Сценарно-орієнтований підхід до використання моделі C2M2 для оцінювання кібербезпеки об’єктів критичної інфраструктури електроенергетичного сектору України
Loading...
Date
DOI
item.page.thesis.degree.name
item.page.thesis.degree.level
item.page.thesis.degree.discipline
item.page.thesis.degree.department
item.page.thesis.degree.grantor
item.page.thesis.degree.advisor
item.page.thesis.degree.committeeMember
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
У роботі розглядається впровадження методики оцінювання кібербезпеки критичної інфраструктури електромереж на основі моделі зрілості C2M2 та структури NIST. Визначено обмеження C2M2, які зосереджуються на організаційних процесах без урахування сценаріїв загроз. Для подолання цих обмежень запропоновано інтеграцію з методикою MOSAR, яка забезпечує сценарно-орієнтований аналіз кіберфізичних атак. Описано інтегрований цикл оцінювання кіберстійкості та запропоновано використання матриці GE/McKinsey як спрощеної альтернативи. Визначено основні обмеження підходу та необхідність пілотного впровадження в енергетичному секторі.
This paper examines the implementation of a methodology for assessing the cybersecurity ofcritical electrical grid infrastructure based on the C2M2 maturity model and the NIST framework.The limitations of C2M2, which focus on organizational processes without considering threatscenarios, are identified. To overcome these limitations, integration with the MOSAR methodologyis proposed, which provides scenario-based analysis of cyber-physical attacks. An integrated cyclefor assessing cyber resilience is described, and the use of the GE/McKinsey matrix is proposed as asimplified alternative. The main constraints of the approach and the need for a pilot implementationin the energy sector are identified.
This paper examines the implementation of a methodology for assessing the cybersecurity ofcritical electrical grid infrastructure based on the C2M2 maturity model and the NIST framework.The limitations of C2M2, which focus on organizational processes without considering threatscenarios, are identified. To overcome these limitations, integration with the MOSAR methodologyis proposed, which provides scenario-based analysis of cyber-physical attacks. An integrated cyclefor assessing cyber resilience is described, and the use of the GE/McKinsey matrix is proposed as asimplified alternative. The main constraints of the approach and the need for a pilot implementationin the energy sector are identified.
Description
Keywords
кафедра інформаційних технологій, штучного інтелекту і кібербезпеки, C2M2, кібербезпека, критична інфраструктура, електроенергетичний сектор, сценарно-орієнтований підхід, оцінювання ризиків, гібридні загрози, управління кібербезпекою, cybersecurity, critical infrastructure, electric power sector, scenario-based approach, risk assessment, hybrid threats, cybersecurity management
Citation
Литвинов, В. А. Сценарно-орієнтований підхід до використання моделі C2M2 для оцінювання кібербезпеки об'єктів критичної інфраструктури електроенергетичного сектору України / В. А. Литвинов, С. В. Грибков, К. Ю. Чорнобай // Штучний інтелект та інформаційні технології (AIIT-2026) : наукові праці Третьої міжнародної науково-практичної конференції, 1–2 червня 2026 р., м. Київ. – Київ : НУХТ, 2026. – С. 234–237
