DOI: 10.30987/2658-6436-2026-3-67-77 ISSN: 2658-3488

MAIN ALGORITHM OF THE METHODOLOGY FOR ENSURING INTEGRATED SECURITY OF STRATEGICALLY IMPORTANT ENTERPRISE RESOURCES

Nataliya Kuznetsova, Tatyana Karlova

The paper develops a classifier of modern threats, with its set of factors formed using the vulnerability database of the Federal Service for Technical and Export Control of Russia (FSTEC of Russia) and the MITRE database. As the components of the main algorithm of the methodology, the article presents flowcharts for data collection on: the threat vector as the threat subject; protection methods as the protection subject; and enterprise automated system (AS) resources as both the threat object and the protection object. To enhance the level of information security, an approach of simultaneous design and modeling of the AS and the automated security system (ASS) is applied, as the protection object and protection subject, respectively. Statistical and mathematical methods, as well as Monte Carlo methods, are recommended as the primary modeling techniques. Special attention is given to the algorithm for assessing security risk dynamics, which consists of a comparative analysis of the information security risk level before and after applying a set of protection methods. The novelty of the work lies in the proposed creative concept of unified accounting for the maximum number of threat factors when forming the threat classifier, the maximum number of characteristics of protected resources when analyzing and modeling the threat object (protection object), and the concept of using the maximum number of sources when forming and updating the set of protection methods as the protection subject. The outcome is a set of step-by-step recommendations for applying data collection and analysis methods, design and modeling methods for protected and protecting enterprise automated systems, and a method for assessing security risk dynamics within the overall methodology for ensuring integrated security of strategically important enterprise resources. Applying the main algorithm of the methodology developed in this article will significantly improve the level of resource protection and substantially reduce the overall enterprise security risk level.