Теоретико-практичні аспекти управління інформаційною безпекою підприємства
Loading...
Date
Authors
item.page.thesis.degree.name
item.page.thesis.degree.level
item.page.thesis.degree.discipline
item.page.thesis.degree.department
item.page.thesis.degree.grantor
item.page.thesis.degree.advisor
item.page.thesis.degree.committeeMember
Journal Title
Journal ISSN
Volume Title
Publisher
Видавнича група "Наукові перспективи"
Abstract
Стаття присвячена дослідженню теоретико-практичних аспектів управління інформаційною безпекою підприємства в умовах цифрової трансформації економіки та зростання інтенсивності кіберзагроз. Актуальність дослідження зумовлена стрімким збільшенням кількості кіберінцидентів у глобальному масштабі, а також специфічними викликами, з якими стикається український бізнес в умовах функціонування під час збройного конфлікту, коли захист інформаційної інфраструктури набуває статусу стратегічного пріоритету корпоративного управління. Здійснено систематизацію наукових підходів вітчизняних та зарубіжних дослідників до проблематики інформаційної безпеки підприємства. На основі проведеного аналізу узагальнено та систематизовано визначення поняття «інформаційна безпека підприємства» відповідно до нормативно-правового, системного, ризик-орієнтованого, стратегічного та процесного підходів, що дозволяє розкрити багатовимірний характер досліджуваного феномену та виявити взаємозв'язки між окремими концептуальними напрямами його тлумачення. Окрему увагу приділено систематизації принципів забезпечення інформаційної безпеки, серед яких комплексність, дотримання конфіденційності, цілісності та доступності інформації, безперервність, мінімальні привілеї, адаптивність, обґрунтованість та відповідальність. Розглянуто методи захисту інформації, що поділяються на організаційні, технічні, криптографічні, правові та методи управління ризиками, застосування яких має носити узгоджений і взаємодоповнюючий характер та відповідати реальному рівню загроз і цінності інформаційних активів підприємства. У дослідженні чітко розмежовано суб'єкти системи управління інформаційною безпекою (від вищого керівництва та директора з інформаційної безпеки до персоналу та зовнішніх аудиторів), а також об'єкти захисту, що включають інформаційні активи, апаратне й програмне забезпечення, мережеву інфраструктуру, бізнес-процеси та репутацію підприємства як нематеріальний актив організації. Зазначено про необхідність впровадження системи управління інформаційною безпекою відповідно до міжнародних стандартів, що передбачає циклічний процес планування, впровадження, перевірки та вдосконалення.
The article is devoted to the study of theoretical and practical aspects of enterprise information security management in the context of digital transformation of the economy and the increasing intensity of cyber threats. The relevance of the study is determined by the rapid growth in the number of cyber incidents on a global scale, as well as by the specific challenges faced by Ukrainian businesses operating under conditions of armed conflict, where the protection of information infrastructure acquires the status of a strategic priority of corporate governance. A systematization of scientific approaches by domestic and foreign researchers to the problem of enterprise information security has been carried out. Based on the analysis performed, definitions of the concept of "enterprise information security" have been generalized and systematized in accordance with regulatory-legal, systemic, riskoriented, strategic, and process-based approaches, which makes it possible to reveal the multidimensional nature of the phenomenon under study and to identify interrelations between individual conceptual directions of its interpretation. Particular attention is paid to the systematization of the principles of ensuring information security, including comprehensiveness, adherence to confidentiality, integrity and availability of information, continuity, minimal privileges, adaptability, justifiability, and accountability. Methods of information protection are examined, divided into organizational, technical, cryptographic, legal, and risk management methods, the application of which should be coordinated and complementary in nature and correspond to the actual level of threats and the value of the enterprise's information assets. The study clearly delineates the subjects of the information security management system (from senior management and the Chief Information Security Officer to personnel and external auditors), as well as the objects of protection, which include information assets, hardware and software, network infrastructure, business processes, and the enterprise's reputation as an intangible asset of the organization. The necessity of implementing an information security management system in accordance with international standards is indicated, which involves a cyclical process of planning, implementation, verification, and improvement.
The article is devoted to the study of theoretical and practical aspects of enterprise information security management in the context of digital transformation of the economy and the increasing intensity of cyber threats. The relevance of the study is determined by the rapid growth in the number of cyber incidents on a global scale, as well as by the specific challenges faced by Ukrainian businesses operating under conditions of armed conflict, where the protection of information infrastructure acquires the status of a strategic priority of corporate governance. A systematization of scientific approaches by domestic and foreign researchers to the problem of enterprise information security has been carried out. Based on the analysis performed, definitions of the concept of "enterprise information security" have been generalized and systematized in accordance with regulatory-legal, systemic, riskoriented, strategic, and process-based approaches, which makes it possible to reveal the multidimensional nature of the phenomenon under study and to identify interrelations between individual conceptual directions of its interpretation. Particular attention is paid to the systematization of the principles of ensuring information security, including comprehensiveness, adherence to confidentiality, integrity and availability of information, continuity, minimal privileges, adaptability, justifiability, and accountability. Methods of information protection are examined, divided into organizational, technical, cryptographic, legal, and risk management methods, the application of which should be coordinated and complementary in nature and correspond to the actual level of threats and the value of the enterprise's information assets. The study clearly delineates the subjects of the information security management system (from senior management and the Chief Information Security Officer to personnel and external auditors), as well as the objects of protection, which include information assets, hardware and software, network infrastructure, business processes, and the enterprise's reputation as an intangible asset of the organization. The necessity of implementing an information security management system in accordance with international standards is indicated, which involves a cyclical process of planning, implementation, verification, and improvement.
Description
Keywords
інформаційна безпека підприємства, управління ризиками, кіберзагрози, система управління інформаційною безпекою, конфіденційність, цілісність, доступність, enterprise information security, risk management, cyber threats, information security management system, ISO/IEC 27001, confidentiality, integrity, availability
Citation
Іпполітов Є. М. Теоретико-практичні аспекти управління інформаційною безпекою підприємства. Успіхи і досягнення у науці. 2026. № 6 (28). С. 744-756. https://doi.org/10.52058/3041-1254-2026-6(28)-744-756.
