Development of a module for information security incident collection and visualization software complex
Jazyk: | ruština |
---|---|
Rok vydání: | 2023 |
Předmět: | |
DOI: | 10.18720/spbpu/3/2023/vr/vr23-1168 |
Popis: | ЦелÑÑ Ð´Ð°Ð½Ð½Ð¾Ð¹ вÑпÑÑкной квалиÑикаÑионной ÑабоÑÑ ÑвлÑеÑÑÑ ÑазÑабоÑка комплекÑной ÑиÑÑÐµÐ¼Ñ Ð·Ð°ÑиÑÑ Ð¸Ð½ÑоÑмаÑии пÑедпÑиÑÑиÑ.ÐÑновнÑе полÑÑеннÑе ÑезÑлÑÑаÑÑ:ÐбоÑнована Ð½ÐµÐ¾Ð±Ñ Ð¾Ð´Ð¸Ð¼Ð¾ÑÑÑ ÑÐ¾Ð·Ð´Ð°Ð½Ð¸Ñ ÐºÐ¾Ð¼Ð¿Ð»ÐµÐºÑной ÑиÑÑÐµÐ¼Ñ Ð·Ð°ÑиÑÑ Ð¸Ð½ÑоÑмаÑии пÑедпÑиÑÑиÑ;РазÑабоÑано ÑÐµÑ Ð½Ð¸ÑеÑкое задание на Ñоздание комплекÑной ÑиÑÑÐµÐ¼Ñ Ð·Ð°ÑиÑÑ Ð¸Ð½ÑоÑмаÑии пÑедпÑиÑÑиÑ;РазÑабоÑан ÑÑкизнÑй пÑÐ¾ÐµÐºÑ ÐºÐ¾Ð¼Ð¿Ð»ÐµÐºÑной ÑиÑÑÐµÐ¼Ñ Ð·Ð°ÑиÑÑ Ð¸Ð½ÑоÑмаÑии пÑедпÑиÑÑиÑ;РазÑабоÑан ÑÐµÑ Ð½Ð¸ÑеÑкий пÑÐ¾ÐµÐºÑ ÐºÐ¾Ð¼Ð¿Ð»ÐµÐºÑной ÑиÑÑÐµÐ¼Ñ Ð·Ð°ÑиÑÑ Ð¸Ð½ÑоÑмаÑии пÑедпÑиÑÑиÑ, обоÑновано ÑеÑение по вÑбоÑÑ ÐºÐ¾Ð¼Ð¿Ð»ÐµÐºÑа ÑÐµÑ Ð½Ð¸ÑеÑÐºÐ¸Ñ ÑÑедÑÑв и пÑиведено обоÑнование ÑооÑвеÑÑÑÐ²Ð¸Ñ Ñозданной ÑиÑÑÐµÐ¼Ñ ÑÑебованиÑм ÑÑководÑÑÐ¸Ñ Ð´Ð¾ÐºÑменÑов;РазÑабоÑан модÑÐ»Ñ Ð´Ð»Ñ Ð¿ÑогÑаммного комплекÑа по ÑбоÑÑ Ð¸ визÑализаÑии инÑиденÑов инÑоÑмаÑионной безопаÑноÑÑи.РкаÑеÑÑве ÑезÑлÑÑаÑа бÑла ÑазÑабоÑана Ð¼Ð¾Ð´ÐµÐ»Ñ Ð´Ð»Ñ ÑбоÑа и визÑализаÑии инÑиденÑов инÑоÑмаÑионной безопаÑноÑÑи. ÐÑновой Ð´Ð»Ñ ÑбоÑа инÑоÑмаÑии, ÑвлÑеÑÑÑ, модеÑнизиÑÐ¾Ð²Ð°Ð½Ð½Ð°Ñ ÐºÐ¾Ð¼Ð¿Ð»ÐµÐºÑÐ½Ð°Ñ ÑиÑÑема заÑиÑÑ Ð¸Ð½ÑоÑмаÑии пÑедпÑиÑÑиÑ. Так же бÑла знаÑиÑелÑно ÑлÑÑÑена заÑиÑа локалÑной вÑÑиÑлиÑелÑной ÑеÑи и оÑганизована полноÑÐµÐ½Ð½Ð°Ñ ÑабоÑа Ñ Ð¿ÐµÑÑоналÑнÑми даннÑми, обÑабаÑÑваемÑÑ Ð² инÑоÑмаÑионной ÑиÑÑеме пеÑÑоналÑнÑÑ Ð´Ð°Ð½Ð½ÑÑ . The purpose of this graduate qualification work is to develop a comprehensive enterprise information security system.The main results obtained:1.     The necessity of creating an integrated system of information protection of the enterprise;2.     The terms of reference for the creation of an integrated enterprise information security system was developed;3.     Draft design of an integrated enterprise information security system was developed;4.     Technical project of the enterprise's integrated information protection system is developed, the decision on the choice of a set of technical means is substantiated and compliance of the created system with the requirements of guideline documents is substantiated;5.     Module for software complex to collect and visualize information security incidents was developed.As a result, a model for the collection and visualization of information security incidents was developed. The basis for the collection of information is an upgraded comprehensive information security system of the enterprise. Also, the protection of the local area network was significantly improved and a full-fledged work with personal data processed in the information system of personal data was organized. |
Databáze: | OpenAIRE |
Externí odkaz: |