METHODOLOGY FOR BUILDING A SECURITY SYSTEM FOR AN INFORMATION ACTIVITY FACILITY PROCESSING RESTRICTED INFORMATION
DOI:
https://doi.org/10.31891/2219-9365-2026-87-37Keywords:
information activity facility, restricted information, security system, risk analysis, evidence base, target security profile, security authorization, continuous monitoringAbstract
The article develops a risk-oriented methodology for building and operating a security system for an information activity facility that processes restricted information. The proposed approach integrates the cybersecurity perimeter of an information and communication system with the physical and engineering protection perimeter of the facility. The methodology covers information classification, inventory of assets and data flows, definition of trust boundaries, threat modelling, risk analysis, development of a target security profile, implementation of controls, evidence management, independent assessment, security authorization and continuous monitoring. Analytical indicators are introduced for inherent and residual risk, weighted coverage of target-profile requirements, completeness of verified evidence and overall readiness for assessment. The study emphasises that numerical scores must not replace professional judgement: an unfulfilled critical requirement, an unacceptable residual risk or the absence of mandatory evidence remains a blocking condition regardless of the aggregate index. The method is illustrated using a conditional system processing official information, including remote access, supplier support, backup and facility-protection scenarios. A RACI responsibility matrix and a twelve-month implementation sequence connect governance decisions with verifiable technical and organisational outcomes. The scientific contribution is the formalised end-to-end relationship “risk — requirement — implementation — evidence — authorization decision” applied simultaneously to logical, physical and engineering domains. The results can support project planning, internal audit, evidence preparation and continuous improvement. The formulas proposed in the article are methodological instruments and do not replace legally established assessment procedures or an organisation’s approved risk-assessment methodology.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Євгенія ІВАНЧЕНКО, Олександр ТУРОВСЬКИЙ, Микола РИЖАКОВ

This work is licensed under a Creative Commons Attribution 4.0 International License.


