|
This article is cited in 2 scientific papers (total in 2 papers)
05.13.00 INFORMATICS, COMPUTER FACILITIES AND MANAGEMENT
05.13.19 INFORMATION SECURITY
Determination of the weight of audit evidence by the method of point ratings in the information security audit
V. A. Voevodin, M. S. Markina, P. V. Markin National Research University of Electronic Technology (MIET)
Abstract:
Information systems of high-tech enterprises that develop and produce high-tech products, including products and services based on nanotechnology, are characterized by large volumes of dynamic information flows and require protection of confidentiality, availability and integrity of information circulating in them. To protect information, an appropriate resource is allocated, which is distributed by tasks and time according to the decision of the appropriate management body. Making such a decision requires information about the current information security environment - a reliable and complete audit report. An information security audit is organized and conducted to formulate a conclusion.To study the problem, a retrospective analysis of the development of goal-setting in the management of the audit program was conducted. The appearance of the reference model of the audit object as a set of interrelated properties of the audit object was developed, and a scientific hypothesis was put forward about the expediency of taking into account the weight of each audit certificate and the cost of obtaining it, mathematical models for processing expert judgments are given. To prove the hypothesis, an experiment was planned and conducted, which resulted in data confirming the hypothesis. A practical example of using the method to determine the weight of audit evidence, taking into account their cost, is given. The direction of further research is indicated.
Keywords:
audit, information security, audit certificate, the method of score assessments.
Received: 20.02.2020
Citation:
V. A. Voevodin, M. S. Markina, P. V. Markin, “Determination of the weight of audit evidence by the method of point ratings in the information security audit”, Comp. nanotechnol., 7:1 (2020), 57–62
Linking options:
https://www.mathnet.ru/eng/cn288 https://www.mathnet.ru/eng/cn/v7/i1/p57
|
|