Methodology for Assessing Information Security Risks at Oil Refining Enterprises

被引:0
|
作者
Luneva, Natalia N. [1 ]
Levina, Tatiana M. [1 ]
Evdokimova, Natalia G. [1 ]
机构
[1] Ufa State Petr Technol Univ, Branch Univ City Salavat, Salavat, Russia
关键词
Economic security; Information security; Digital" economy; Methodology; Assessment; Risks; Risk models; Regulatory documents; Categories; Risk probability; Severity of consequences; Business processes;
D O I
10.1007/978-3-030-93244-2_74
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The basis of Russia's economic security is the effectiveness of financial management of oil refining enterprises in the context of global digitalization and the transition of enterprises to a new technological order. Moreover, the current high level of automation of business processes of oil refining enterprises leads to the adoption of development strategies, taking into account the risks from compliance with information security. Discussion of law enforcement practice by oil refineries, of the Federal Law dated July 27, 2006 No. 149 Federal-Law "On information, information technology, and information protection", issued to replace the Federal Law of February 20, 1995 No. 24 Federal Law "On Information, Informatization, and Information Protection", which are held with the support and participation of the Federal Security Service of the Russian Federation, Ministries of Internal Affairs of the Russian Federation and Defense of Russia, Federal Service for Technical and Export Control of Russia, Federal Security Service of Russia, Ministry (Emergency Situations) for Civil Defense, Emergencies and Elimination of Consequences of Natural Disasters of the Russian Federation, Ministry of Digital Development of the Russian Federation, Roskomnadzor (FS for Supervision in the Area of Communications), Ministry of Economic Development of the Russian Federation, Ministry of Energy of the Russian Federation, Ministry of Transport of the Russian Federation, Ministry of Finance of the Russian Federation, The Central Bank of the Russian Federation, and many of the remaining federal ministries and departments of the Russian Federation is posed as a particularly important task of the "digital" economy of Russia in terms of the importance of identifying, accounting, and reducing threats from information security risks. The main purpose of this article is to develop a methodology for assessing the information security risks of enterprises in the oil refining industry, taking into account the delineation of areas of responsibility in the event of threats to information security from the security services and information technologies of the enterprise. Justification of the calculation of information security risks, taking into account the transition of oil refineries to the conditions of the "digital" economy set out on the example of the standards of the general process "Risk Management" and regulatory documents: ISO 20000 series; ISO 27000 series; ISO 22000 series; Interstate Standard R 53647 series; ISO 31000 series. The proposed methodology for assessing information security risks of oil refining enterprises was implemented using the example of ISO 31000, the choice of indicators of direct and indirect types of threats in assessing the risk category was determined according to the Interstate Standard R ISO/IEC 13335-3-2007 security methods and means. A set of methods for the internal process of oil refineries, risk assessment, and, as a result, damage prevention, a mathematical apparatus was used for statistical data processing. A redistributed map of business processes of a refinery was obtained, which allows assessing possible threats, identify channels of information leakage, and take prompt measures to counter information security risks at enterprises of the oil refining industry as a way to improve the efficiency of an enterprise in a digital economy in the area of economic security of PJSC "GAZPROM".
引用
收藏
页码:679 / 690
页数:12
相关论文
共 50 条
  • [31] Risks on the Security of Oil and Gas Supply
    Doukas, H.
    Flamos, A.
    Psarras, J.
    [J]. ENERGY SOURCES PART B-ECONOMICS PLANNING AND POLICY, 2011, 6 (04) : 417 - 425
  • [32] Risks Management relating to Information Systems Security Treatment of IT Equipment Security Risks
    Baicu, Floarea
    Baicu, Andrei Mihai
    [J]. QUALITY-ACCESS TO SUCCESS, 2012, 13 (131): : 108 - 112
  • [33] The processes of heavy metals refining: Methods of assessing occupational risks
    Gaweda, E
    [J]. PRZEMYSL CHEMICZNY, 2005, 84 (01): : 9 - 13
  • [34] A framework for the management of information security risks
    Jones, A.
    [J]. BT TECHNOLOGY JOURNAL, 2007, 25 (01) : 30 - 36
  • [35] ASSESSING AND ADDRESSING US HEALTH SECURITY RISKS
    Watson, Crystal R.
    [J]. HEALTH SECURITY, 2017, 15 (01) : 15 - 16
  • [36] New Frontiers: Assessing and Managing Security Risks
    Oppliger, Rolf
    Pernul, Gnther
    Katsikas, Sokratis
    [J]. COMPUTER, 2017, 50 (04) : 49 - 51
  • [37] Import Security: Assessing the Risks of Imported Food
    Welburn, Jonathan
    Bier, Vicki
    Hoerning, Steven
    [J]. RISK ANALYSIS, 2016, 36 (11) : 2047 - 2064
  • [38] SOCIAL ENGINEERING: AN INFORMATION SECURITY THREAT IN ENTERPRISES
    Acilar, Ali
    Bastug, Ayse
    [J]. GLOBAL BUSINESS RESEARCH CONGRESS (GBRC) 2016, VOL 2, 2016, 2 : 289 - 297
  • [39] Systems of Information Security Indicators for Industrial Enterprises
    Fatkieva, R. R.
    [J]. AUTOMATIC DOCUMENTATION AND MATHEMATICAL LINGUISTICS, 2019, 53 (04) : 216 - 224
  • [40] Information security issues facing virtual enterprises
    Steinke, G
    Leamon, R
    [J]. IEMC 96 PROCEEDINGS - MANAGING VIRTUAL ENTERPRISES: A CONVERGENCE OF COMMUNICATIONS, COMPUTING, AND ENERGY TECHNOLOGIES, 1996, : 641 - 644