АСПЕКТИ СТВОРЕННЯ ЗАХИЩЕНИХ ІНФОРМАЦІЙНО-КОМУНІКАЦІЙНИХ СИСТЕМ

Автор(и)

  • Наталія Паламарчук Військовий інститут телекомунікацій та інформатизації імені Героїв Крут https://orcid.org/0000-0001-8818-7794
  • Світлана Паламарчук Військовий інститут телекомунікацій та інформатизації імені Героїв Крут https://orcid.org/0000-0001-7483-9165
  • Вячеслав Овсянніков Військовий інститут телекомунікацій та інформатизації імені Героїв Крут https://orcid.org/0000-0003-0186-6220
  • Тетяна Побережець Військовий інститут телекомунікацій та інформатизації імені Героїв Крут https://orcid.org/0000-0001-8007-8614
  • Олександр Вороной Військовий інститут телекомунікацій та інформатизації імені Героїв Крут https://orcid.org/0009-0007-1427-4431

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1263

Ключові слова:

авторизована система з безпеки;, автоматизована система;, захист інформації;, інформаційно-комунікаційна система;, кіберзахист;, кібербезпеки;, комплексна система захисту інформації;, технологія хмарних обчислень.

Анотація

У статті розглянуто створення захищених інформаційно-комунікаційних систем в умовах реформування системи кіберзахисту в Україні на основі міжнародних стандартів та практик. Виокремлено нормативні, організаційні та технічні аспекти створення захищених ІКС відповідно до вимог законодавства. Наразі відбувається перехід від класичної моделі створення комплексних систем захисту інформації та їх державної експертизи до ризик-орієнтованого підходу, що ґрунтується на застосуванні профілів безпеки та авторизації систем з безпеки. Розглянуто та проаналізовано складові сучасної інформаційної інфраструктури, зокрема, автоматизовані системи класів 1, 2 і 3, хмарні технології та сервіси/послуги, що надаються централізованими сервісними інфраструктурами, а також підходи до організації захисту за умови обробки державних інформаційних ресурсів або інформації з обмеженим доступом. Серед розповсюджених безпекових сервісів (функцій) виокремлено застосування захищених вузлів доступу до мережі Інтернет, центрів реагування на кіберінциденти (Security Operations Center), кваліфікованих надавачів електронних довірчих послуг та засобів електронної ідентифікації. Окрему увагу приділено організації захисту інформації та кіберзахисту ІКС, розгорнутих у хмарній інфраструктурі (хмарні послуги), на основі моделі спільної відповідальності між провайдером хмарних послуг та власником ІКС. Узагальнено основні підходи до організації захисту інформації (інформаційної безпеки) та кіберзахисту залежно від класу системи, ступеня обмеження доступу до інформації та умов функціонування інформаційної інфраструктури.

Завантаження

Дані завантаження ще не доступні.

Посилання

Palamarchuk, S., Martyniuk, V., Ovsiannikov, V., & Shuhalii, O. (2025). Transitional period of legislative changes regarding information protection and cybersecurity of information and communication systems. In Proceedings of the V International Scientific and Practical Conference “Communication Systems and Technologies, Informatization and Cybersecurity: Current Issues and Development Trends” (pp. 184–185). VITI. https://mitit.mil.gov.ua/page/science

Verkhovna Rada of Ukraine. (2025). Pro vnesennia zmin do deiakykh zakoniv Ukrainy shchodo zakhystu informatsii ta kiberzakhystu derzhavnykh informatsiinykh resursiv, obiektiv krytychnoi informatsiinoi infrastruktury [On amendments to certain laws of Ukraine regarding information protection and cybersecurity of state information resources and critical information infrastructure facilities] (Law of Ukraine No. 4336-IX, March 27, 2025). https://zakon.rada.gov.ua/laws/show/4336-20#Text

Verkhovna Rada of Ukraine. (1994). Pro zakhyst informatsii v informatsiino-telekomunikatsiinykh systemakh [On information protection in information and telecommunication systems] (Law of Ukraine No. 80/94-VR, July 5, 1994). https://zakon.rada.gov.ua/laws/show/80/94-вр#Text

Verkhovna Rada of Ukraine. (2017). Pro osnovni zasady zabezpechennia kiberbezpeky Ukrainy [On the basic principles of ensuring cybersecurity of Ukraine] (Law of Ukraine No. 2163-VIII, October 5, 2017). https://zakon.rada.gov.ua/laws/show/2163-19#Text

Verkhovna Rada of Ukraine. (2022). Pro khmarni posluhy [On cloud services] (Law of Ukraine No. 2075-IX, February 17, 2022). https://zakon.rada.gov.ua/laws/show/2075-20#Text

Verkhovna Rada of Ukraine. (2017). Pro elektronnu identyfikatsiiu ta elektronni dovirchi posluhy [On electronic identification and electronic trust services] (Law of Ukraine No. 2155-VIII, October 5, 2017). https://zakon.rada.gov.ua/laws/show/2155-19#Text

Cabinet of Ministers of Ukraine. (2025). Deiaki pytannia zakhystu informatsiinykh, elektronnykh komunikatsiinykh, informatsiino-komunikatsiinykh, tekhnolohichnykh system [Certain issues of protection of information, electronic communication, information and communication, and technological systems] (Resolution No. 712, June 18, 2025). https://zakon.rada.gov.ua/laws/show/712-2025-%D0%BF#Text

Cabinet of Ministers of Ukraine. (2006). Pro zatverdzhennia Minimalnykh vymoh do zakhystu informatsiinykh, elektronnykh komunikatsiinykh, informatsiino-komunikatsiinykh ta tekhnolohichnykh system [On approval of minimum requirements for the protection of information, electronic communication, information and communication, and technological systems] (Resolution No. 373, March 29, 2006). https://zakon.rada.gov.ua/laws/show/373-2006-%D0%BF#Text

Cabinet of Ministers of Ukraine. (2019). Pro zatverdzhennia Zahalnykh vymoh do kiberzakhystu obiektiv krytychnoi infrastruktury [On approval of general requirements for cybersecurity of critical infrastructure facilities] (Resolution No. 518, June 19, 2019). https://zakon.rada.gov.ua/laws/show/518-2019-%D0%BF#Text

National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53 Rev. 5). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

National Institute of Standards and Technology. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30 Rev. 1). https://csrc.nist.gov/pubs/sp/800/30/r1/final

European Parliament & Council of the European Union. (2022). Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No. 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive). Official Journal of the European Union. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555&qid=1708526

International Organization for Standardization, International Electrotechnical Commission, & Institute of Electrical and Electronics Engineers. (2023). Systems and software engineering – System life cycle processes (ISO/IEC/IEEE 15288:2023, 2nd ed.). https://online.budstandart.com/ua/catalog/doc-page.html?id_doc=116499

International Organization for Standardization, International Electrotechnical Commission, & Institute of Electrical and Electronics Engineers. (2026). Systems and software engineering – Software life cycle processes (ISO/IEC/IEEE 12207:2026, 2nd ed.). https://online.budstandart.com/ua/catalog/doc-page.html?id_doc=77957

DSTU ISO/IEC 27001:2023. (2023). Informatsiina bezpeka, kiberbezpeka ta zakhyst konfidentsiinosti. Systemy keruvannia informatsiinoiu bezpekoiu. Vymohy [Information security, cybersecurity and privacy protection. Information security management systems. Requirements] (ISO/IEC 27001:2022, IDT). https://online.budstandart.com/ua/catalog/doc

International Organization for Standardization & International Electrotechnical Commission. (2022). Information security, cybersecurity and privacy protection – Guidance on managing information security risks (ISO/IEC 27005:2022). https://www.iso.org/standard/80585.html

Administration of the State Service of Special Communications and Information Protection of Ukraine. (2025). Pro zatverdzhennia Bazovykh zakhodiv z kiberzakhystu, Metodychnykh rekomendatsii shchodo zdiisnennia bazovykh zakhodiv z kiberzakhystu [On approval of basic cybersecurity measures and methodological recommendations for implementing basic cybersecurity measures] (Order No. 54, January 30, 2025). https://surl.lt/ywfofy

Lutsenko, V. M. (2011). Correspondence of the stages of building information protection systems to the stages of creating automated systems. Zakhyst Informatsii, (3). https://www.docsity.com/ru/vidpovidnist-etapiv-pobudovi-sistem-zahistu-informaciji-stadiyam-stvorennya-avtomatizovanih-sistem/4654185/

Lukova-Chuiko, N., Nakonechnyi, V., Toliupa, S., & Ziubina, R. (2020). Problems of protection of critical infrastructure facilities. Information Systems and Technologies Security, 1(2), 31–39. https://doi.org/10.17721/10.17721/ISTS.2020.1.31-39

Toliupa, S., & Shtanenko, S. (2023). Mathematical model of information security management system relationships. Information Systems and Technologies Security, 1(6), 28–36. https://doi.org/10.17721/ISTS.2023.1.28-36

Administration of the State Service of Special Communications and Information Protection of Ukraine. (2024). Poriadok vyboru zakhodiv zakhystu informatsii, vymoha shchodo zakhystu yakoi vstanovlena zakonom ta ne stanovyt derzhavnoi taiemnytsi, dlia informatsiinykh system [Procedure for selecting information protection measures for information systems where the information protection requirement is established by law and the information does not constitute a state secret] (ND TZI 3.6-006-24; Order No. 234, April 30, 2024). https://surl.li/gliojs

Administration of the State Service of Special Communications and Information Protection of Ukraine. (2025). Pro zatverdzhennia bazovoho profiliu bezpeky systemy, de obrobliaietsia vidkryta abo konfidentsiina informatsiia [On approval of the basic security profile for a system processing open or confidential information] (Order No. 409, June 30, 2025). https://cip.gov.ua/ua/docs/nakaz-pro-zatverdzhennya-bazovogo-profilyu-bezpeki-sistemi-de-obroblyayetsya-vidkrita-abo-konfidenciina-informaciya

Administration of the State Service of Special Communications and Information Protection of Ukraine. (2025). Pro zatverdzhennia bazovoho profiliu bezpeky systemy, de obrobliaietsia sluzhbova informatsiia [On approval of the basic security profile for a system processing official information] (Order No. 419, July 2, 2025). https://cip.gov.ua/ua/docs/nakaz-administraciyi-derzhspeczv-yazku-vid-02-07-2025-419-pro-zatverdzhennya-bazovogo-profilyu-bezpeki-sistemi-de-obroblyayetsya-sluzhbova-informaciya

Palamarchuk, N. A., Palamarchuk, S. A., Poberezhets, T. V., & Martyniuk, V. V. (2026). Information protection and cybersecurity of information and communication systems in the defense sector: Trends of changes and issues. In Proceedings of the IV International Scientific and Practical Conference “Security and Defense Sector of Ukraine in Protection of National Interests: Current Problems and Tasks under Martial Law” (pp. 1131–1134). NADPSU Publishing House. https://dspace.nadpsu.edu.ua/handle/123456789/5873

Department of Special Telecommunication Systems and Information Protection of the Security Service of Ukraine. (1999). Klasyfikatsiia avtomatyzovanykh system i standartni funktsionalni profili zakhyshchenosti obrobliuvanoi informatsii vid nesanktsionovanoho dostupu [Classification of automated systems and standard functional security profiles for processed information against unauthorized access] (ND TZI 2.5-005-99; Order No. 22, April 28, 1999).

Cabinet of Ministers of Ukraine. (2020). Deiaki pytannia funktsionuvannia Natsionalnoi elektronnoi komunikatsiinoi merezhi [Certain issues concerning the functioning of the National Electronic Communication Network] (Resolution No. 1358, December 16, 2020). https://zakon.rada.gov.ua/laws/show/1358-2020-%D0%BF#Text

Administration of the State Service of Special Communications and Information Protection of Ukraine. (2023). Pro zatverdzhennia Polozhennia pro systemu zakhyshchenoho dostupu derzhavnykh orhaniv do merezhi Internet [On approval of the regulation on the system of secure Internet access for state authorities] (Order No. 771, August 30, 2023). https://zakon.rada.gov.ua/laws/show/z1624-23#Text

Cabinet of Ministers of Ukraine. (2023). Pro zatverdzhennia Polozhennia pro intehrovanu systemu elektronnoi identyfikatsii [On approval of the regulation on the integrated electronic identification system] (Resolution No. 1150, November 3, 2023). https://zakon.rada.gov.ua/laws/show/1150-2023-%D0%BF#Text

Radchenko, M. M., Dykyi, O. V., Palamarchuk, N. A., Palamarchuk, S. A., & Bondarenko, O. Ye. (2021). Approaches to information protection in information and telecommunication systems built using cloud technologies. Visnyk VITI. Communication and Information Systems, (2), 82–95. https://www.viti.edu.ua/files/zbk/2021/2021-2.pdf

Zhylin, A., Divitskyi, A., & Kozachok, A. (2019). Problems of information resources protection when using cloud technologies. Information Technology and Security, 7(2), 171–182. https://ela.kpi.ua/handle/123456789/33886

Downloads


Переглядів анотації: 8

Опубліковано

2026-09-24

Як цитувати

Паламарчук, Н., Паламарчук, С., Овсянніков, В., Побережець, Т., & Вороной, О. (2026). АСПЕКТИ СТВОРЕННЯ ЗАХИЩЕНИХ ІНФОРМАЦІЙНО-КОМУНІКАЦІЙНИХ СИСТЕМ. Електронне фахове наукове видання «Кібербезпека: освіта, наука, техніка», 2(34), 775–786. https://doi.org/10.28925/2663-4023.2026.34.1263