Сопоставление паттернов NIST cybersecurity framework и требований 31 приказа ФСТЭК: матрица соответствия и методика интеграции

Авторы:
Аннотация:

Предметом исследования выступают два наиболее значимых документа в сфере информационной безопасности: международный стандарт NIST Cybersecurity Framework версии 2.0 и российский нормативный акт — приказ ФСТЭК № 31. Предметом исследования являются концептуальные и структурные взаимосвязи между функциями NIST CSF и группами мер защиты информации, установленными 31 приказом. Методологическую основу составили сравнительный анализ оригинальных текстов документов, сопоставительные таблицы Positive Technologies, а также методология архитектурного проектирования TOGAF. В результате исследования разработана матрица соответствия, сопоставляющая 17 групп мер 31 приказа с шестью функциями ядра NIST CSF 2.0. Выявлено, что покрытие функций CSF мерами приказа варьируется от 40−60% для класса К3 до 95−100% для класса К1, при этом функция Govern не имеет прямого аналога в российском документе. Предложена методика гэп-анализа, позволяющая организациям выявлять недостающие меры защиты при интеграции двух подходов. Сформулированы практические рекомендации по приоритезации защитных мер на основе риск-ориентированного подхода. Результаты могут быть использованы при проектировании архитектуры информационной безопасности организаций, работающих с объектами критической информационной инфраструктуры и государственными информационными системами.

  • Список литературы

    ARPP Soft. N.d. A case study on implementing automated process control system protection at Severstal facilities. URL: https://arppsoft.ru/ (accessed: 13.02.2026).
    Australian Signals Directorate. 2024. Essential Eight Maturity Model. URL: https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight (accessed: 13.02.2026).
    Brock J., Brennig K., Lohr B., Bartelheimer C., von Enzberg S. 2024. Improving Process Mining Maturity — From Intentions to Actions. Business & Information Systems Engineering. DOI: 10.1007/s12599-024-00882-7.
    Center for Internet Security. 2024. CIS Controls Version 8.1. URL: https://www.cisecurity.org/controls (accessed: 13.02.2026).
    FSTEC of Russia. 2014. Order No. 31 of March 14, 2014, "On Approval of Requirements for Ensuring Information Security in Automated Control Systems for Production and Technological Processes at Critical Facilities, Potentially Hazardous Facilities, and Facilities Posing an Increased Danger to Human Life and Health and the Environment" (as amended on March 23, 2017, August 9, 2018, and March 15, 2021). URL: https://fstec.ru/dokumenty/vse-dokumenty/prikazy/prikaz-fstek-rossii-ot-14-marta-2014-g-31 (accessed: 13.02.2026).
    Gartner. 2024. Hype Cycle for Security Operations, 2024. URL: https://www.gartner.com (accessed: 13.02.2026).
    Gordon L.A., Loeb M.P., Lucyshyn W., Zhou L. 2023. The impact of information sharing on cybersecurity underinvestment: A real options perspective. Journal of Accounting and Public Policy 42 (3), 107-125. DOI: 10.1016/j.jaccpubpol.2023.107125.
    Henshel D., Sample C., Cains M.G. 2024. A survey of cybersecurity standards for critical infrastructure protection. IEEE Access 12, 33456-33478. DOI: 10.1109/ACCESS.2024.3378921.
    IBM Corporation. 2024. Cost of a Data Breach Report 2024 URL: https://www.ibm.com/reports/data-breach (accessed: 13.02.2026).
    INNER. 2025. Cybersecurity Standards Comparison Chart: IEC 62443 vs NIST CSF 2.0. URL: https://inner.su/articles/tablitsa-standartov-kiberbezopasnosti-iec-62443-vs-nist-csf-2-0-sootvetstvie/ (accessed: 13.02.2026).
    iTPROTECT. N.d. Industrial Vulnerability Management Project. URL: https://itprotect.ru/projects/upravleniye-uyazvimostyami.proj (accessed: 13.02.2026).
    Ivanov D., Sokolov B. 2024. Cyber-physical systems resilience: State-of-the-art and future challenges. International Journal of Production Research 62 (8), 2845-2864. DOI: 10.1080/00207543.2023.2292441.
    Jet CSIRT. 2025. Research into the protection of industrial control systems from targeted attacks. URL: https://jetcsirt.su/upload/2025_Исследование_Защита_АСУ_ТП.pdf (accessed: 13.02.2026).
    Johnson M.E., Goetz E. 2025. Security standards alignment for critical infrastructure protection. IEEE Security & Privacy 23 (1), 56-68. DOI: 10.1109/MSEC.2024.3489217.
    Kitsios F., Chatzidimitriou E., Kamariotou M. 2024. Developing a risk-based strategic cybersecurity framework for digital transformation. International Journal of Information Management 75, 102-118. DOI: 10.1016/j.ijinfomgt.2023.102118.
    Lukatsky A. 2019. What can be borrowed from the NIST CSF for the development of FSTEC orders? URL: https://www.securitylab.ru/blog/personal/Business_without_danger/156177.php (accessed: 13.02.2026).
    NIST. 2020. NIST Special Publication 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations. URL: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final (accessed: 13.02.2026).
    NIST. 2024. NIST Cybersecurity Framework 2.0. URL: https://www.nist.gov/cyberframework (accessed: 13.02.2026).
    Positive Technologies. 2012. Comparison of the requirements of the FSTEC order of March 14, 2014 No. 31 with the requirements of international standards (NERC CIP, ISA/IEC 62443,
    NIST SP 800-82, NIST SP 800-53). URL: https://static.ptsecurity.com/uploads/files/pt_isim_comparison_of_fstec_requirements_with_international_standards_c5a982acfe.pdf (accessed: 13.02.2026).
    Schmitt M., Schafer C., Weber C. 2025. Integration of security standards in enterprise architectures: A systematic literature review. Computers & Security 148, 104-122. DOI: 10.1016/j.cose.2024.104122.
    SECURITM. N.d. Comparison of NIST CSF 2.0 and FSTEC Order No. 31. URL: https://service.securitm.ru/help/compliance (accessed: 13.02.2026).
    Shackelford S.J. 2023. The NIST Cybersecurity Framework and the evolution of cyber risk governance. Berkeley Business Law Journal 20 (1), 45-78. DOI: 10.15779/Z38G737H0B.
    Van Looy A. 2021. Business Process Maturity: A Comparative Study on a Sample of Business Process Maturity Models. Cham: Springer. DOI: 10.1007/978-3-319-04202-2.

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License
Предыдущая статьяСледующая статья