RUS  ENG
Full version
JOURNALS // Computational nanotechnology // Archive

Comp. nanotechnol., 2023 Volume 10, Issue 4, Pages 23–38 (Mi cn444)

METHODS AND SYSTEMS OF INFORMATION PROTECTION, INFORMATION SECURITY

The modeling of processes of design of information protection systems in financial information systems

Ya. E. Prokusheva, S. V. Ponomarenkob, R. R. Maksimovb

a Plekhanov Russian University of Economics
b Belgorod University of Cooperation, Economics & Law

Abstract: The relevance and necessity of implementing measures to protect information in banks, as well as in other organizations of the financial and credit sphere of activity is due to a number of reasons. Firstly, these are the requirements of regulators in the field of information security. For systems of this type, there are also requirements for information security measures, which are set out in GOST R 57580.1–2017. Secondly, it is the objective presence of threats of various nature that require mandatory neutralization and exist in many modern information systems. In order to ensure information security, the security mechanisms used in the banking sector should take into account such factors as a significant amount of processed information, the need to ensure correct, stable and trouble-free operation, the multi-user nature of access to information resources, and ensuring the security of managed equipment. It is particularly worth highlighting the fact that failures and errors in the operation of banking information systems can entail not only economic damage or negative social consequences. In general, ensuring the information security of banking facilities is one of the most important tasks currently being solved at the state level, since they directly affect the stability of its economy. These circumstances determine the relevance of writing the article. The purpose of writing this paper is to develop a set of models describing the features of organizational, legal and technical processes that must be performed in banking information systems. As a methodological basis for writing the work, GOST R 57580.1–2017, as well as regulatory legal acts of the FSTEC of Russia, which are in the public domain, were used. To describe the ongoing work that must be performed to ensure the protection of information in banking information systems, the methodology of functional graphical modeling IDEF0 was used. The result of the research presented in this paper is a set of graphical and symbolic models describing the processes performed at the stages of designing and functioning of the information security system in critical information infrastructures.

Keywords: modeling of information security processes, information security, information security management, graphical modeling, methodology of functional graphical modeling, financial information systems.

UDC: 004.056.53

DOI: 10.33693/2313-223X-2023-10-4-23-38



© Steklov Math. Inst. of RAS, 2024