<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Scalarization of the vector criterion of information system survivability based on information security indicators ⋆</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Oleh Bakaiev</string-name>
          <email>oleg.bakaiev@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ihor Syvachenko</string-name>
          <email>igor.syvachenko@gmail.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Viktor Shevchenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>CPITS-II 2024: Workshop on Cybersecurity Providing in Information and Telecommunication Systems II</institution>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Institute of Software Systems of the National Academy of Sciences of Ukraine</institution>
          ,
          <addr-line>40-5 Akademik Hlushkov ave., 03187 Kyiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <fpage>294</fpage>
      <lpage>300</lpage>
      <abstract>
        <p>The paper considers the formulation of the problem of ensuring the survivability of the information system in the presence of harmful external influences. The main factors affecting survivability are identified, such as the level of information security and the level of cyber security. The possible structure of the vector criterion of survivability, which is based on indicators of the level of information security according to the security profiles of the information system: integrity, availability, and confidentiality, is analyzed. Considered ways of transition from a multi-criteria optimization problem to a single-criteria one: the method of transformation of criteria into constraints and the method of scalarization of a vector criterion. The method of scalarization of the vector criterion using scalar convolutions was chosen as the main method of transition to a single-criteria optimization problem. It was determined that additive convolution was the most widespread in scalarization problems. For the use in one convolution of criteria that may differ in physical nature, approaches were considered for the normalization of information security level values according to security profiles and the normalization of the corresponding weighting factors. An information security level assessment model based on additive convolution was created for the scenario when all component indicators and weighting factors dynamically change according to periodic laws. The simulation result shows the dynamics of changes in the general level of information security, which directly affects the level of survivability of the information system. It is shown that the obtained result is not trivial and the model is practically useful. The simulation model was created using the MatLab algorithmic language.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;information system</kwd>
        <kwd>model</kwd>
        <kwd>scalarization</kwd>
        <kwd>additive convolution</kwd>
        <kwd>survivability</kwd>
        <kwd>cyber security</kwd>
        <kwd>information security</kwd>
        <kwd>evaluation</kwd>
        <kwd>management</kwd>
        <kwd>decision support 1</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>Digital technologies permeate all spheres of society. A large
number of industries can no longer exist without computer
support. Digital systems facilitate and speed up many
processes of people’s activities. But digital accessibility, at
the same time, facilitates the implementation of harmful
effects on information systems. This reduces the
survivability of information systems. Survivability is the
ability of an information system to maintain its performance
in conditions of harmful effects on the information system.
One of the most common types of impacts on the
survivability of information systems is impacts on
information security, in particular its component—cyber
security. Ensuring survivability is relevant for information
systems at all levels: personal, corporate, state, and global.
Ensuring the viability of information systems that process
any state and community information [1], public and
private sector enterprises [2], scientific and educational
information [3, 4], as well as the personal information of
citizens of Ukraine and citizens of Ukraine’s partner
countries is urgent. This is evidenced by the analysis of the
main trends regarding the state of cyber security in the
world [5]. This question became especially relevant in the
conditions of the full-scale war of the Russian Federation
against Ukraine.</p>
      <p>Unfortunately, any use of information protection leads
to a decrease in performance. That is, the protection systems
themselves, in a certain sense, are also a threat to the
efficiency, that is, to the survivability of the system. A
certain balance is required between the level of protection
and the functionality of the information system. For this, it
is necessary to optimize information protection according
to all information protection profiles: integrity,
confidentiality, and availability. That is, it is necessary to
solve a multi-criteria problem, according to at least three
criteria. Others can be added to these criteria directly related
to safety and survivability, for example, minimum time to
identify hazards, minimum time to create a security system,
minimum costs for security, etc. One of the effective ways
to solve multicriteria problems is to reduce them to single
0009-0004-5427-1196 (O. Bakaiev);
0009-0005-3248-3371 (I. Syvachenko);
0000-0002-9457-7454 (V. Shevchenko)
© 2024 Copyright for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).
criteria using scalar convolutions, among which additive
audit of information infrastructure are presented in [23].
convolutions are the most common.
2. Analysis of existing studies
Usually, the costs of information protection correlate with
the costs of information technologies that need protection.
guarantee capability of automated information systems of
critical infrastructure objects are considered. Ensuring the
cyber security of critical infrastructure facilities today in the
conditions of war in Ukraine is one of the main tasks. In
[14], a general analysis of the danger of cybernetic attacks
on critical infrastructure is performed. Regulatory aspects
of
ensuring
the
information
security
of
critical
infrastructure objects are considered in [15]. Approaches to
cyber
protection
of critical infrastructure
based
on
integrated systems at the national level are studied in [16].
The issue of protecting critical infrastructure objects from
cyber-attacks
by
decentralizing
telecommunication
networks is discussed in [17]. The advantage of works [13–
17] is the systematic study of the issue. The disadvantage is
the concentration on the features of critical infrastructure
objects only. The situation requires universal approaches
that could ensure the survivability of information systems
within the framework of Ukraine’s digital transformation.</p>
      <p>General approaches to information security and cyber
security management are considered in [18, 19]. More
specific methodical approaches of NIST standards for
assessing and ensuring cyber security in the creation of
electronic government are considered in [20]. Targeted
management is possible only if there are metrics and
methods for evaluating the state of the process. Approaches
to assessing the level of information security in distributed
wireless systems are considered in [21]. Methods of
assessing the level of security of communication systems
against cyber-attacks are studied in [22]. Approaches to the</p>
      <p>Approaches to assessing information security risks are studied
in [24, 25]. Methodical approaches to the creation and
implementation of complex cybersecurity programs are
presented in [26]. Approaches to assessing information security
risks and creating information security systems are presented
in [27, 28]. Unfortunately, in works [18–28] we did not receive
the appropriate development of the model based on additive
convolutions, which reduced the possibilities of numerically
taking into account all the necessary representative factors, in
particular, and not only safety factors.
3. The purpose of the work</p>
      <p>and optimality criteria
The purpose of the work is the development of models and
methods for optimizing information protection according to
many criteria by reducing multi-criteria problems to
singlecriteria ones using scalar additive convolutions.</p>
      <p>On the way to the set goal, it is necessary to take into
account the fact that on the scale of the organization, costs
for information technology and costs for information
protection exist within the framework of a single budget.
The problem arises of its optimal distribution between
functionality and protection on two levels:
1.
2.</p>
      <p>At the stage of creation of defense systems and
information systems in general by establishing the
share of defense funding within the general budget.
During operation, the computing resource of the
information system is between tasks of basic
functionality and tasks of information protection.
This is done by choosing the mode of operation of
the protection system (setting the degree of
protection of the information system) by the
security scenario of the information system [7].</p>
      <p>At the strategic level, certain types of resources can be
the governing parameters that determine the level of
survivability, in particular, information system protection:</p>
      <p>is a resource spent on creating an information
system,</p>
      <p>is a resource spent on creating an
information protection system, 
is an information
resource spent on the main functions of the system, 
is an information resource spent on information protection.</p>
      <p>The
main
quality
criteria, according
to
which
information protection optimization should be performed,
are as follows: 
=</p>
      <p>is level of information security,  =
—the level of ensuring system functionality, 
= 
is the level of budget savings in the creation of information
technologies, 
=</p>
      <p>is the level of budget savings when
using information technologies.</p>
      <p>On the one hand, the given list of criteria can be
expanded
with</p>
      <p>other criteria by the situation and
clarification of the problem statement. On the other hand,
the given criteria can be a collapse of more detailed
additional criteria. For example, the information security
level criterion may consist of the following subcriteria:
=</p>
      <p>is ensuring information security according to
the integrity profile (Integrity), 
= 
is ensuring
information security according to the availability profile
(Availability), 
=</p>
      <p>is ensuring information security
according to the confidentiality profile (Confidentiality).</p>
      <p>As you can see, a two-level hierarchy of quality criteria
of the optimization process is formed. However, the number
of levels of the hierarchy of criteria can be greater. For
example, the integrity criterion may contain the following
components: 
=</p>
      <p>is the level of ensuring data
integrity at the physical level (physical destruction of the
information carrier), 
= 
is the level of ensuring
data integrity at the program level (program erasure of
information), 
=</p>
      <p>is data integrity level at the
addressing level (destruction of the FAT file location table).</p>
      <p>The number of levels of the hierarchy of quality criteria
is determined according to the statement of the problem.</p>
      <p>As you can see, many of the criteria are contradictory.
Most of the criteria cannot be nested in a complementary
hierarchy, such as a situation where improving the integrity
criterion can simultaneously improve the performance of
the availability criterion. In most cases, the situation is
different. For example, the minimum time criterion is
contradictory to the minimum cost criterion. Because if you
need to speed up the execution of the task, then you need to
spend more resources on its implementation (more funding,
more equipment, more personnel).
4. Transition to a single-criteria
problem by the method of
replacing criteria with restrictions
It is precisely because of the inconsistency of the criteria
that
multi-criteria
optimization
problems have
great
difficulties in solving them. To solve the problem,
multicriteria problems are converted to single-criteria problems.
The main methods of transition to single-criteria problems
are the following: replacing criteria with restrictions and
convolution of criteria.</p>
      <p>Replacing part of the criteria with restrictions. For
example, the minimum time criterion
 =</p>
      <p>→ 
can be replaced by a limitation—to spend no more than a
certain time on execution</p>
      <sec id="sec-1-1">
        <title>Or the minimum cost criterion</title>
      </sec>
      <sec id="sec-1-2">
        <title>Task 1.</title>
        <p>= 
constraint.</p>
        <p>Task 2.1.
 = 


= 

≤  .</p>
        <p>→ 
≤  .
→ 
, 
≤  , 
≥  .
replace with restrictions—spend no more than a given
amount of money on the project</p>
        <p>Usually, all criteria except one, the most uncertain, the most
variable, or the most important, are turned into constraints.
After that, a solution to the single-criteria optimization problem
is found, taking into account the constraints.</p>
        <p>For example, the task of minimizing time, finances and
simultaneously maximizing the effect
→ 

= 
,</p>
        <p>= 
→ 
→ 
can be transformed into one of the following problems with</p>
        <p>Task 2.3.</p>
        <p>≤  , 
= 
→ 
, 
≥  .
≤  , 
≤  , 
= 
→</p>
        <p>Unfortunately, it is not always clear which problem 2.1,
2.2, or 2.3 is the most adequate to the primary formulation
of problem 1. Secondly, this transformation of the problem
is not always adequate in principle. Such a transformation
occurs relatively easily if the importance of one criterion is
much higher than the importance of others. If all criteria
have approximately the same importance or the importance
changes over time, then such a transformation of the
problem statement may not be sufficiently justified.
5. Transition to a single-criterion
problem by the method of scalar
convolution
In such cases, another approach can be used—criteria
convolution (or vector criterion scalarization). At the same
time, it is worth remembering that for the criteria to be used
together in a single calculation procedure, they must be
normalized, that is, brought to a single scale of values. In
this case, it will be possible to build a general dependency
to determine the assessment of the level of information
security of the information system as a whole

=  ( ,  ,</p>
        <p>).

= 
(
, 
,</p>
        <p>).
 =</p>
        <p>.</p>
        <p>
          A similar dependency can be used at the next level
An additive convolution can be used as a function  [8–10]
(1)
(2)
(
          <xref ref-type="bibr" rid="ref13">3</xref>
          )
(4)
(5)
(6)
 =
        </p>
        <p>.</p>
        <p>Here  is the index of constituent elements at the  th level
of the hierarchy,  is the number of constituent elements at
the  th level of the hierarchy,  is the criterion of the lower
level of the hierarchy (component of the vector criterion), 
is the criterion of the upper level of the hierarchy (scalarized
criterion).</p>
        <p>Additive (or it is also called linear) convolution is the
most widespread type of scalar convolution. It is called
scalar because it allows us to move from multi-criteria
optimization (when we have a multi-dimensional vector of
criteria) to single-criteria when the optimization criterion is
represented by a scalar value. Additive convolution
collapses the set of criteria  to one scalar criterion  . Next,
to simplify the study, we will consider the features of scalar
convolutions on the example of a one-level convolution
 =</p>
        <p>.</p>
        <p>Here  is the serial number of a separate criterion,  is
the total number of criteria, 
is the component of the
collapsing vector criterion,  is a scalar criterion resulting
from the convolution.</p>
        <p>
          It is worth noting that the 
criteria have different
importance. Therefore, weight coefficients 
are usually used,
which determine the importance of the relevant criteria
(7)
(8)
(9)
(
          <xref ref-type="bibr" rid="ref19 ref27">10</xref>
          )
(11)
(12)
(13)
Weighting factors are determined expertly based on
experience
and
according
to
the
scenario
under
consideration. The fact is that different scenarios targeted
by the optimization task can have different sets of weighting
factors. This should be taken into account when preparing
assessments by experts. It would be better to determine the
values of the weighting factors based on more objective
data.
        </p>
        <p>However, this
requires a
clear
mathematical
procedure, which is usually simply absent at the initial
stages of research. Expert assessment in such a case is a
quick decision, which, regardless of its inaccuracy in details,
gives a good assessment in general. That is, with the help of
expert evaluation, it is possible to determine the value of the
weighting coefficients at a level that allows you to
adequately find a scalar criterion based on several known
constituent criteria. But that’s not all.
6. Normalization of scalar</p>
        <p>convolution
For various components of quality criteria to work together,
they must be normalized. For example, so that they all have
values in the same range of values. Most often, the range
from 0 to 1 is used as such a range. Then, if the
nonnormalized values of individual criteria were equal to  ,
and the maximum possible value of the corresponding
, then the normalized value of the
criterion is equal to 
criterion will be equal to

=

7. Modeling of assessment of the
level of information security
With the help of the given formalisms regarding the
normalization of weighting factors and quality criteria, we
will build a model of the level of information security, which
includes components according to the profiles of integrity,
availability, and confidentiality. Let’s introduce the notation
for the weighting coefficients.</p>
        <p>= 
= 
= 
information security according to the Integrity profile.
—the
weighting</p>
        <p>factor
—the
weighting
factor
for
for
normalized weight coefficients  ̅ will take the form
of the weighting coefficients of the importance of protection
, availability 
and
in the weighting coefficients of the importance of protection
of weighting coefficients of the importance of protection
We will present the information security level model as follows</p>
        <p>—weight factor and level of ensuring
information security according to the integrity profile,</p>
        <p>—weight factor and level of ensuring information
security according to the availability profile, 
, 
—the
weighting factor and the level of ensuring information
security according to the confidentiality profile. At the same
time, we take into account that all the specified values
change over time and depending on the information risk
scenario. That is, the refined model takes the form</p>
        <p>If the values of the levels of ensuring information
security according to the security profiles of integrity,
availability, and confidentiality do not change over time and
are equal to each other (Fig. 5)
then the resulting level of ensuring information security
 ( ) also does not change over time (Fig. 6) without
referring to the significant dynamics of changes in
weighting factors (Fig. 1).
(20)
(21)
(22)
the
profiles
of integrity  , availability 
and
confidentiality  , provided that the specified security levels
are equal
information security ensuring 
under the condition of
equality of components according to the profiles of integrity
 , availability 
and confidentiality 
A completely different picture is observed if the values of
the levels of ensuring information security according to the
profiles of integrity  , availability 
and confidentiality</p>
        <p>change dynamically over time (Fig. 7). In this case, the
resulting
level
of
information security ensuring  under the condition of the
dynamic change over time of the components according to
the
profiles of integrity  , availability 
and
confidentiality 
The
problem
remains to provide the
model with
representative input data regarding the values of the
criteria. Here you can rely on data from
objective
the case of weighting coefficients, on data from expert
assessments.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>8. Conclusions</title>
      <p>The creation of an effective information protection system
requires determining the correct balance between expenses
for protection and the functioning of the system.</p>
      <p>Decisions regarding the optimization of protection
should be made both for the stage of creating an information
system and for the stage of its operation.</p>
      <p>Quality criteria for information security should form a
certain structure, one of which options is a hierarchical
structure.</p>
      <p>The study is planned to maximize the level of
information protection according to a set of different
criteria: integrity, confidentiality, availability, minimum
time to detect danger, minimum resources, and minimum
time to create an information security system.</p>
      <p>Solving a multi-criteria optimization problem is a big
problem. To simplify the decision, it was decided to reduce
the multi-criteria problem to a single-criteria one.</p>
      <p>The scalarization of quality criteria using additive
convolution is adopted as the main method of transition to
a single-criteria problem.</p>
      <p>To simplify the processing of criteria that have different
physical nature, individual criteria were normalized and
weighting factors were normalized.</p>
      <p>The directions of further research are the construction
of a complete structure of quality criteria for all security
profiles, as well as the approbation of the proposed
approach based on simplified data of a real system
containing the personal data of users.
[1] Y. Dreis, et al., Model to Formation Data Base of
Secondary Parameters for Assessing Status of the
State Secret Protection, in: Cyber Security and Data
Protection, vol. 3800 (2024) 1–11.
[2] O. Burov, et
al.,</p>
      <sec id="sec-2-1">
        <title>Cybersecurity in</title>
      </sec>
      <sec id="sec-2-2">
        <title>Educational</title>
        <p>Networks, Advances in Intelligent Systems and
Computing (2020) 359–364. doi:
10.1007/978-3-03039512-4_56.
[3] V. Buriachok, V. Sokolov, Implementation of Active
Learning in the Master’s Program on Cybersecurity,
Advances in Computer Science for Engineering and
Education II, vol. 938 (2020) 610-624.
doi:10.1007/9783-030-16621-2_57.
[4] V. Buriachok, et al., Implementation of Active
Cybersecurity Education in Ukrainian Higher School,
Information Technology for Education, Science, and
Technics, vol. 178 (2023) 533–551.
doi:10.1007/978-3031-35467-0_32.
[5] V. Svanadze, Near Future of Cyber Security and New
Trends in Cyberspace, Global Foundation for Cyber</p>
      </sec>
      <sec id="sec-2-3">
        <title>Studies and Research (2020).</title>
        <p>[6]</p>
        <p>
          V. Shevchenko, et al., Designing of Functionally Stable
Information Systems Optimal for a Minimum of
Losses, in: 15th International Conference on the
Experience of Designing and Application of CAD
Systems
(CADSM)
(
          <xref ref-type="bibr" rid="ref12 ref14">2019</xref>
          )
36–40.
        </p>
        <p>doi:
10.1109/CADSM.2019.8779299.
[7]</p>
        <p>V. Shevchenko, D. Rabchun, Setting the Problem of
Resource Optimization of a Complex of Software</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          <source>Systems and Military Equipment</source>
          ,
          <volume>3</volume>
          (
          <issue>51</issue>
          ) (
          <year>2017</year>
          )
          <fpage>89</fpage>
          -
          <lpage>94</lpage>
          . [8]
          <string-name>
            <given-names>V.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , Optimization Modeling in Strategic
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          <string-name>
            <surname>Planning</surname>
            ,
            <given-names>TsVSD NUOU</given-names>
          </string-name>
          (
          <year>2011</year>
          ). [9]
          <string-name>
            <given-names>V.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Mathematical modeling of</source>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          <string-name>
            <given-names>T.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          (
          <year>2020</year>
          ). [10]
          <string-name>
            <given-names>V.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Management of defense</source>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          and MS of Ukraine (
          <year>2002</year>
          ). [11]
          <string-name>
            <given-names>V.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Predictive modeling of</source>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <article-title>computer virus epidemics, K.: UkrNC RIT (</article-title>
          <year>2019</year>
          ). [12]
          <string-name>
            <given-names>V.</given-names>
            <surname>Grechaninov</surname>
          </string-name>
          , et al.,
          <source>Formation of Dependability</source>
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <source>Internet of Things</source>
          , vol.
          <volume>3149</volume>
          (
          <year>2022</year>
          )
          <fpage>107</fpage>
          -
          <lpage>117</lpage>
          . [13]
          <string-name>
            <given-names>H.</given-names>
            <surname>Hulak</surname>
          </string-name>
          , et al.,
          <source>Dynamic Model of Guarantee</source>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <source>Critical Automated System, in: 2nd Int. Conf. on</source>
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <surname>Networks</surname>
          </string-name>
          , vol.
          <volume>3530</volume>
          (
          <year>2023</year>
          )
          <fpage>102</fpage>
          -
          <lpage>111</lpage>
          . [14]
          <string-name>
            <given-names>O.</given-names>
            <surname>Dovgan</surname>
          </string-name>
          ,
          <article-title>Critical Infrastructure as an Object of</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          (
          <year>2013</year>
          )
          <fpage>17</fpage>
          -
          <lpage>20</lpage>
          . [15]
          <string-name>
            <given-names>S.</given-names>
            <surname>Toliupa</surname>
          </string-name>
          , I. Parkhomenko,
          <string-name>
            <given-names>H.</given-names>
            <surname>Shvedova</surname>
          </string-name>
          , Security
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          <string-name>
            <given-names>Objects</given-names>
            <surname>Functioning</surname>
          </string-name>
          and Cyberpower Level 142
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          <string-name>
            <surname>Assesment</surname>
          </string-name>
          ,
          <source>3rd Int. Conf. Adv. Inf. Commun. Technol.</source>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          (
          <year>2019</year>
          )
          <fpage>463</fpage>
          -
          <lpage>468</lpage>
          . [16]
          <string-name>
            <given-names>L.</given-names>
            <surname>Slipachuk</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Toliupa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Nakonechnyi</surname>
          </string-name>
          , The Process
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          <string-name>
            <surname>Ukraine</surname>
          </string-name>
          ,
          <source>3rd Int. Conf. Adv. Inf. Commun. Technol.</source>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          (
          <year>2019</year>
          )
          <fpage>451</fpage>
          -
          <lpage>454</lpage>
          . [17]
          <string-name>
            <given-names>P.</given-names>
            <surname>Anakhov</surname>
          </string-name>
          , et al.,
          <source>Protecting Objects of Critical</source>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          <string-name>
            <surname>and Telecommunication Systems II</surname>
          </string-name>
          , vol.
          <volume>3550</volume>
          (
          <year>2023</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          240-
          <fpage>245</fpage>
          . [18]
          <string-name>
            <given-names>V.</given-names>
            <surname>Svanadze</surname>
          </string-name>
          , Doctoral Thesis “Cybersecurity Policy
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          <string-name>
            <surname>University</surname>
          </string-name>
          (
          <year>2023</year>
          ). [19]
          <string-name>
            <given-names>M.</given-names>
            <surname>Antunes</surname>
          </string-name>
          , et al.,
          <source>Information Security and</source>
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          <source>in Portugal, J. Cybersecur. Priv</source>
          .
          <volume>1</volume>
          (
          <year>2021</year>
          )
          <fpage>219</fpage>
          -
          <lpage>238</lpage>
          . doi:
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          10.3390/jcp1020012. [20]
          <string-name>
            <given-names>E. Y.</given-names>
            <surname>Handri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. A. W.</given-names>
            <surname>Putro</surname>
          </string-name>
          ,
          <string-name>
            <surname>D. I. Sensuse</surname>
          </string-name>
          , Evaluating
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          <string-name>
            <surname>Informatics</surname>
          </string-name>
          , and
          <string-name>
            <surname>Cybersecurity</surname>
          </string-name>
          (ICoCICs) (
          <year>2023</year>
          )
          <fpage>82</fpage>
          -
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          87. doi:
          <volume>10</volume>
          .1109/icocics58778.
          <year>2023</year>
          .
          <volume>10277024</volume>
          . [21]
          <string-name>
            <given-names>V.</given-names>
            <surname>Buriachok</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Sokolov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Skladannyi</surname>
          </string-name>
          , Security
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          <source>Workshop of the 8th International Conference on</source>
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          <string-name>
            <surname>Science</surname>
          </string-name>
          , vol.
          <volume>2386</volume>
          (
          <year>2019</year>
          )
          <fpage>222</fpage>
          -
          <lpage>233</lpage>
          . [22]
          <string-name>
            <given-names>A.</given-names>
            <surname>Storchak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Salnyk</surname>
          </string-name>
          , A Method of Assessing the
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          <string-name>
            <surname>Threats</surname>
          </string-name>
          , Inf. Proces. Syst.
          <volume>3</volume>
          (
          <issue>158</issue>
          ) (
          <year>2019</year>
          )
          <fpage>98</fpage>
          -
          <lpage>109</lpage>
          . [23]
          <string-name>
            <given-names>F.</given-names>
            <surname>Kipchuk</surname>
          </string-name>
          , et al.,
          <source>Assessing Approaches of IT</source>
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          <string-name>
            <given-names>Infrastructure</given-names>
            <surname>Audit</surname>
          </string-name>
          ,
          <source>in: IEEE 8th Int. Conf. on</source>
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          <string-name>
            <surname>Problems</surname>
          </string-name>
          of Infocommun.,
          <string-name>
            <surname>Sci</surname>
          </string-name>
          . and
          <string-name>
            <surname>Technol.</surname>
          </string-name>
          (
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          <source>doi: 10.1109/picst54195</source>
          .
          <year>2021</year>
          .
          <volume>9772181</volume>
          . [24]
          <string-name>
            <given-names>O.</given-names>
            <surname>Arkhypov</surname>
          </string-name>
          ,
          <article-title>Application of a Risk-based Approach</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          <string-name>
            <given-names>Security</given-names>
            <surname>Systems</surname>
          </string-name>
          ,
          <source>in: 1st Int. Workshop CITRisk</source>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          130-
          <fpage>143</fpage>
          . [25]
          <string-name>
            <given-names>H.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          , et al.,
          <source>Information Security Risk</source>
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          <volume>2923</volume>
          (
          <year>2021</year>
          )
          <fpage>309</fpage>
          -
          <lpage>317</lpage>
          . [26]
          <string-name>
            <surname>J. Brown</surname>
          </string-name>
          , Executive's Cybersecurity Program
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          <string-name>
            <given-names>Packt</given-names>
            <surname>Publishing</surname>
          </string-name>
          (
          <year>2023</year>
          ). [27]
          <string-name>
            <given-names>O.</given-names>
            <surname>Arkhypov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Arkhypova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Krejčí</surname>
          </string-name>
          , Adaptation of a
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          <source>Functioning of Information Security Systems</source>
          , in: 2nd
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          <article-title>Technologies for Risk-Informed Systems</article-title>
          , vol.
          <volume>3101</volume>
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          (
          <year>2021</year>
          )
          <fpage>83</fpage>
          -
          <lpage>92</lpage>
          . [28]
          <string-name>
            <given-names>S.</given-names>
            <surname>Shevchenko</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zhdanovа</surname>
          </string-name>
          , K. Kravchuk,
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          <string-name>
            <surname>Business</surname>
          </string-name>
          , Cybersecur. Edu., Sci.,
          <source>Technique</source>
          <volume>2</volume>
          (
          <issue>14</issue>
          )
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          (
          <year>2021</year>
          )
          <fpage>158</fpage>
          -
          <lpage>175</lpage>
          . doi:
          <volume>10</volume>
          .28925/
          <fpage>2663</fpage>
          -
          <lpage>4023</lpage>
          .
          <year>2021</year>
          .
          <volume>14</volume>
          .158175.
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>