<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta>
      <journal-title-group>
        <journal-title>Cybersecurity Providing in Information and Telecommunication Systems, February</journal-title>
      </journal-title-group>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Challenges and Solutions for Cybersecurity and Information Security Management in Organizations</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vladimer Svanadze</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Maksim Iavich</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Sergiy Gnatyuk</string-name>
          <xref ref-type="aff" rid="aff2">2</xref>
          <xref ref-type="aff" rid="aff3">3</xref>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Business and Technology University</institution>
          ,
          <addr-line>82 Ilia Chavchavadze ave, Tbilisi, 0160</addr-line>
          ,
          <country country="GE">Georgia</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Caucasus University</institution>
          ,
          <addr-line>1 Paata Saakadze str., Tbilisi, 0102</addr-line>
          ,
          <country country="GE">Georgia</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Maksyma Zaliznyaka str.</institution>
          ,
          <addr-line>Kyiv, 03142</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>State Scientific and Research Institute of Cybersecurity Technologies and Information Protection</institution>
        </aff>
        <aff id="aff4">
          <label>4</label>
          <institution>Yessenov University</institution>
          ,
          <addr-line>32 microdistrict, Aktau, 130000</addr-line>
          ,
          <country country="KZ">Kazakhstan</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2024</year>
      </pub-date>
      <volume>28</volume>
      <issue>2024</issue>
      <fpage>0000</fpage>
      <lpage>0001</lpage>
      <abstract>
        <p>The rapid development of Internet technologies and the current global situation have accelerated the growing demand for digital transformation in organizations. The technological components of digital transformation make it easier for organizations to operate, but at the same time, it is essential to maintain a balance between technological innovation and cybersecurity, as much as possible to protect the activities of organizations in cyberspace. The process of introducing digital transformation involves high-level management of organizations, as well as information security managers, cybersecurity specialists, and representatives of other structural units. This is necessary as digital transformation is a complex process and such joint involvement facilitates the development of cybersecurity strategies and policies within digital transformation, with proper planning of the process in a given direction. Digital transformation is an innovative approach that ensures the full or partial digitization of organizations and, in turn, is a serious challenge to the process of introducing proper cybersecurity management in organizations, which must be in line with each direction of digital transformation. Given the increasingly complex conditions posed by threats, the introduction and development of effective cybersecurity management is a major challenge for many organizations. The paper analyzes the existing problems of cyber security systems management in organizations and offers an innovative and efficient cyber security management model.</p>
      </abstract>
      <kwd-group>
        <kwd>1 Internet technologies</kwd>
        <kwd>digital transformation</kwd>
        <kwd>cyber security</kwd>
        <kwd>information security</kwd>
        <kwd>innovative approaches</kwd>
        <kwd>risk assessment</kwd>
        <kwd>threat</kwd>
        <kwd>standard</kwd>
        <kwd>report</kwd>
        <kwd>commitment</kwd>
        <kwd>necessary resource</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Security management is a process that allows
to control of internal and external threats that
prevent the normal functioning of
organizations. Security management of
organizations also means effective
coordination of actions aimed at the maximum
reduction of risks, which in turn ensures
maximum security of organizations. All of this
contributes to the safe transfer of information
both inside and outside the organization and
making appropriate decisions.</p>
      <p>In addition, one of the main components of
the security of organizations can be considered
the responsibility of each employee, and
security decisions should be made at all levels
of management of organizations. For this, it is
necessary that the top management correctly
assess the risks so that the regulations and
rules are properly implemented within the
organizations [1, 2].
In general, in the direction of security, the
problems that organizations face in the course
of their activities should be considered, and
those approaches that are suitable for the
organization should be selected. This is
important because the implementation of
security processes does not mean that security
will be fully ensured [3].</p>
      <p>
        Security approaches should be consistent
with the organization’s governance and
functioning, should be embedded in a unified
governance system, and should function in a
complex manner in harmony with other
organizational-structural units. Along with all
this, it is necessary for the security direction to
assess both internal and external risks, that are
a threat to the normal functioning of
organizations, and, taking this into account, to
implement the relevant rules and regulations,
the fulfillment of which will be a necessary
obligation for all levels of management [
        <xref ref-type="bibr" rid="ref4">4, 5</xref>
        ].
      </p>
      <p>Otherwise, to avoid this or that threat,
employees will try to act independently within
the framework of an incompetent approach to
the issue, which will ultimately harm the
normal functioning of organizations.</p>
      <p>
        There is no universal approach to the issue
of security, because the approaches within
organizations, which should ensure the safe
functioning of organizations, are different. In
particular, on the one hand, organizations may
adopt a formalized approach to security with
clearly defined roles and business processes,
and on the other hand, organizations may choose
a more informal management approach
involving security control and decision-making
[
        <xref ref-type="bibr" rid="ref5 ref6 ref7">6–8</xref>
        ]. Some questions need to be answered that
help organizations determine how formal
decisions and approaches should be, namely:
• How big is the organization and how
difficult is its organizational and structural
arrangement?
• What resources are available for effective
security governance?
• In what field does the organization
operate, what goals does it have and how
important is security for the organization’s
activities and achieving the set goals?
• Are there any kind of external and
internal requirements, be they
agreements, normative or sectoral, or
legal requirements?
      </p>
      <p>In practice, correct approaches reveal the
following:
• Security decisions must be taken.
• The person or groups of people who will
implement the safety management
process.
• Information necessary to make a correct
and reasonable choice.</p>
      <p>
        Regardless of the level of formality, the
following factors should be considered during
the effective management of organizations:
• All security measures must be in
accordance and consistent with the goals
and priorities of organizations.
• At all levels, a person or a group of people
responsible for making safety decisions
should be defined and allowed to carry
out their activities.
• Ensuring responsibility for decisions.
• Provide feedback to decision-makers.
• Any approach to safety governance must
be consistent with the wider system of
governance of organizations. Security
must be considered in the overall
structure of the organization, along with
other business priorities [
        <xref ref-type="bibr" rid="ref8">9</xref>
        ].
      </p>
      <p>The ISO/IEC27001 standard (Fig. 1),
developed by the International Organization
for Standardization (ISO) and the International
Electrotechnical Commission (IEC), defines
information technology governance as “a system
by which an organization directs and controls
security governance, defines an accountability
structure, and provides oversight to ensure
appropriate risk mitigation when management
implements the necessary controls to reduce
risks.”</p>
      <p>
        Given the increasingly complex threat
landscape, implementing and developing
effective cybersecurity governance is a
challenge for many organizations [
        <xref ref-type="bibr" rid="ref10 ref9">10, 11</xref>
        ].
      </p>
      <p>As research and organizational assessments
reveal, many organizations struggle to address
five fundamental cybersecurity and information
security governance issues, namely:
1. Cyber security strategy and goals.
2. Standardized processes.
3. Enforcement and accountability.
4. Implementation of supervision and
control at the high level.</p>
      <p>5. Necessary resources.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Cyber Security Strategy and</title>
    </sec>
    <sec id="sec-3">
      <title>Objectives</title>
      <p>
        To create an effective cybersecurity
governance program, organizations must
clearly define their risk management policies,
strategies, and objectives. Before the strategy
and objectives are defined, senior management
must evaluate its approach to risk
management. The strategy should be a
highlevel document that guides organizations in
maintaining and improving risk management
[
        <xref ref-type="bibr" rid="ref11 ref12">12, 13</xref>
        ]. Once the cyber security strategy and
goals are finalized, implementation across the
organization is essential.
      </p>
      <p>The main components of an effective cyber
security governance strategy are:
• Perceiving and understanding how
cyber security risks are related to the
organization’s business process
continuity and critical operations.
• Determination and development of
strategic goals of the organization.
• Identifying the need for cyber security
and developing goals.
• Determination of Key Performance</p>
      <p>Indicators (KPIs).
• Determination of resource needs.</p>
      <p>Establishment of continuous monitoring.</p>
    </sec>
    <sec id="sec-4">
      <title>3. Standardized Processes</title>
      <p>Without the implementation of existing and
approved standardized processes in
organizations, organizations can't ensure
normal functioning and achieve efficiency,
quality, and consistency. The latter,
consistency, is important in terms of common
understanding and management of risks
across organizations. A key factor in an
organization’s overall cybersecurity
management program is the repeatable
establishment of processes. In short, a
cybersecurity management program that is ad
hoc and inconsistent will eventually lead to
deficiencies. An ineffective cybersecurity
management program will lead to increased
security breaches, compromises, and a
dramatic increase in the number of attacks.</p>
    </sec>
    <sec id="sec-5">
      <title>4. Enforcement and Accountability</title>
      <p>It is necessary to have processes in place to
help ensure compliance with requirements.
Otherwise, cybersecurity programs will
become irrelevant to common processes, and
inconsistent, requests will be ignored, and
system crashes will occur. There is a risk that
those responsible for the implementation of
the cyber security program in organizations, as
soon as they notice the lack of accountability
and governance in the cyber security program,
immediately start looking for ways to solve the
problem, thereby disregarding the established
norms and standards. This is already a serious
problem for the entire system. Cybersecurity
management must be measurable and
enforceable, and responsibility for its
protection must be held at all levels of staff.</p>
      <p>
        The National Institute of Standards and
Technology (NIST) Risk Management
Framework (RMF) recommends a
multilayered approach to risk management
throughout the Information Systems
Development Life Cycle (SDLC) to help develop
security and privacy capabilities. This
approach can be implemented through
continuous monitoring, as well as constant
awareness of high-level management [
        <xref ref-type="bibr" rid="ref13 ref14 ref15">14–16</xref>
        ].
      </p>
    </sec>
    <sec id="sec-6">
      <title>5. Supervision and Control</title>
    </sec>
    <sec id="sec-7">
      <title>Exercised by the Upper Echelon</title>
      <p>
        Our Managing cyber security processes are the
concern and prerogative of top management in
organizations. The decision-making link and
the well-being of the organization depend on
their making the right decision. If the
organization’s e. year If “top management”
does not promote and support the issue of
proper management of cyber security, then
risk management in organizations will fail and
will experience complete collapse. Senior
management should be involved throughout
the “life” process, contributing not only to their
high awareness of the issue but also to
realizing their willingness and ability to
manage cybersecurity processes at a high level
[
        <xref ref-type="bibr" rid="ref16 ref17 ref18">17–19</xref>
        ]. The fifth section of ISO 27001
contains a list of leadership principles that are
important in developing an effective
cybersecurity management program, namely:
• It should be ensured that the
information security policy is created
and goals are set, which will be
consistent with the activities of the
organization’s strategic direction.
• Ensuring the integration of information
security management system
requirements into the organization’s
processes.
• Provision of information security
management systems with all necessary
resources.
• Constant awareness of the importance of
information security systems
management efficiency and its
requirements.
• Ensuring the achievement of the set goal
of the information security management
system.
• Staff support to increase the
effectiveness of the information security
management system.
• Promotion of continuous process
improvement.
      </p>
      <p>Senior management should create a
cybersecurity policy that:
• Corresponds to the goals of the
organization.
• Contains information security
objectives, or the structure to be used for
information security objectives.
• Contains the obligation to meet
requirements related to information
security protection.
• Includes the obligation of continuous
improvement of the information security
management system.
• Available as documented information.
• Distributed within organizations and
accessible to all stakeholders when
needed.</p>
      <p>Let’s represent the components of the
cybersecurity management system with some
variables and explain their significance:</p>
      <p>ISMP: Information Security Management
Policy.</p>
      <p>ISMS: Information Security Management
System.</p>
      <p>G: Goals of the organization.</p>
      <p>S: Strategic direction of the organization.</p>
      <p>R: Integration of ISMS requirements into
organizational processes.</p>
      <p>Resources: Necessary resources for ISMS.
E: Efficiency of ISMS and its requirements.
Goal: The set goal of ISMS.</p>
      <p>Staff: Staff support for increasing ISMS
effectiveness.</p>
      <p>P: Promotion of continuous process
improvement.</p>
      <p>Now, let’s define some mathematical
relationships:</p>
      <sec id="sec-7-1">
        <title>ISMP should be consistent</title>
        <p>organization’s goals (G) and
direction (S):</p>
        <p>ISMP = f(G, S).</p>
        <p>Integration of ISMS Requirements (R) into
organizational processes is crucial:</p>
      </sec>
      <sec id="sec-7-2">
        <title>Provision of</title>
        <p>(Resources) for ISMS:</p>
        <p>R = g(ISMS).</p>
        <p>Resources = h(ISMS).</p>
        <p>necessary
resources</p>
        <p>Constant awareness (E) of the importance
of ISMS efficiency and its requirements:</p>
        <p>Ensuring the achievement of the set goal
(Goal) of ISMS:</p>
        <p>Staff support (Staff) to increase ISMS
effectiveness:</p>
      </sec>
      <sec id="sec-7-3">
        <title>Promotion</title>
        <p>improvement (P):
of
continuous
process</p>
        <p>E = i(ISMS).</p>
        <p>Goal = j(ISMS).
Staff = k(ISMS).</p>
        <p>P = l(ISMS).</p>
      </sec>
      <sec id="sec-7-4">
        <title>Provision of</title>
        <p>(Resources) for ISMS:
necessary
resources</p>
        <p>The cybersecurity policy (ISMP) should
contain information security objectives and
the obligation to meet the requirements:
ISMP = m(Objectives, Requirements).
(8)</p>
        <p>The cybersecurity policy (ISMP) should
include the obligation of continuous
improvement of the ISMS:</p>
        <p>ISMP = n(Continuous_Improvement).
(9)</p>
        <p>The functions f, g, h, i, j, k, l, m, and n are
abstract and represent the relationships and
dependencies between the components. The
formulation of these functions can depend
specific organization’s structure, culture, and
goals.</p>
        <p>But we can represent the needed
parameters as follows:</p>
        <p>ISMP should be consistent with the
organization’s goals (G) and strategic
direction (S):</p>
        <p>Integration of ISMS requirements (R) into
organizational processes is crucial:</p>
        <p>ISMP = G+S.</p>
        <p>R = 2×ISMS.</p>
        <p>Resources = 3×ISMS.
(1)
(2)
(3)
(4)
(5)
(6)
(7)
(10)
(11)
(12)
with the
strategic</p>
        <p>Constant awareness (E) of the importance
of ISMS efficiency and its requirements:
E = 0.5×ISMS.</p>
        <p>Goal = ISMS/2.</p>
        <p>Ensuring the achievement of the set goal
(Goal) of ISMS:</p>
        <p>Staff support (Staff) to increase ISMS
effectiveness:</p>
        <p>Staff = ISMS+needed_number.</p>
        <p>continuous
process</p>
      </sec>
      <sec id="sec-7-5">
        <title>Promotion improvement (P): of</title>
        <p>P = ISMS×calculated_coefficient.</p>
        <p>The cybersecurity policy (ISMP) should
contain information security objectives and
the obligation to meet the requirements:
ISMP = Objectives+Requirement.
(17)</p>
        <p>The cybersecurity policy (ISMP) should
include the obligation of continuous
improvement of the ISMS:</p>
        <p>ISMP = Continuous_Improvement×2.
(18)
(13)
(14)
(15)
(16)</p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>6. Necessary Resources</title>
      <p>
        Top management must provide all necessary
resources needed to effectively implement and
comply with cybersecurity and information
security management systems. Funding should
be allocated taking into account the priorities
for the protection of information and
information systems that are adequate to the
relevant risks [
        <xref ref-type="bibr" rid="ref19 ref20">20, 21</xref>
        ]. Allocated financial
means should also consider qualified
personnel and their training. Also, allocated
resources should allow and ensure the ability
to purchase the necessary tools and
equipment, as well as ensure the continuity of
the process.
      </p>
      <p>
        The management of cyber security systems
begins with the top management of the
organization and all subsequent links,
personnel have their role, and their share of
responsibility in ensuring the protection of
information and information systems in the
organization. It is also necessary to take into
account the fact that it is necessary to conduct
cyber hygiene courses for the staff in the
organization, which in turn further reduces the
risks in the organization related to the
provision of cyber security [
        <xref ref-type="bibr" rid="ref21 ref22">22, 23</xref>
        ].
      </p>
      <p>
        Cybercriminals will become increasingly savvy
and dangerous to organizations, taking
advantage of the latest technological advances.
The most dangerous is the fact that not only
simple hackers are behind cyber-attacks, but
entire criminal syndicates, and even more
dangerous and alarming is the fact that
organizations and companies are increasingly
turning to the services of cybercriminals as
part of corporate espionage to gain their
advantages [
        <xref ref-type="bibr" rid="ref23">24–26</xref>
        ].
      </p>
      <p>Below are some recommended steps that
organizations can take to strengthen an
effective cybersecurity and information
security management system:</p>
      <p>1. The Chief Information Security Officer
(CISO) must report directly to the CEO, which
in turn emphasizes the strategic importance of
cyber security in the organization. Those
responsible for the protection of information
and information systems in organizations
should discuss and agree on the issue of cyber
security strategy and plans with the
organization’s senior management and the
board of directors. The CISO should actively
participate in board meetings and regularly
provide them with updated information on
threats, preparedness, and response plans.</p>
      <p>2. Conducting internal cyber security policy
review. It is necessary to conduct an
independent objective assessment to ensure
the validity of the cyber security policy and the
measures taken. The board of directors and all
internal stakeholders of the organizations
should be involved in this process so that full
support and agreement are achieved [27].</p>
      <p>3. We must make sure that organizations’
cyber security processes and control
mechanisms are reliable. In particular, are
security controls integrated, and is the
organization compliant with the NIST
Cybersecurity Framework?</p>
      <p>4. It is necessary to be familiar with all legal
and normative acts related to the circulation of
information in organizations and its
protection, as well as cyber security processes.
At the same time, the obligation to disclose
personal data to employees should not be
violated, and GDPR requirements should be
observed [28–30].</p>
      <p>5. Correct, targeted, and sufficient
budgeting of cyber security is necessary. As
practice shows, it should be about 10–12 % of
the total budget of the information technology
direction of organizations. Organizations’
boards of directors and senior management
must be informed of existing risks, the
cybersecurity landscape, and emerging threats
to budget appropriately and plan for response.
It should also be noted here that in the event of
an increase in risks and threats, budgeting
should be increased accordingly.</p>
      <p>
        6. A comprehensive incident response
strategy should be developed and regularly
updated. This allows organizations’ critical
infrastructure to be on constant alert for cyber
incidents. Also, in the development of response
plans against incidents, the participation of
other structural units of organizations and
their active involvement is necessary [
        <xref ref-type="bibr" rid="ref23">24, 31,
32</xref>
        ].
      </p>
      <p>7. It is necessary to have constant contact
with partners, suppliers, and clients of
organizations, to introduce and provide them
with advanced methods of ensuring cyber
security within the framework of this
relationship, and it is also necessary to demand
maximum compliance with established
requirements and rules from their side. This
will reduce risks and ensure better protection
of organizations' infrastructure.</p>
    </sec>
    <sec id="sec-9">
      <title>7. Conclusions</title>
      <p>The rapid development of Internet
technologies and the global situation have
accelerated the increase in demand for the
process of implementing digital
transformation in organizations. The
components of digital transformation make it
easier for organizations to operate, but at the
same time, it is necessary to maintain a balance
between technological innovation and cyber
security, in which both the board of directors,
senior management, information security
manager, and other structural units should be
involved. This is a complex process and such
joint engagement will help to develop a
cybersecurity strategy and policy within the
framework of digital transformation and to
properly plan the process.</p>
      <p>The World Economic Forum noted in its
annual risk assessment index that
cyberattacks and the resulting increased risks have
become one of the most important challenges
for corporations. The potential dangers
associated with such attacks go beyond
monetary and data loss, as a cyber-attack on a
victim can lead to customer attacks,
reputational damage, and fines from
regulatory authorities. All this can cause great
damage to the business. At the global level, [5]
2020 was a serious challenge in the direction
of cyber security. The same report notes that in
2021, the threats and methods of cyber-attacks
that existed in 2020 will remain.</p>
      <p>Digital transformation is the innovative
approach to the implementation of electronic
services and governance, which ensures full or
partial digitalization of organizations and, in
turn, is a serious challenge for the process of
introducing the correct management of cyber
security and information security in
organizations, which must be consistent and
consistent with other directions of digital
transformation. Therefore, it is obligatory to
offer the cyber security management model for
the organizations. The model offered in this
paper considers the major part of the
obligatory parameters.</p>
    </sec>
    <sec id="sec-10">
      <title>Acknowledgment</title>
      <p>This work was funded by the Shota Rustaveli
National Foundation of Georgia (SRNSFG)
(NFR-22-14060).</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <string-name>
            <given-names>F.</given-names>
            <surname>Kipchuk</surname>
          </string-name>
          , et al.,
          <source>Assessing Approaches of IT Infrastructure Audit, in: IEEE 8th International Conference on Problems of Infocommunications, Science and Technology</source>
          (
          <year>2021</year>
          ). doi:
          <volume>10</volume>
          .1109/ picst54195.
          <year>2021</year>
          .
          <volume>9772181</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <given-names>H.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Information security risk analysis SWOT, in: Workshop on Cybersecurity Providing in Information and Telecommunication Systems, CPITS</source>
          , vol.
          <volume>2923</volume>
          (
          <year>2021</year>
          )
          <fpage>309</fpage>
          -
          <lpage>317</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          ,
          <article-title>Security Rating Metrics for Distributed Wireless Systems</article-title>
          ,
          <source>in: Workshop of the 8th International Conference on “Mathematics. Information Technologies. Education:” Modern Machine Learning Technologies and Data Science</source>
          , vol.
          <volume>2386</volume>
          (
          <year>2019</year>
          )
          <fpage>222</fpage>
          -
          <lpage>233</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>V.</given-names>
            <surname>Svanadze</surname>
          </string-name>
          , Doctoral Thesis “Cybersecurity Policy and Strategy of Management,” Georgian Technical University,
          <year>2023</year>
          . V.
          <string-name>
            <surname>Svanadze</surname>
          </string-name>
          ,
          <source>The Impact of COVID-19 on the Future Development of Cybersecurity, Global Foundation for Cyber Studies and Research</source>
          , July
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>M.</given-names>
            <surname>Iavich</surname>
          </string-name>
          , et al.,
          <source>The Novel System of Attacks Detection in 5G, Lecture Notes in Networks and Systems</source>
          , vol.
          <volume>226</volume>
          (
          <year>2021</year>
          )
          <fpage>580</fpage>
          -
          <lpage>591</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>V.</given-names>
            <surname>Svanadze</surname>
          </string-name>
          ,
          <source>Near Future of Cyber Security and New Trends in Cyberspace, Global Foundation for Cyber Studies and Research</source>
          , Dec
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Zhmurko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Falat</surname>
          </string-name>
          ,
          <article-title>Efficiency Increasing Method for Quantum Secure Direct Communication Protocols</article-title>
          ,
          <source>Proceedings of the 2015 IEEE 8th International Conference on Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications</source>
          (IDAACS'
          <year>2015</year>
          ), Warsaw, Poland, Sept.
          <fpage>24</fpage>
          -
          <lpage>26</lpage>
          , vol.
          <volume>1</volume>
          (
          <year>2015</year>
          )
          <fpage>468</fpage>
          -
          <lpage>472</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>V.</given-names>
            <surname>Svanadze</surname>
          </string-name>
          ,
          <article-title>The Importance of Education in the Development of Cyber Security</article-title>
          ,
          <string-name>
            <given-names>Sci. Pract. Cyber</given-names>
            <surname>Secur</surname>
          </string-name>
          . J.
          <volume>5</volume>
          (
          <issue>2</issue>
          ) (
          <year>2021</year>
          )
          <fpage>39</fpage>
          -
          <lpage>44</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>P.</given-names>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <article-title>Evaluation Method of the Physical Compatibility of Equipment in a Hybrid Information Transmission Network</article-title>
          ,
          <source>J. Theor. Appl. Inf. Technol</source>
          .
          <volume>100</volume>
          (
          <issue>22</issue>
          ) (
          <year>2022</year>
          )
          <fpage>6635</fpage>
          -
          <lpage>6644</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>H.</given-names>
            <surname>Hulak</surname>
          </string-name>
          , et al.,
          <article-title>Dynamic Model of Guarantee Capacity and Cyber Security Management in the Critical Automated System</article-title>
          ,
          <source>in: 2nd Int. Conf. on Conflict Management in Global Information Networks</source>
          , vol.
          <volume>3530</volume>
          (
          <year>2023</year>
          )
          <fpage>102</fpage>
          -
          <lpage>111</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <source>[12] The Global Risks Report</source>
          <year>2021</year>
          ,
          <article-title>16th Edition of the World Economic Forum, In partnership with Marsh McLennan</article-title>
          , SK Group and Zurich Insurance Group,
          <volume>19</volume>
          Jan.,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [13]
          <article-title>Guide to Good Governance in Cybersecurity, DCAF Business and Security Division, Directorate for Security Cooperation and Defence (DCSD) of the French Ministry of Europe</article-title>
          and Foreign Affairs,
          <volume>19</volume>
          Jan.,
          <year>2021</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>V.</given-names>
            <surname>Svanadze</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gotsiridze</surname>
          </string-name>
          , Cyber Defense. Major Players in Cyberspace.
          <source>Cyber Security Policy, Strategy and Int. Conf. of Programming</source>
          , vol.
          <volume>2866</volume>
          Challenges (
          <article-title>Collection of Papers and (</article-title>
          <year>2020</year>
          )
          <fpage>164</fpage>
          -
          <lpage>173</lpage>
          . Articles),
          <source>Ministry of Defense of Georgia</source>
          [25]
          <string-name>
            <surname>J. Brown</surname>
          </string-name>
          , Executive's
          <string-name>
            <surname>Cybersecurity</surname>
          </string-name>
          (
          <year>2015</year>
          ).
          <source>Program Handbook: A Comprehensive</source>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Hu</surname>
          </string-name>
          , et al.,
          <article-title>Method of Searching Guide to Building and Operationalizing a Birationally Equivalent Edwards Curves Complete Cybersecurity Program, Packt over Binary Fields</article-title>
          , Advances in Publishing (
          <year>2023</year>
          ).
          <source>Intelligent Systems and Computing</source>
          , vol. [26]
          <string-name>
            <given-names>P.</given-names>
            <surname>Prystavka</surname>
          </string-name>
          , et al.,
          <source>Devising Information</source>
          <volume>754</volume>
          (
          <year>2019</year>
          )
          <fpage>309</fpage>
          -
          <lpage>319</lpage>
          . Technology for Determining the
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>S.</given-names>
            <surname>Gnatyuk</surname>
          </string-name>
          , et al.,
          <article-title>Method of Algorithm Redundant Information Content of a Building for Modular Reducing by Digital Image</article-title>
          ,
          <string-name>
            <surname>East</surname>
          </string-name>
          .-
          <source>Eur. J. Enterp. Irreducible Polynomial, Proceedings of Technol. 6</source>
          (
          <issue>2</issue>
          -
          <fpage>114</fpage>
          ) (
          <year>2021</year>
          )
          <fpage>59</fpage>
          -
          <lpage>70</lpage>
          . the 16th International Conference on [27]
          <string-name>
            <given-names>E. Y.</given-names>
            <surname>Handri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. A. W.</given-names>
            <surname>Putro</surname>
          </string-name>
          ,
          <string-name>
            <surname>D. I. Sensuse</surname>
          </string-name>
          , Control,
          <source>Automation and Systems</source>
          , Oct. Evaluating the People, Process, and
          <volume>16</volume>
          -19, Gyeongju, Korea (
          <year>2016</year>
          )
          <fpage>1476</fpage>
          -
          <article-title>Technology Priorities for NIST 1479</article-title>
          . Cybersecurity Framework Implementation
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>M.</given-names>
            <surname>Ekstedt</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Securi</surname>
            <given-names>CAD</given-names>
          </string-name>
          <article-title>by in E-Government, in: 2023 IEEE Int</article-title>
          .
          <article-title>Conf. Foreseeti: A CAD Tool for Enterprise on Cryptography, Informatics, and Cyber Security Management</article-title>
          , in: 2015
          <source>Cybersecurity (ICoCICs)</source>
          ,
          <source>Bogor, IEEE 19th Int. Enterprise Distributed Indonesia</source>
          (
          <year>2023</year>
          )
          <fpage>82</fpage>
          -
          <lpage>87</lpage>
          , doi: Object Computing Workshop, Adelaide,
          <volume>10</volume>
          .1109/icocics58778.
          <year>2023</year>
          .10277024.
          <string-name>
            <surname>SA</surname>
          </string-name>
          , Australia, (
          <year>2015</year>
          )
          <fpage>152</fpage>
          -
          <lpage>155</lpage>
          , doi: [28]
          <string-name>
            <given-names>D.</given-names>
            <surname>Kucherov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Berezkin</surname>
          </string-name>
          , L. Onikienko,
          <volume>10</volume>
          .1109/edocw.
          <year>2015</year>
          .
          <volume>40</volume>
          .
          <article-title>Detection of Signals from a LoRa System</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>C.</given-names>
            <surname>Schmittner</surname>
          </string-name>
          , et al.,
          <article-title>A Preliminary View under Interference Conditions</article-title>
          ,
          <source>in: Int. on Automotive Cyber Security Scientific-Practical Conf. on Problems of Management Systems</source>
          , in: 2020 Design, Infocommunications: Science and Automation &amp; Test in Europe Conference Technology (
          <year>2018</year>
          )
          <fpage>437</fpage>
          -
          <lpage>441</lpage>
          . &amp;
          <string-name>
            <surname>Exhibition</surname>
            (DATE), Grenoble, France [29]
            <given-names>T.</given-names>
          </string-name>
          <string-name>
            <surname>Khodadadi</surname>
          </string-name>
          , et al.,
          <article-title>Exploring the (</article-title>
          <year>2020</year>
          )
          <fpage>1634</fpage>
          -
          <lpage>1639</lpage>
          , doi: 10.23919/ Benefits and Drawbacks of Machine date48585.
          <year>2020</year>
          .
          <volume>9116406</volume>
          . Learning in Cybersecurity to Strengthen
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>N.</given-names>
            <surname>Goderdzishvili</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Khutsishvili</surname>
          </string-name>
          , Cyber- Cybersecurity
          <string-name>
            <surname>Defences</surname>
          </string-name>
          ,
          <source>2023 IEEE 30th crime in Georgia: Current Challenges and Annual Software Technology Conference Possible Developments, PMCG Research (STC)</source>
          , MD, USA (
          <year>2023</year>
          ). doi: Center,
          <year>2021</year>
          .
          <volume>10</volume>
          .1109/STC58598.
          <year>2023</year>
          .
          <volume>00005</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>M.</given-names>
            <surname>Antunes</surname>
          </string-name>
          , et al.,
          <source>Information Security</source>
          [30]
          <string-name>
            <given-names>O.</given-names>
            <surname>Chebanyuk</surname>
          </string-name>
          ,
          <article-title>An approach to software and Cybersecurity Management: A Case assets reusing</article-title>
          . In: Zlateva,
          <string-name>
            <given-names>T.</given-names>
            ,
            <surname>Goleva</surname>
          </string-name>
          ,
          <string-name>
            <surname>R.</surname>
          </string-name>
          <article-title>Study with SMEs in Portugal</article-title>
          . J. (eds.)
          <source>CSECS 2022. Lecture Notes of the Cybersecur. Priv</source>
          .
          <volume>1</volume>
          (
          <year>2021</year>
          )
          <fpage>219</fpage>
          -
          <lpage>238</lpage>
          , doi: Institute for Computer Sciences, Social
          <volume>10</volume>
          .3390/jcp1020012. Informatics and Telecommunications
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>F. E.</given-names>
            <surname>Catota</surname>
          </string-name>
          , et al.,
          <source>Cybersecurity Engineering</source>
          , vol.
          <volume>450</volume>
          (
          <year>2022</year>
          )
          <fpage>73</fpage>
          -
          <lpage>83</lpage>
          .
          <article-title>Education in a Developing nation: The doi</article-title>
          :
          <volume>10</volume>
          .1007/978-3-
          <fpage>031</fpage>
          -17292-
          <issue>2</issue>
          _
          <fpage>6</fpage>
          .
          <string-name>
            <given-names>Ecuadorian</given-names>
            <surname>Environment</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Cybersecur</surname>
          </string-name>
          . [31]
          <string-name>
            <given-names>K.</given-names>
            <surname>Tharot</surname>
          </string-name>
          , et al.,
          <string-name>
            <surname>Industrial Cybersecurity</surname>
          </string-name>
          (
          <year>2019</year>
          )
          <fpage>1</fpage>
          -
          <lpage>19</lpage>
          .
          <article-title>Game-Scenarios based on the MITRE</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [22]
          <string-name>
            <surname>I. Lee</surname>
          </string-name>
          ,
          <article-title>Internet of Things Cybersecurity: ATT&amp;CK Framework, in: 2023 Asia Literature Review and IoT Cyber Risk Meeting on Environment and Electrical Management</article-title>
          .
          <source>Future Internet</source>
          <year>2020</year>
          ,
          <volume>12</volume>
          .
          <string-name>
            <surname>Engineering (EEE-AM</surname>
            <given-names>)</given-names>
          </string-name>
          , Hanoi, Vietnam doi:
          <volume>10</volume>
          .3390/fi12090157. (
          <year>2023</year>
          )
          <fpage>1</fpage>
          -
          <lpage>4</lpage>
          , doi: 10.1109/eee-
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>R. J.</given-names>
            <surname>Raimundo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. T.</given-names>
            <surname>Rosário</surname>
          </string-name>
          , Cybersecu-
          <fpage>am58328</fpage>
          .
          <year>2023</year>
          .
          <volume>10395155</volume>
          . rity in the Internet of Things in Industrial [32]
          <string-name>
            <given-names>O.</given-names>
            <surname>Oksiiuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Chaikovska</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Fesenko</surname>
          </string-name>
          ,
          <source>Management. Appl. Sci</source>
          .
          <year>2022</year>
          ,
          <volume>12</volume>
          . doi: Security
          <source>Technique for Authentication</source>
          <volume>10</volume>
          .3390/app12031598.
          <article-title>Process in the Cloud Environment</article-title>
          , in: Int.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>O.</given-names>
            <surname>Chebanyuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Palahin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Markov</surname>
          </string-name>
          ,
          <string-name>
            <surname>Scientific-Practical Conf</surname>
          </string-name>
          .
          <article-title>Problems of Domain Engineering Approach of Infocommunications Science and Software Requirement Analysis</article-title>
          ,
          <source>in: 12th Technology</source>
          (
          <year>2019</year>
          )
          <fpage>379</fpage>
          -
          <lpage>382</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>