<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-id journal-id-type="elibrary">9004</journal-id>
      <journal-title-group>
        <journal-title>Problems of information security. Computer systems</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Проблемы информационной безопасности. Компьютерные системы</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2071-8217</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">8</article-id>
      <article-id pub-id-type="doi">10.66424/2071-8217-2026-1-8</article-id>
      <title-group>
        <article-title>The impact of the Shadow IT on data processing security in infrastructure of institutions: risks and solutions</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Влияние Shadow IT на безопасность обработки данных в инфраструктуре учреждений: риски и методы противодействия</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0000-0001-5518-5565</contrib-id>
          <name>
            <surname>Ponachugin</surname>
            <given-names>Alexander</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>sasha3@bk.ru</email>
        </contrib>
        <contrib contrib-type="author">
          <contrib-id contrib-id-type="orcid">0009-0002-3427-1514</contrib-id>
          <name>
            <surname>Andreeva</surname>
            <given-names>Arina</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
          <email>a.andreeva@naash.ru</email>
        </contrib>
      </contrib-group>
      <aff id="aff1">Minin Nizhny Novgorod State Pedagogical University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-03-30">
        <day>30</day>
        <month>03</month>
        <year>2026</year>
      </pub-date>
      <issue>1</issue>
      <fpage>109</fpage>
      <lpage>122</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://jisp.spbstu.ru/userfiles/files/soderzhaniya/2026_1_7-8.pdf"/>
      <abstract xml:lang="en">
        <p>The article presents an analysis of the factors contributing to the emergence of Shadow IT, an assessment of its impact on data security properties, and a set of formalized measures aimed at mitigating the associated risks in Internet-oriented information systems. The study employs a systems analysis of information systems, a comparative analysis of Shadow IT management approaches, information security threat analysis, generalization of practices in the application of technical and organizational security controls, and an analysis of the frequency of Shadow IT occurrence. As a result, architectural and organizational prerequisites for the proliferation of Shadow IT in distributed and cloud-based data processing environments are identified; the impact of unauthorized IT services on the confidentiality, integrity, and availability of information is analyzed; approaches to the detection and control of Shadow IT are examined; and a set of formalized measures is proposed, aimed at increasing transparency in the use of IT resources and improving the manageability of data processing processes. The conducted analysis and proposed measures are expected to reduce the level of uncontrolled information security risks and enhance the resilience of data processing in the long term.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>Shadow IT</kwd>
        <kwd>information security</kwd>
        <kwd>internet-oriented infrastructure</kwd>
        <kwd>data security</kwd>
        <kwd>access management</kwd>
      </kwd-group>
    </article-meta>
  </front>
</article>
