To obtain access to full text of journal and articles you must register!
- Article name
- Information security threats and related vulnerabilities at enterprise informatization facilities
- Authors
- Saakova M. N., , maya.arm@yandex.ru, MIREA - Russian Technological University; The State Public Institution of the City of Moscow "Information City", Moscow, Russia
Moskvitin G. I., , mgi81@mail.ru, MIREA - Russian Technological University, Moscow, Russia
- Keywords
- enterprise information security / IT infrastructure vulnerabilities / FSTEC Database of Russia / information security risk management / NIST IR 8286 / personal data protection / vulnerability monitoring / CTEM / CVSS v4.0 / EPSS
- Year
- 2026 Issue 3 Pages 21 - 26
- Code EDN
- IBMOGZ
- Code DOI
- 10.52190/2073-2600_2026_3_21
- Abstract
- The article examines approaches to ensuring information security of enterprise informatization facilities in the context of import substitution and the growth of cyber threats. Based on the analysis of the domestic regulatory framework, NIST IR 8286 and ISO/IEC 27005 standards, as well as data from the FSTEC database, a systematization of anthropogenic and man-made risk factors was carried out. The transition from static protection to a continuous threat impact management (CTEM) model is justified. An algorithm for prioritizing vulnerabilities based on an integral indicator combining CVSS v4.0 metrics, the probability of EPSS exploitation, and the component's reachability coefficient is proposed. The necessity of using artificial intelligence to automate vulnerability analysis is shown. The practical significance of the work lies in the formation of tools for choosing priority protection measures with limited resources of the organization.
- Text
- BUY for read the full text of article
- Buy
- 800.00 rub