Issues of mathematical interpretation of the information security audit process using Petri nets
DOI: 10.21293/1818-0442-2024-27-2-15-20
DOI: 10.21293/1818-0442-2024-27-2-15-20
Abstract: This article presents the way to compose a mathematical model of the information security audit process. The model is based on the use of temporary Petri nets to describe the states of the information security audit process and the changes in the states of the audit process. The changes in the state of the information security audit process are described, that consist in identifying audit evidence, analyzing audit evidence and identifying violations in the implementation of information security measures, analyzing violations in the implementation of information security measures and developing comments that should be formed as the main result of the information security audit process. The reference indicators of the Petri net on the composition of components and connections between them have been developed to assess the completeness and correctness of the structure of real information security audit processes. The mathematical model obtained when assessing the efficiency of the information security audit process is primarily designed to answer the question of the sufficiency of audit components in the organization under study. In addition, the obtained mathematical model of the information security audit process represents the basis for simulation modeling of the audit process in order to assess the probability of achieving audit goals for a given period of audit time and a certain set of detected audit evidence.
Keywords: graphs, audit, information security audit, Petri net, trust, trust assessment, information security, cybersecurity
Funding: This work was supported by the National Technology Initiative (NTI) Project Support Fund as part of the NTI Competence Center's "Trusted Interaction Technologies" Program (agreement dated December 14, 2021, No. 70-2021-00246).
For citation:
Ognev I. A. Issues of mathematical interpretation of the information security audit process using Petri nets. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki, 2024, vol. 27, no. 2, pp. 15–20. DOI: 10.21293/1818-0442-2024-27-2-15-20
Authors and copyright holders:
Executive Secretary of the Editor’s Office
Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia
Phone / Fax: + 7 (3822) 701-582
Viktor N. Maslennikov
Executive Secretary of the Editor’s Office
Editor’s Office: 40 Lenina Prospect, Tomsk, 634050, Russia
Phone / Fax: + 7 (3822) 51-21-21 / 51-43-02