<?xml version="1.0" encoding="UTF-8"?>
<article xml:lang="ru" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="1.1">
<front>
<journal-meta>
<journal-title-group>
<journal-title xml:lang="ru">Правовая информатика</journal-title>
<trans-title-group xml:lang="en">
<trans-title>Legal Informatics</trans-title>
</trans-title-group>
</journal-title-group>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.24412/1994-1404-2026-1-00-02</article-id>
<title-group>
<article-title xml:lang="ru">ИНДЕКС ПАРЕТО КАК КРИТЕРИЙ АДАПТИВНОГО БЮДЖЕТИРОВАНИЯ ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ</article-title>
<trans-title-group xml:lang="en">
<trans-title>PARETO INDEX AS A CRITERION FOR ADAPTIVE BUDGETING OF INFORMATION SECURITY </trans-title>
</trans-title-group>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name-alternatives>
<name xml:lang="ru">
<surname>Мандрица</surname>
<given-names>Игорь Владимирович</given-names>
</name>
<name xml:lang="en">
<surname>Mandritsa</surname>
<given-names>Igor V.</given-names>
</name>
</name-alternatives>
<email>d_artman@mail.ru</email>
<xref ref-type="aff" rid="lbrr-1"/>
</contrib>
<aff-alternatives id="lbrr-1">
<aff>
<institution xml:lang="ru">Северо-Кавказский федеральный университет</institution>
<city xml:lang="ru">Ставрополь</city>
<country xml:lang="ru">Российская Федерация</country>
</aff>
<aff>
<institution xml:lang="en">North Caucasus Federal University</institution>
<city xml:lang="en">Stavropol</city>
<country xml:lang="en">Russian Federation</country>
</aff>
</aff-alternatives>
<contrib contrib-type="author">
<name-alternatives>
<name xml:lang="ru">
<surname>Антонов</surname>
<given-names>Владислав Васильевич</given-names>
</name>
<name xml:lang="en">
<surname>Antonov</surname>
<given-names>Vladislav V.</given-names>
</name>
</name-alternatives>
<email>antonov_vlad@mail.ru</email>
<xref ref-type="aff" rid="lbrr-2"/>
</contrib>
<aff-alternatives id="lbrr-2">
<aff>
<institution xml:lang="ru">Северо-Кавказский федеральный университет</institution>
<city xml:lang="ru">Ставрополь</city>
<country xml:lang="ru">Российская Федерация</country>
</aff>
<aff>
<institution xml:lang="en">North Caucasus Federal University</institution>
<city xml:lang="en">Stavropol</city>
<country xml:lang="en">Russian Federation</country>
</aff>
</aff-alternatives>
<contrib contrib-type="author">
<name-alternatives>
<name xml:lang="ru">
<surname>Мандрица</surname>
<given-names>Ольга Владимировна</given-names>
</name>
<name xml:lang="en">
<surname>Mandritsa</surname>
<given-names>Olga V.</given-names>
</name>
</name-alternatives>
<email>man_olga@mail.ru</email>
<xref ref-type="aff" rid="lbrr-3"/>
</contrib>
<aff-alternatives id="lbrr-3">
<aff>
<institution xml:lang="ru">Ставропольский филиал РТУ МИРЭА</institution>
<city xml:lang="ru">Ставрополь</city>
<country xml:lang="ru">Российская Федерация</country>
</aff>
<aff>
<institution xml:lang="en">Stavropol Branch of the Russian Technological University — MIREA</institution>
<city xml:lang="en">Stavropol</city>
<country xml:lang="en">Russian Federation</country>
</aff>
</aff-alternatives>
<contrib contrib-type="author">
<name-alternatives>
<name xml:lang="ru">
<surname>Бугаева</surname>
<given-names>Анна Валерьевна</given-names>
</name>
<name xml:lang="en">
<surname>Bugaeva</surname>
<given-names>Anna V.</given-names>
</name>
</name-alternatives>
<email>a.bugaeva55@gmail.com</email>
<xref ref-type="aff" rid="lbrr-4"/>
</contrib>
<aff-alternatives id="lbrr-4">
<aff>
<institution xml:lang="ru">Северо-Кавказский федеральный университет</institution>
<city xml:lang="ru">Ставрополь</city>
<country xml:lang="ru">Российская Федерация</country>
</aff>
<aff>
<institution xml:lang="en">North Caucasus Federal University</institution>
<city xml:lang="en">Stavropol</city>
<country xml:lang="en">Russian Federation</country>
</aff>
</aff-alternatives>
</contrib-group>
<self-uri xlink:href="http://uzulo.su/prav-inf/pdf-jpg/pi-2026-1-st02-s016-030.pdf">http://uzulo.su/prav-inf/pdf-jpg/pi-2026-1-st02-s016-030.pdf</self-uri>
<kwd-group xml:lang="ru">
<kwd>ядро Парето</kwd>
<kwd>кластеризация угроз</kwd>
<kwd>токсичность угроз</kwd>
<kwd>методология бюджетирования затрат на защиту информации</kwd>
<kwd>адаптивное управление рисками</kwd>
<kwd>киберландшафт</kwd>
<kwd>перераспределение финансовых ресурсов</kwd>
<kwd>математическая модель</kwd>
</kwd-group>
<kwd-group xml:lang="en">
<kwd>Pareto core</kwd>
<kwd>threat clustering</kwd>
<kwd>threat toxicity</kwd>
<kwd>methodology for budgeting expenditures on information security</kwd>
<kwd>adaptive risk management</kwd>
<kwd>cyber landscape</kwd>
<kwd>redistribution of financial resources</kwd>
<kwd>mathematical model</kwd>
</kwd-group>
<abstract xml:lang="ru">
<p>Цель работы состоит в разработке адаптивной методологии бюджетирования затрат на защиту информации на основе индекса Парето — формализованного критерия, определяющего порог экономической эффективности расходов (затрат) на защиту информации субъекта от информационных угроз, а также подтвердить гипотезу оптимальности индекса Парето как порогового значения адаптивного перераспределения финансовых ресурсов субъекта между динамическим поведением (изменением) массовых и катастрофических типов угроз.</p><p>Метод исследования заключается в разработке метрики токсичности угроз (TDI) и метода кластеризации для выявления текущего ядра Парето для возможных мер защиты информации субъекта, построении математической модели дрейфа ядра Парето и определении условий для возникновения «точки перегиба» Парето-индекса на остаточной кривой риска в рамках 16-факторной модели угроз субъекта.</p><p>Результаты исследования: предложена концепция индекса Парето как динамического ориентира для оптимизации бюджетов на информационную безопасность организаций. На основе кластерного анализа 227 угроз из базы данных ФСТЭК с использованием критериев токсичности показано, что ядро Парето (набор угроз, доминирующих в риске) смещается по мере изменения уровня защиты субъекта защиты, что требует адаптивного перераспределения бюджетных ресурсов.</p><p>Разработана формализованная методология определения «точки перегиба» бюджета информационной безопасности — порог, за пределами которого предельные затраты на защиту от массовых угроз превышают предельные выгоды от снижения рисков. Индекс Парето показан как квантильная характеристика распределения токсичности угрозы и может служить экономически обоснованным критерием для принятия решений о распределении бюджета между защитой от массовых (Opportunistic) и катастрофических (Apex Predator) угроз.</p><p>Создана математическая основа для оптимизации (адаптации) бюджетирования информационной безопасности, учитывающей динамику киберландшафта для социо-экономической среды субъекта.</p>
</abstract>
<trans-abstract xml:lang="en">
<p>Purpose of work: The aim of this study is to develop an adaptive methodology for budgeting information security costs based on the Pareto index – a formalised criterion that determines the threshold of economic efficiency of expenditures on protecting an entity’s information from information threats. The work also seeks to validate the hypothesis of the Pareto index’s optimality as a threshold value for the adaptive redistribution of an entity’s financial resources in response to the dynamic behaviour (changes) of mass and catastrophic threat types.</p><p>Research method of the work is to develop an adaptive methodology for budgeting the costs of information protection, based on the Pareto index – a formalized criterion that determines the threshold of economic efficiency of expenses (costs) for the protection of the subject’s information from information threats, as well as to confirm the hypothesis of the optimality of the Pareto index as a threshold value of the adaptive redistribution of the subject’s financial resources between dynamic behavior (change) of mass and catastrophic types of threats.</p><p>The results of the study: The concept of the Pareto Index is proposed as a dynamic benchmark for optimising information security budgets across organisational entities. Based on a cluster analysis of 227 threat vectors from the FSTEC Bank of Threats database, using threat toxicity criteria, it has been demonstrated that the Pareto core (the set of threats dominating the risk profile) shifts as the protection posture of the defended entity changes, necessitating an adaptive redistribution of budgetary resources.</p><p>A formalised methodology has been developed to determine the inflection point of the information security budget – a critical threshold beyond which the marginal cost of protection against opportunistic threats exceeds the marginal benefit derived from risk mitigation. The Pareto index is presented as a quantile characteristic of the threat toxicity distribution and can serve as an economically justified criterion for decision-making on budget allocation between protection against opportunistic and catastrophic (Apex Predator) threats.</p><p>A mathematical framework has been established for optimising (adapting) information security budgeting strategies, explicitly accounting for the dynamics of the cyber threat landscape within the socio-economic context of the organisational entity.</p>
</trans-abstract>
</article-meta>
</front>
<back>
<ref-list>
<ref id="rfr-1">
<label>1.</label>
<citation-alternatives>
<mixed-citation>Hubbard DW, Seiersen R. How to measure anything in cybersecurity risk. 2nd ed. Hoboken (NJ): Wiley; 2023. DOI: 10.1002/9781119892335.</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-2">
<label>2.</label>
<citation-alternatives>
<mixed-citation>Frey R.S., Fichtner J. Cyber risk, market failures, and the role of insurance // The Geneva Papers on Risk and Insurance – Issues and Practice. 2020. Vol. 45. No. 4. P. 529–558. DOI: 10.1057/s41288-020-00188-1.</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-3">
<label>3.</label>
<citation-alternatives>
<mixed-citation>Taleb N.N. Statistical Consequences of Fat Tails: Real World Preasymptotics, Epistemology, and Applications (The Technical Incerto Collection) // STEM Academic Press. 2020. P. 51. ISBN 978-1-5445-0805-4. URL: https://www.ssmrmh.ro/wp-content/uploads/2020/09/STATISTICAL-CONSEQUENCES-OF-FAT-TAILS_compressed-1-51-PART-1.pdf</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-4">
<label>4.</label>
<citation-alternatives>
<mixed-citation>Anderson R, Barton C, Bohme R, Clayton R, van Eeten M, Levi M, et al. Measuring the changing cost of cybercrime. J Cybersecur. 2019;5(1):tyz009. DOI: 10.1093/cybsec/tyz009. URL: https://academic.oup.com/cybersecurity/article/5/1/tyz009/5554879</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-5">
<label>5.</label>
<citation-alternatives>
<mixed-citation>Sinha K., Suh E.S. Pareto-optimization of complex system architecture for structural complexity and modularity // Research in Engineering Design (Res Eng Des). 2018. Vol. 29, № 1. P. 123–141. DOI: 10.1007/s00163-017-0260-9. URL: https://link.springer.com/article/10.1007/s00163-017-0260-9</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-6">
<label>6.</label>
<citation-alternatives>
<mixed-citation>Linkov I, Trump BD. The science and practice of resilience. Cham: Springer; 2019. DOI: 10.1007/978-3-030-04563-0. ISBN: 978-3-030-04562-3.</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-7">
<label>7.</label>
<citation-alternatives>
<mixed-citation>Cartwright E, Hernandez Castro J, Cartwright A. To pay or not: game theoretic models of ransomware. J Cybersecur. 2019. 5(1):tyz009. DOI: 10.1093/cybersecurity/tyz009. URL: https://academic.oup.com/cybersecurity/article/5/1/tyz009/5554879</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-8">
<label>8.</label>
<citation-alternatives>
<mixed-citation>Brundage M., Avin S., Wang J., Belfield H., Krueger G., Hadfield G. et al. Toward trustworthy AI development: mechanisms for supporting verifiable claims // Science. 2023. Vol. 379. No. 6636. P. eadf3225. DOI: 10.1126/science.adf3225.</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-9">
<label>9.</label>
<citation-alternatives>
<mixed-citation>Gordon LA, Loeb MP, Zhou L. Information segmentation and investing in cybersecurity. J Inf Security. 2021;12:115–36. DOI: 10.4236/jis.2021.122006.</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-10">
<label>10.</label>
<citation-alternatives>
<mixed-citation>Fedotenkov I. A review of more than one hundred Pareto-tail index estimators // Statistica. 2020. Vol. 80, № 3. P. 245–299. DOI: 10.6092/issn.1973-2201/10852.</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-11">
<label>11.</label>
<citation-alternatives>
<mixed-citation>Dutton WH, Creese S, Shillair R, Bada M. Cybersecurity capacity: Does it matter? J Inf Policy. 2019;9:280–306. DOI: 10.5325/jinfopoli.9.2019.0280. URL: https://scholarlypublishingcollective.org/psup/information-policy/article-abstract/doi/10.5325/jinfopoli.9.2019.0280/314505.</mixed-citation>
</citation-alternatives>
</ref>
<ref id="rfr-12">
<label>12.</label>
<citation-alternatives>
<mixed-citation>International Organization for Standardization. ISO/IEC 27005:2022 Information security risk management – guidelines. Geneva: ISO; 2022.</mixed-citation>
</citation-alternatives>
</ref>
</ref-list>
</back>
</article>
