Affiliation:
1. Russian Timiryazev State Agrarian University
Abstract
The article is devoted to the assessment of information security risks of organizations for the purpose of leveling or reducing them. Approaches to the content, regulatory regulation, methods of analysis and assessment of information risks are considered. Analytical procedures for assessing and managing information security risks for a specific municipal enterprise were performed. The results obtained can be used by municipal enterprises to ensure the security of the information system and sustainable business development.
Publisher
PANORAMA Publishing House
Reference11 articles.
1. Presidential Decree of December 5, 2016 № 646 “On approval of the Information Security Doctrine of the Russian Federation”, access mode: http://base.garant.ru/71556224/#ixzz5V1TdGusO (circulation date 08.04.2021).
2. National Standard of the Russian Federation GOST R ISO / IEC 27002-2012 “Information technology. Methods and means of security. Code of norms and rules of information security management “approved. By the order of Rosstandart 14.09.2012 № 423-st (valid from 01.01.2014). — Аccess mode: http://docs.cntd.ru/document/1200103619 (circulation date: 08.04.2021).
3. National standard of the Russian Federation GOST R ISO / IEC 27005-2010 “Information technology. Methods and means of security. Information security risk management “approved. and enacted by order of the Federal Agency for Technical Regulation and Metrol ogy 30.11.2010 № 632-st. — Аccess mode: http://docs.cntd.ru/document/1200084141 (circulation date: 08.04.2021).
4. National standard of the Russian Federation GOST R 57580.1-2017 «Security of financial (banking) operations. Protection of information of financial organizations. Basic set of organizational and technical measures”, approved. Order of Rosstandart 08.08.2017 № 822-st. — Аccess mode: http://www.cbr.ru/Content/Document/File/46913/882-ct. pdf (circulation date: 08.04.2021).
5. Methodical document. Methodology for assessing threats to information security (approved by FSTEC of Russia 05.02.2021). — Аccess mode: http://www.consultant.ru/ document/cons_doc_LAW_378330/ (circulation date: 09.04.2021).