<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">2</article-id>
      <article-id pub-id-type="doi">10.48612/jisp/mp7a-vpp7-xu6f</article-id>
      <title-group>
        <article-title>Determining the optimal response time to information security threats in a limited resource environment</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Выбор подхода для расчета оптимального времени выявления и реагирования на угрозы информационной безопасности в условиях ограниченных ресурсов</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0004-4143-7302</contrib-id>
          <name>
            <surname>Sintsov</surname>
            <given-names>Mikhail</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>sinzovmi@gmail.com</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">National University of Oil and Gas «Gubkin University»</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2025-12-26">
        <day>26</day>
        <month>12</month>
        <year>2025</year>
      </pub-date>
      <issue>4</issue>
      <fpage>23</fpage>
      <lpage>34</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/pib_4.pdf"/>
      <abstract xml:lang="en">
        <p>In research proposed an approach in which the total time of detection, analysis and response to the actions of an attacker does not tend to a minimum value, but is within such limits, in which the possibility of active counteraction to the attacker remains, not allowing him to cause unacceptable damage, which allows to maintain the necessary and sufficient level of information security of the organization with limited resources. Calculated the average time spent by a SOC expert on the analysis of a suspicion of an incident, in which the quality of this analysis allows engineers to take effective actions to contain the attacker. Options for reducing this indicator are considered in view of the need to process all incoming incident suspicions in a high-quality manner in conditions of limited resources. As part of the proposed approach testing, the calculation of the optimal total time of detection, analysis and response for two types of incident suspicions is carried out.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Information security</kwd>
        <kwd>retrospective search</kwd>
        <kwd>acceptable level of damage</kwd>
        <kwd>median time of an attacker’s presence in the IT infrastructure</kwd>
        <kwd>response to information security threats</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
