Simulation Modeling of the Risk Processing Process
摘要
The article suggests a method for evaluating information security risks in automated process control systems, state information systems, municipal information systems, personal data information systems, and critical information infrastructure objects by adhering to the legal requirements of the Russian Federation concerning the protection of these specific types of information systems, the draft national standard GOST R ISO/IEC 27005, planned for adoption in the near future, and risk assessment standards in the framework of the Russian Federation. These standards are built on the basis of GOST R 57193-2016, which describes the processes of the life cycle of human-made systems. The problem of residual risk handling for unacceptable risks is considered, after analyzing which another principle of safety management is proposed. A methodology for assessing the trust in the risk management system is obtained, with the help of which it is necessary to build a risk management system at critical information infrastructure objects.