Corporate system of information and cybersecurity

Authors

  • Yu.M. Lysetskyi https://orcid.org/0000-0002-5080-1856 , SNT Ukraine
  • S.I. Bobrov https://orcid.org/0000-0003-3604-2256 , SNT Ukraine
  • O.I. Danchenko https://orcid.org/0009-0003-8844-1213 , State Special Communications Service of Ukraine image/svg+xml

Keywords:

information security, cybersecurity, technologies, systems, architecture, components, corporate information system

Abstract

The article analyses modern cybersecurity technologies and systems such as next-generation firewalls, micro-segmentation, network access control systems, zero-trust remote access, systems protecting against distributed denial-of-service attacks, systems protecting against portal attacks, secure access brokers to the cloud, malware protection systems, email attack protection system, mobile device management systems, user account and authorization management systems, privileged access management systems, physical access protection systems, data leak protection systems, multi-factor authentication and authorization systems, database protection systems, vulnerability analysis systems, attack simulation systems, cyber decoy systems, log and action collection, correlation, and analysis systems, as well as automation systems for actions during an investigation or incident response. The choice of necessary cybersecurity systems for designing a corporate information and cybersecurity system is determined, considering the corporate IT landscape. Critically important components of this system include network protection solutions such as NGFW, workstation and server protection against malicious software based on EDR/XDR, and email system protection. Highly recommended components also include network access management systems and remote access with zero trust, information leakage protection, and a complex system of authentication and authorization. For organizations with medium or high complexity of IT landscapes, cybersecurity analytics cluster systems are critically important, especially event collection and correlation systems and vulnerability analysis systems. Considering the above, a corporate architecture of information and cybersecurity is proposed, which will ensure a layered system of effective protection against cyber threats.

References

1. Економіка і регіон. URL: https://eir.nupp.edu.ua/files/2022/1_84_2022.pdf (дата звернення: 10.01.2023).

2. Лисецький Ю.М. Забезпечення інформаційної безпеки. Global science: prospects and innovations: зб. статей III Міжнар. наук.-практ. конф. (м. Ліверпуль, 2–4 лист. 2023 р.). Великобританія, Ліверпуль, 2023. С. 273–276.

3. Лисецький Ю.М., Калбазов Д.І. Інформаційна безпека корпоративних баз даних. Математичні машини і системи. 2023. № 3. С. 31–37.

4. Міжмережевий екран: що це та як працює? URL: https://ukeywaf.com/baza/mizhmerezhevyj-ekranshho-cze-yak-praczyuye/ (дата звернення: 10.01.2023).

5. Лисецький Ю.М. Управління доступом до IT-систем. Scientists and existing problems of human development: зб. тез IX Міжнар. наук.-практ. конф. (м. Загреб, 14–17 лист. 2023 р.). Хорватія, Загреб, 2023. С. 378–379.

6. Лисецкий Ю.М. Информационная безопасность: защита от DDoS-атак. System Analysis and Information Technologies SAIT 2014: 16-th International сonf. (Kyiv, 26–30 May 2014). Kyiv, 2014. P. 405–406.

7. Лисецький Ю., Калбазов Д. Особливості управління правами користувачів у корпоративних ІТсистемах. Математичні машини і системи. 2023. № 2. С. 28–33.

8. IBM Security Cost of a Data Breach Report. 2023. URL: https://www.ibm.com/reports/data-breach (дата звернення: 10.01.2023).

Downloads

Views: 60
Downloads: 29

Published

2024-12-03

Issue

Section

INFORMATION AND TELECOMMUNICATION TECHNOLOGY

How to Cite

Corporate system of information and cybersecurity. (2024). Mathematical Machines and Systems, 3-4, 37-49. https://j-mms.de/index.php/mms/article/view/2024-3-4-a2