Issues of mathematical interpretation of the information security audit process using Petri nets

DOI: 10.21293/1818-0442-2024-27-2-15-20

Download article in PDF format

JATS xml

Abstract: This article presents the way to compose a mathematical model of the information security audit process. The model is based on the use of temporary Petri nets to describe the states of the information security audit process and the changes in the states of the audit process. The changes in the state of the information security audit process are described, that consist in identifying audit evidence, analyzing audit evidence and identifying violations in the implementation of information security measures, analyzing violations in the implementation of information security measures and developing comments that should be formed as the main result of the information security audit process. The reference indicators of the Petri net on the composition of components and connections between them have been developed to assess the completeness and correctness of the structure of real information security audit processes. The mathematical model obtained when assessing the efficiency of the information security audit process is primarily designed to answer the question of the sufficiency of audit components in the organization under study. In addition, the obtained mathematical model of the information security audit process represents the basis for simulation modeling of the audit process in order to assess the probability of achieving audit goals for a given period of audit time and a certain set of detected audit evidence.

Keywords: graphs, audit, information security audit, Petri net, trust, trust assessment, information security, cybersecurity

Funding: This work was supported by the National Technology Initiative (NTI) Project Support Fund as part of the NTI Competence Center's "Trusted Interaction Technologies" Program (agreement dated December 14, 2021, No. 70-2021-00246).

For citation:
Ognev I. A. Issues of mathematical interpretation of the information security audit process using Petri nets. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2024, vol. 27, no. 2, pp. 15–20. DOI: 10.21293/1818-0442-2024-27-2-15-20

Authors and copyright holders:

  • Ognev I. A. , Novosibirsk State Technical University (Novosibirsk, Russia)

  • 1. Al-Fatlawi Q.A., Al Farttoosi D.S., Almagtome A.H. Accounting Information Security and IT Governance Under COBIT 5 Framework: A Case Study. Webology, 2021, vol. 18, no. Special Iss. 2, pp. 294–310.
  • 2. Da Veiga A., Astakhova L.V., Botha A., Herselman M. Defining organisational information security culture-Perspectives from academia and industry. Computers & Security, 2020, vol. 92, p. 101713.
  • 3. Makarenko S.I. [Information security audit: main stages, conceptual framework, classification of activities]. Control, Communication and Security Systems, 2018, no. 1, pp. 1–29 (in Russ.)
  • 4. Seeba M., Affia A.O., Mäses S., Matulevičius R. Create your own MUSE: A method for updating security level evaluation instruments. Computer Standards & Interfaces, 2024, no. 87, p. 103776.
  • 5. Parker S., Wu Z., Christofides P.D. Cybersecurity in process control, operations, and supply chain. Computers & Chemical Engineering, 2023, no. 171, p. 108169.
  • 6. Shelupanov A.A., Bragin D.S., Konev A.A., Permyakov R.A. [Technologies of trusted interaction in the ecosystem of the National Technology Initiative]. Sovremennoe obrazovanie: integratsiya obrazovaniya, nauki, biznesa i vlasti [Modern education: integration of education, science, business and government]. Tomsk, 2022, pp. 15–20 (in Russ.)
  • 7. Orlov S.P., Susarev, S.V. [Simulation models on Petri nets for analyzing maintenance and repair processes of complex technical systems]. Vestnik of Samara State Technical University. Technical Sciences Series, 2023, no. 30, pp. 49–75 (in Russ.)
  • 8. Naumov V. N., Buinevich M.V., Strelets A.D. [Analysis of the applicability of a process approach based on graph analytics to the study of organizational systems]. Bulletin of St. Petersburg University State Fire Service EMERCOM of Russia, 2022, no. 3, pp. 89–101 (in Russ.)
  • 9. Sochnev A.N. [Optimization of assembly production based on Petri net simulation]. Bulletin of MSTU im. N.E. Bauman. Instrumentation Series, 2021, vol. 135, no. 2, pp. 133–146 (in Russ.)
  • 10. Sitskaya A.V., Selifanov V.V., Zvyagintseva P.A. [Information security audit issues]. Digital Technology Security, 2023, vol. 110, no. 3, pp. 67–82 (in Russ.)
  • 11. ISO 19011:2018 – Guidelines for auditing management systems. Available at: https://pqm-online.com/assets/files/pubs/translations/std/iso-19011-2018-(rus).pdf, free (Accessed: May 20, 2024)
  • 12. GOST R ISO/MEK 27007–2014 Informatsionnaya tekhnologiya (IT). Metody i sredstva obespecheniya bezopasnosti. Rukovodstva po auditu sistem menedzhmenta informatsionnoi bezopasnosti [ISO/IEC 27007–2014 Information technology (IT). Methods and means of ensuring security. Guidelines for auditing information security management systems] (in Russ.) Available at: https://internet-law.ru/gosts/gost/57828/, free (Accessed: May 19, 2024)
  • 13. Senkiv D.A. Audit as a Means of Ensuring Information Security of Web Applications and Used Computer Systems. American Scientific Journal, 2020, vol. 40, no. 2, pp. 54–57.
  • 14. Metodicheskii dokument «Metodika otsenki ugroz bezopasnosti informatsii» (utv. Federal'noi sluzhboi po tekhnicheskomu i eksportnomu kontrolyu 5 fevralya 2021 g.). [Methodological document «Methodology for assessing threats to information security» (approved by the Federal Service for Technical and Export Control on February 5, 2021)] (in Russ.) Available at: https://www.garant.ru/products/ipo/prime/doc/400325044/, free (Accessed: May 20, 2024).
  • 15. Kitsios F., Chatzidimitriou E., Kamariotou M. The ISO/IEC 27001 Information Security Management Standard: How to Extract Value from Data in the IT Sector. Sustainability, 2023, vol. 15, no. 7, p. 5828.
  • 16. Denisenko V.V., Goncharov A.M., Maslov I.P. [Information Security Audit of Organizations: Methods and Benefits]. Scienceosphere, 2023, no. 11–2, pp. 135–140 (in Russ.)
  • 17. Shirokova S.V., Rostova O.V., Bolsunovskaya M.V., Dmitrieva L.A., Almataev T.O. Information security audit for a manufacturing company. Information and Control Systems, 2023, vol. 122, no. 1, pp. 41–50.
  • 18. Sirotskii A.A., Reznichenko S.A. [Formalized Model of Audit of Organization Information Security for Compliance with Standards Requirements]. Information Technology Security, 2021, vol. 28, no. 3, pp. 103–117 (in Russ.)
  • 19. [Decree of the Government of the Russian Federation of February 17, 2018 № 162 «On approval of the Rules for the implementation of state control in the field of ensuring the security of significant objects of critical information infrastructure of the Russian Federation»] (in Russ.). Available at: https://base.garant.ru/71883452/, free (Accessed: May 21, 2024).
Editorial office address

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 701-582

  journal@tusur.ru

 

Viktor N. Maslennikov

Executive Secretary of the Editor’s Office

 Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia

  Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02

Subscription for updates