The increase in the use of artificial intelligence (AI) in geographic information systems (GIS) brings new challenges related to information security. The aim of this study is to develop a method for managing AI threats in the context of GIS, using the ISO 27001 standard to ensure data integrity, confidentiality, and availability. Despite the growing body of research on AI and GIS, there is a limited amount of work focusing on managing AI risks in the context of GIS using information security standards. This gap indicates the need to develop specific methods and tools that can be applied in practice. The study uses a blended approach, combining literature analysis and thematic analysis with empirical research. Existing standards and guidelines were reviewed, followed by expert interviews and surveys among the organization’s employees using GIS and AI. These methods allow you to collect qualitative and quantitative data on experiences, challenges, and opinions on AI threat management. The results of the study indicate that the application of ISO 27001 in the context of GIS and AI is effective in managing information security risks. The implementation of the standard allows systematic risk identification, assessment, and management, leading to increased data security and trust in AI systems. The study also highlights the need for further research and adaptation of safety standards to the specific requirements of AI and GIS. The findings of the study can be used by organizations that want to effectively manage AI risks in their GIS systems while ensuring compliance with international information security standards.
The article presents an overview of scientific articles and reports on the integration of the NIS 2 Directive into GIS systems in critical sectors. The aim of this article is to analyze the impact of the integration of the NIS 2 Directive with geographic information systems (GIS) in critical sectors on the level of security of organizations using the services of this type of systems. An innovative approach to the use of GIS as a tool supporting risk management and monitoring of critical infrastructure is presented. The practical value of the work lies in showing how the integration of GIS with NIS 2 can contribute to increasing the security of business continuity and resilience of critical infrastructure. The article describes the research methods used to analyze the impact of the NIS 2 directive on GIS systems and presents the results of these studies. The results of the research are discussed in the context of the existing literature and empirical research, indicating significant changes in the field of risk management and cybersecurity. The main results of the work indicate that the integration of GIS with NIS 2 enables effective monitoring of the technical condition of the infrastructure, quick identification of threats and coordination of corrective actions. In addition, the results highlight the benefits of integrating NIS 2 with GIS, but also highlight the technological and financial challenges that organizations face. The practical value of the work lies in showing how the integration of GIS with NIS 2 can contribute to increasing the resilience of critical infrastructure. In conclusion, the integration of NIS 2 with GIS in critical sectors is a demanding but necessary process to ensure a high level of cybersecurity and brings numerous benefits, including increasing the security and resilience of critical infrastructure, which contributes to social and economic stability.
In the face of growing cyber threats, ensuring the resilience of geographic information systems (GIS) is becoming a priority for organizations around the world The aim of the article is to analyze cyber resilience management in geographic information systems (GIS) taking into account the role of DORA, NIS 2, NIST and ISO 27001 standards. It looked at how different security standards can be integrated to enhance the protection of GISs. This work brings a novel approach by integrating various compliance standards in the context of GIS, which has not been widely discussed in the literature so far. The practical value of the article lies in providing comprehensive recommendations for organizations that want to increase their resilience to cyber threats. The study used a literature review method, including an analysis of existing research, industry reports, and compliance standards, and a case study of the implementation of these standards in the selected GIS, assessing the effectiveness and challenges of their implementation. The main results indicate that the implementation of DORA, NIS 2, NIST and ISO 27001 significantly increases the level of security and operational resilience of GIS systems. These standards emphasize the importance of risk management, rapid incident response, and continuous improvement of security procedures. The article also provides specific recommendations for organizations, such as the implementation of risk management methodologies, regular audits, employee training, and monitoring compliance with standards. These findings are supported by case studies and empirical data, making them plausible and practical for cybersecurity professionals.
The paper analyses the use of artificial intelligence (AI) in the risk and reliability management of IT systems in the context of the DevSecOps approach, which integrates security into the software lifecycle. In response to the growing number of cyber incidents and the limitations of traditional methods, specific AI tools and algorithms used in the automation of security tests, IT infrastructure monitoring and failure prediction were presented. The research was based on a review of 42 scientific publications and the analysis of empirical data from five IT organizations, using quantitative and qualitative methods (surveys, interviews, case studies). The results indicate that the integration of AI in DevSecOps increases the effectiveness of threat detection by 35%, reduces incident response time by 40%, and improves the reliability of IT systems. Key challenges such as data quality, model interpretability, and regulatory compliance were also identified. The article formulates recommendations for DevSecOps teams and technology decision-makers and indicates directions for further research in the field of ethics, interoperability, and auditability of AI systems.
This article explores the integration of security practices within the DevSecOps methodology in the context of Geographic Information Systems (GIS). The primary objective of the study is to analyze the impact of DevSecOps on ensuring business continuity and system resilience against cybersecurity threats. The specific goals of the research include: evaluating the effectiveness of DevSecOps in enhancing the resilience of GIS systems, identifying the benefits of automating security processes throughout the software development lifecycle (SDLC), analyzing organizational and technical challenges associated with implementing DevSecOps across various sectors. The novelty of the study lies in applying DevSecOps to the GIS domain, which is characterized by high demands for data availability, spatial data integrity, and regulatory compliance. The authors argue that traditional security approaches, typically implemented at the end of the system lifecycle, are insufficient in the face of evolving cyber threats. The article presents empirical findings and case studies from multiple organizations, demonstrating the practical benefits of DevSecOps in GIS environments. These include faster detection and remediation of vulnerabilities, increased automation of security testing, and improved system resilience. The study contributes to the growing body of knowledge on GIS security and offers practical recommendations for organizations adopting DevSecOps
The article defines and analyzes two basic concepts: cyber resilience strategy and business continuity plan in relation to GIS systems. To combine cyber resilience with the GIS business continuity system, in the context of the landscape of possible cyber threats and uncertainties, we used several aspects: cyber resilience framework and standards, business continuity team, a package of necessary documentation for ISO 22301:2019, technologies and tools supporting the implementation of the process ensures business continuity and a set of indicators for measuring GIS cyber resilience in the light of ensuring its business continuity. In each of these aspects, differences can be noticed in the approach to both the GIS cyber resilience strategy and the business continuity plan.
This article explores the relationship between today's threats and cyber resilience by defining key concepts, highlighting the role of cyber resilience, and examining how cyber resilience can play a significant role in stopping cyberattacks and keeping digital data secure. The essence of cyber resilience is the use of such a level of cyber protection that the cost of carrying out an attack on the subject of action exceeds the cost of possible damage. The aim of the article is also to encourage further discussion and progress towards the integration of cybersecurity and cyber resilience by proposing new concepts and models of cyber resilience systems, as well as assessing how to implement these concepts in different actors.
The purpose of this paper is to propose a way to measure security culture as a determinant of organizational safeguards for sensitive resources in GIS-class systems. Based on a critical analysis of the results of the risk estimation of sensitive resources in GIS, a variant of the model and then the methodology for measuring security culture was proposed, its basic elements were described, and then the criteria that should be met by each organizational safeguard, considered in the measurement of security culture, were identified and established. Based on the developed model of security culture measurement, methods for measuring this phenomenon in GIS from the perspective of the organizational safeguard system are indicated. Attention was focused on theoretical aspects and elements of best practice that indicate the feasibility of developing and applying a security culture model to measure security performance of GIS.
Elements of good practice and principles of a risk-based approach are often used in measurement models to assess the level of security of the information resource. The practical problem of measuring the level of information security is the selection of an appropriate model, followed by measures and a method that will be adequate to the specific organization. This puts in light second problem related to set a proper method of binding them together to generate consistent measure for determining the total information security level within organization. Paper presents two models proposed by authors for this use case. The proposed models can become the starting point for creating an information security evaluation system for each type of organization.
Paper is focused on theoretical and practical considerations related to risk management and cyber security based on the cyber kill chain concept introduced by Lockheed Martin. Proposed approach of cyber risk management embedded on the cyber kill chain is new and not reflected in the available literature. Proposed risk management process of identifying, analyzing, evaluating, assessing and ultimately responding to cyber threats and monitoring risks in each stage of the cyber kill chain is the heart of proposed approach. The approach may be used in organizations which are going to implement security mechanisms to align with the in-force requirements or to reduce cyber risks to accepted level. The process of the risk assessment introduced by the authors follows with the description of the example risk evaluation method based on a continuous-time Markov chain as a model of the cyber kill chain.
The article presents the concept of a security service model for the needs of maintaining the required level of information security of an organization’s information resources. The model of the security service was defined and its basic elements were characterized, such as: the objective of the security service, the organizational structure and the subject of action.
The article presents the concept of a security service model for the needs of maintaining the required level of information security of an organization’s information resources. The model of the security service was defined and its basic elements were characterized, such as: the objective of the security service, the organizational structure and the subject of action.
The article outlines a concept of maintaining the required level of security of assets of the information system in the organization (ISO) by making appropriate steering decisions, initiating the generation of the security configurations. The authors proposed and formulated the models of security subject and object as well as the model of the information system in the organization for controlling current level of information security (information recourses) and current performance properties of the operation subsystems, included in the ISO.
The article presents a method of assessing the usefulness of a security system (SS) and selecting the best from a set of solitary solutions after an emergency situation. It is believed that the best security system is the one that not only ensures that the required level of security of information resources is maintained, but it is characterized by the best values describing its useful properties. It is proposed that this problem should be considered as a task of multi-criteria optimization. Values describing functional properties of SS and partial criteria of measures of its usefulness have been proposed. The functional usability, reliability and security indicators are quantitative measures of the utility of SS.
The article presents a method of assessing the usefulness of a security system (SS) and selecting the best from a set of solitary solutions after an emergency situation. It is believed that the best security system is the one that not only ensures that the required level of security of information resources is maintained, but it is characterized by the best values describing its useful properties. It is proposed that this problem should be considered as a task of multi-criteria optimization. Values describing functional properties of SS and partial criteria of measures of its usefulness have been proposed. The functional usability, reliability and security indicators are quantitative measures of the utility of SS.
The article presents the concept of maintaining the required level of the engineering infrastructure (IT) usefulness through the use of a reconfiguration mechanism in relation to the usefulness of the safeguard subsystem and the hazard subsystem. Basic IT elements have been emphasized and characterized from the point of view of controlling its current level of usefulness (reliability and security). A model of engineering infrastructure was proposed for maintaining the required level of usefulness. Desired current IT usefulness is obtained by generating appropriate functional and IT security configurations from a set of allowable solutions. The proposed concept of ensuring reliability and security, taking into consideration the impact of not only various types of risk factors, but also changes in the conditions of the working/operating environment of both IT, its basic domain systems, and the information system, is the authors’ own proposition.
The subject of the article is the concept of a vector risk model and its application in the process of risk estimation and evaluation in relation to the basic features of the utility of engineering infrastructure. This model, with the help of dimensions such as e.g.: functionality (F), reliability (N), safety (B), continuity of operation (C), etc. as well as parameters concerning conditions and operating environment (E) takes into account the set of potential hazards to engineering infrastructure and a set of risk factors resulting both from the structure of the engineering infrastructure itself and its environment. This model allows for easy selection or development of the method of risk estimation and management, which in turn may be the basis for determining the current level of the usefulness of engineering infrastructure and the risk of its loss. The value of IT risk is determined using synthetic indicators expressed in the form of conventional potentials calculated on the basis of parameters and indices of basic engineering infrastructure elements. The model determined this way also allows, among others, for: continuous control of selected operational indicators of the basic elements of engineering infrastructure (for early detection of hazard, hazard and vulnerability analysis, risk assessment and evaluation related to individual features of engineering infrastructure), monitoring of infrastructure risk level and its changes to the music of introducing innovativeness and modern technological solutions to it, e.g. information technology solutions.
The article outlines the concept of maintaining the required security level of the information system in the organization (SIO) through appropriate control of the security configurations of the security system. The security system (SS) model was proposed and its basic elements characterized to maintain the current security level of the information resources. The desired current security feature of the SIO shall be obtained by generating appropriate security technical and organizational configurations from the set of permissible solutions. The proposed concept, which takes into account the impact of not only basic security elements of the information resources (e.g. types of resources, security attributes, risks, vulnerability), but also changes in the working conditions of the information system and security system as well as the entire security and quality management environment of the organization, constitutes own proposal of the authors.
The article addresses the issue of efficiency assessment of the security system (SS) in terms of the Information Security Management System (information resources of the information system in an organization). It is assumed that the purpose of such security system is to achieve a declared level of protection of the information system resources. Therefore, the level of security of information system in a given organization shall be determined by the efficiency assessment of the security system. The efficiency of the security system mainly depends on the functional properties of its components and other factors occurring in its environment. The article mainly focuses on security configuration, i.e. technical configuration and security organization configuration. The thesis was adopted that the efficiency of the security system may be considered as a set-theoretic efficiency sum of the security configurations invoked in such system. Additionally, it was assumed that a prerequisite for the desired measures (indicators) of the efficiency assessment of the SS shall be to propose such measures and develop appropriate ways (methods) of their calculation. The efficiency measure for the SS as well as two methods of efficiency assessment of the SS were proposed in the article.