Оценка рисков возникновения компьютерных инцидентов
Журнал: НБИ технологии @nbi-technologies
Рубрика: Информационные технологии в безопасности и телекоммуникациях
Статья в выпуске: 1 т.19, 2025 года.
Бесплатный доступ
В статье рассматриваются современные подходы к оценке рисков в области кибербезопасности. В условиях стремительного развития технологий и увеличения числа киберугроз эффективное управление рисками становится критически важным для организаций всех размеров. Авторы анализируют основные методологии и инструменты, используемые для оценки и управления рисками, включая рамочные программы, такие как NIST Cybersecurity Framework и рекомендации ENISA. Особое внимание уделяется актуальным угрозам, выявленным в последних отчетах, и практическим шагам, которые организации могут предпринять для повышения своей киберустойчивости. Статья предназначена для специалистов в области кибербезопасности, руководителей и менеджеров, стремящихся улучшить свои знания и навыки в управлении рисками, а также для исследователей, интересующихся последними тенденциями и вызовами в данной области.
Короткий адрес: https://sciup.org/149151783
IDS: 149151783 | УДК: 621.39(043) | DOI: 10.15688/NBIT.jvolsu.2025.1.2
Risk assessment of occurrence computer incidents
This article explores contemporary methodologies for risk assessment associated with computer incidents in the field of cybersecurity. The study highlights the growing importance of effective risk management due to the rapid advancement of technology and the increasing frequency of cyber threats. The authors analyze prominent frameworks, emphasizing their unique approaches to identifying, evaluating, and mitigating risks. The article underscores the adaptability of NIST, the operational focus of OCTAVE, and the quantitative precision of FAIR, while also noting their respective limitations, such as resource intensity or data dependency. Practical implementation steps are outlined, including asset identification, vulnerability analysis, risk evaluation, and the development of mitigation strategies. The authors stress the need for continuous monitoring and adaptation to address evolving threats. Additionally, the article highlights the critical role of fostering a security culture within organizations through employee training, clear policies, and leadership involvement. Technological innovations like artificial intelligence and machine learning are presented as valuable tools for enhancing threat detection and response. The study concludes by addressing the human factor, advocating for increased awareness and competency development among staff to minimize risks. Targeted at cybersecurity professionals, managers, and researchers, the article provides actionable insights and methodologies to strengthen organizational cyber resilience in an increasingly complex threat landscape.