A Risk-Oriented Framework for Forming and Modelling Information Security Profiles in Modern Cyberspace
DOI:
https://doi.org/10.33445/psssj.2025.6.4.6Keywords:
Security Profile, ND TZI 3.6-006-24, NIST SP 800-53, Mathematical Modelling, Risk Management, Critical Infrastructure, Information Security, Cyber ResilienceAbstract
The purpose of the article is to substantiate the theoretical foundations for forming information security profiles in Ukraine and to adapt established probabilistic, optimization, and economic models for assessing their effectiveness, resilience, and resource feasibility in critical infrastructure information systems. The study combines historical-regulatory and comparative analysis of Ukrainian requirements with NIST SP 800-series and ISO/IEC standards, set-theoretic formalization, a two-state continuous-time Markov model, binary optimization under a budget constraint, annualized loss expectancy, and return on security investment. The development of Ukrainian regulation between 2021 and 2026 is represented as three stages: institutional preparation and wartime transition, harmonization with international standards, and implementation of a risk-oriented approach. Four types of security profiles are distinguished: basic, sectoral, target, and adapted. A security profile is formalized as a set of security and privacy requirements, selected controls, control enhancements, organization-defined parameters, and mappings to identified threats and risks. The proposed indicators support risk-weighted threat coverage, a simplified availability-like resilience estimate, and selection of controls subject to resource constraints. The study integrates and adapts established regulatory, probabilistic, optimization, and economic approaches to the Ukrainian technical information protection framework rather than claiming a universal assessment model. The models may support owners and administrators of critical infrastructure information systems in documenting, selecting, assessing, and authorizing protective measures, provided that model parameters are empirically calibrated for the relevant system.
Downloads
References
Administration of the State Service of Special Communications and Information Protection of Ukraine. (2024). ND TZI 3.6-006-24: Procedure for selecting measures to protect information, the protection requirement for which is established by law and which does not constitute a state secret, for information systems [In Ukrainian; author’s translation]. https://cip.gov.ua/services/cm/api/attachment/download?id=66109
Bojanc, R., Jerman-Blažič, B., & Tekavčič, M. (2012). Managing the investment in information security technology by use of a quantitative modeling. Information Processing & Management, 48(6), 1031–1052. https://doi.org/10.1016/j.ipm.2012.01.001
Cabinet of Ministers of Ukraine. (2025). Resolution No. 712 of June 18, 2025 [In Ukrainian]. https://zakon.rada.gov.ua/go/712-2025-%D0%BF
Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004). A model for evaluating IT security investments. Communications of the ACM, 47(7), 87–92. https://doi.org/10.1145/1005817.1005828
Dempsey, K., Chawla, N., Johnson, L., Johnston, R., Jones, A., Orebaugh, A., Scholl, M., & Stine, K. (2011). Information security continuous monitoring (ISCM) for federal information systems and organizations (NIST SP 800-137). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-137
Gisladottir, V., Ganin, A. A., Keisler, J. M., Kepner, J., & Linkov, I. (2017). Resilience of cyber systems with over- and underregulation. Risk Analysis, 37(9), 1644–1651. https://doi.org/10.1111/risa.12729
Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4), 438–457. https://doi.org/10.1145/581271.581274
Hubbard, D. W., & Seiersen, R. (2016). How to measure anything in cybersecurity risk. Wiley.
Humayed, A., Lin, J., Li, F., & Luo, B. (2017). Cyber-physical systems security—A survey. IEEE Internet of Things Journal, 4(6), 1802–1831. https://doi.org/10.1109/JIOT.2017.2703172
International Organization for Standardization. (2018). ISO 31000:2018 risk management—Guidelines.
International Organization for Standardization. (2022). ISO/IEC 27005:2022 information security, cybersecurity and privacy protection—Guidance on managing information security risks.
Joint Task Force. (2018). Risk management framework for information systems and organizations: A system life cycle approach for security and privacy (NIST SP 800-37 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-37r2
Joint Task Force. (2020a). Security and privacy controls for information systems and organizations (NIST SP 800-53 Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5
Joint Task Force. (2020b). Control baselines for information systems and organizations (NIST SP 800-53B). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53B
Joint Task Force. (2022). Assessing security and privacy controls in information systems and organizations (NIST SP 800-53A Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53Ar5
Joint Task Force Transformation Initiative. (2011). Managing information security risk: Organization, mission, and information system view (NIST SP 800-39). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-39
Kott, A., & Linkov, I. (Eds.). (2019). Cyber resilience of systems and networks. Springer. https://doi.org/10.1007/978-3-319-77492-3
Linkov, I., Eisenberg, D. A., Plourde, K., Seager, T., Allen, J., & Kott, A. (2013). Resilience metrics for cyber systems. Environment Systems and Decisions, 33(4), 471–476. https://doi.org/10.1007/s10669-013-9485-y
National Institute of Standards and Technology. (2012). Guide for conducting risk assessments (NIST SP 800-30 Rev. 1). https://doi.org/10.6028/NIST.SP.800-30r1
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
National Institute of Standards and Technology. (2025a). Integrating cybersecurity and enterprise risk management (NIST IR 8286 Rev. 1). https://doi.org/10.6028/NIST.IR.8286r1
National Institute of Standards and Technology. (2025b). Identifying and estimating cybersecurity risk for enterprise risk management (NIST IR 8286A Rev. 1). https://doi.org/10.6028/NIST.IR.8286Ar1
National Institute of Standards and Technology. (2025c). Staging cybersecurity risks for enterprise risk management and governance oversight (NIST IR 8286C Rev. 1). https://doi.org/10.6028/NIST.IR.8286Cr1
Nelson, A., Rekhi, S., Souppaya, M., & Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST SP 800-61 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r3
Ross, R., Pillitteri, V., Graubart, R., Bodeau, D., & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST SP 800-160 Vol. 2 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v2r1
Sonnenreich, W., Albanese, J., & Stout, B. (2006). Return on security investment (ROSI)—A practical quantitative model. Journal of Research and Practice in Information Technology, 38(1), 45–56. https://doi.org/10.3316/informit.937199632104879
State Enterprise “UkrNDNC.” (2023). DSTU ISO/IEC 27001:2023 information security, cybersecurity and privacy protection—Information security management systems—Requirements (ISO/IEC 27001:2022, IDT) [In Ukrainian].
Wang, J., Neil, M., & Fenton, N. (2020). A Bayesian network approach for cybersecurity risk assessment implementing and extending the FAIR model. Computers & Security, 89, Article 101659. https://doi.org/10.1016/j.cose.2019.101659
Wheeler, E. (2011). Security risk management: Building an information security risk management program from the ground up. Syngress.
Yevseyeva, I., Basto-Fernandes, V., Emmerich, M., & van Moorsel, A. (2015). Selecting optimal subset of security controls. Procedia Computer Science, 64, 1035–1042. https://doi.org/10.1016/j.procs.2015.08.625
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Ruslan Netrebko

This work is licensed under a Creative Commons Attribution 4.0 International License.
The authors agree with the following conditions:
1. Authors retain copyright and grant the journal right of first publication (Download agreement) with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
2. Authors have the right to complete individual additional agreements for the non-exclusive spreading of the journal’s published version of the work (for example, to post work in the electronic repository of the institution or to publish it as part of a monograph), with the reference to the first publication of the work in this journal.
3. Journal’s politics allows and encourages the placement on the Internet (for example, in the repositories of institutions, personal websites, SSRN, ResearchGate, MPRA, SSOAR, etc.) manuscript of the work by the authors, before and during the process of viewing it by this journal, because it can lead to a productive research discussion and positively affect the efficiency and dynamics of citing the published work (see The Effect of Open Access).









