Quarterly journal published in SPbPU
and edited by prof. Dmitry Zegzhda
Peter the Great St. Petersburg Polytechnic University
Institute of computer sciences and technologies
information security of computer systems
Information Security Problems. Computer Systems
Published since 1999.
ISSN 2071-8217
METHOD OF PROVIDING AND CONDUCTING INTERNAL AUDIT OF INFORMATION SECURITY OF ORGANISATIONS ON THE BASIS OF RISK-ORIENTED APPROACH
P. A. Glibovsky, P. V. Timashov, V. I. ChernyshovMozhaisky Military Aerospace Academy, Military Academy of the General Staff of the Armed Forces of the Russian Federation
Annotation: In order to guarantee effective information security of an organization, a systematic and comprehensive approach is necessary. One of the most effective tools for obtaining an independent and objective assessment of organizations' security against information security risks and threats and evaluating the level of organization IS provision is the internal information security audit. Nowadays, more and more additional requirements are imposed to the methods of ensuring and conducting IS audit. Having analyzed the scientific literature, training manuals and articles in the field of information security, a method based on the risk-oriented approach is developed. The risk management theory and the internal audit methodology built on its basis should become the tools for conducting the audit. Information security audit based on the risk-oriented approach will make it possible to assess the security of the organization, identify risks, create and (or) adjust the plan of measures to minimize them, improve the interaction of departments responsible for control and risk management.
Keywords: information security audit, risk-oriented approach, risk matrix, information security threats, security level.
Pages 09-24