Правовая информатика ♦ Legal Informatics
выпуск № 1 за 2026 г., статья № 2 ♦ issue #1 of 2026, article #2


 Название ♥ Title • DOI • .pdf  Авторы ♥ Authors 

 Ключевые слова ♥ Keywords  Аннотация ♥ Abstract  Сведения об авторах ♥ Info on the authors 

 Список источников 

 Правообладатель, лицензия  Метаданные: открытая лицензия 

 XML-описание элементов статьи ♥ XML description of elements of the paper 


Название ♦ Title  ↑ (наверх) ↑ 

Рус: ИНДЕКС ПАРЕТО КАК КРИТЕРИЙ АДАПТИВНОГО БЮДЖЕТИРОВАНИЯ ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ
Eng: PARETO INDEX AS A CRITERION FOR ADAPTIVE BUDGETING OF INFORMATION SECURITY

DOI: 10.24412/1994-1404-2026-1-00-02

 Гиперссылка на полнотекстовую версию статьи (.pdf) 


Авторы ♦ Authors  ↑ (наверх) ↑ 

РУС: Мандрица И. В., Антонов В. В., Мандрица О. В., Бугаева А. В.
ENG: Igor V. Mandritsa, Vladislav V. Antonov, Olga V. Mandritsa, Anna V. Bugaeva


Ключевые слова ♦ Keywords  ↑ (наверх) ↑ 

РУС: ядро Парето, кластеризация угроз, токсичность угроз, методология бюджетирования затрат на защиту информации, адаптивное управление рисками, киберландшафт, перераспределение финансовых ресурсов, математическая модель
ENG: Pareto core, threat clustering, threat toxicity, methodology for budgeting expenditures on information security, adaptive risk management, cyber landscape, redistribution of financial resources, mathematical model


Аннотация ♦ Abstract  ↑ (наверх) ↑ 

РУС:
Цель работы состоит в разработке адаптивной методологии бюджетирования затрат на защиту информации на основе индекса Парето — формализованного критерия, определяющего порог экономической эффективности расходов (затрат) на защиту информации субъекта от информационных угроз, а также подтвердить гипотезу оптимальности индекса Парето как порогового значения адаптивного перераспределения финансовых ресурсов субъекта между динамическим поведением (изменением) массовых и катастрофических типов угроз.

Метод исследования заключается в разработке метрики токсичности угроз (TDI) и метода кластеризации для выявления текущего ядра Парето для возможных мер защиты информации субъекта, построении математической модели дрейфа ядра Парето и определении условий для возникновения «точки перегиба» Парето-индекса на остаточной кривой риска в рамках 16-факторной модели угроз субъекта.

Результаты исследования: предложена концепция индекса Парето как динамического ориентира для оптимизации бюджетов на информационную безопасность организаций. На основе кластерного анализа 227 угроз из базы данных ФСТЭК с использованием критериев токсичности показано, что ядро Парето (набор угроз, доминирующих в риске) смещается по мере изменения уровня защиты субъекта защиты, что требует адаптивного перераспределения бюджетных ресурсов.

Разработана формализованная методология определения «точки перегиба» бюджета информационной безопасности — порог, за пределами которого предельные затраты на защиту от массовых угроз превышают предельные выгоды от снижения рисков. Индекс Парето показан как квантильная характеристика распределения токсичности угрозы и может служить экономически обоснованным критерием для принятия решений о распределении бюджета между защитой от массовых (Opportunistic) и катастрофических (Apex Predator) угроз.

Создана математическая основа для оптимизации (адаптации) бюджетирования информационной безопасности, учитывающей динамику киберландшафта для социо-экономической среды субъекта.

ENG:
Purpose of work: The aim of this study is to develop an adaptive methodology for budgeting information security costs based on the Pareto index – a formalised criterion that determines the threshold of economic efficiency of expenditures on protecting an entity’s information from information threats. The work also seeks to validate the hypothesis of the Pareto index’s optimality as a threshold value for the adaptive redistribution of an entity’s financial resources in response to the dynamic behaviour (changes) of mass and catastrophic threat types.

Research method of the work is to develop an adaptive methodology for budgeting the costs of information protection, based on the Pareto index – a formalized criterion that determines the threshold of economic efficiency of expenses (costs) for the protection of the subject’s information from information threats, as well as to confirm the hypothesis of the optimality of the Pareto index as a threshold value of the adaptive redistribution of the subject’s financial resources between dynamic behavior (change) of mass and catastrophic types of threats.

The results of the study: The concept of the Pareto Index is proposed as a dynamic benchmark for optimising information security budgets across organisational entities. Based on a cluster analysis of 227 threat vectors from the FSTEC Bank of Threats database, using threat toxicity criteria, it has been demonstrated that the Pareto core (the set of threats dominating the risk profile) shifts as the protection posture of the defended entity changes, necessitating an adaptive redistribution of budgetary resources.

A formalised methodology has been developed to determine the inflection point of the information security budget – a critical threshold beyond which the marginal cost of protection against opportunistic threats exceeds the marginal benefit derived from risk mitigation. The Pareto index is presented as a quantile characteristic of the threat toxicity distribution and can serve as an economically justified criterion for decision-making on budget allocation between protection against opportunistic and catastrophic (Apex Predator) threats.

A mathematical framework has been established for optimising (adapting) information security budgeting strategies, explicitly accounting for the dynamics of the cyber threat landscape within the socio-economic context of the organisational entity.


Сведения об авторах ♦ Information on the authors  ↑ (наверх) ↑ 

Ф. И. О.
РУС:
Мандрица Игорь Владимирович
ENG: Igor V. Mandritsa
Место работы
РУС:
Северо-Кавказский федеральный университет
ENG: North Caucasus Federal University
Город, страна
РУС:
Ставрополь, Российская Федерация
ENG: Stavropol, Russian Federation

Ф. И. О.
РУС:
Антонов Владислав Васильевич
ENG: Vladislav V. Antonov
Место работы
РУС:
Северо-Кавказский федеральный университет
ENG: North Caucasus Federal University
Город, страна
РУС:
Ставрополь, Российская Федерация
ENG: Stavropol, Russian Federation

Ф. И. О.
РУС:
Мандрица Ольга Владимировна
ENG: Olga V. Mandritsa
Место работы
РУС:
Ставропольский филиал РТУ МИРЭА
ENG: Stavropol Branch of the Russian Technological University — MIREA
Город, страна
РУС:
Ставрополь, Российская Федерация
ENG: Stavropol, Russian Federation

Ф. И. О.
РУС:
Бугаева Анна Валерьевна
ENG: Anna V. Bugaeva
Место работы
РУС:
Северо-Кавказский федеральный университет
ENG: North Caucasus Federal University
Город, страна
РУС:
Ставрополь, Российская Федерация
ENG: Stavropol, Russian Federation


Список источников  ↑ (наверх) ↑ 

  1. Hubbard DW, Seiersen R. How to measure anything in cybersecurity risk. 2nd ed. Hoboken (NJ): Wiley; 2023. DOI: 10.1002/9781119892335.
  2. Frey R.S., Fichtner J. Cyber risk, market failures, and the role of insurance // The Geneva Papers on Risk and Insurance – Issues and Practice. 2020. Vol. 45. No. 4. P. 529–558. DOI: 10.1057/s41288-020-00188-1.
  3. Taleb N.N. Statistical Consequences of Fat Tails: Real World Preasymptotics, Epistemology, and Applications (The Technical Incerto Collection) // STEM Academic Press. 2020. P. 51. ISBN 978-1-5445-0805-4. URL: https://www.ssmrmh.ro/wp-content/uploads/2020/09/STATISTICAL-CONSEQUENCES-OF-FAT-TAILS_compressed-1-51-PART-1.pdf
  4. Anderson R, Barton C, Bohme R, Clayton R, van Eeten M, Levi M, et al. Measuring the changing cost of cybercrime. J Cybersecur. 2019;5(1):tyz009. DOI: 10.1093/cybsec/tyz009. URL: https://academic.oup.com/cybersecurity/article/5/1/tyz009/5554879
  5. Sinha K., Suh E.S. Pareto-optimization of complex system architecture for structural complexity and modularity // Research in Engineering Design (Res Eng Des). 2018. Vol. 29, № 1. P. 123–141. DOI: 10.1007/s00163-017-0260-9. URL: https://link.springer.com/article/10.1007/s00163-017-0260-9
  6. Linkov I, Trump BD. The science and practice of resilience. Cham: Springer; 2019. DOI: 10.1007/978-3-030-04563-0. ISBN: 978-3-030-04562-3.
  7. Cartwright E, Hernandez Castro J, Cartwright A. To pay or not: game theoretic models of ransomware. J Cybersecur. 2019. 5(1):tyz009. DOI: 10.1093/cybersecurity/tyz009. URL: https://academic.oup.com/cybersecurity/article/5/1/tyz009/5554879
  8. Brundage M., Avin S., Wang J., Belfield H., Krueger G., Hadfield G. et al. Toward trustworthy AI development: mechanisms for supporting verifiable claims // Science. 2023. Vol. 379. No. 6636. P. eadf3225. DOI: 10.1126/science.adf3225.
  9. Gordon LA, Loeb MP, Zhou L. Information segmentation and investing in cybersecurity. J Inf Security. 2021;12:115–36. DOI: 10.4236/jis.2021.122006.
  10. Fedotenkov I. A review of more than one hundred Pareto-tail index estimators // Statistica. 2020. Vol. 80, № 3. P. 245–299. DOI: 10.6092/issn.1973-2201/10852.
  11. Dutton WH, Creese S, Shillair R, Bada M. Cybersecurity capacity: Does it matter? J Inf Policy. 2019;9:280–306. DOI: 10.5325/jinfopoli.9.2019.0280. URL: https://scholarlypublishingcollective.org/psup/information-policy/article-abstract/doi/10.5325/jinfopoli.9.2019.0280/314505.
  12. International Organization for Standardization. ISO/IEC 27005:2022 Information security risk management – guidelines. Geneva: ISO; 2022.


Правообладатель и лицензия на использование  ↑ (наверх) ↑ 

Использование статьи осуществляется на условиях простой (неисключительной) лицензии CC BY-NC, с обязательным указанием авторства и источника публикации, исключительно в некоммерческих целях.


Открытая лицензия на использование метаданных  ↑ (наверх) ↑ 

Использование метаданных статьи осуществляется на условиях открытой лицензии CC0.