Теоретико-практичні аспекти управління інформаційною безпекою підприємства

Loading...
Thumbnail Image

Date

item.page.thesis.degree.name

item.page.thesis.degree.level

item.page.thesis.degree.discipline

item.page.thesis.degree.department

item.page.thesis.degree.grantor

item.page.thesis.degree.advisor

item.page.thesis.degree.committeeMember

Journal Title

Journal ISSN

Volume Title

Publisher

Видавнича група "Наукові перспективи"

Abstract

Стаття присвячена дослідженню теоретико-практичних аспектів управління інформаційною безпекою підприємства в умовах цифрової трансформації економіки та зростання інтенсивності кіберзагроз. Актуальність дослідження зумовлена стрімким збільшенням кількості кіберінцидентів у глобальному масштабі, а також специфічними викликами, з якими стикається український бізнес в умовах функціонування під час збройного конфлікту, коли захист інформаційної інфраструктури набуває статусу стратегічного пріоритету корпоративного управління. Здійснено систематизацію наукових підходів вітчизняних та зарубіжних дослідників до проблематики інформаційної безпеки підприємства. На основі проведеного аналізу узагальнено та систематизовано визначення поняття «інформаційна безпека підприємства» відповідно до нормативно-правового, системного, ризик-орієнтованого, стратегічного та процесного підходів, що дозволяє розкрити багатовимірний характер досліджуваного феномену та виявити взаємозв'язки між окремими концептуальними напрямами його тлумачення. Окрему увагу приділено систематизації принципів забезпечення інформаційної безпеки, серед яких комплексність, дотримання конфіденційності, цілісності та доступності інформації, безперервність, мінімальні привілеї, адаптивність, обґрунтованість та відповідальність. Розглянуто методи захисту інформації, що поділяються на організаційні, технічні, криптографічні, правові та методи управління ризиками, застосування яких має носити узгоджений і взаємодоповнюючий характер та відповідати реальному рівню загроз і цінності інформаційних активів підприємства. У дослідженні чітко розмежовано суб'єкти системи управління інформаційною безпекою (від вищого керівництва та директора з інформаційної безпеки до персоналу та зовнішніх аудиторів), а також об'єкти захисту, що включають інформаційні активи, апаратне й програмне забезпечення, мережеву інфраструктуру, бізнес-процеси та репутацію підприємства як нематеріальний актив організації. Зазначено про необхідність впровадження системи управління інформаційною безпекою відповідно до міжнародних стандартів, що передбачає циклічний процес планування, впровадження, перевірки та вдосконалення.
The article is devoted to the study of theoretical and practical aspects of enterprise information security management in the context of digital transformation of the economy and the increasing intensity of cyber threats. The relevance of the study is determined by the rapid growth in the number of cyber incidents on a global scale, as well as by the specific challenges faced by Ukrainian businesses operating under conditions of armed conflict, where the protection of information infrastructure acquires the status of a strategic priority of corporate governance. A systematization of scientific approaches by domestic and foreign researchers to the problem of enterprise information security has been carried out. Based on the analysis performed, definitions of the concept of "enterprise information security" have been generalized and systematized in accordance with regulatory-legal, systemic, riskoriented, strategic, and process-based approaches, which makes it possible to reveal the multidimensional nature of the phenomenon under study and to identify interrelations between individual conceptual directions of its interpretation. Particular attention is paid to the systematization of the principles of ensuring information security, including comprehensiveness, adherence to confidentiality, integrity and availability of information, continuity, minimal privileges, adaptability, justifiability, and accountability. Methods of information protection are examined, divided into organizational, technical, cryptographic, legal, and risk management methods, the application of which should be coordinated and complementary in nature and correspond to the actual level of threats and the value of the enterprise's information assets. The study clearly delineates the subjects of the information security management system (from senior management and the Chief Information Security Officer to personnel and external auditors), as well as the objects of protection, which include information assets, hardware and software, network infrastructure, business processes, and the enterprise's reputation as an intangible asset of the organization. The necessity of implementing an information security management system in accordance with international standards is indicated, which involves a cyclical process of planning, implementation, verification, and improvement.

Description

Citation

Іпполітов Є. М. Теоретико-практичні аспекти управління інформаційною безпекою підприємства. Успіхи і досягнення у науці. 2026. № 6 (28). С. 744-756. https://doi.org/10.52058/3041-1254-2026-6(28)-744-756.

Endorsement

Review

Supplemented By

Referenced By