Attributing the information to the state secrets held by state expert on secrets by setting, justification and determination of possible damage to national security if such disclosure for a decision on their degree of secrecy. Existing means of calculating such damage is overwhelmingly based on a conditional (scoring) assess its predicted value. The paper presents the methodology for the synthesis of systems analysis and estimation of possible damage to national security that allows model-based integrated presentation of damage parameters obtained by existing analysis tools in the protection of state secrets, to assess the damage as in conventional (ball) units and in value (monetary) value of loss. Founded she developed method: analysis and assessment of damage to national security in the protection of state secrets, assessing the importance of information on certain areas of state secrets, determine the level of competence of the expert committee members at state expert on secrets. In addition, the methodology enables to display the results in both qualitative and quantitative form, for example, using linguistic variables that are often used to describe complex systems. Software implementation of the system with an integrated database of existing tools allows an analysis and estimate of the possible damage to national security with additional automated reporting its results.
In the article presented block diagram ofsystem analysis and evaluation of the protection level of state information resources from social engineering attacks based on logical-linguistic approach and methodology for the synthesis of systems analysis and assessment of the level of protection of state information resources from attack by the class. On the basis of the proposed solutions have developed an algorithm and a tool, which, on the one hand, allows for an objective assessment of the level of preparedness of a particular person from the staff to social engineering attacks, and the other - to assess the overall level of security of government information resources, based on the responses of users. The effectiveness of the developed product has been proved in the experiment, the essence of which is disclosed in the paper. The software product implements a new approach to certification of personnel involved in the maintenance of state information resources, particularly related to their safety.
In the article presents synthesis methodology for the systems analysis and assessment of the protection level of state information resources socio-technical attacks which nowadays constitute one of the biggest threats and significantly affect the overall level of information security. A methodology is a flexible tool and makes it possible to assess the extent of preparedness of staff to socio-technical attacks on the different characteristics of management, technical base companies. The advantages of the proposed methodology is the use of this parameter as a quality expert to improve the quality of expert evaluation of threats, and use logical-linguistic approach and mathematical fuzzy logic, which makes it possible to formalize the risk assessment.
Розроблено програмну модель вибору механізмів захисту інформаційних ресурсів, яка за рахунок використання нечіткої логіки, дозволяє визначити здатність відповідної системи захисту протистояти кібератакам.