Methodology of Information Security Audit of Critical Information Infrastructure Subjects: Synthesis of Reference Modeling and Quality Assessment
( Pp. 223-235)
More about authors
Nilov Nikita A.
chief expert, Information Security Center, postgraduate student; National Research University of Electronic Technology (MIET); Zelenograd ORCID: 0009-0004-1855-0745
JSC “Gazprombank”
Moscow, Russian Federation Dushkin Alexander V. Dr. Sci. (Eng.), Associate Professor; Professor, Department of Information Security, Professor, Department of Radio Engineering; Voronezh State Technical University; Voronezh, Russian Federation
National Research University of Electronic Technology (MIET)
Zelenograd, Moscow, Russian Federation Portnov Evgeny M. Dr. Sci. (Eng.), Professor; Professor, Institute of System and Software Engineering and Information Technology; National Research University of Electronic Technology (MIET); Zelenograd, Moscow, Russian Federation
Voronezh State Technical University
Voronezh, Russian Federation Savchenko Yury V. Dr. Sci. (Eng.), Professor; Professor, Institute of Microdevices and Control Systems named after L.N. Presnukhina; National Research University of Electronic Technology (MIET); Zelenograd, Moscow, Russian Federation
JSC “Gazprombank”
Moscow, Russian Federation Dushkin Alexander V. Dr. Sci. (Eng.), Associate Professor; Professor, Department of Information Security, Professor, Department of Radio Engineering; Voronezh State Technical University; Voronezh, Russian Federation
National Research University of Electronic Technology (MIET)
Zelenograd, Moscow, Russian Federation Portnov Evgeny M. Dr. Sci. (Eng.), Professor; Professor, Institute of System and Software Engineering and Information Technology; National Research University of Electronic Technology (MIET); Zelenograd, Moscow, Russian Federation
Voronezh State Technical University
Voronezh, Russian Federation Savchenko Yury V. Dr. Sci. (Eng.), Professor; Professor, Institute of Microdevices and Control Systems named after L.N. Presnukhina; National Research University of Electronic Technology (MIET); Zelenograd, Moscow, Russian Federation
Abstract:
This article examines the discrepancy between the growing volume of regulatory requirements for protecting the Russian Federation’s critical information infrastructure and the lack of objective methods for quantitatively assessing their implementation. A comparative analysis of domestic regulations and international standards reveals a fundamental methodological discrepancy at the metric level: Russian regulations rely on qualitative, binary assessments, while global practice is shifting toward quantitative measurement of process efficiency and maturity. A two-tier qualimetric assessment model is proposed that synthesizes mandatory regulatory requirements with CMMI principles. The model includes the calculation of a basic «hygienic minimum» performance indicator and an integrated maturity assessment across five domains (identification, protection, detection, response, and recovery) based on an ordinal scale and weighting factors. Implementation of the proposed approach helps overcome this discrepancy, objectify audit results, and create incentives for the continuous improvement of critical information infrastructure protection systems in the face of escalating cyber threats.
How to Cite:
Nilov N.A., Dushkin A.V., Portnov E.M. and Savchenko Yu.V. Methodology of information security audit of critical information infrastructure subjects: Synthesis of reference modeling and quality assessment. Computational Nanotechnology. 13, 2 (2026), 223–235. DOI: 10.33693/2313-223X-2026-13-2-223-235. EDN: YBYJRV
Reference list:
An V.R., Selifanov V.V., Tabakaeva V.A. et al. Development of a methodology for auditing the cybersecurity of GIS related to critical information infrastructure facilities of the Russian Federation. Collection of Scientific Papers of NSTU. 2019. No. 3-4 (96). Pp. 84–95. (In Rus.). DOI: 10.17212/2307-6879-2019-3-4-84-95. EDN: BOGOJY.
Aristova N., Bychenok P. Changes in the regulation of critical information infrastructure: the trend towards software localization is increasing. Internal Control in a Credit Institution. 2025. No. 4. Pp. 12–16. (In Rus.).
Belov A.S., Dobryshin M.M., Gromov Yu.Yu., Dushkin A.V. Qualimetric analysis of secure infocommunication systems. A.V. Dushkin (ed.). Moscow: Hot Line – Telecom, 2025. 155 p. ISBN: 978-5-9912-1158-1.
Belov A.S., Dobryshin M.M., Dushkin A.V. A systems approach to designing information security systems. A.V. Dushkin (ed.). Moscow: Hot Line – Telecom, 2023. 232 p. EDN: DCSYJQ. ISBN: 978-5-9912-1067-6.
Vulfin A.M. Models and methods for comprehensive assessment of security risks of critical information infrastructure facilities based on intelligent data analysis. Systems Engineering and Information Technology. 2023. Vol. 5. No. 4 (13). Pp. 50–76. (In Rus.). DOI 10.54708/2658-5014-SIIT-2023-no3-p50. EDN: FJPFKC.
Livshits I.I. Models and methods for auditing the information security of integrated control systems for complex industrial facilities. Dis. ... of Dr. Sci. (Eng.). St. Petersburg: SPIIRAS, 2018. 407 p. EDN: WUMWGA.
Livshits I.I., Baksheev A.S. Study of methods for monitoring the level of information security at critical information infrastructure facilities. Cybersecurity Issues. 2022. No. 6 (52). Pp. 40–52. (In Rus.). DOI: 10.21681/2311-3456-2022-6-40-52. EDN: NSWOOI.
Livshits I.I., Baksheev A.S. Development of a methodology for monitoring the level of information security of critical information infrastructure objects. Cybersecurity Issues. 2023. No. 2 (54). Pp. 85–98. (In Rus.). DOI: 10.21681/2311-3456-2023-2-85-98. EDN: KQLCWV.
Makarenko S.I. Information security audit: main stages, conceptual foundations, classification of measures. Control, Communications and Security Systems. 2018. No. 1. Pp. 1–29. (In Rus.). DOI: 10.24411/2410-9916-2018-10101. EDN: LWCFFF.
Makarenko S.I., Smirnov G.E. Model for auditing the security of a critical information infrastructure facility using test information technology impacts. Transactions of Educational Institutions of Communication. 2021. No. 1. Pp. 94–104. (In Rus.). DOI: 10.31854/1813-324X-2021-7-1-94-104. EDN: UBKIYS.
Smirnov G.E., Makarenko S.I. Using test information technology impacts for preventive security audit of information and telecommunication networks. Economics and Quality of Communication Systems. 2020. No. 3 (17). Pp. 43–58. (In Rus.). EDN: VLWMLJ.
Kochedykov S.S., Novoseltsev V.I., Kobzistyy S.Y., Dushkin A.V. Algorithm and method for recognizing critical situations using semantic networks on critical information infrastructure facilities as a result of cyber-attacks. In: Proceedings of the IEEE Conference of Russian Young Researchers in Electrical and Electronic Engineering (EIConRus), (St. Petersburg, Moscow, 27–30.01.2020). IEEE, 2020. Pp. 2066–2071. DOI: 10.1109/EIConRus49466.2020.9039255. EDN: QNQBCU.
Aristova N., Bychenok P. Changes in the regulation of critical information infrastructure: the trend towards software localization is increasing. Internal Control in a Credit Institution. 2025. No. 4. Pp. 12–16. (In Rus.).
Belov A.S., Dobryshin M.M., Gromov Yu.Yu., Dushkin A.V. Qualimetric analysis of secure infocommunication systems. A.V. Dushkin (ed.). Moscow: Hot Line – Telecom, 2025. 155 p. ISBN: 978-5-9912-1158-1.
Belov A.S., Dobryshin M.M., Dushkin A.V. A systems approach to designing information security systems. A.V. Dushkin (ed.). Moscow: Hot Line – Telecom, 2023. 232 p. EDN: DCSYJQ. ISBN: 978-5-9912-1067-6.
Vulfin A.M. Models and methods for comprehensive assessment of security risks of critical information infrastructure facilities based on intelligent data analysis. Systems Engineering and Information Technology. 2023. Vol. 5. No. 4 (13). Pp. 50–76. (In Rus.). DOI 10.54708/2658-5014-SIIT-2023-no3-p50. EDN: FJPFKC.
Livshits I.I. Models and methods for auditing the information security of integrated control systems for complex industrial facilities. Dis. ... of Dr. Sci. (Eng.). St. Petersburg: SPIIRAS, 2018. 407 p. EDN: WUMWGA.
Livshits I.I., Baksheev A.S. Study of methods for monitoring the level of information security at critical information infrastructure facilities. Cybersecurity Issues. 2022. No. 6 (52). Pp. 40–52. (In Rus.). DOI: 10.21681/2311-3456-2022-6-40-52. EDN: NSWOOI.
Livshits I.I., Baksheev A.S. Development of a methodology for monitoring the level of information security of critical information infrastructure objects. Cybersecurity Issues. 2023. No. 2 (54). Pp. 85–98. (In Rus.). DOI: 10.21681/2311-3456-2023-2-85-98. EDN: KQLCWV.
Makarenko S.I. Information security audit: main stages, conceptual foundations, classification of measures. Control, Communications and Security Systems. 2018. No. 1. Pp. 1–29. (In Rus.). DOI: 10.24411/2410-9916-2018-10101. EDN: LWCFFF.
Makarenko S.I., Smirnov G.E. Model for auditing the security of a critical information infrastructure facility using test information technology impacts. Transactions of Educational Institutions of Communication. 2021. No. 1. Pp. 94–104. (In Rus.). DOI: 10.31854/1813-324X-2021-7-1-94-104. EDN: UBKIYS.
Smirnov G.E., Makarenko S.I. Using test information technology impacts for preventive security audit of information and telecommunication networks. Economics and Quality of Communication Systems. 2020. No. 3 (17). Pp. 43–58. (In Rus.). EDN: VLWMLJ.
Kochedykov S.S., Novoseltsev V.I., Kobzistyy S.Y., Dushkin A.V. Algorithm and method for recognizing critical situations using semantic networks on critical information infrastructure facilities as a result of cyber-attacks. In: Proceedings of the IEEE Conference of Russian Young Researchers in Electrical and Electronic Engineering (EIConRus), (St. Petersburg, Moscow, 27–30.01.2020). IEEE, 2020. Pp. 2066–2071. DOI: 10.1109/EIConRus49466.2020.9039255. EDN: QNQBCU.
Keywords:
audit, information security, qualitative assessment, qualimetric model, cyber threat, quantitative assessment, critical information infrastructure.