<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">1</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/5hvf-zvdp-akn4</article-id>
      <title-group>
        <article-title>Method of providing and conducting internal audit of information security of organisations on the basis of risk-oriented approach</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Метод обеспечения и проведения внутреннего аудита информационной безопасности организаций на основе риск-ориентированного подхода</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Glibovsky</surname>
            <given-names>Pavel</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>vka@mil.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Timashov</surname>
            <given-names>Pavel</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>vka@mil.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <name>
            <surname>Chernyshov</surname>
            <given-names>Vladimir</given-names>
          </name>
          <xref ref-type="aff" rid="aff2"/>
        </contrib>
      </contrib-group>
      <aff id="aff1">Mozhaisky Military Aerospace Academy</aff>
      <aff id="aff2">Military Academy of the General Staff of the Armed Forces of the Russian Federation</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2023-09-29">
        <day>29</day>
        <month>09</month>
        <year>2023</year>
      </pub-date>
      <issue>3</issue>
      <fpage>9</fpage>
      <lpage>24</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2023_3-5-6.pdf"/>
      <abstract xml:lang="en">
        <p>In order to guarantee effective information security of an organization, a systematic and comprehensive approach is necessary. One of the most effective tools for obtaining an independent and objective assessment of organizations’ security against information security risks and threats and evaluating the level of organization IS provision is the internal information security audit. Nowadays, more and more additional requirements are imposed to the methods of ensuring and conducting IS audit. Having analyzed the scientific literature, training manuals and articles in the field of information security, a method based on the risk-oriented approach is developed. The risk management theory and the internal audit methodology built on its basis should become the tools for conducting the audit. Information security audit based on the risk-oriented approach will make it possible to assess the security of the organization, identify risks, create and (or) adjust the plan of measures to minimize them, improve the interaction of departments responsible for control and risk management</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>information security audit</kwd>
        <kwd>risk-oriented approach</kwd>
        <kwd>risk matrix</kwd>
        <kwd>information security threats</kwd>
        <kwd>security level</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
