<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "https://jats.nlm.nih.gov/publishing/1.3/JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xml:lang="en">
  <front xmlns:xlink="http://www.w3.org/1999/xlink">
    <journal-meta>
      <journal-title-group>
        <journal-title>Technoeconomics</journal-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Technoeconomics</trans-title>
        </trans-title-group>
      </journal-title-group>
      <issn pub-type="epub">2949-1290</issn>
    </journal-meta>
    <article-meta xmlns:xlink="http://www.w3.org/1999/xlink">
      <article-id pub-id-type="publisher-id">5</article-id>
      <article-id pub-id-type="doi">10.57809/2026.5.2.17.4</article-id>
      <title-group>
        <article-title>Comparison of NIST Cybersecurity Framework Patterns and the Requirements of Federal Service For Technical and Export Control (FSTEC) Order No. 31: Compliance Matrices and Integration Methodology</article-title>
        <trans-title-group xml:lang="ru">
          <trans-title>Сопоставление паттернов NIST cybersecurity framework и требований 31 приказа ФСТЭК: матрица соответствия и методика интеграции</trans-title>
        </trans-title-group>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name>
            <surname>Yakovleva</surname>
            <given-names>Alena</given-names>
          </name>
          <xref ref-type="aff" rid="aff1"/>
        </contrib>
      </contrib-group>
      <aff id="aff1">Peter the Great St.Petersburg Polytechnic University</aff>
      <pub-date publication-format="electronic" date-type="pub" iso-8601-date="2026-06-30">
        <day>30</day>
        <month>06</month>
        <year>2026</year>
      </pub-date>
      <volume>5</volume>
      <issue>2</issue>
      <issue-id pub-id-type="publisher-id">17</issue-id>
      <fpage>47</fpage>
      <lpage>59</lpage>
      <self-uri xmlns:xlink="http://www.w3.org/1999/xlink" content-type="pdf" xlink:href="https://technoeconomics.spbstu.ru/userfiles/files/Issues/17/4_yakovleva.pdf"/>
      <abstract xml:lang="en">
        <p>This study focuses on two of the most significant documents in the field of information security: the international standard NIST Cybersecurity Framework version 2.0 and the Russian regulatory act, FSTEC Order No. 31. The subject of the study is the conceptual and structural relationships between the NIST CSF functions and the groups of information security measures established by Order No. 31. The methodological basis consists of a comparative analysis of the original texts of the documents, Positive Technologies comparison tables, and the TOGAF architectural design methodology. The study resulted in the development of a correspondence matrix comparing 17 groups of measures from Order No. 31 with six functions of the NIST CSF 2.0 core. It was found that coverage of CSF functions by the Order's measures varies from 40-60% for class K3 to 95-100% for class K1, while the Govern function has no direct equivalent in the Russian document. A gap analysis methodology is proposed, allowing organizations to identify missing security measures when integrating the two approaches. Practical recommendations for prioritizing protective measures based on a risk-based approach have been developed. The results can be used in designing information security architectures for organizations working with critical information infrastructure and government information systems.</p>
      </abstract>
      <kwd-group xml:lang="en">
        <kwd>NIST Cybersecurity Framework 2.0</kwd>
        <kwd>FSTEC Order 31</kwd>
        <kwd>information security risk management</kwd>
        <kwd>standards integration</kwd>
        <kwd>cybersecurity patterns</kwd>
        <kwd>business architecture</kwd>
        <kwd>critical information infrastructure</kwd>
        <kwd>government information systems</kwd>
        <kwd>information security</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="ref1">
        <mixed-citation publication-type="journal">ARPP Soft. N.d. A case study on implementing automated process control system protection at Severstal facilities. URL: https://arppsoft.ru/ (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation publication-type="journal">Australian Signals Directorate. 2024. Essential Eight Maturity Model. URL: https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation publication-type="journal">Brock J., Brennig K., Lohr B., Bartelheimer C., von Enzberg S. 2024. Improving Process Mining Maturity — From Intentions to Actions. Business &amp; Information Systems Engineering. DOI: 10.1007/s12599-024-00882-7.</mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation publication-type="journal">Center for Internet Security. 2024. CIS Controls Version 8.1. URL: https://www.cisecurity.org/controls (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation publication-type="journal">FSTEC of Russia. 2014. Order No. 31 of March 14, 2014, "On Approval of Requirements for Ensuring Information Security in Automated Control Systems for Production and Technological Processes at Critical Facilities, Potentially Hazardous Facilities, and Facilities Posing an Increased Danger to Human Life and Health and the Environment" (as amended on March 23, 2017, August 9, 2018, and March 15, 2021). URL: https://fstec.ru/dokumenty/vse-dokumenty/prikazy/prikaz-fstek-rossii-ot-14-marta-2014-g-31 (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation publication-type="journal">Gartner. 2024. Hype Cycle for Security Operations, 2024. URL: https://www.gartner.com (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation publication-type="journal">Gordon L.A., Loeb M.P., Lucyshyn W., Zhou L. 2023. The impact of information sharing on cybersecurity underinvestment: A real options perspective. Journal of Accounting and Public Policy 42 (3), 107-125. DOI: 10.1016/j.jaccpubpol.2023.107125.</mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation publication-type="journal">Henshel D., Sample C., Cains M.G. 2024. A survey of cybersecurity standards for critical infrastructure protection. IEEE Access 12, 33456-33478. DOI: 10.1109/ACCESS.2024.3378921.</mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation publication-type="journal">IBM Corporation. 2024. Cost of a Data Breach Report 2024 URL: https://www.ibm.com/reports/data-breach (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation publication-type="journal">INNER. 2025. Cybersecurity Standards Comparison Chart: IEC 62443 vs NIST CSF 2.0. URL: https://inner.su/articles/tablitsa-standartov-kiberbezopasnosti-iec-62443-vs-nist-csf-2-0-sootvetstvie/ (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation publication-type="journal">iTPROTECT. N.d. Industrial Vulnerability Management Project. URL: https://itprotect.ru/projects/upravleniye-uyazvimostyami.proj (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation publication-type="journal">Ivanov D., Sokolov B. 2024. Cyber-physical systems resilience: State-of-the-art and future challenges. International Journal of Production Research 62 (8), 2845-2864. DOI: 10.1080/00207543.2023.2292441.</mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation publication-type="journal">Jet CSIRT. 2025. Research into the protection of industrial control systems from targeted attacks. URL: https://jetcsirt.su/upload/2025_Исследование_Защита_АСУ_ТП.pdf (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation publication-type="journal">Johnson M.E., Goetz E. 2025. Security standards alignment for critical infrastructure protection. IEEE Security &amp; Privacy 23 (1), 56-68. DOI: 10.1109/MSEC.2024.3489217.</mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation publication-type="journal">Kitsios F., Chatzidimitriou E., Kamariotou M. 2024. Developing a risk-based strategic cybersecurity framework for digital transformation. International Journal of Information Management 75, 102-118. DOI: 10.1016/j.ijinfomgt.2023.102118.</mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation publication-type="journal">Lukatsky A. 2019. What can be borrowed from the NIST CSF for the development of FSTEC orders? URL: https://www.securitylab.ru/blog/personal/Business_without_danger/156177.php (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation publication-type="journal">NIST. 2020. NIST Special Publication 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations. URL: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation publication-type="journal">NIST. 2024. NIST Cybersecurity Framework 2.0. URL: https://www.nist.gov/cyberframework (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation publication-type="journal">Positive Technologies. 2012. Comparison of the requirements of the FSTEC order of March 14, 2014 No. 31 with the requirements of international standards (NERC CIP, ISA/IEC 62443,</mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation publication-type="journal">NIST SP 800-82, NIST SP 800-53). URL: https://static.ptsecurity.com/uploads/files/pt_isim_comparison_of_fstec_requirements_with_international_standards_c5a982acfe.pdf (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation publication-type="journal">Schmitt M., Schafer C., Weber C. 2025. Integration of security standards in enterprise architectures: A systematic literature review. Computers &amp; Security 148, 104-122. DOI: 10.1016/j.cose.2024.104122.</mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation publication-type="journal">SECURITM. N.d. Comparison of NIST CSF 2.0 and FSTEC Order No. 31. URL: https://service.securitm.ru/help/compliance (accessed: 13.02.2026).</mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation publication-type="journal">Shackelford S.J. 2023. The NIST Cybersecurity Framework and the evolution of cyber risk governance. Berkeley Business Law Journal 20 (1), 45-78. DOI: 10.15779/Z38G737H0B.</mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation publication-type="journal">Van Looy A. 2021. Business Process Maturity: A Comparative Study on a Sample of Business Process Maturity Models. Cham: Springer. DOI: 10.1007/978-3-319-04202-2.</mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>
