<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <issn pub-type="ppub">1613-0073</issn>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Methodological Approach to Assessing Information Security of Critical Infrastructure Objects</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Yuri Samokhvalov</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Mykola Brailovskyi</string-name>
          <email>brailovskyim@knu.ua</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Bohdan Zhuravel</string-name>
          <email>bohdan.zhuravel.uk@gmail.com</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Workshop</string-name>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Taras Shevchenko National University of Kyiv</institution>
          ,
          <addr-line>Volodymyrs'ka str. 64/13, Kyiv, 01601</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>University of York, University Rd.</institution>
          ,
          <addr-line>Heslington, York, YO105DD, England</addr-line>
        </aff>
      </contrib-group>
      <fpage>317</fpage>
      <lpage>329</lpage>
      <abstract>
        <p>Currently, the most common approaches to assessing information security are verification and risk based. However, information security metrics in these approaches are not informative enough, since they consider only the objective aspects of security, completely ignoring the subjective ones. Therefore, they do not allow for the formulation of basic judgments about the level of information security of critical infrastructure objects. In this regard, there is a need to develop a methodological framework for assessing the information security of critical infrastructure objects, considering both objective and subjective aspects of security. The article proposes an approach to assessing information security based on the confidence criterion that the adopted security policy is implemented on a critical infrastructure object. Confidence assessment includes evaluating the trust in the information security of a critical infrastructure object, the quality of the trust assessment model, the background of individuals who conducted such an assessment, and the evaluation of knowledge regarding threats. The generalized desirability function of Harrington is used as a measure of confidence. The proposed approach is relatively simple to implement and can be used as a pilot for developing appropriate methodologies for assessing the information security of both critical infrastructure objects and organizations of various forms of ownership.</p>
      </abstract>
      <kwd-group>
        <kwd>function</kwd>
        <kwd>maturity model</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Recently, almost all spheres of human activity, society, and the state have become dependent on
information, its quality, and relevance. Consequently, there has been a significant increase in
cyberattacks on information resources, aiming to obtain crucial information or damage it. Critical
infrastructure (CI) objects are most often subjected to these cyberattacks - these are information systems
of state bodies, institutions, and companies. A disruption in their operation has a substantial negative
impact on the social and economic spheres of the state, its defense capability, and national security [1].
Therefore, issues of information security (IS) are the cornerstone in the operation of such ob jects. As
W. Churchill liked to say, "One has to pay for security, and pay dearly for its absence.</p>
      <p>When assessing information security, the following main types of IS
metrics are identified:
implementation metrics, used to measure the degree to which the security policy is put into practice,
and efficiency metrics, used to measure the performance of security services. These metrics form the
basis of the most widespread current approaches to assessing information protection: verification-based
and risk-oriented. The verification approach is based on comparing the activities and measures to ensure
the IS of a CI object with the requirements of standards or guiding documents in the field of information
security and protection. As a result, an assessment of the degree of IS compliance with the requirements
of the set standards is formed. The risk-oriented approach is associated with risk assessment and
management or risk management. It involves considering all possible factors threatening information
security, the likelihood of their realization (attacks or incidents), and the value of protected information
assets.</p>
      <p>2023 Copyright for this paper by its authors.
CEUR</p>
      <p>ceur-ws.org</p>
      <p>As a result, an assessment of the CI object's ability to effectively manage IS risks achieving its goals
will be formed. However, these approaches share a common drawback: they are not informative enough,
as they only consider objective aspects of security, completely ignoring the subjective ones. Therefore,
they do not allow for a comprehensive assessment of the state of confidentiality, integrity, and
availability of information and the overall IS level of the CI object.</p>
      <p>In the ISO/IEC TR 15443-1:2005 standard [3], the concept of 'trust' is introduced for the first time
as a subjective category of IT security, and methods to ensure trust are provided. These methods can be
specific to a particular stage in the lifecycle of a trust object, in accordance with the ISO 9000 series
standards, ISO/IEC 15408-1:2009 [4], and the SSE-CMM standard (ISO/IEC 21827:2008) [5]. In work
[6], models for assessing trust in information security are proposed, as well as examples of organizing
and using measures to ensure assurance and trust. However, the provided examples do not allow for
their practical use in assessing IS. In [6], models for assessing assurance in information security are
proposed, as well as examples of organizing and using guarantees and trust. Yet, the reviewed examples
do not allow for their practical use in evaluating information security. The use of confidentiality as a
subjective indicator of an acceptable level of information security is also unquestionable. Moreover, in
[7-10], issues of group decision-making based on trust criteria are considered. In [11], an approach to
assessing information security is proposed that considers both objective and subjective aspects of
security, using measures to ensure assurance and trust. This article is a further development of this
approach and addresses issues of accounting for the completeness of information when assessing the
information security of critical infrastructure objects.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Categories of confidence and trust</title>
      <p>From an objective point of view, security can be determined by the state of its object, the presence
or absence of certain properties, abilities, etc. From a subjective point of view, security is defined as a
certain feeling, perception, awareness, or perception of it by a person. Moreover, it is the subjective
interpretation of the concept of "safety" that dominates in everyday consciousness, as evidenced by the
results of the study [11]: out of 1506 respondents to the question of how they most often understand
"safety" 234 answered - as "calm", 185 - as "confidence" and 128 as "rest."</p>
      <p>The safety assessment can be obtained by different methods. However, whatever method is used,
such an assessment will be subjective, since the choice of threshold values of security indicators is
subjective, expert assessments are subjective, and the assessment of IS risks is subjective. Thus, the
object receives the status of "dangerous" or "safe" only because of human evaluative activities, which
serves as another confirmation of the need to consider subjective aspects in defining the concept of
"safety". The informational security of a critical infrastructure (CI) object, as a state of protection of the
informational environment, directly depends on the security of its informational infrastructure. As
practice shows, this infrastructure is the primary source of vulnerabilities and IS threats. As new
information technologies emerge, so do new vulnerabilities and new attacks. It's evident that mistakes,
vulnerabilities, and risks will always exist. Therefore, it's almost impossible to guarantee the security
of a CI object's operation. In this situation, we can only assert with a certain degree of confidence that
an organization implements (realizes) the adopted security policy. This, in turn, prompts the application
of relevant technical and organizational security measures to mitigate vulnerabilities and threats, aiming
to ensure a sufficiently acceptable level of trust in the CI object's IS.</p>
      <p>It should be noted that the notions "trust" and "confidence" are not identical and are not
interchangeable. From the standpoint of psychology, as noted in the standard [6], confidence in the CI
object's IS from the point of view of an individual is associated with the belief that he has confidence
in its information security, while trust is associated with the proven ability of an organization's
information security system to ensure the fulfillment of its security goal. Thus, confidence is an
expression of conviction obtained through an assessment of confidence. Trust is determined by the
evidence obtained from the assessment of the object. Evidence, usually including an assurance
argument, documentation, and other relevant work material, provides the basis for an assurance
assertion that is based on the results of the design and security assessment activities.</p>
      <p>Confidence is the subject of the individual's perception of the specific safety requirements and the
information obtained from the assessment that the assessed item will function in accordance with the
specified requirements. Confidence refers to knowledge of the criteria, method, assurance system, and
assessment procedures used. At the same time, confidence is based on the knowledge that the dangers
we know do not have channels of influence on us, or they are minimized (protection has been
undertaken), and we know the capabilities of this protection, or the probability of possible dangers is
negligible. Regarding unknown dangers, we have a system that can predict them or to identify them and
adequately adapt to them. In addition, the reputation, qualifications, and experience of the assessors are
also important factors in building confidence. As a result of individual perception, different people may
have different degrees of confidence because of the use of an appropriate method of ensuring
confidence, both by the individual and by the organization.</p>
      <p>According to [6], it is important to differentiate between trust in accuracy (correctness) and trust in
effectiveness. Trust in accuracy is related to the assessment of the compliance of the critical
infrastructure object's information security with the requirements of standards or leading global
practices in the field of information security and information protection. In contrast, confidence in
effectiveness refers to the ability of security functions (processes) to withstand perceived or identified
threats. Both correctness assurance and efficiency assurance are important characteristics, and neither
is advantageous because both types of assurance operate on significant aspects of the object.</p>
      <p>Moreover, in [6] it is noted: "If the security capabilities of an object take into account potential
threats and these capabilities have not been analyzed regarding the establishment of accuracy and
project implementation, then one cannot be confident in the object's success in countering an attack.
Similarly, if an analysis has established the accuracy of the project and the correct implementation of
the security capabilities of the object, and the project does not provide for corresponding security
functions to counter probable threats, then one cannot be sure that the object will withstand these
threats." Therefore, in order to gain overall trust, the object must be assessed for project correctness,
implementation, and operation (element of correctness) and must have the appropriate security
capabilities to counter identified threats (element of effectiveness)." That is, a combination of these trust
measures is needed to gain overall trust in the information security of the critical infrastructure object,
which will serve as the basis for our confidence that the organization is implementing the adopted
security policy.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Model for assessing information security</title>
      <p>The most important purpose of an IS assessment of an CI object is to create information needs to
improve it IS. In this case, the purpose of the IS assessment is to determine the degree of confidence
with which the CI object has implemented the security policy. As noted, confidence in the organization's
information security is based on:</p>
      <p>• trust in information security, the quality of the trust assessment model and the background of the
persons conducting the trust assessment.</p>
      <p>• knowledge that known threats do not have channels of influence on business processes or they are
minimized (protection has been undertaken) and we know the capabilities of this protection, or the
probability of possible threats is negligible.</p>
      <p>• knowledge that relatively unknown threats are available that can predict or detecting them.</p>
      <p>For clarity, these factors can be represented by the following graph (Fig. 1). Here, the background
refers to the reputation, qualifications, and experience of a specialist. Let's introduce the notation:




is confidence in the IS.</p>
      <p>is credence to IS.
  is trust in correctness.
Сэ is confidence in efficiency;</p>
      <p>is the quality of the confidence assessment procedures.
  is the quality of procedures for assessing confidence in correctness.
Рэ is quality of procedures for assessing confidence in efficiency;
 is background of persons conducting trust assessment.
  is background of persons conducting the assessment of trust in correctness.
Вэ is the background of persons conducting the assessment of the credibility of effectiveness;
is knowledge of threats.
 is knowledge of the impact of known threats.
 is knowledge of forecasting and identifying new threats.</p>
      <p>Then the formation of confidence in the CI object’s information security can be represented as a
display</p>
      <p>: ( ,  ,  ,  ) →  ,
in which objects  ,  ,  ,  , in turn, are mappings of the form:
: (  ,  э) →   : (  ,  э) →  ,  : (  ,  э) →  ,  : ( ,  ) →  .</p>
      <sec id="sec-3-1">
        <title>Confidence in the information security of the CI object</title>
        <p>
          (
          <xref ref-type="bibr" rid="ref1">1</xref>
          )
(
          <xref ref-type="bibr" rid="ref2">2</xref>
          )
(
          <xref ref-type="bibr" rid="ref3">3</xref>
          )
        </p>
      </sec>
      <sec id="sec-3-2">
        <title>Knowledge of the impact of known threats</title>
      </sec>
      <sec id="sec-3-3">
        <title>Background of</title>
        <p>persons conducting
the assessment of
trust in correctness</p>
      </sec>
      <sec id="sec-3-4">
        <title>Background of individuals undergoing a performance</title>
      </sec>
      <sec id="sec-3-5">
        <title>Knowledge of predictive and new threat detection tools</title>
        <p>Trust in
information
security</p>
      </sec>
      <sec id="sec-3-6">
        <title>Trust in</title>
        <p>correctness
Quality of trust
assessment
models</p>
      </sec>
      <sec id="sec-3-7">
        <title>Backgroun d</title>
      </sec>
      <sec id="sec-3-8">
        <title>The quality of the validation confidence assessment model</title>
        <p>If we identify the mapping data with the corresponding tasks, then the assessment of an CI object’s
information security consists in solving five interrelated and interdependent tasks: assessing confidence
in the organization's information security, assessing confidence in information security, measuring the
quality of trust assessment procedures, assessing the background of individuals, assessing trust and
assessing knowledge regarding the impact known threats and forecasting and identifying new ones. At
the same time, the main problem that arises when solving these problems is the choice of the appropriate
indicator and the method for calculating it.</p>
        <p>One of the basic principles that must be guided when choosing criteria for assessing information
security is the unconditional reflection by the criterion of usefulness for the CI object in terms of
confidentiality, integrity, and availability of information [12]. Therefore, it is proposed to use
confidence as a criterion for assessing information security, since it is an expression of conviction that
an CI object’s information security system provides these security services, and as an indicator of
confidence - the generalized function of Harrington desirability [13]. This allows the use of a single
universal psychophysical measurement scale, which establish a correspondence between natural values
of indicators in physical scales and psychophysical parameters параметрами subjective linguistic
assessments of the "desirability (utility)" of these values for a person. We will use the one-way
constrained Harrington desirability function, which is given by:
  = 
( − 
( −  н)),
where  н is the normalized value of the indicator,   ,   is the desirability.</p>
        <p>
          In this case,  ′ the values are calculated by the formula:
) ,
)
 ′ = −2 + 7⋅(  −  (
          <xref ref-type="bibr" rid="ref4">4</xref>
          )
        </p>
        <p>(  − 
where   and   are the lower and upper boundaries of the area of change of the indicator   .</p>
        <p>After calculating the desirability   , they are convolved into a generalized indicator D a generalized
desirability function. This function is given by the formula:</p>
        <p>=  √∏ =1   .</p>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Assessment of confidence in the CI object’s information security</title>
      <p>
        According to (
        <xref ref-type="bibr" rid="ref2">2</xref>
        ), trust in information security  is based on trust   in the correct implementation
of processes and protective measures and trust  э in the effectiveness of information security processes.
      </p>
      <p>Assessment of confidence in the correctness of processes and protective measures. Confidence in
the correctness of processes and protective measures is reduced to assessing the degree of their
compliance with the requirements of the standard, which is taken as the standard ISO/IEC 27000:2009
[1]. This standard (as a family of standards) has been chosen as the base one because, in our opinion,
firstly, it absorbed the requirements and recommendations of international standards and best world
practices on the field of information security, and secondly, it contains methodological
recommendations for assessing information security, which can be applied to organizations of various
forms of ownership. If necessary, this standard can be supplemented by national standards in the field
of information security, as well as the requirements and recommendations of industry regulatory
documents on information security.</p>
      <p>To assess the level of IS compliance with the requirements of this standard, group and private IS
indicators are used. Group indicators of information security reflect the areas of ensuring the CI object’s
information security, and private indicators - the requirements of this standard for each of the areas.
With the help of private indicators, attributes of the information security processes that are different in
nature are assessed, which makes it possible to assess the level of compliance with the requirements of
this standard. An integral assessment of the fulfillment of the requirements of the standard [1] is formed
from the assessments of the IS group indicators.</p>
      <p>
        Let  = {  , | = 1,  }be a set of areas of information security; and   = {  | = 1,   } be the set
of requirements of the standard for the i-th area. We will measure the degree of fulfillment   of the
requirements using the Harrington scale. As a result, private estimates   of the correctness
(desirability) of the implementation of these requirements will be obtained. Then the group indicator
  , reflecting the correctness of the implementation of the requirements for the i-th area of information
security, is calculated by the formula:
(
        <xref ref-type="bibr" rid="ref5">5</xref>
        )
(
        <xref ref-type="bibr" rid="ref6">6</xref>
        )
(
        <xref ref-type="bibr" rid="ref7">7</xref>
        )
and the integral estimate by the formula:
  =  √∏ =1   ,
  =  √∏ =1
      </p>
      <p>This assessment reflects the degree of confidence in the correctness of the implementation of
processes and protective measures for ensuring the CI object’s IS in the requirements of the standard
[1]. Assessment of confidence in the effectiveness of information security processes. Confidence in the
effectiveness of information security processes is based on the requirements for the composition and
maturity model of information technology processes, which are widely used in the field of information
security. In [14,15] provides a comparative analysis of the most common and frequently used maturity
models, namely:
• Open Information Security Management Maturity Model (O-SIM3).
• Process Capability Model (PCM).
• Business Process Management Maturity Model (BPM MM).</p>
      <p>• Community Cyber Security Maturity Model (CCSMM).</p>
      <p>The analysis shows that none of the models considered fully reflects all the modern IS requirements
for CI objects of various sizes and areas of activity. Therefore, the CI object must be selected and
applied to its needs, and, possibly, developed its own maturity model with suitable metrics for it, using
the considered models as a template. At the same time, the PCM model in comparison with others,
firstly, has a recommendatory rather than descriptive character. Secondly, it is oriented on the IT
infrastructure and, thirdly, it is recommended by the standard [2] in the banking sector.</p>
      <p>This model will be used as a reference model for the maturity of information security processes. The
PCM maturity model is a measure for assessing the completeness, adequacy, and effectiveness of
information security management processes. This model defines six levels of maturity from zero to five.
The level of maturity of IS processes is determined by how fully and consistently the organization's
management is guided by IS principles, implements IS policies and requirements, uses the accumulated
experience and improves information security management system.</p>
      <p>We will assess the maturity level of information security processes according to the ISF (Information
Security Forum) methodology, which PwC companies widely use to assess the maturity of information
security processes in organizations. 21 information security processes are subject to assessment, which
are described considering the most well-known international practices and accepted standards
(ISO27000, COBIT5 for Information Security, SANS, NIST, etc.) (Table 1). We will assess the level
of maturity of IS processes according to the following scale (Table 2).</p>
      <p>This scale offers a way to assess "from initial to maximum", by absorbing the requirements of the
previous level of maturity by the next. For example, a process meets the second level of maturity only
if all the requirements for the first level are met.</p>
      <p>
        Let  = {  |  = 1,21}be the set of IS processes, and   be the assessment of the maturity of the
ith process, and  нis the normalized value   of the assessment calculated according to (
        <xref ref-type="bibr" rid="ref4">4</xref>
        ), where  
=0 and   = 5. Then the particular desirability   of the process   is calculated by the formula (
        <xref ref-type="bibr" rid="ref3">3</xref>
        )
and the assessment  эof confidence in the effectiveness of the of confidence in the effectiveness of the
CI object’s information security processes is calculated by the formula s is calculated by the formula:
      </p>
      <p>
        And finally, the assessment of confidence in the organization's information security is determined
by the value of the function:
(
        <xref ref-type="bibr" rid="ref8">8</xref>
        )
(
        <xref ref-type="bibr" rid="ref9">9</xref>
        )
  = √  ⋅  э
      </p>
      <p>Name of the IB process</p>
    </sec>
    <sec id="sec-5">
      <title>5. Measuring the quality of the trust and background assessment model</title>
      <p>As follows from the above, the assessment of trust is the result of an examination. Therefore, the
quality of the trust assessment model in this case depends on the extent to which the expert method and
the procedure for its implementation ensure the combination of mathematical models and value
judgments of experts to obtain a reliable result. Based on this, quality of model assessment can be
represented by a tuple:
&lt;  ,  &gt; , where  is the expert method,  is the procedure for its implementation. We will evaluate
these attributes on the Harrington scale in terms of their usefulness. Let    ,   and   э ,   э be estimates
of the usefulness of the expert method and the procedure for its implementation, which were used to
get С and Сэ, accordingly. Then the assessments   and  э quality of models for assessing confidence
in correctness and efficiency are calculated by the formulas:</p>
      <p>= √   ⋅    and  э = √  э ⋅   э,
and the quality of the IS trust assessment model according to the formula:
  = √  ⋅  э</p>
      <p>We will also give an assessment of the background of individuals who have assessed confidence in
information security using the Harrington scale. Let    and   э be a desirability of the persons
conducting the assessment of trust in correctness and efficiency. Then the background assessment of
the persons who assessed the confidence in information security can be obtained by the formula:
  = √   ⋅   э</p>
      <p>It should be noted that to obtain more accurate assessments of the quality of the trust computation
model for information security and the background of those conducting such calculations, a group
expert evaluation is required. In this context, the approach discussed in [16] can be used to reconcile
expert assessments.</p>
    </sec>
    <sec id="sec-6">
      <title>6. Assessment of knowledge regarding threats</title>
      <p>Knowledge of threats (Z) can be characterized by the completeness and reliability of information
(evidence) that, firstly, known threats do not have channels of influence on IS object or they are
minimized (protection has been undertaken) and we know the capabilities of this protection, or is
negligible the probability of possible threats (R). And second, that there are means capable of predicting
or detecting new threats (F).</p>
      <p>
        Evaluation of information completeness. The completeness of information relates to the main
informational dialectical contradiction between the need for complete knowledge about threats and the
lack of this knowledge. In socio-technical systems, the completeness of information is an indicator  ∈
[0,1) characterizing the measure of its sufficiency for deciding. This is a very uncertain and relative
indicator since the completeness of information is evaluated solely in relation to a specific task. Given
the above, we will assess the completeness of the initial data by filtering by comparing the available
information and the “reference”, which is sufficient to assess knowledge about threats. Such
(
        <xref ref-type="bibr" rid="ref12">12</xref>
        )
(
        <xref ref-type="bibr" rid="ref13">13</xref>
        )
(
        <xref ref-type="bibr" rid="ref14">14</xref>
        )
information, in accordance with DSTU 3396.0-96 [17], will be represented by the corresponding
morphological threat tree (Fig. 2).
      </p>
      <sec id="sec-6-1">
        <title>THREAT SS</title>
      </sec>
      <sec id="sec-6-2">
        <title>Sources of</title>
        <p>threats</p>
        <p>Forms of
implementation
foreign intelligence</p>
        <p>activities
unintentionally
intended</p>
        <p>entities
individuals</p>
        <p>radio
technical channels</p>
        <p>channels of special
influence by forming
fields and signals</p>
        <p>with a purpose
acoustic
chemical
optical
Compromising
emanation
destruction</p>
        <p>of the
protection</p>
        <p>system
violation of
information</p>
        <p>integrity
unauthorized
access
masquerading as a
registered user
overcoming
security measures
to use information
or impose false
information</p>
        <p>using
embedded
devices or
programs and</p>
        <p>rooting
computer
viruses
by connecting to
equipment and
communication
lines</p>
        <p>This tree consists of elementary structures (Fig. 3), which define the morphology of the
corresponding information headings ( ) with the required level of detail (ℎ ). Each detail, in turn, is a
parent rubric.</p>
        <p>For example, the heading Sources has a detail of the activities of foreign intelligence services, not
intentional and intentional. In turn, detailing not intentional and intentional are headings with detailing
individuals and legal entities. Then the headings (subheadings) of this tree are assigned the weights of
their influence (importance) on the top-level elements. Further, the available information is compared
with the morphological tree by assigning a Boolean parameter to   its elements:   = 1 if the i -th
rubric (subcategory) is present in the source data and   = 0 otherwise. Then, similarly to the procedure
for synthesizing global priorities of the method of analysis of hierarchies, the convolution of the
obtained estimates of the elements of the morphological tree is carried out. As a result, an estimate of
the completeness of the initial information will be obtained.</p>
        <p>Let the elements of the structure (Fig. 3) have the following parameters: 
= ( ,  ), ℎ =
{(  ,   )| = 1,  }, where  ,  and   ,   are the weight coefficients and. Boolean values of the elements
 and ℎ , respectively. Then the result of the convolution of the estimates of this structure is the value

that is taken  ∗ = ∑ =1   ⋅   as a parameter of  its parent element  . This parameter, in fact,
expresses the degree of informational completeness of the corresponding heading, considering the
importance of its subheadings, and, as a result, is taken as an assessment   of the completeness of the
original information. Assessment of the reliability of information. Under the reliability of information,
we mean its property to reflect the objective reality with the necessary accuracy. The criterion for
reliable information is the absence of distorted or false data, and the probability of its truth is used as a
measure of quantitative assessment. When assessing the reliability of information according to, we will
use the Kent scheme [18], which gives a clear classification of information in terms of the degree of its
reliability (Table 3).</p>
        <p>
          Then, knowing the reliability of the information available regarding threats and its
completeness, using the Harrington scale, it is possible to determine the usefulness of this
knowledge as a factor in ensuring confidence. Let   ,  
be assessments of the reliability of
evidence of knowledge R and F also  is an assessment of information’s density. Then estimates
  ,   ,   can be obtained using formulas (
          <xref ref-type="bibr" rid="ref3">3</xref>
          ) and (
          <xref ref-type="bibr" rid="ref4">4</xref>
          ). Then the assessment of the usefulness of
knowledge is calculated by the formula:
is determined by the value of the function:
        </p>
        <p>
          Finally, the degree   of confidence with which an CI object has implemented a security policy
  = 3√  ⋅   ⋅  
 
= 4√  ⋅   ⋅   ⋅  
(
          <xref ref-type="bibr" rid="ref15">15</xref>
          )
(
          <xref ref-type="bibr" rid="ref16">16</xref>
          )
        </p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>7. Practical implementation</title>
      <p>Consider an example that illustrates the proposed approach to assessing an CI object’s information
security. To ensure a comprehensive analysis and objectivity of assessments, it is advisable to involve
heads of information security services in CI object as experts [19]. A. Assessment of confidence in the
CI object’s information security. As noted, trust in information security is based on trust in the correct
implementation of processes and protective measures and trust in the effectiveness of information
security processes. The assessment of confidence in the correctness (correctness) of processes and
protective measures will be given using group and private indicators of information security. The
corresponding areas of information security (Table 4) are used as group indicators.</p>
      <p>
        For each area of information security assurance, there is a corresponding list of specific evaluation
indicators. To reduce the volume of the article, we will consider, for example, only the 4th and 6th areas
of information security and the first 4 private indicators that correspond to these areas. The assessment
of indicators is carried out according to a methodology that includes questionnaires using the Harrington
scale, and group indicators are calculated using the formula (
        <xref ref-type="bibr" rid="ref6">6</xref>
        ). The corresponding estimates are given
in Tables 5 and 6.
      </p>
      <p>
        As a result, the assessment of confidence in the correctness (correctness) of processes and protective
measures according to (
        <xref ref-type="bibr" rid="ref7">7</xref>
        ) is equal to:
  = √ 1 ⋅  2 = √0,78 ⋅ 0,85 = 0,81.
      </p>
      <p>Private
indicator
evaluation
 
0,83
0,68
0,95
0,7
0,78
Indicator
number</p>
      <p>Assessment of confidence in the effectiveness of information security processes. Such an assessment
is carried out for all processes presented in Table 3 on a scale (Table 4). The following evidence should
be used for analysis [10]:</p>
      <p> documentary evidence of the assessment of potential losses (damage) to the CI object’s business
because of the impact (possible implementation) of information security threats.</p>
      <p> documentary evidence of the choice of the risk minimization (treatment) option in relation to all
risks assessed after the process has been completed.</p>
      <p> documentary evidence of a decrease in the number of potential incidents caused by risks and
identified ex post facto.</p>
      <p> documentary evidence of an increase in the number of identified risks, the impact of which has
been weakened.</p>
      <p>Private indicators of information security when using cryptographic
 Э = 21√∏2=11   = 21√0,282 = 0,942 .</p>
      <p>
        Thus, the assessment of confidence in the CI object’s information security is determined by
the value of the function (
        <xref ref-type="bibr" rid="ref11">11</xref>
        ):
      </p>
      <p>= √0,81 ⋅ 0,942 = 0,874</p>
      <p>
        B. Measuring the quality of the trust and background assessment model. According to clause 6.
The quality of the trust assessment model will be assessed from the point of view of the extent to
which the expert method and the procedure for its implementation ensure the combination of
mathematical models and value judgments of experts to obtain a reliable result. In this case, we
will use the Harrington scale. Let    = 0.85,    = 0.93 and   э = 0.95,   э = 0.93 be
estimates of the usefulness of the expert method and the procedure for its implementation for
obtaining reliable estimates of confidence С and Сэ, accordingly. Then, using formulas (
        <xref ref-type="bibr" rid="ref12">12</xref>
        ) and
(
        <xref ref-type="bibr" rid="ref13">13</xref>
        ), we obtain the following estimates:
      </p>
      <p>= √0.85 ⋅ 0.93 = 0.89, э = √0.95 ⋅ 0.93 = 0.94,   = √0.89 ⋅ 0.94 = 0.91.</p>
      <p>We will also give an assessment of the background of individuals who have assessed confidence
in information security using the Harrington scale.</p>
      <p>
        Let    = 0.76 and   э = 0.83 be the assessments of the background of the persons who
assessed the trust in correctness and efficiency. Then according to (
        <xref ref-type="bibr" rid="ref14">14</xref>
        ) we get:
      </p>
      <p>
        C. Assessment of knowledge regarding threats. Let   = 81 and   = 90 be estimates of the
reliability of evidence of knowledge R and F according to the Kent scale, =0.85 is the degree of
completeness of the available information. Assuming for confidence estimates in (
        <xref ref-type="bibr" rid="ref4">4</xref>
        )   = 1 and
  = 99 we get: , and to estimate the degree of completeness, assuming
and , we get . Then desirability dR, dF and   according to (
        <xref ref-type="bibr" rid="ref3">3</xref>
        ), will
have the following values: , , And finally, using formula (
        <xref ref-type="bibr" rid="ref15">15</xref>
        ),
we obtain an estimate of the usefulness of knowledge regarding threats:
      </p>
      <p>
        = 3√  ⋅   ⋅   = 3√0,98 ⋅ 0,99 ⋅ 0.98 = 0.98,
and according to formula (
        <xref ref-type="bibr" rid="ref16">16</xref>
        ) the degree of confidence with which the CI object has implemented
the security policy:
      </p>
      <p>= 4√  ⋅   ⋅   ⋅   = 4√0,87 ⋅ 0,91 ⋅ 0,79 ⋅ 0,98 = 0,88</p>
      <p>Such confidence on the Harrington scale can be interpreted as “very high”.</p>
    </sec>
    <sec id="sec-8">
      <title>8. Conclusion</title>
      <p>A methodical approach to assessing the information security of an CI object by the criterion of confidence
is proposed. The factors of confidence formation are considered, and the generalized Harrington function is
proposed as its integral indicator. The assurance assessment includes an assessment of the CI object’s
information security assurance, the quality of the assurance assessment model, the background of the
individuals who conducted the assessment, and the threat knowledge assessment. In general, the considered
approach can be used as a pilot for the development of appropriate methods for assessing the information
security of CI objects of various forms of ownership, and the considered example clearly demonstrates its
availability.
9. References</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>[1] Law of Ukraine "On Critical Infrastructure" No. 1882-IX</source>
          ,
          <year>2021</year>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2] ISO/IEC 27000:
          <year>2009</year>
          ,
          <article-title>Information security management systems - Overview and vocabulary (Information security management system</article-title>
          .
          <source>General overview and terminology)</source>
          .
          <source>[Electronic resource]</source>
          . - URL https://www.iso.org/standard/41933.html.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <source>[3] ISO/IEC TR 15443-1</source>
          :2005 «
          <article-title>Information technology - Security techniques - A framework for IT security assurance</article-title>
          .
          <source>Part</source>
          <volume>1</volume>
          : Overview and framework». [Electronic resource]. - URL https://www.iso.org/standard/39733.html
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4] ISO/IEC 15408-1:2009 Information technology --
          <string-name>
            <surname>Security</surname>
          </string-name>
          techniques -
          <article-title>- Evaluation criteria for IT security -- Part 1: Introduction and general model [Electronic resource]</article-title>
          . - URL https://www.iso.org/standard/50341.html
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5] ISO/IEC 21827:2008 Information technology --
          <string-name>
            <surname>Security</surname>
          </string-name>
          techniques --
          <string-name>
            <surname>Systems Security</surname>
          </string-name>
          Engineering -- Capability Maturity Model®
          <article-title>(SSE-CMM®) [Electronic resource]</article-title>
          . - URL https://www.iso.org/standard/44716.html
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>Imamverdiev</given-names>
            <surname>Ya</surname>
          </string-name>
          .N.
          <article-title>Model for assessing confidence in the information security of an e-state // Problems of information technologies</article-title>
          .
          <source>Institute of Information Technologies of ANAS</source>
          , Baku, Azerbaijan.
          <year>2015</year>
          , No.
          <issue>1</issue>
          , pp.
          <fpage>25</fpage>
          -
          <lpage>32</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>Samokhvalov</given-names>
            <surname>Yu</surname>
          </string-name>
          .Y.
          <article-title>Developing the Analytic Hierarchy Process Under Collective Decision-Making Based on Aggregated Matrices of Pairwise Comparisons</article-title>
          .
          <source>Cybern Syst Anal</source>
          <volume>58</volume>
          ,
          <fpage>758</fpage>
          -
          <lpage>763</lpage>
          (
          <year>2022</year>
          ). https://doi.org/10.1007/s10559-022-00509-3
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>W.</given-names>
            <surname>Wu</surname>
          </string-name>
          , G. Kou, and
          <string-name>
            <given-names>Y.</given-names>
            <surname>Peng</surname>
          </string-name>
          , “
          <article-title>Group decision-making using improved multi-criteria decision making methods for credit risk analysis</article-title>
          ,
          <source>” Filomat</source>
          , Vol.
          <volume>30</volume>
          ,
          <string-name>
            <surname>Iss</surname>
          </string-name>
          .
          <volume>15</volume>
          ,
          <fpage>4135</fpage>
          -
          <lpage>4150</lpage>
          (
          <year>2016</year>
          ). https://doi.org/10.2298/FIL1615135W.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>K.</given-names>
            <surname>Peniwati</surname>
          </string-name>
          , “
          <article-title>Group decision making: Drawing out and reconciling differences</article-title>
          ,
          <source>” Int. J. Anal. Hierarchy Process</source>
          , Vol.
          <volume>9</volume>
          , No.
          <volume>3</volume>
          ,
          <fpage>385</fpage>
          -
          <lpage>389</lpage>
          (
          <year>2017</year>
          ). https://doi.org/10.13033/ijahp.v9i3.
          <fpage>533</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>E.</given-names>
            <surname>Forman</surname>
          </string-name>
          and
          <string-name>
            <given-names>K.</given-names>
            <surname>Peniwati</surname>
          </string-name>
          , “
          <article-title>Aggregating individual judgments and priorities with the analytic hierarchy process,”</article-title>
          <string-name>
            <surname>Eur. J. Oper. Res.</surname>
          </string-name>
          , Vol.
          <volume>108</volume>
          ,
          <string-name>
            <surname>Iss</surname>
          </string-name>
          .
          <volume>1</volume>
          ,
          <fpage>165</fpage>
          -
          <lpage>169</lpage>
          (
          <year>1998</year>
          ). https://doi.org/10.1016/s0377-
          <volume>2217</volume>
          (
          <issue>97</issue>
          )
          <fpage>00244</fpage>
          -
          <lpage>0</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>Samokhvalov</given-names>
            <surname>Yu</surname>
          </string-name>
          .Y.,
          <string-name>
            <surname>Brailovskyi M.M.</surname>
          </string-name>
          <article-title>Assessment of organization's information security on the criterion of confidence</article-title>
          .
          <source>Ukrainian Information Security Research Journal</source>
          .
          <year>2019</year>
          . Vol.
          <volume>21</volume>
          , no. 1. URL: https://doi.org/10.18372/
          <fpage>2410</fpage>
          -
          <lpage>7840</lpage>
          .
          <fpage>21</fpage>
          .13445
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>Canadian</given-names>
            <surname>Tusted Computer Product Evaluation Criteria</surname>
          </string-name>
          , v.
          <volume>3</volume>
          .0.
          <string-name>
            <given-names>Canadian</given-names>
            <surname>System Security Centre</surname>
          </string-name>
          ,
          <source>Communications Security Establishment, Government of Canada</source>
          ,
          <year>1993</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Harrington</surname>
            ,
            <given-names>E.C.</given-names>
          </string-name>
          <article-title>The desirable function</article-title>
          .
          <source>Industrial Quality Control. - 1965</source>
          . -Vol.
          <volume>21</volume>
          . No.
          <volume>10</volume>
          . - pp.
          <fpage>494</fpage>
          -
          <lpage>498</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14] [11]
          <article-title>Cobit 5: a model for evaluating processes [Electronic resource]</article-title>
          . - URL: https://cleverics.ru/subjectfield/articles/554-cobit5-pam
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Smirnov</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kutyrev</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kiktev</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          (
          <year>2021</year>
          ).
          <article-title>Neural network for identifying apple fruits on the crown of a tree. E3S Web of Conferences. International scientific forum on computer and energy Sciences</article-title>
          ,
          <source>WFCES</source>
          <year>2021</year>
          ,
          <volume>01021</volume>
          . https://doi.org/10.1051/e3sconf/202127001021
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Samokhvalov</surname>
          </string-name>
          , Yu.Ya.
          <article-title>Matching of expert estimates in preference relation matrices (2002) Upravlyayushchie Sistemy i Mashiny, (6</article-title>
          ), pp.
          <fpage>49</fpage>
          -
          <lpage>54</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          <source>[17] DSTU 3396</source>
          .0-
          <fpage>96</fpage>
          [Electronic resource]. - URL https://tzi.com.ua/downloads/DSTU%203396.
          <fpage>0</fpage>
          -
          <lpage>96</lpage>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Kent</surname>
            <given-names>S.</given-names>
          </string-name>
          <string-name>
            <surname>Strategic Intelligence</surname>
          </string-name>
          for American World Policy. Princeton: Princeton University Press. - 1949. -
          <fpage>226р</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Babenko</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hnatiienko</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ignisca</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Iavich</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <article-title>Modeling of critical nodes in complex poorly structured organizational systems</article-title>
          .
          <source>Proceedings of the 26th International Conference on Information Society</source>
          and University Studies (IVUS
          <year>2021</year>
          ), Kaunas, Lithuania, April
          <volume>23</volume>
          ,
          <year>2021</year>
          / CEUR Workshop Proceedings,
          <year>2021</year>
          ,
          <volume>2915</volume>
          , pp.
          <fpage>92</fpage>
          -
          <lpage>101</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>