<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="ru">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">2</article-id>
      <title-group>
        <article-title>The method for selecting technical implementation of incident response measures</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Метод выбора технической реализации мер реагирования на инциденты</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0002-7160-1845</contrib-id>
          <name>
            <surname>Kuznetsov</surname>
            <given-names>Aleksandr</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>1283_my@mail.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">RTK IB LLC; Financial University under the Government of the Russian Federation</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-06-09">
        <day>09</day>
        <month>06</month>
        <year>2026</year>
      </pub-date>
      <issue>2</issue>
      <fpage>22</fpage>
      <lpage>29</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/pib_2.pdf"/>
      <abstract xml:lang="en">
        <p>Considering the increasing importance of timely response to information security incidents, the method for selecting technical implementation of information security incident response measures without the involvement of a response team is proposed. The method considers specified constraints on provided mandates and the coverage of response tools. Unlike known methods, this method considers the selection problem as an integer (boolean) linear programming problem. The terms of the objective function are logical variables for the information security incident localization that included into response plans. Thereby minimizing the time spent for information security incident localization.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Response tool</kwd>
        <kwd>response team</kwd>
        <kwd>incident (containment) localization</kwd>
        <kwd>automated response</kwd>
        <kwd>action mandate</kwd>
        <kwd>response plan</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
