A Risk-Oriented Framework for Forming and Modelling Information Security Profiles in Modern Cyberspace

Authors

DOI:

https://doi.org/10.33445/psssj.2025.6.4.6

Keywords:

Security Profile, ND TZI 3.6-006-24, NIST SP 800-53, Mathematical Modelling, Risk Management, Critical Infrastructure, Information Security, Cyber Resilience

Abstract

The purpose of the article is to substantiate the theoretical foundations for forming information security profiles in Ukraine and to adapt established probabilistic, optimization, and economic models for assessing their effectiveness, resilience, and resource feasibility in critical infrastructure information systems. The study combines historical-regulatory and comparative analysis of Ukrainian requirements with NIST SP 800-series and ISO/IEC standards, set-theoretic formalization, a two-state continuous-time Markov model, binary optimization under a budget constraint, annualized loss expectancy, and return on security investment. The development of Ukrainian regulation between 2021 and 2026 is represented as three stages: institutional preparation and wartime transition, harmonization with international standards, and implementation of a risk-oriented approach. Four types of security profiles are distinguished: basic, sectoral, target, and adapted. A security profile is formalized as a set of security and privacy requirements, selected controls, control enhancements, organization-defined parameters, and mappings to identified threats and risks. The proposed indicators support risk-weighted threat coverage, a simplified availability-like resilience estimate, and selection of controls subject to resource constraints. The study integrates and adapts established regulatory, probabilistic, optimization, and economic approaches to the Ukrainian technical information protection framework rather than claiming a universal assessment model. The models may support owners and administrators of critical infrastructure information systems in documenting, selecting, assessing, and authorizing protective measures, provided that model parameters are empirically calibrated for the relevant system.

Downloads

Download data is not yet available.

References

Administration of the State Service of Special Communications and Information Protection of Ukraine. (2024). ND TZI 3.6-006-24: Procedure for selecting measures to protect information, the protection requirement for which is established by law and which does not constitute a state secret, for information systems [In Ukrainian; author’s translation]. https://cip.gov.ua/services/cm/api/attachment/download?id=66109

Bojanc, R., Jerman-Blažič, B., & Tekavčič, M. (2012). Managing the investment in information security technology by use of a quantitative modeling. Information Processing & Management, 48(6), 1031–1052. https://doi.org/10.1016/j.ipm.2012.01.001

Cabinet of Ministers of Ukraine. (2025). Resolution No. 712 of June 18, 2025 [In Ukrainian]. https://zakon.rada.gov.ua/go/712-2025-%D0%BF

Cavusoglu, H., Mishra, B., & Raghunathan, S. (2004). A model for evaluating IT security investments. Communications of the ACM, 47(7), 87–92. https://doi.org/10.1145/1005817.1005828

Dempsey, K., Chawla, N., Johnson, L., Johnston, R., Jones, A., Orebaugh, A., Scholl, M., & Stine, K. (2011). Information security continuous monitoring (ISCM) for federal information systems and organizations (NIST SP 800-137). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-137

Gisladottir, V., Ganin, A. A., Keisler, J. M., Kepner, J., & Linkov, I. (2017). Resilience of cyber systems with over- and underregulation. Risk Analysis, 37(9), 1644–1651. https://doi.org/10.1111/risa.12729

Gordon, L. A., & Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4), 438–457. https://doi.org/10.1145/581271.581274

Hubbard, D. W., & Seiersen, R. (2016). How to measure anything in cybersecurity risk. Wiley.

Humayed, A., Lin, J., Li, F., & Luo, B. (2017). Cyber-physical systems security—A survey. IEEE Internet of Things Journal, 4(6), 1802–1831. https://doi.org/10.1109/JIOT.2017.2703172

International Organization for Standardization. (2018). ISO 31000:2018 risk management—Guidelines.

International Organization for Standardization. (2022). ISO/IEC 27005:2022 information security, cybersecurity and privacy protection—Guidance on managing information security risks.

Joint Task Force. (2018). Risk management framework for information systems and organizations: A system life cycle approach for security and privacy (NIST SP 800-37 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-37r2

Joint Task Force. (2020a). Security and privacy controls for information systems and organizations (NIST SP 800-53 Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5

Joint Task Force. (2020b). Control baselines for information systems and organizations (NIST SP 800-53B). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53B

Joint Task Force. (2022). Assessing security and privacy controls in information systems and organizations (NIST SP 800-53A Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53Ar5

Joint Task Force Transformation Initiative. (2011). Managing information security risk: Organization, mission, and information system view (NIST SP 800-39). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-39

Kott, A., & Linkov, I. (Eds.). (2019). Cyber resilience of systems and networks. Springer. https://doi.org/10.1007/978-3-319-77492-3

Linkov, I., Eisenberg, D. A., Plourde, K., Seager, T., Allen, J., & Kott, A. (2013). Resilience metrics for cyber systems. Environment Systems and Decisions, 33(4), 471–476. https://doi.org/10.1007/s10669-013-9485-y

National Institute of Standards and Technology. (2012). Guide for conducting risk assessments (NIST SP 800-30 Rev. 1). https://doi.org/10.6028/NIST.SP.800-30r1

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29

National Institute of Standards and Technology. (2025a). Integrating cybersecurity and enterprise risk management (NIST IR 8286 Rev. 1). https://doi.org/10.6028/NIST.IR.8286r1

National Institute of Standards and Technology. (2025b). Identifying and estimating cybersecurity risk for enterprise risk management (NIST IR 8286A Rev. 1). https://doi.org/10.6028/NIST.IR.8286Ar1

National Institute of Standards and Technology. (2025c). Staging cybersecurity risks for enterprise risk management and governance oversight (NIST IR 8286C Rev. 1). https://doi.org/10.6028/NIST.IR.8286Cr1

Nelson, A., Rekhi, S., Souppaya, M., & Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST SP 800-61 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r3

Ross, R., Pillitteri, V., Graubart, R., Bodeau, D., & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST SP 800-160 Vol. 2 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v2r1

Sonnenreich, W., Albanese, J., & Stout, B. (2006). Return on security investment (ROSI)—A practical quantitative model. Journal of Research and Practice in Information Technology, 38(1), 45–56. https://doi.org/10.3316/informit.937199632104879

State Enterprise “UkrNDNC.” (2023). DSTU ISO/IEC 27001:2023 information security, cybersecurity and privacy protection—Information security management systems—Requirements (ISO/IEC 27001:2022, IDT) [In Ukrainian].

Wang, J., Neil, M., & Fenton, N. (2020). A Bayesian network approach for cybersecurity risk assessment implementing and extending the FAIR model. Computers & Security, 89, Article 101659. https://doi.org/10.1016/j.cose.2019.101659

Wheeler, E. (2011). Security risk management: Building an information security risk management program from the ground up. Syngress.

Yevseyeva, I., Basto-Fernandes, V., Emmerich, M., & van Moorsel, A. (2015). Selecting optimal subset of security controls. Procedia Computer Science, 64, 1035–1042. https://doi.org/10.1016/j.procs.2015.08.625

Downloads


Abstract views: 9
Downloads: 7

Published

2025-12-31

How to Cite

Netrebko, R. (2025). A Risk-Oriented Framework for Forming and Modelling Information Security Profiles in Modern Cyberspace. Political Science and Security Studies Journal, 6(4), 52-63. https://doi.org/10.33445/psssj.2025.6.4.6

Issue

Section

Articles