On the issue of categorization of objects of critical information infrastructure of seaports
Вопрос категоризации объектов критической информационной инфраструктуры морских портов
2020-06-01
SCID: 54.1/td47bxv4
Discuss with AI
CII categorizationKaliningrad commercial seaportRussian Government Resolution No. 127critical information infrastructureseaports
Figures from the paper
Abstract (AI)
The purpose of the article is to consider the problematic issues that arise during the categorization of CII objects. Seaports are of strategic importance for the development of the Russian Federation's economy and transport support for foreign trade. In accordance with Federal law No. 187-FZ of July 26, 2017 "on security of critical information infrastructure of the Russian Federation", seaports are subjects of CII in the field of transport. Compliance with the requirements of this law, in particular, addressing issues related to the categorization of CII objects in accordance with Russian Government Resolution No. 127 of February 8, 2018 "on approval of the rules for categorizing critical information infrastructure objects of the Russian Federation, as well as the list of indicators of the criteria for the significance of critical information infrastructure objects of the Russian Federation and their values", requires careful study and evaluation, because, that CI subjects are increasingly faced with the complexity of processes and the need to take into account the specifics of a particular area of their activities. This article considers the subject of the Kaliningrad commercial sea port CII and categorizes one of the information systems as the author's recommendations for the implementation of the Decree of the Government of the Russian Federation No. 127 of February 8, 2018 for information systems of seaports. In conclusion, the authors note the importance of developing industry regulations for categorizing and ensuring the security of CII, the importance of developing standard models of violators that would take into account industry characteristics, and the need to attract narrowly focused specialists to the work of the Commission, both from the organization and from outside.
Key Findings
1
Categorization of critical information infrastructure (CII) objects in seaports is problematic and requires careful study and evaluation.
2
Commissions responsible for categorization should include narrowly focused specialists from both the organization and external experts to address sector-specific complexities.
3
Seaports are designated as CII subjects in transport under Russian Federal Law No. 187-FZ and must comply with Government Resolution No. 127 (2018) categorization rules.
4
The article applies the categorization rules to the Kaliningrad commercial seaport and categorizes one of its information systems, providing author's recommendations for implementation.
5
There is a need to develop industry-specific regulations and standard attacker models that account for seaport characteristics to improve CII categorization and security.
Research Object
Critical information infrastructure (CII) object — an information system of the Kaliningrad commercial seaport
Research Subject
Categorization of the seaport CII object according to Russian CII security law and Government Resolution No. 127 (criteria, category assignment, and implementation recommendations)
Publication Details
Publication Date
2020-06-01
Journal
Publisher
ISSN
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest