Правовая информатика ♦ Legal Informatics
выпуск № 2 за 2026 г., статья № 5 ♦ issue #2 of 2026, article #5
Метод: с использованием системного подхода объект защиты исследован как совокупность взаимосвязанных компонентов и их связей с внешней средой, формирующей новые угрозы безопасности информационным ресурсам. Изменение содержания объекта защиты продемонстрировано методом анализа нормативных правовых актов и стандартов, а также сравнительно-правового исследования нормативных требований государственного регулятора.
Результат: автором выделены особенности генезиса объекта защиты в современных условиях, раскрыто актуальное понимание объекта защиты в информационной инфраструктуре, выявлена тенденция усложнения и конкретизации объекта защиты, а также ориентация требований государственного регулятора на выделение из широкого спектра потенциальных опасностей наиболее значимых угроз информационной безопасности и угроз безопасности информации. С учетом опыта отражения компьютерных атак на российскую критическую и иную информационную инфраструктуру усилия операторов информационных систем сфокусированы ФСТЭК России на наиболее чувствительных объектах защиты. Установлено, что различные подходы к определению понятия «защита информации» расширяют сферу регулирования и конкретизируют границы идентификации угроз информационной безопасности, включая компьютерные инциденты. Введение новых требований к организации системы защиты информационных систем посредством уточнения объектов защиты способствует концентрации практических мер и мероприятий на противодействии актуальным угрозам информационной безопасности и безопасности информации.
ENG:
Purpose of work: the purpose of the article is to show that modern doctrinal approaches to determining the object of protection in the field of information security and the existing conflicts in the classification of relevant incidents (including computer attacks) necessitate the allocation of priority objects of technical information protection and the regulatory consolidation of their definitions, as well as criteria for classifying this category of objects of protection in the requirements of regulators. The work is aimed at identifying changes in the regulatory requirements for the object of protection to ensure the stability and security of information systems, data and infrastructure in the context of increased manufacturability and the number of computer attacks.
Research methods: using a systematic approach, the object of protection is studied as a set of interrelated components and their connections with the external environment, which forms new threats to the security of information resources. The change in the content of the object of protection is demonstrated by analyzing regulatory legal acts and standards, as well as comparative legal research of the regulatory requirements of the state regulator.
Results of the study: the author highlights the features of the genesis of the object of protection in modern conditions, reveals the current understanding of the object of protection in the information infrastructure, reveals the tendency to complicate and specify the object of protection, as well as the orientation of the requirements of the state regulator to identify the most significant threats to information security and information security from a wide range of potential hazards. Taking into account the experience of repelling computer attacks on Russian critical and other information infrastructure, the efforts of information system operators are focused by the FSTEC of Russia on the most sensitive protection facilities. It is established that different approaches to the definition of the concept of “information protection” expand the scope of regulation and specify the boundaries of identification of threats to information security, including computer incidents. The introduction of new requirements for the organization of the information system protection system by clarifying the objects of protection contributes to the concentration of practical measures and measures to counteract current threats to information security and information security.
Ф. И. О.
РУС: Метельков Александр Николаевич
ENG: Aleksandr N. Metelkov
Место работы
РУС: Санкт-Петербургский университет ГПС МЧС России
ENG: Saint-Petersburg University of State Fire Service of EMERCOM of Russia
Город, страна
РУС: Санкт-Петербург, Российская Федерация
ENG: Saint Petersburg, Russian Federation