between the concepts  
(Table 6).
qi
0.246
due to the choice of a small number of factors
scientists suggest finding its density (cluster
coefficient) using the formula
 =

 2
,
where n is the total number of connections, N
is the total number of concepts.</p>
      </sec>
      <sec id="sec-1-25">
        <title>Therefore,</title>
        <p>=
22
132 = 0,13.</p>
        <p>It's obvious that the more connections, the
higher
the
density,
and
thus,
more
opportunities for change. In our case, the
density is a moderate value. This is expected
(threats and vulnerabilities).
3.2. Fuzzy Cognitive Map for
Situational Analysis of
that requires protection, vulnerabilities, and
threats were identified, relationships between
them
were</p>
        <p>designed, and their influence
strength was determined. We will construct a
cognitive</p>
        <p>map in the form of a weighted
directed graph (Fig. 5).</p>
        <p>C</p>
        <p>4
C
3</p>
        <p>C
5
C</p>
        <p>2
0,1014</p>
        <p>C</p>
        <p>6
0,0533
0,04212
0,00294
0,0278</p>
        <p>0,00224
0,0017
C
1
0,0272</p>
        <p>C
7
0,02696
0,00724
0,00332
0,00177
0,0026</p>
        <p>C</p>
        <p>13
0,0082
0,0022</p>
        <p>C</p>
        <p>8
0,00277
0,00199</p>
        <p>C</p>
        <p>9
0,00193</p>
        <p>C</p>
        <p>10
C</p>
        <p>11
0,00128
0,00099</p>
        <p>C
12</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>4. Conclusions</title>
      <p>This graph represents a scenario modeling the
situation’s development without influencing
the process. By comparing the obtained risk
level
with
the standard
outlined in
the
organization's Security
Policy, the
leader
makes decisions regarding the treatment of
these risks: minimize, transfer, prevent, or
accept. In the next stage, various scenario
modeling is carried out depending on the
actions chosen by the leader and the company.</p>
      <p>The proposed
methodical approach to
information
management
and
using
cyber
security</p>
      <p>risk
modeling
and SWOT
analysis allows for prioritizing actions to
ensure
the</p>
      <p>confidentiality, integrity, and
availability of information.
5. Acknowledgments
This research was tested in the educational
process of Boris Grinchenko Kyiv University
with students majoring in Cybersecurity and</p>
      <sec id="sec-2-1">
        <title>Information Protection. 303</title>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>What</given-names>
            <surname>Businesses</surname>
          </string-name>
          <article-title>Need to Know about Cybersecurity in 2023</article-title>
          . https://www.bdo.ua/uk-ua/insights2/information-materials/
          <year>2023</year>
          <article-title>/whatbusinesses-need-to-know-aboutcybersecurity-in-2023</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>B.</given-names>
            <surname>Bebeshko</surname>
          </string-name>
          , et al.,
          <source>Application of Game Theory</source>
          ,
          <article-title>Fuzzy Logic and Neural Networks for Assessing Risks and Forecasting Rates of Digital Currency</article-title>
          ,
          <source>Journal of Theoretical and Applied Information Technology</source>
          <volume>100</volume>
          (
          <issue>24</issue>
          ) (
          <year>2022</year>
          )
          <fpage>7390</fpage>
          -
          <lpage>7404</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          , et al.,
          <article-title>Method for Increasing the Various Sources Data Consistency for IoT Sensors</article-title>
          ,
          <source>in: IEEE 9th Int. Conf. on Problems of Infocommun</source>
          .,
          <string-name>
            <surname>Sci</surname>
            . and
            <given-names>Technol. (PICST</given-names>
          </string-name>
          ) (
          <year>2023</year>
          )
          <fpage>522</fpage>
          -
          <lpage>526</lpage>
          . doi:
          <volume>10</volume>
          .1109/ PICST57299.
          <year>2022</year>
          .
          <volume>10238518</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>M.</given-names>
            <surname>Vladymyrenko</surname>
          </string-name>
          , et al.,
          <article-title>Analysis of Implementation Results of the Distributed Access Control System</article-title>
          .
          <source>in: 2019 IEEE Int. Sci</source>
          .-Practical
          <string-name>
            <surname>Conf</surname>
          </string-name>
          . Problems of Infocommun.,
          <string-name>
            <surname>Sci</surname>
          </string-name>
          . and
          <string-name>
            <surname>Technol.</surname>
          </string-name>
          (
          <year>2019</year>
          ). doi:
          <volume>10</volume>
          .1109/picst47496.
          <year>2019</year>
          .
          <volume>9061376</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          ,
          <article-title>Security Rating Metrics for Distributed Wireless Systems</article-title>
          ,
          <source>in: Workshop of the 8th Int. Conf. on “Mathematics. Information Technologies. Education:” Modern Machine Learning Technologies and Data Science</source>
          <volume>2386</volume>
          (
          <year>2019</year>
          )
          <fpage>222</fpage>
          -
          <lpage>233</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>F.</given-names>
            <surname>Kipchuk</surname>
          </string-name>
          , et al.,
          <source>Assessing Approaches of IT Infrastructure Audit, in: IEEE 8th Int. Conf. on Problems of Infocommun., Sci. and Technol</source>
          . (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1109/ picst54195.
          <year>2021</year>
          .
          <volume>9772181</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>M.</given-names>
            <surname>Eling</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Wirfs</surname>
          </string-name>
          ,
          <source>What Are the Actual Costs of Cyber Risk Events? European J. of Operational Research</source>
          <volume>272</volume>
          (
          <issue>3</issue>
          ) (
          <year>2019</year>
          )
          <fpage>1109</fpage>
          -
          <lpage>1119</lpage>
          . URL: https://www.science direct.com/science/article/abs/pii/S037 722171830626X
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>V.</given-names>
            <surname>Mokhor</surname>
          </string-name>
          , S. Honchar,
          <article-title>Research of Validity of Presentation of Risks by Vectors in the Euclidean Space</article-title>
          ,
          <source>Electronic Modeling</source>
          <volume>41</volume>
          (
          <year>2019</year>
          )
          <fpage>73</fpage>
          -
          <lpage>84</lpage>
          . https://www.emodel.org.ua/images/em/ 41-4/Mokhor.pdf
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>O.</given-names>
            <surname>Arkhipov</surname>
          </string-name>
          ,
          <article-title>Introduction to the Theory of Risks: Information Risks, Nat</article-title>
          . Acad. SBU,
          <string-name>
            <surname>Kyiv</surname>
          </string-name>
          (
          <year>2015</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>O.</given-names>
            <surname>Arkhypov</surname>
          </string-name>
          ,
          <article-title>Application of a Risk-based Approach using Reflexive Risk Models in Building Information Security Systems</article-title>
          ,
          <source>in: 1st Int. Workshop CITRisk</source>
          (
          <year>2020</year>
          )
          <fpage>130</fpage>
          -
          <lpage>143</lpage>
          . https://ela.kpi.ua/bitstream/123456789/ 41515/1/CITRisk_Risk-Based%
          <volume>20</volume>
          Approach.pdf
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>O.</given-names>
            <surname>Arkhypov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Arkhypova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Krejčí</surname>
          </string-name>
          ,
          <article-title>Adaptation of a Risk-based Approach to the Tasks of Building and Functioning of Information Security Systems</article-title>
          ,
          <source>in: 2nd Int. Workshop on Computational &amp; Information Technologies for RiskInformed Systems</source>
          <volume>3101</volume>
          (
          <year>2021</year>
          )
          <fpage>83</fpage>
          -
          <lpage>92</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>H.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Information Security Risk Analysis SWOT, Cybersecurity Providing in Information and Telecommunication Systems</source>
          <volume>2923</volume>
          (
          <year>2021</year>
          )
          <fpage>309</fpage>
          -
          <lpage>317</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zhdanovа</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Kravchuk</surname>
          </string-name>
          ,
          <article-title>Information Protection Model based on Information Security Risk Assessment for Small and Medium-Sized Business</article-title>
          . Cybersecur. Edu., Sci.,
          <source>Technique</source>
          <volume>2</volume>
          (
          <issue>14</issue>
          ) (
          <year>2021</year>
          )
          <fpage>158</fpage>
          -
          <lpage>175</lpage>
          . doi:
          <volume>10</volume>
          .28925/
          <fpage>2663</fpage>
          -
          <lpage>4023</lpage>
          .
          <year>2021</year>
          .
          <volume>14</volume>
          .158175.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>V.</given-names>
            <surname>Veksler</surname>
          </string-name>
          , et al.,
          <source>Cognitive Models in Cybersecurity: Learning From Expert Analysts and Predicting Attacker Behavior, Frontiers in Psychology</source>
          <volume>11</volume>
          (
          <year>2020</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>V.</given-names>
            <surname>Shapar</surname>
          </string-name>
          , Modern Explanatory Psychological Dictionary, Kharkiv, Prapor (
          <year>2007</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>R.</given-names>
            <surname>Axelrod</surname>
          </string-name>
          ,
          <article-title>The Structure of Decision: Cognitive Maps of Political Elites</article-title>
          . Princeton University Press (
          <year>1976</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>B.</given-names>
            <surname>Kosko</surname>
          </string-name>
          ,
          <source>Fuzzy Cognitive Maps. Int. J. ManMachine Studies</source>
          <volume>24</volume>
          (
          <year>1986</year>
          )
          <fpage>65</fpage>
          -
          <lpage>75</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>F.</given-names>
            <surname>Roberts</surname>
          </string-name>
          , Discrete Mathematical Models with Applications to Social, Biological, and
          <string-name>
            <given-names>Environmental</given-names>
            <surname>Problems</surname>
          </string-name>
          . Englewood Cliffs,
          <string-name>
            <surname>Prentice-Hall</surname>
          </string-name>
          (
          <year>1976</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>Y.L. Miliavskyi</given-names>
            <surname>Identification</surname>
          </string-name>
          and
          <source>Control of Complex Systems based on Cognitive Maps Impulse Processes Models, Thesis for doctoral degree National</source>
          Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute” (
          <year>2021</year>
          ). https://ela.kpi.ua/handle/123456789/43 830
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>O</given-names>
            <surname>Hordei</surname>
          </string-name>
          ,
          <string-name>
            <surname>B Patsai</surname>
          </string-name>
          ,
          <article-title>The Use of Modeling in the Learning Process in the Formation of the Necessary Competencies</article-title>
          ,
          <source>Economic Analysis</source>
          <volume>32</volume>
          (
          <issue>2</issue>
          ) (
          <year>2022</year>
          )
          <fpage>62</fpage>
          -
          <lpage>72</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>V.</given-names>
            <surname>Kazymyr</surname>
          </string-name>
          ,
          <string-name>
            <surname>A</surname>
          </string-name>
          .
          <source>Posadska Researching the Cognitive Maps by Simulation Modeling Technical Sciences and Technologies</source>
          <volume>1</volume>
          (
          <issue>7</issue>
          ) (
          <year>2021</year>
          )
          <fpage>98</fpage>
          -
          <lpage>105</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>O.</given-names>
            <surname>Babak</surname>
          </string-name>
          , О. Tatarinov,
          <article-title>Cognitive Modelling of the State of an Object based on a Thought Experiment</article-title>
          ,
          <source>Control Systems and Computers 5</source>
          <volume>-6</volume>
          (
          <year>2021</year>
          )
          <fpage>35</fpage>
          -
          <lpage>44</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <surname>Т. Prokopenko</surname>
          </string-name>
          ,
          <article-title>Complex Model of strategic Management of Organizing-Technical System in Conditions of the Uncertainty Bulletin of Lviv State University of Life Safety 7 (</article-title>
          <year>2018</year>
          )
          <fpage>55</fpage>
          -
          <lpage>60</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>O.</given-names>
            <surname>Salieva</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Yaremchuk</surname>
          </string-name>
          ,
          <article-title>Development of a Cognitive Model for Analyzing the Impact of Threats on the Level of Computer Network Security, Registration</article-title>
          ,
          <source>Storage and Processing of Data</source>
          <volume>21</volume>
          (
          <issue>4</issue>
          ) (
          <year>2019</year>
          )
          <fpage>28</fpage>
          -
          <lpage>39</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>I. Yaldin</surname>
          </string-name>
          ,
          <article-title>Cognitive Modelling in Forecasting Scenarios of the Strategy of Stable Development of an Integrated Structure of Business, The Problems of Economy 4 (</article-title>
          <year>2011</year>
          )
          <fpage>142</fpage>
          -
          <lpage>150</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>