Skip to content

Methodology of information security audit of critical information infrastructure subjects: synthesis of reference modeling and quality assessment

Aug 2026 · Computational nanotechnology · 0 citations · 3 references

Abstract

This article examines the discrepancy between the growing volume of regulatory requirements for protecting the Russian Federation’s critical information infrastructure and the lack of objective methods for quantitatively assessing their implementation. A comparative analysis of domestic regulations and international standards reveals a fundamental methodological discrepancy at the metric level: Russian regulations rely on qualitative, binary assessments, while global practice is shifting toward quantitative measurement of process efficiency and maturity. A two-tier qualimetric assessment model is proposed that synthesizes mandatory regulatory requirements with CMMI principles. The model includes the calculation of a basic «hygienic minimum» performance indicator and an integrated maturity assessment across five domains (identification, protection, detection, response, and recovery) based on an ordinal scale and weighting factors. Implementation of the proposed approach helps overcome this discrepancy, objectify audit results, and create incentives for the continuous improvement of critical information infrastructure protection systems in the face of escalating cyber threats.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.