Protection of the information resources of a library based on analysis of business processes
- Authors: Rodionova Z.V.1, Bobrov L.K.1
- 
							Affiliations: 
							- Department of Economic Informatics
 
- Issue: Vol 43, No 1 (2016)
- Pages: 20-27
- Section: Article
- URL: https://journals.rcsi.science/0147-6882/article/view/175026
- DOI: https://doi.org/10.3103/S0147688216010032
- ID: 175026
Cite item
Abstract
This paper justifies the relevance of the reliable protection of information and the development of measures to reduce information risks in libraries with comprehensive information resources. A brief description of the objects of protection and the main threats, including those that are related to the processing of personal data, is provided. It is alleged that analysis of models of the business processes of a library makes it possible to track the impacts of changes on many aspects of information security. The position of the information system for security analysis of the business process in the overall system of information security is determined. Steps for the formalization and updating of the rights of access to information resources of a library are illustrated. It is emphasized that the basic document for information-security risk management is a threat model that reflects the data on sources of threats and vulnerabilities of the system, impacted objects, and a number of other parameters. A block diagram that illustrates the process of analyzing the threats and vulnerabilities and a knowledge meta-model for the management of information-security risks are provided. It is concluded that based on the relationship of business processes that are reflected in a formal notation it is possible to automatically obtain the data on the degree of influence of security aspects of information objects of a particular sub-process on the results of business processes of a higher level, and as a result, on the achievability of the purposes of an organization.
About the authors
Z. V. Rodionova
Department of Economic Informatics
							Author for correspondence.
							Email: z.v.rodionova@nsuem.ru
				                					                																			                												                	Russian Federation, 							Novosibirsk						
L. K. Bobrov
Department of Economic Informatics
														Email: z.v.rodionova@nsuem.ru
				                					                																			                												                	Russian Federation, 							Novosibirsk						
Supplementary files
 
				
			 
					 
						 
						 
						 
						 
				 
  
  
  
  
  Email this article
			Email this article  Open Access
		                                Open Access Access granted
						Access granted Subscription Access
		                                		                                        Subscription Access
		                                					