ASPECTS OF CREATING SECURED INFORMATION AND COMMUNICATION SYSTEMS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1263Keywords:
authorized security system;, automatization system;, information security;, information and communication system;, cybersecurity;, comprehensive information security system;, cloud computing technology.Abstract
The article considers the creation of secure information and communication systems in the context of the reform of the cyber defense system in Ukraine based on international standards and practices. The normative, organizational and technical aspects of creating secure ICS in accordance with the requirements of the legislation are highlighted. Currently, there is a transition from the classical model of creating complex information protection systems and their state expertise to a risk-oriented approach based on the use of security profiles and authorization of security systems. The components of modern information infrastructure are considered and analyzed, in particular, automated systems of classes 1, 2 and 3, cloud technologies and services/services provided by centralized service infrastructures, as well as approaches to organizing protection when processing state information resources or information with limited access. Among the widespread security services (functions), the use of secure Internet access nodes, cyber incident response centers (Security Operations Center), qualified providers of electronic trust services and electronic identification means are highlighted. Special attention is paid to the organization of information protection and cyber protection of ICS deployed in cloud infrastructure (cloud services), based on the model of joint responsibility between the cloud service provider and the ICS owner. The main approaches to the organization of information protection (information security) and cyber protection are summarized depending on the class of the system, the degree of restriction of access to information and the conditions of operation of the information infrastructure.
Downloads
References
Palamarchuk, S., Martyniuk, V., Ovsiannikov, V., & Shuhalii, O. (2025). Transitional period of legislative changes regarding information protection and cybersecurity of information and communication systems. In Proceedings of the V International Scientific and Practical Conference “Communication Systems and Technologies, Informatization and Cybersecurity: Current Issues and Development Trends” (pp. 184–185). VITI. https://mitit.mil.gov.ua/page/science
Verkhovna Rada of Ukraine. (2025). Pro vnesennia zmin do deiakykh zakoniv Ukrainy shchodo zakhystu informatsii ta kiberzakhystu derzhavnykh informatsiinykh resursiv, obiektiv krytychnoi informatsiinoi infrastruktury [On amendments to certain laws of Ukraine regarding information protection and cybersecurity of state information resources and critical information infrastructure facilities] (Law of Ukraine No. 4336-IX, March 27, 2025). https://zakon.rada.gov.ua/laws/show/4336-20#Text
Verkhovna Rada of Ukraine. (1994). Pro zakhyst informatsii v informatsiino-telekomunikatsiinykh systemakh [On information protection in information and telecommunication systems] (Law of Ukraine No. 80/94-VR, July 5, 1994). https://zakon.rada.gov.ua/laws/show/80/94-вр#Text
Verkhovna Rada of Ukraine. (2017). Pro osnovni zasady zabezpechennia kiberbezpeky Ukrainy [On the basic principles of ensuring cybersecurity of Ukraine] (Law of Ukraine No. 2163-VIII, October 5, 2017). https://zakon.rada.gov.ua/laws/show/2163-19#Text
Verkhovna Rada of Ukraine. (2022). Pro khmarni posluhy [On cloud services] (Law of Ukraine No. 2075-IX, February 17, 2022). https://zakon.rada.gov.ua/laws/show/2075-20#Text
Verkhovna Rada of Ukraine. (2017). Pro elektronnu identyfikatsiiu ta elektronni dovirchi posluhy [On electronic identification and electronic trust services] (Law of Ukraine No. 2155-VIII, October 5, 2017). https://zakon.rada.gov.ua/laws/show/2155-19#Text
Cabinet of Ministers of Ukraine. (2025). Deiaki pytannia zakhystu informatsiinykh, elektronnykh komunikatsiinykh, informatsiino-komunikatsiinykh, tekhnolohichnykh system [Certain issues of protection of information, electronic communication, information and communication, and technological systems] (Resolution No. 712, June 18, 2025). https://zakon.rada.gov.ua/laws/show/712-2025-%D0%BF#Text
Cabinet of Ministers of Ukraine. (2006). Pro zatverdzhennia Minimalnykh vymoh do zakhystu informatsiinykh, elektronnykh komunikatsiinykh, informatsiino-komunikatsiinykh ta tekhnolohichnykh system [On approval of minimum requirements for the protection of information, electronic communication, information and communication, and technological systems] (Resolution No. 373, March 29, 2006). https://zakon.rada.gov.ua/laws/show/373-2006-%D0%BF#Text
Cabinet of Ministers of Ukraine. (2019). Pro zatverdzhennia Zahalnykh vymoh do kiberzakhystu obiektiv krytychnoi infrastruktury [On approval of general requirements for cybersecurity of critical infrastructure facilities] (Resolution No. 518, June 19, 2019). https://zakon.rada.gov.ua/laws/show/518-2019-%D0%BF#Text
National Institute of Standards and Technology. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53 Rev. 5). https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
National Institute of Standards and Technology. (2012). Guide for conducting risk assessments (NIST Special Publication 800-30 Rev. 1). https://csrc.nist.gov/pubs/sp/800/30/r1/final
European Parliament & Council of the European Union. (2022). Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No. 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive). Official Journal of the European Union. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022L2555&qid=1708526
International Organization for Standardization, International Electrotechnical Commission, & Institute of Electrical and Electronics Engineers. (2023). Systems and software engineering – System life cycle processes (ISO/IEC/IEEE 15288:2023, 2nd ed.). https://online.budstandart.com/ua/catalog/doc-page.html?id_doc=116499
International Organization for Standardization, International Electrotechnical Commission, & Institute of Electrical and Electronics Engineers. (2026). Systems and software engineering – Software life cycle processes (ISO/IEC/IEEE 12207:2026, 2nd ed.). https://online.budstandart.com/ua/catalog/doc-page.html?id_doc=77957
DSTU ISO/IEC 27001:2023. (2023). Informatsiina bezpeka, kiberbezpeka ta zakhyst konfidentsiinosti. Systemy keruvannia informatsiinoiu bezpekoiu. Vymohy [Information security, cybersecurity and privacy protection. Information security management systems. Requirements] (ISO/IEC 27001:2022, IDT). https://online.budstandart.com/ua/catalog/doc
International Organization for Standardization & International Electrotechnical Commission. (2022). Information security, cybersecurity and privacy protection – Guidance on managing information security risks (ISO/IEC 27005:2022). https://www.iso.org/standard/80585.html
Administration of the State Service of Special Communications and Information Protection of Ukraine. (2025). Pro zatverdzhennia Bazovykh zakhodiv z kiberzakhystu, Metodychnykh rekomendatsii shchodo zdiisnennia bazovykh zakhodiv z kiberzakhystu [On approval of basic cybersecurity measures and methodological recommendations for implementing basic cybersecurity measures] (Order No. 54, January 30, 2025). https://surl.lt/ywfofy
Lutsenko, V. M. (2011). Correspondence of the stages of building information protection systems to the stages of creating automated systems. Zakhyst Informatsii, (3). https://www.docsity.com/ru/vidpovidnist-etapiv-pobudovi-sistem-zahistu-informaciji-stadiyam-stvorennya-avtomatizovanih-sistem/4654185/
Lukova-Chuiko, N., Nakonechnyi, V., Toliupa, S., & Ziubina, R. (2020). Problems of protection of critical infrastructure facilities. Information Systems and Technologies Security, 1(2), 31–39. https://doi.org/10.17721/10.17721/ISTS.2020.1.31-39
Toliupa, S., & Shtanenko, S. (2023). Mathematical model of information security management system relationships. Information Systems and Technologies Security, 1(6), 28–36. https://doi.org/10.17721/ISTS.2023.1.28-36
Administration of the State Service of Special Communications and Information Protection of Ukraine. (2024). Poriadok vyboru zakhodiv zakhystu informatsii, vymoha shchodo zakhystu yakoi vstanovlena zakonom ta ne stanovyt derzhavnoi taiemnytsi, dlia informatsiinykh system [Procedure for selecting information protection measures for information systems where the information protection requirement is established by law and the information does not constitute a state secret] (ND TZI 3.6-006-24; Order No. 234, April 30, 2024). https://surl.li/gliojs
Administration of the State Service of Special Communications and Information Protection of Ukraine. (2025). Pro zatverdzhennia bazovoho profiliu bezpeky systemy, de obrobliaietsia vidkryta abo konfidentsiina informatsiia [On approval of the basic security profile for a system processing open or confidential information] (Order No. 409, June 30, 2025). https://cip.gov.ua/ua/docs/nakaz-pro-zatverdzhennya-bazovogo-profilyu-bezpeki-sistemi-de-obroblyayetsya-vidkrita-abo-konfidenciina-informaciya
Administration of the State Service of Special Communications and Information Protection of Ukraine. (2025). Pro zatverdzhennia bazovoho profiliu bezpeky systemy, de obrobliaietsia sluzhbova informatsiia [On approval of the basic security profile for a system processing official information] (Order No. 419, July 2, 2025). https://cip.gov.ua/ua/docs/nakaz-administraciyi-derzhspeczv-yazku-vid-02-07-2025-419-pro-zatverdzhennya-bazovogo-profilyu-bezpeki-sistemi-de-obroblyayetsya-sluzhbova-informaciya
Palamarchuk, N. A., Palamarchuk, S. A., Poberezhets, T. V., & Martyniuk, V. V. (2026). Information protection and cybersecurity of information and communication systems in the defense sector: Trends of changes and issues. In Proceedings of the IV International Scientific and Practical Conference “Security and Defense Sector of Ukraine in Protection of National Interests: Current Problems and Tasks under Martial Law” (pp. 1131–1134). NADPSU Publishing House. https://dspace.nadpsu.edu.ua/handle/123456789/5873
Department of Special Telecommunication Systems and Information Protection of the Security Service of Ukraine. (1999). Klasyfikatsiia avtomatyzovanykh system i standartni funktsionalni profili zakhyshchenosti obrobliuvanoi informatsii vid nesanktsionovanoho dostupu [Classification of automated systems and standard functional security profiles for processed information against unauthorized access] (ND TZI 2.5-005-99; Order No. 22, April 28, 1999).
Cabinet of Ministers of Ukraine. (2020). Deiaki pytannia funktsionuvannia Natsionalnoi elektronnoi komunikatsiinoi merezhi [Certain issues concerning the functioning of the National Electronic Communication Network] (Resolution No. 1358, December 16, 2020). https://zakon.rada.gov.ua/laws/show/1358-2020-%D0%BF#Text
Administration of the State Service of Special Communications and Information Protection of Ukraine. (2023). Pro zatverdzhennia Polozhennia pro systemu zakhyshchenoho dostupu derzhavnykh orhaniv do merezhi Internet [On approval of the regulation on the system of secure Internet access for state authorities] (Order No. 771, August 30, 2023). https://zakon.rada.gov.ua/laws/show/z1624-23#Text
Cabinet of Ministers of Ukraine. (2023). Pro zatverdzhennia Polozhennia pro intehrovanu systemu elektronnoi identyfikatsii [On approval of the regulation on the integrated electronic identification system] (Resolution No. 1150, November 3, 2023). https://zakon.rada.gov.ua/laws/show/1150-2023-%D0%BF#Text
Radchenko, M. M., Dykyi, O. V., Palamarchuk, N. A., Palamarchuk, S. A., & Bondarenko, O. Ye. (2021). Approaches to information protection in information and telecommunication systems built using cloud technologies. Visnyk VITI. Communication and Information Systems, (2), 82–95. https://www.viti.edu.ua/files/zbk/2021/2021-2.pdf
Zhylin, A., Divitskyi, A., & Kozachok, A. (2019). Problems of information resources protection when using cloud technologies. Information Technology and Security, 7(2), 171–182. https://ela.kpi.ua/handle/123456789/33886
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Наталія Паламарчук, Світлана Паламарчук, Вячеслав Овсянніков, Тетяна Побережець, Олександр Вороной

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.