Lecture
Information culture is
It should also be regarded as algorithms of human behavior and symbolic structures in the infosphere that give this behavior meaning and significance from the human point of view.
Information culture can be regarded as an integral part of general culture, oriented toward the information support of human activity. Information culture reflects the levels achieved in the organization of information processes and in the effectiveness of creating, collecting, storing, processing, presenting and using information, which ensure a holistic view of the world, its modeling, and the anticipation of the results of decisions made by a person.


The difficulty stems from the ambiguity of the very concept of "information culture." There are many concepts that are close but not identical in meaning: "library and bibliographic culture," "reading culture," "computer literacy." Library and bibliographic culture is a set of knowledge, abilities and skills of the reader that ensure effective use of the reference and bibliographic apparatus and the holdings of a library. It includes knowledge of the structure of the library collection, the composition of library catalogs, card files and bibliographic aids, and the rules for using libraries; and the ability to find the necessary sources of information in bibliographic aids, catalogs and card files. Reading culture is an integral part of the general culture of the individual, a set of skills for working with books that includes the conscious choice of subjects, systematic and consistent reading, the ability to apply rational reading techniques, to absorb and deeply comprehend what has been read to the maximum extent, and to handle printed works with care. Computer literacy is the knowledge, abilities and skills in the field of informatics that every person needs in order to use computer technologies effectively in his or her activity. In addition, the structure of information culture includes elements of the following cultures: communicative (culture of communication); lexical (language, the culture of writing and of preparing business documentation); intellectual (the culture of scientific research and mental work); information-legal; worldview-related and moral. All components of information culture are interconnected and interdependent.
There are many definitions of the concept of "information culture." A. Kudrina, Candidate of Pedagogical Sciences, Associate Professor and Head of the Department of Automated Information Processing Technology at KemGAKIT, characterizes it as "a set of knowledge, value orientations, convictions and attitudes that determine the actions and, in general, the activity of a person"; N. B. Zinovieva, Doctor of Pedagogical Sciences and Associate Professor at KGUKI, considers the main subject of forming the information culture of the individual to be "the process of harmonizing a person's inner world in the course of mastering the entire body of socially significant information"6; V. A. Minkina, Doctor of Pedagogical Sciences and Professor at SPbGUKI, holds that "the formation of a person's information culture takes place in his or her everyday activity under the influence of acquired everyday knowledge and skills, information from the mass media, in the course of self-education, and through learning in the family and at work." According to the interpretation of Yu. S. Zubov, Doctor of Pedagogical Sciences and Professor at MGUKI, "information culture is a systematized set of knowledge, abilities, skills
INFORMATION CULTURE OF THE TEACHER
INFORMATION CULTURE OF THE LEARNER
Information security (English: Information Security, also InfoSec) is the practice of preventing unauthorized access, use, disclosure, distortion, alteration, examination, recording or destruction of information. This universal concept applies regardless of the form the data may take (electronic or, for example, physical). The main task of information security is the balanced protection of the confidentiality, integrity and availability of data , with due regard to practicality of application and without any damage to the productivity of the organization . This is achieved mainly through a multi-stage risk management process that makes it possible to identify key assets and intangible assets, sources of threats, vulnerabilities, the potential degree of impact and the possibilities for managing risks. This process is accompanied by an assessment of the effectiveness of the risk management plan .

Fig. 1. Diagram of cause-and-effect relationships
It should be noted that information culture also has both an objective and a subjective nature, and the individual is at the same time both the subject and the object of information culture. Noting the ambiguity of all three concepts, O. A. Panchenko and L. V. Panchenko present a complex structure of their cause-and-effect relationships (Fig. 1).
In order to standardize this activity, the scientific and professional communities are in constant cooperation aimed at developing a basic methodology, policies and industry standards in the field of technical measures for information protection, legal liability, and standards for training users and administrators. This standardization is developed to a considerable extent under the influence of a wide range of laws and regulations that govern the ways data is accessed, processed, stored and transmitted. However, the implementation of any standards and methodologies in an organization can have only a superficial effect if a culture of continuous improvement has not been properly instilled
The main problem discussed in this article is the specific features of the socialization of modern children and adolescents amid rapidly
growing information flows, above all in the electronic space. The Internet, which has become a natural communication
environment for the younger generation, unquestionably influences the worldview and behavior of schoolchildren. This environment is full of useful information and at the same time serves as a channel for transmitting the risks of socialization. Current risks include, for example, the "death communities" that have become widespread in social networks and actively provoke suicidal acts; thematic groups that encourage various kinds of addictions; and the harmful content widely available on the Internet, which can damage the psycho-emotional health and the moral and intellectual development of children and adolescents. These risks become more real against the background of relatively low parental and pedagogical control, whose exercise, like the prevention of risks, is made harder by the fact that modern children and adolescents far surpass adults in digital competence. In this situation it is important to find productive approaches that ensure favorable socialization of schoolchildren and, where possible, neutralize the risks of the information environment that threaten personal development.
To achieve the stated goals and to clarify the factors that determine the safety of schoolchildren's socialization in the information
environment, we analyzed current domestic and foreign studies relevant to the topic and attempted to determine the relationship between the restrictive and the personality-developing approaches to the problem of ensuring the information security of
students.
The importance of forming the information culture of the individual is fully recognized, as shown by various conferences and the increased number of publications. Having recognized this problem as interdisciplinary, representatives of many fields of knowledge have joined in studying it: librarians, computer scientists, culture scholars, sociologists and philosophers. However, although united by common interests, they consider different phenomena. "Librarians customarily put reader skills and abilities into the concept of the information culture of the individual. Computer scientists link it with computer literacy and the ability to work in electronic networks. Sociologists believe that the manifestation of information culture is a person's orientation in rapidly changing social conditions and the ability to adapt to them by evaluating incoming information critically and independently. Culture scholars and philosophers approach the problem most broadly: they see information culture as a way of human life in the information society and as a component of the process of forming the culture of humanity"3. And all these points of view are valid.
According to the interpretation of Yu. S. Zubov, Doctor of Pedagogical Sciences and Professor at MGUKI, "information culture is a systematized set of knowledge, abilities and skills that ensures the optimal performance of individual information activity aimed at satisfying both professional and non-professional needs"8. According to the definition of E. P. Semenyuk, one of the leading domestic specialists in the field of informatization, information culture is "the information component of human culture as a whole, objectively characterizing the level of all the information processes existing in society and the existing information relations"9. Leading specialists of the Kemerovo State Academy of Culture and Arts N. I. Gendina, N. I. Kolkova, I. L. Skipor and G. A. Starodubova, who have studied this problem in depth, offer the following interpretation of the concept of "information culture of the individual": "The information culture of the individual is one of the components of a person's general culture; a set of an information worldview and a system of knowledge and abilities that ensure purposeful, independent activity for the optimal satisfaction of individual information needs using both traditional and new information technologies. It is the most important factor of successful professional and non-professional activity, as well as of the social protection of the individual in the information society"10. Summarizing all these definitions, we can say that information culture is a systematized set of knowledge, abilities and skills aimed at satisfying information needs that arise in the course of educational, scientific-cognitive and other kinds of activity. The criteria of a person's information culture can be considered his or her ability to formulate an information need adequately, to search effectively for the necessary information across the whole set of information resources, to process information and create qualitatively new information, to maintain individual information retrieval systems, as well as the capacity for information communication and computer literacy. The information culture of society and of the individual must make possible continuous education of the person and greater responsibility for the decisions he or she makes. In the first case, information culture serves as a means of social protection for an individual who is capable of independently building up knowledge, changing the sphere of activity, and regulating his or her own behavior on the basis of a comprehensive analysis of the situation. In the second, information culture is a means of protecting society from ill-considered actions by a person, a guarantee that fundamental decisions in any sphere, whether social, economic or technological, are made only after a thorough analysis of all the available information
Information security is built on the activity of protecting information: ensuring its confidentiality, availability and integrity, and preventing any compromise of it in a critical situation . Such situations include natural, man-made and social disasters, computer failures, physical theft and similar events. While the record keeping of most organizations in the world is still based on paper documents , which require appropriate information security measures, there is a steady rise in the number of initiatives to introduce digital technologies in enterprises , which entails bringing in information technology (IT) security specialists to protect information. These specialists ensure the information security of the technology (in most cases, some kind of computer system). A computer in this context means not only an ordinary household personal computer, but digital devices of any complexity and purpose, ranging from primitive and isolated ones, such as electronic calculators and household appliances, up to industrial control systems and supercomputers connected by computer networks. The largest enterprises and organizations, because of the vital importance and value of information to their business, hire information security specialists, as a rule, onto their own staff. Their tasks include protecting all technologies from malicious cyberattacks, which are often aimed at stealing important confidential information or at taking over control of the organization's internal systems.
Information security, as a field of employment, has developed and grown significantly in recent years. It has given rise to many professional specializations, for example, network and related infrastructure security, software and database protection, information systems auditing, business continuity planning, electronic records discovery and computer forensics[en]. Information security professionals enjoy very stable employment and high demand in the labor market. Large-scale research conducted by the organization (ISC)² showed that as of 2017, 66% of information security managers acknowledged an acute shortage of workforce in their departments, and it is forecast that by 2022 the shortage of specialists in this field will amount to 1,800,000 people worldwide .
Information security threats can take very diverse forms. As of 2018, the most serious are considered to be threats related to "crime as a service" (Crime-as-a-Service), the Internet of Things, supply chains and the growing complexity of regulatory requirements[10]. "Crime as a service" is a model in which mature criminal communities offer packages of criminal services on the darknet market at affordable prices to novice cybercriminals . This allows the latter to carry out hacker attacks that were previously out of reach because of their high technical complexity or cost, making cybercrime a mass phenomenon . Organizations are actively adopting the Internet of Things, whose devices are often designed without regard for security requirements, which opens up additional opportunities for attack. Moreover, the rapid development and growing complexity of the Internet of Things reduce its transparency, which, combined with vaguely defined legal norms and terms, allows organizations to use the personal data of their customers collected by the devices at their own discretion, without the customers' knowledge. In addition, it is problematic for the organizations themselves to track which of the data collected by Internet of Things devices is transmitted outside. The supply chain threat is that organizations, as a rule, hand over various valuable and confidential information to their suppliers, and as a result lose direct control over it. Thus, the risk of a breach of the confidentiality, integrity or availability of this information increases significantly. More and more new regulatory requirements greatly complicate the management of organizations' vital information assets. For example, the General Data Protection Regulation (GDPR), which came into force in the European Union in 2018, requires any organization, at any time, in any part of its own activity or supply chain, to demonstrate what personal data is held there and for what purposes, how it is processed, stored and protected. Moreover, this information must be provided not only during inspections by authorized bodies, but also at the first request of a private individual who owns that data. Complying with such requirements demands diverting significant budget funds and resources from the organization's other information security tasks. And although putting the processing of personal data in order implies an improvement in information security in the long term, in the short term the organization's risks increase noticeably.
Most people are affected in one way or another by information security threats. For example, they become victims of malicious software (viruses and worms, Trojan programs, ransomware), phishing or identity theft. Phishing is a fraudulent attempt to obtain confidential information (for example, an account name, password or credit card data). Usually an Internet user is lured to a fraudulent website that is indistinguishable from the original website of some organization (a bank, an online store, a social network, etc.) . As a rule, such attempts are made by means of mass mailings of forged e-mails supposedly sent on behalf of the organization itself , containing links to fraudulent sites. After opening such a link in a browser, the unsuspecting user enters their credentials, which fall into the hands of the fraudsters. The term Identity Theft appeared in the English language in 1964 to denote actions in which someone's personal data (for example, a name, a bank account or a credit card number, often obtained by means of phishing) is used for fraud and to commit other crimes. The person in whose name criminals obtain illegal financial advantages and loans or commit other crimes often becomes the accused himself, which can have far-reaching and severe financial and legal consequences for him. Information security has a direct impact on privacy , the definition of which can differ greatly in different cultures .
Government bodies, armed forces, corporations, financial institutions, medical institutions and private entrepreneurs constantly accumulate large amounts of confidential information about their employees, customers, products, scientific research and financial results. If such information falls into the hands of competitors or cybercriminals, it can entail far-reaching legal consequences and irreparable financial and reputational losses for the organization and its customers. From a business point of view, information security must be balanced against costs; the Gordon-Loeb economic model describes a mathematical apparatus for solving this problem[24]. The main ways of countering information security threats, or information risks, are:
With the appearance of the earliest means of communication, diplomats and military leaders realized the need to develop mechanisms for protecting confidential correspondence and ways of detecting attempts to falsify it . For example, Julius Caesar is credited with inventing, around 50 BC, the Caesar cipher, which was designed to prevent his secret messages from being read by those for whom they were not intended[26]. However, for the most part, protection was provided by controlling the very procedure of handling secret correspondence. Confidential messages were marked so that they would be protected and transmitted only with trusted persons under guard, and kept in secured rooms or strong boxes .
With the development of the postal service, government organizations began to emerge for intercepting, decrypting, reading and resealing letters. Thus in England the Secret Office appeared for these purposes in 1653 . In Russia, the interception of mail was carried out at least since the time of Peter I: from 1690 in Smolensk all letters going abroad were opened. The practice of secretly copying the correspondence of almost all foreign diplomats, so that the addressee would have no suspicions, became systematic in the middle of the 18th century, when the so-called "black chambers" appeared. After a letter was opened, cryptanalysis of the message was required, for which the leading mathematicians of the time were brought into the work of the black chambers. The most outstanding results were achieved by Christian Goldbach, who managed to decrypt 61 letters of Prussian and French ministers in half a year of work. In some cases, after a letter was successfully decrypted, its contents were replaced, a kind of forerunner of the man-in-the-middle attack .
At the beginning of the 19th century in Russia, with the accession of Alexander I, all cryptographic activity came under the authority of the Chancellery of the Ministry of Foreign Affairs. From 1803 the eminent Russian scientist Pavel Lvovich Schilling served in this department. One of the most significant achievements of the Chancellery was the decryption of the orders and correspondence of Napoleon I during the Patriotic War of 1812 . In the middle of the 19th century more complex systems for classifying secret information appeared, allowing governments to manage information depending on its degree of confidentiality. For example, in 1889 the British government to some extent legitimized such a classification by publishing the Official Secrets Act[en][33].
During the First World War, multilevel classification and encryption systems were used by all the belligerents to transmit information, which contributed to the emergence and intensive use of encryption and cryptanalysis units. Thus by the end of 1914 one of the sections of the British Admiralty was formed, "Room 40", which became the leading cryptographic body of Great Britain. On 26 August 1914 the light German cruiser Magdeburg ran aground on the rocks near the island of Odensholm at the mouth of the Gulf of Finland, which then belonged to the Russian Empire. The Germans destroyed all the documents and blew up the ship, but Russian divers, examining the seabed, found two copies of the signal book, one of which was handed over to the British. Having soon obtained the code books for auxiliary vessels, as well as those for communication between ships in distant seas and the enemy vessels accompanying them, the British managed to decrypt the German naval codes. Breaking the code made it possible to read intercepted enemy radio messages. From the end of November 1914, "Room 40" began regular decryption of the radio messages of the German fleet, which carried practically all orders and instructions[34]. The decrypted data was first attempted to be used during the sortie of the German fleet to the British coast on 16 December 1914[35].
In the interwar period encryption systems became more and more complex, so that special machines came to be used for encrypting and decrypting secret messages, of which the best known is the Enigma, created by German engineers in the 1920s. Already in 1932 the Cipher Bureau of Polish intelligence managed to break the Enigma cipher by the method of reverse engineering[36].
The volume of information exchanged by the countries of the anti-Hitler coalition during the Second World War required formal harmonization of national classification systems and of control and management procedures. A set of security classifications, accessible only to the initiated, took shape, defining who may handle documents (as a rule, officers rather than rank-and-file soldiers) and where they should be stored, given the appearance of ever more sophisticated safes and vaults. The belligerents developed procedures for the guaranteed destruction of secret documents. Some violations of such procedures led to the most significant intelligence achievements of the entire war. For example, the crew of the German submarine U-570 failed to properly destroy many secret documents, which fell into the hands of the British who captured it . A vivid example of the use of information security tools is the Enigma mentioned above, a more complex version of which appeared in 1938 and was widely used by the Wehrmacht and other services of the Third Reich. In Great Britain, cryptanalysis of enemy messages encrypted with the Enigma was successfully carried out by a group led by Alan Turing. The decryption machine they developed, the "Turing Bombe", gave considerable help to the anti-Hitler coalition, and is sometimes credited with a decisive role in the Allied victory . In the USA, for encrypting radio communications in the Pacific theater of war, signalmen were recruited from the Navajo Indian tribe, whose language was known to no one outside the USA . The Japanese never managed to find the key to this exotic method of protecting information[40]. In the USSR, from the 1930s, the so-called VCh communication (high-frequency communication) was used to protect the telephone conversations of the country's highest governing bodies (including the Stavka of the Supreme High Command) from eavesdropping; it was based on voice modulation of high-frequency signals and their subsequent scrambling. However, the lack of cryptographic protection made it possible, using a spectrometer, to recover messages from the intercepted signal .
The second half of the 20th century and the beginning of the 21st were marked by the rapid development of telecommunications, computer hardware and software, and data encryption. The appearance of compact, powerful and inexpensive computer equipment made electronic data processing accessible to small businesses and home users. Very quickly computers were connected by the Internet, which led to explosive growth of electronic business. All this, combined with the emergence of cybercrime and numerous cases of international terrorism, created a need for better methods of protecting computers and the information they store, process and transmit. Scientific disciplines such as "Computer Security" and "Information Protection Methods" arose, along with many professional organizations pursuing the common goals of ensuring the security and reliability of information systems .
Below are definitions of the term "information security" from various sources:
In 1975, Jerome Saltzer and Michael Schroeder, in their paper "The Protection of Information in Computer Systems", were the first to propose dividing security violations into three main categories: unauthorized information release, unauthorized information modification and unauthorized denial of use of information. These categories were later given short names and standardized definitions:
Confidentiality is the property of information being unavailable or closed to unauthorized persons, entities or processes;
Integrity is the property of safeguarding the accuracy and completeness of assets[54];
Availability is the property of information being accessible and ready for use on demand by an authorized subject entitled to it.
Taken together, these three key principles of information security are called the CIA triad.
In 1992, the OECD published its own information security model consisting of nine principles: awareness, responsibility, response, ethics, democracy, risk assessment, security design and implementation, security management and reassessment. In 1996, building on the 1992 OECD publication, the American National Institute of Standards and Technology (NIST) formulated eight basic principles, which state that computer security "supports the mission of the organization", "is an integral element of sound management", "should be cost-effective", "requires a comprehensive and integrated approach", "is constrained by societal factors", "should be periodically reassessed", that "responsibilities and accountability for computer security should be made explicit", and that "system owners have security responsibilities outside their own organizations". On the basis of this model, in 2004 NIST published 33 principles for the engineering design of information security systems, for each of which practical guidelines and recommendations were developed, and these continue to be developed and kept up to date to this day.
In 1998, Donn Parker supplemented the classic CIA triad with three more aspects: possession or control, authenticity and utility. The merits of this model, known as the Parkerian hexad[en] (from hexad, meaning "a group of six items"), are a subject of debate among information security specialists[61].
In 2009, the US Department of Defense published the "Three Fundamental Principles of Computer Security": system susceptibility, access to the flaw and capability to exploit the flaw.
In 2011, the international consortium The Open Group published the information security management standard O-ISM3, in which it abandoned the conceptual definition of the components of the classic CIA triad in favor of an operational definition of them. According to O-ISM3, an individual set of security objectives can be identified for each organization, belonging to one of five categories that correspond to one component of the triad or another: prioritized security objectives (confidentiality), long-term security objectives (integrity), information quality objectives (integrity), access control objectives (availability) and technical security objectives.
Of all the information security models mentioned above, the classic CIA triad remains the most widely recognized and widespread in the international professional community. It is enshrined in national and international standards and has been included in the main educational and certification programs in information security, such as CISSP. Some Russian authors use a calque of it, the "KTsD triad" (the Russian abbreviation for confidentiality, integrity, availability). In the literature, all three of its components, confidentiality, integrity and availability, are synonymously referred to as principles, security attributes, properties, fundamental aspects, information criteria, critical characteristics or basic building blocks .
Meanwhile, debates continue in the professional community about whether the CIA triad keeps pace with rapidly developing technologies and business requirements. As a result of these discussions, recommendations appear on the need to establish a link between security and privacy, as well as proposals for additional principles . Some of them have already been included in the standards of the International Organization for Standardization (ISO):
The confidentiality of information is achieved by granting access to it with the least privileges, on the basis of the need-to-know[en] principle. In other words, an authorized person should have access only to the information that he or she needs to perform official duties. The privacy-related crimes mentioned above, such as identity theft, are violations of confidentiality. One of the most important measures for ensuring confidentiality is the classification of information, which makes it possible to designate it as strictly confidential, or intended for public or internal use. Encryption of information is a typical example of a means of ensuring confidentiality.
Precise execution of operations or the making of correct decisions in an organization is possible only on the basis of reliable data stored in files, databases or systems, or transmitted over computer networks. In other words, information must be protected against deliberate, unauthorized or accidental modification relative to its original state, as well as against any distortion during storage, transmission or processing. However, its integrity is threatened by computer viruses and logic bombs, programming errors and malicious changes to program code, data substitution, unauthorized access, backdoors and the like. Besides deliberate actions, in many cases unauthorized changes to important information result from technical failures or human errors, made through carelessness or because of insufficient professional training. For example, integrity is violated by accidental deletion of files, entry of erroneous values, changes to settings and execution of incorrect commands, and this applies to ordinary users and system administrators alike.
Protecting the integrity of information requires a wide variety of controls and change-management measures for the information and the systems that process it. A typical example of such measures is limiting the group of people with change rights to only those who need such access to perform their official duties. In doing so, the principle of separation of duties[en] should be observed, according to which changes to data or to an information system are made by one person and are approved or rejected by another. In addition, any changes during the life cycle of information systems must be coordinated, tested for the preservation of information integrity, and introduced into the system only through correctly formed transactions. Software updates must be carried out in compliance with security measures. Any actions that entail changes must be logged.
According to this principle, information must be available to authorized persons when it is needed. The main factors affecting the availability of information systems are DoS attacks (an abbreviation of Denial of Service), ransomware attacks and sabotage. In addition, sources of threats to availability include unintentional human errors made through carelessness or insufficient professional training: accidental deletion of files or database records and erroneous system settings; denial of service resulting from exceeding permissible capacity or a shortage of hardware resources, or from communication network failures; an unsuccessful hardware or software update; and systems shutting down because of power supply failures. Natural disasters also play a significant role in disrupting availability: earthquakes, tornadoes, hurricanes, fires, floods and similar phenomena. In all cases the end user loses access to the information needed for his or her work, and forced downtime results. The criticality of the system to the user and its importance for the survival of the organization as a whole determine how much downtime affects it. Insufficient security measures increase the risk of malware infection, data destruction, outside intrusion or DoS attacks. Such incidents can make systems unavailable to ordinary users.
The term "non-repudiation" (sometimes written as one word, Nonrepudiation) first appeared in 1988 in the international standard "Security Architecture for Open Systems Interconnection" (ISO 7498-2). It is usually understood as the opposite of the Anglo-Saxon legal term repudiation, meaning "rejection, denial", which has two main interpretations. On the one hand, it means the fundamental right of a party to refuse, on lawful grounds, to perform obligations under a transaction if, for example, a signature on a paper document was forged, or the original signature was obtained unlawfully (as a result of fraud). In that case the burden of proving the authenticity of the signature lies with the party relying on it. The other interpretation is wrongful refusal to honor obligations. In the context of computer security, this may be, for example, one party's denial of the fact of sending, receiving, authorship or content of an electronic message. In the context of information security, "non-repudiation" is understood as confirmation of the integrity and original origin of data, excluding the possibility of forgery, which can be verified by third parties at any time, or as the establishment of identity (of a person, document or object) that can be considered authentic with a high degree of certainty and cannot be refuted.
A systems approach to describing information security proposes distinguishing the following components of information security:
Each of the components of information security will be examined in detail below in this section.
The goal of implementing information security for any object is to build an information security assurance system (ISAS) for that object. To build and effectively operate an ISAS, it is necessary to:
As the last stage of work shows, the process of implementing an ISAS is continuous and cyclically returns (after each review) to the first stage, repeating all the others in sequence. In this way the ISAS is adjusted to perform information protection tasks effectively and to meet the new requirements of a constantly updated information system.
In the Russian Federation, the regulatory legal acts in the field of information security include[74]:
Acts of federal legislation:
The lists and content of these regulatory documents in the field of information security are discussed in more detail in the section on Information Law.
The regulatory and methodological documents include
Depending on the field of application of information protection activities (within state authorities or commercial organizations), the activity itself is organized by special state bodies (units) or by departments (services) of an enterprise.
State bodies of the Russian Federation that oversee activity in the field of information protection:
Services organizing information protection at the enterprise level
To describe the information protection technology of a specific information system, a so-called Information Security Policy, or Security Policy of the information system in question, is usually built.
Security policy (of information in an organization) (Organizational security policy) is a set of documented rules, procedures, practices or guidelines in the field of information security that an organization follows in its activities.
Security policy of information and communication technologies (ICT security policy) consists of rules, directives and established practices that determine how, within an organization and its information and communication technologies, assets, including critical information, are managed, protected and distributed.
To build an Information Security Policy, it is recommended to consider separately the following areas of protection of the information system:
For each of the areas listed above, the Information Security Policy must describe the following stages in creating information protection means:
The Information Security Policy is formalized as documented requirements for the information system. Documents are usually divided by the level of description (detail) of the protection process.
Top-level documents of the Information Security Policy reflect the organization's position on information protection activities and its aspiration to comply with state and international requirements and standards in this area. Such documents may be called "IS Concept", "IS Management Regulations", "IS Policy", "IS Technical Standard", etc. The distribution of top-level documents is usually not restricted, although such documents may also be issued in two editions, for external and for internal use.
According to GOST R ISO/IEC 17799—2005, the following documents must be drawn up at the top level of the Information Security Policy: the "IS Assurance Concept", the "Rules for Acceptable Use of Information System Resources" and the "Business Continuity Plan".
The middle level includes documents concerning individual aspects of information security. These are requirements for the creation and operation of information protection means and for the organization of the organization's information and business processes in a specific area of information protection. For example: Data Security, Communications Security, Use of Cryptographic Protection Means, Content Filtering, etc. Such documents are usually issued in the form of internal technical and organizational policies (standards) of the organization. All middle-level documents of the information security policy are confidential.
The lower-level information security policy includes work regulations, administration manuals and operating instructions for individual information security services.
The literature proposes the following classification of information protection means.[73]
Organizational protection is the regulation of production activity and of the relationships among performers on a legal and regulatory basis that excludes or substantially hinders the unlawful acquisition of confidential information and the manifestation of internal and external threats. Organizational protection provides for:
The main organizational measures include:
In each specific case, organizational measures take a form and content specific to the given organization, aimed at ensuring information security in particular conditions.
Many small business managers underestimate the importance of information
продолжение следует...
Часть 1 Information Culture and Security for Schoolchildren and Employees, Risk Assessment
Часть 2 Enterprise Information Security - Information Culture and Security for Schoolchildren
Часть 3 See also - Information Culture and Security for Schoolchildren and
Comments