Corporate system of information and cybersecurity
Abstract
The article analyses modern cybersecurity technologies and systems such as next-generation firewalls, micro-segmentation, network access control systems, zero-trust remote access, sys-tems protecting against distributed denial-of-service attacks, systems protecting against portal attacks, secure access brokers to the cloud, malware protection systems, email attack protection system, mobile device management systems, user account and authorization management sys-tems, privileged access management systems, physical access protection systems, data leak pro-tection systems, multi-factor authentication and authorization systems, database protection sys-tems, vulnerability analysis systems, attack simulation systems, cyber decoy systems, log and action collection, correlation, and analysis systems, as well as automation systems for actions during an investigation or incident response. The choice of necessary cybersecurity systems for designing a corporate information and cybersecurity system is determined, considering the cor-porate IT landscape. Critically important components of this system include network protection solutions such as NGFW, workstation and server protection against malicious software based on EDR/XDR, and email system protection. Highly recommended components also include net-work access management systems and remote access with zero trust, information leakage pro-tection, and a complex system of authentication and authorization. For organizations with me-dium or high complexity of IT landscapes, cybersecurity analytics cluster systems are critically important, especially event collection and correlation systems and vulnerability analysis sys-tems. Considering the above, a corporate architecture of information and cybersecurity is pro-posed, which will ensure a layered system of effective protection against cyber threats.