<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">oo</journal-id><journal-title-group><journal-title xml:lang="ru">Открытое образование</journal-title><trans-title-group xml:lang="en"><trans-title>Open Education</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">1818-4243</issn><issn pub-type="epub">2079-5939</issn><publisher><publisher-name>Plekhanov Russian University of Economics</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.21686/1818-4243-2019-3-25-32</article-id><article-id custom-type="elpub" pub-id-type="custom">oo-621</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>НОВЫЕ ТЕХНОЛОГИИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>NEW TECHNOLOGIES</subject></subj-group></article-categories><title-group><article-title>Повышение эффективности формирования профессиональных компетенций магистров по направлению «Информационная безопасность»  на основе применения CASE-технологий</article-title><trans-title-group xml:lang="en"><trans-title>Improving the efficiency of the formation of professional competencies Masters in “Information Security” based on the use o CASE-technologies</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Гаврилов</surname><given-names>А. В.</given-names></name><name name-style="western" xml:lang="en"><surname>Gavrilov</surname><given-names>A. V.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Александр Викторович Гаврилов – кандидат технических наук, доцент, доцент кафедры Прикладной информатики и информационной безопаcности </p><p>Москва</p></bio><bio xml:lang="en"><p>Aleksandr V. Gavrilov – Cand. Sci. (Engineering) Associate Professor, Associate Professor at the Department of Applied Informatics and Information Security </p><p>Moscow</p></bio><email xlink:type="simple">Gavrilov.AV@rea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Сизов</surname><given-names>В. А.</given-names></name><name name-style="western" xml:lang="en"><surname>Sizov</surname><given-names>V. A.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Валерий Александрович Сизов – доктор технических наук, профессор, профессор кафедры Прикладной информатики и информационной безопасности </p><p>Москва</p></bio><bio xml:lang="en"><p>Valeriy A. Sizov – Dr. Sci. (Engineering), Professor, Professor at the Department of Applied Informatics and Information Security </p><p>Moscow</p></bio><email xlink:type="simple">Sizov.VA@rea.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Российский экономический университет им. Г.В Плеханова</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Plekhanov Russian University of Economics</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2019</year></pub-date><pub-date pub-type="epub"><day>26</day><month>06</month><year>2019</year></pub-date><volume>23</volume><issue>3</issue><fpage>25</fpage><lpage>32</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Гаврилов А.В., Сизов В.А., 2019</copyright-statement><copyright-year>2019</copyright-year><copyright-holder xml:lang="ru">Гаврилов А.В., Сизов В.А.</copyright-holder><copyright-holder xml:lang="en">Gavrilov A.V., Sizov V.A.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://openedu.rea.ru/jour/article/view/621">https://openedu.rea.ru/jour/article/view/621</self-uri><abstract><sec><title>Цель исследования</title><p>Цель исследования. В современных условиях для построения эффективной системы информационной безопасности предприятия требуются специалисты, обладающие соответствующими профессиональными компетенциями и навыками системного подхода при анализе совокупности факторов, оказывающих влияние на состояние информационной безопасности предприятия. Для подготовки такого рода специалистов требуются качественные изменения в содержании учебных дисциплин, основанные на использовании в процессе построения системы информационной безопасности методов и средств системного анализа. </p><p>Существующие в настоящее время подходы в оценке рисков предприятия основаны на формировании реестра его информационных ресурсов, необходимого для дальнейшей обработки рисков. Адекватная оценка стоимости ресурса невозможна без правильного понимания семантики этого ресурса и его роли в реализуемых бизнес-процессах. Современные подходы к вопросу формирования реестра информационных ресурсов предприятия, по мнению авторов, не предлагают эффективной методики выявления ресурсов и оценки их стоимости. </p><p>В настоящей работе рассматривается подход, основанный на применении в подготовке магистров по направлению «Информационная безопасность» методики структурно-функционального анализа и CASE-технологий при формировании реестра информационных ресурсов предприятия. </p></sec><sec><title>Материалы и методы</title><p>Материалы и методы. Для формирования реестра информационных ресурсов предприятия предлагается выполнять построение структурно-функциональной модели предприятия с использованием нотации IDEF0. Моделирование бизнес-процессов выполнялось в среде Business Studio компании «Современные технологии управления». </p><p>В качестве примера для анализа рисков рассматривалась деятельность типовой компании IT-индустрии, занимающейся разработкой и внедрением информационных систем управления предприятием. </p></sec><sec><title>Результаты</title><p>Результаты. Методика прошла успешную апробацию в учебном процессе. По мнению авторов статьи, использование данной методики при проведении лабораторных занятий для магистров, обучающихся по направлению «Информационная безопасность» позволило повысить эффективность формирования у обучающихся профессиональных компетенций и, следовательно, в целом, качество обучения. </p><p>Полученные результаты могут быть использованы не только в качестве методики обучения специалистов в области информационной безопасности. Применение рассматриваемой в статье методики формирования реестра информационных ресурсов предприятия в практической деятельности по обеспечению информационной безопасности предприятия позволит повысить обоснованность решений по защите информации предприятия. </p></sec><sec><title>Заключение</title><p>Заключение. В работе предложена методика, позволяющая обосновать выбор основных направлений по защите информации предприятия на основе анализа его бизнес-процессов. Отличительной особенностью методики является использование современных CASE-технологий для принятия решений в области информационной безопасности предприятия. </p><p>Реализация методики позволяет сформировать реестр информационных ресурсов предприятия, включающий оценку вероятного ущерба по каждому ресурсу. Реестр показывает узкие места в организации защиты, на которые следует обратить первоочередное внимание при планировании мероприятий по защите информации. На основе полученных данных можно сформировать обоснованную с экономической точки зрения стратегию и тактику развития системы защиты информации предприятия. </p></sec><sec><title> </title><p> </p></sec></abstract><trans-abstract xml:lang="en"><sec><title>Purpose of the study</title><p>Purpose of the study. In modern conditions, building an effective information security system for an enterprise requires specialists with appropriate professional competencies and systems approach skills in analyzing a combination of factors that influence the state of information security of an enterprise. For the preparation of such kind of specialists, qualitative changes in the content of educational disciplines are required, based on the use of methods and means of system analysis in the process of building an information security system. </p><p>The current approaches to assessing the risk of an enterprise are based on the formation of a register of its information resources necessary for the further processing of risks. Adequate assessment of the value of a resource is impossible without a correct understanding of the semantics of this resource and its role in the implemented business processes. Modern approaches to the formation of the register of enterprise information resources, according to the authors, do not offer an effective method of identifying resources and estimating their value.</p><p>This paper considers an approach based on the use of structural and functional analysis methods and CASE-technologies in the formation of a register of information resources of the enterprise in the training of masters in the direction of “Information Security”. </p></sec><sec><title>Materials and methods</title><p>Materials and methods. For the formation of the register of enterprise information resources, it is proposed to build a structural-functional enterprise model using the IDEF0 notation. Business process modeling was performed in the Business Studio environment of «Modern Control Technologies». </p><p>As an example for risk analysis, the activities of a typical IT-industry company engaged in the development and implementation of enterprise management information systems were considered. </p></sec><sec><title>Results</title><p>Results. The technique was successfully tested in the educational process. According to the authors of the article, the use of this technique in conducting laboratory classes for masters enrolled in the “Information Security” direction has made it possible to increase the efficiency of the formation of professional competencies in students and, consequently, in general, the quality of education. </p><p>The results obtained can be used not only as a training method for specialists in the field of information security. The application of the methodology of forming the register of information resources of an enterprise considered in the article in practical activities to ensure the information security of an enterprise will increase the validity of decisions to protect the information of the enterprise. </p></sec><sec><title>Conclusion</title><p>Conclusion. The paper proposes a method to justify the choice of the main directions for the protection of enterprise information based on the analysis of its business processes. A distinctive feature of the technique is the use of modern CASE-technologies for decision-making in the field of enterprise information security. </p><p>The implementation of the methodology allows you to create a register of information resources of the enterprise, including an assessment of the likely damage for each resource. The registry shows the bottlenecks in the organization of protection, which should be given priority when planning measures to protect information. On the basis of the data obtained, it is possible to form a strategy and tactics for developing an enterprise information protection system that is reasonable from an economic point of view. </p></sec></trans-abstract><kwd-group xml:lang="ru"><kwd>CASE-технологии</kwd><kwd>IDEF0</kwd><kwd>защита информации</kwd><kwd>бизнес-процесс</kwd></kwd-group><kwd-group xml:lang="en"><kwd>CASE-technology</kwd><kwd>IDEF0</kwd><kwd>information security</kwd><kwd>business process</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р ИСО/МЭК 27005-2010. Информационная технология. Методы и средства обеспечения безопасности. Менеджмент риска информационной безопасности. Взамен ГОСТ Р ИСО/МЭК ТО 13335-3-2007 и ГОСТ Р ИСО/ МЭК ТО 13335-4-2007; Введ. с 30.11.2010. М.: Стандартинформ, 2011.</mixed-citation><mixed-citation xml:lang="en">GOST R ISO / IEC 27005-2010. Information technology. Methods and means of security. Information security risk management. Instead, GOST R ISO / IEC 13335-3-2007 and GOST R ISO / IEC 13335-4-2007; Enter from 11/30/2010. Moscow: Standardinform; 2011. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р ИСО 31000-2010. Менеджмент риска. Принципы и руководство.; Введен с 01.09.2011. М.: Стандартинформ, 2012.</mixed-citation><mixed-citation xml:lang="en">GOST R ISO 31000-2010. Risk management. Principles and guidelines .; Entered from 09/01/2011. Moscow: Standardinform; 2012. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Международный стандарт ISO/IEC 27001- 2013. Информационные технологии – Методы защиты – Системы менеджмента информационной безопасности – Требования.</mixed-citation><mixed-citation xml:lang="en">The international standard ISO / IEC 27001-2013. Information technology - Protection methods - Information security management systems - Requirements. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">ГОСТ Р ИСО/МЭК 17799-2005. Информационная технология. Практические правила управления информационной безопасностью. Утвержден и введен в действие Приказом Федерального агентства по техническому регулированию и метрологии от 29 декабря 2005 г. № 447-ст.</mixed-citation><mixed-citation xml:lang="en">GOST R ISO / IEC 17799-2005. Information technology. Practical rules of information security management. Approved and enacted by the Order of the Federal Agency for Technical Regulation and Metrology of December 29; 2005 No. 447-st. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Кривякин К.С., Изотова А.Р., Федоров В.М. Методический подход к оценке рисков информационной безопасности предприятия // Экономинфо. 2018. Т. 15. № 2. С. 82–90.</mixed-citation><mixed-citation xml:lang="en">Krivyakin K.S., Izotova A.R., Fedorov V.M. Methodical approach to risk assessment of information security of an enterprise. Ekonominfo. 2018; 15 (2): 82-90. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Ильченко Л.М., Брагина Е.К., Егоров И.Э., Зайцев С.И. Расчет рисков информационной безопасности телекоммуникационного предприятия // Открытое образование. 2018. Т. 22. № 2. С. 61–70.</mixed-citation><mixed-citation xml:lang="en">Il’chenko L.M., Bragina E.K., Egorov I.E., Zaytsev S.I. Calculation of risks of information security of a telecommunications enterprise. Otkrytoye obrazovaniye = Open Education. 2018; 22 (2): 61-70. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Плетнев П.В., Белов В.М. Методика оценки рисков информационной безопасности на предприятиях малого и среднего бизнеса // Доклады Томского государственного университета систем управления и радиоэлектроники. 2012. № 1–2 (25). С. 83–86.</mixed-citation><mixed-citation xml:lang="en">Pletnev P.V., Belov V.M. Methods of assessing information security risks in small and medium-sized businesses. Doklady Tomskogo gosudarstvennogo universiteta sistem upravleniya i radioelektroniki = Reports of Tomsk State University of Control Systems and Radioelectronics. 2012; 1–2 (25): 83– 86. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Одинцова М.А. Методика управления рисками для малого и среднего бизнеса // Экономический журнал. 2014. № 3 (35).</mixed-citation><mixed-citation xml:lang="en">Odintsova M.A. Risk Management Technique for Small and Medium Businesses. Ekonomicheskiy zhurnal = Economic Journal. 2014; 3 (35). (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Выборнова О.Н., Давидюк Н.В., Кравченко К.Л. Оценка информационных рисков на основе экспертной информации (на примере ГБУЗ АО «Центр медицинской профилактики») // Инженерный вестник Дона. 2016. № 4 (43). С. 86.</mixed-citation><mixed-citation xml:lang="en">Vybornova O.N., Davidyuk N.V., Kravchenko K.L. Information risk assessment based on expert information (for example, GBUZ JSC “Center for Medical Prevention”). Inzhenernyy vestnik Dona = Engineering Bulletin of the Don. 2016; 4 (43): 86. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Баранова Е.К. Методики анализа и оценки рисков информационной безопасности // Вестник Московского университета им. С.Ю. Витте. 2015. № 1. С. 73–79.</mixed-citation><mixed-citation xml:lang="en">Baranova E.K. Methods of analysis and risk assessment of information security. Vestnik Moskovskogo universiteta im. S.YU. Vitte = Bulletin of Vitte Moscow University. 2015 (1): 73- 79. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">Астахов А.М. Искусство управления информационными рисками. М.: ДМК Пресс, 2010. 312 с.</mixed-citation><mixed-citation xml:lang="en">Astakhov A.M. Iskusstvo upravleniya informatsionnymi riskami = The art of information risk management. Moscow: DMK Press; 2010. 312 p. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">Сизов В.А. Применение деловых игр в подготовке магистров по программе «Защита информационного пространства субъектов экономической деятельности» // Открытое образование. 2018. Т. 22. № 6. С. 59–64.</mixed-citation><mixed-citation xml:lang="en">Sizov V.A. The use of business games in the preparation of masters program “Protection of the information space of subjects of economic activity”. Otkrytoye obrazovaniye = Open Education. 2018; 22 (6): 59-64. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">Замула А.А., Одарченко А.С., Дейнеко А.А. Методы оценивания и управления информационными рисками // Прикладная радиоэлектроника. 2015. № 3. С. 182–187.</mixed-citation><mixed-citation xml:lang="en">Zamula A.A., Odarchenko A.S., Dey-neko A.A. Methods of evaluation and information risk management. Prikladnaya radioelektronika = Applied Radio Electronics. 2015 (3): 182-187. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">Зарипова А. И., Коваленко С.В. Финансовые риски при обеспечении экономической безопасности предприятий [Электрон. ресурс] // Молодой ученый. 2018. № 1. С. 61–63. URL: https://moluch.ru/archive/187/47652/ (дата обращения: 16.05.2019)</mixed-citation><mixed-citation xml:lang="en">Zaripova A. I., Kovalenko: V. Financial Risks in Ensuring the Economic Security of Enterprises [Internet]. Molodoy uchenyy = Young scientist. 2018; 1: 61-63. URL: https://moluch.ru/archive/187/47652/ (Cited: 16.05.2019). (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit15"><label>15</label><citation-alternatives><mixed-citation xml:lang="ru">Р 50.1.028-2001. Методология функционального моделирования. Рекомендации по стандартизации. Приняты и введены в действие Постановлением Госстандарта России от 02.07.2001 № 256 ст.</mixed-citation><mixed-citation xml:lang="en">R 50.1.028-2001. Methodology of functional modeling. Recommendations for standardization. Adopted and put into effect by the Resolution of the State Standard of Russia of July 2; 2001 No. 256, Art. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit16"><label>16</label><citation-alternatives><mixed-citation xml:lang="ru">Гаврилов А.В. Методика выбора CASE- средств структурного проектирования для обучения по направлению подготовки «Прикладная информатика» // (ИП&amp;УЗ-2015): сборник научных трудов XVIII научно-практической конференции (21–24 апреля 2015 г., Москва) Под науч. ред. Ю. Ф. Тельнова. М.: Московский государственный университет экономики, статистики и информатики (МЭСИ), 2015. С. 230–241.</mixed-citation><mixed-citation xml:lang="en">Gavrilov A.V. Methods of selecting CASE-tools of structural design for training in the direction of training “Applied Informatics”. (IP&amp;UZ-2015): sbornik nauchnykh trudov XVIII nauchno-prakticheskoy konferentsii = (IP &amp; UZ- 2015): collection of scientific papers of the XVIII scientific-practical conference (April 21-24, 2015, Moscow) Ed. Yu. F. Telnov. Moscow: Moscow State University of Economics, Statistics and Informatics (MESI); 2015: 230-241. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit17"><label>17</label><citation-alternatives><mixed-citation xml:lang="ru">Гаврилов А.В. Анализ функциональных возможностей бесплатных CASE-средств проектирования баз данных // Открытое образование. 2016. Т. 20. № 4. С. 39–43.</mixed-citation><mixed-citation xml:lang="en">Gavrilov A.V. Analysis of the functionality of free CASE-database design tools. Otkrytoye obrazovaniye = Open Education. 2016; 20 (4): 39- 43. (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit18"><label>18</label><citation-alternatives><mixed-citation xml:lang="ru">Пример функциональной модели (IDEF0) промышленного предприятия в Business Studio. [Электрон. ресурс] URL: http://www.businessstudio.ru/publication/proizv_predpr_abc/businessmodel. php?lang=ru-ru (дата обращения 02.02.2019).</mixed-citation><mixed-citation xml:lang="en">An example of a functional model (IDEF0) of an industrial enterprise in Business Studio. [Internet] URL: http://www.businessstudio.ru/publication/proizv_predpr_abc/businessmodel. php?lang=ru-ru (Cited 02.02.2019). (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit19"><label>19</label><citation-alternatives><mixed-citation xml:lang="ru">Пример функциональной модели компании, осуществляющей деятельность по проектированию, монтажу и обслуживанию инженерно-технических систем. [Электрон. ресурс] URL http://publication.businessstudio.ru/businessmodel.php?lang=ru-ru&amp;oguid=2be70b1c-a108-4228-b272-1c9eefbc464e (дата обращения 02.02.2019).</mixed-citation><mixed-citation xml:lang="en">An example of a functional model of a company engaged in the design, installation and maintenance of engineering systems. [Internet] URL http://publication.businessstudio.ru/businessmodel.php?lang=ru-ru&amp;oguid=2be70b1c-a108-4228-b272-1c9eefbc464e (Cited 02.02.2019). (In Russ.)</mixed-citation></citation-alternatives></ref><ref id="cit20"><label>20</label><citation-alternatives><mixed-citation xml:lang="ru">Федеральный государственный образовательный стандарт высшего образования по направлению подготовки 10.04.01 Информационная безопасность (уровень магистратуры). Утвержден приказом Министерства образования и науки Российской Федерации от 01.12.2016 г. № 1513.</mixed-citation><mixed-citation xml:lang="en">Federal State Educational Standard of Higher Education in the field of preparation 10.04.01 Information security (master’s level). Approved by order of the Ministry of Education and Science of the Russian Federation of 01.12.2016, № 1513. (In Russ.)</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
