DECISION FACTORS AND DECISION CONTEXT FOR MILITARY COMMAND AUTHORITIES DURING CYBER INCIDENTS

Authors

DOI:

https://doi.org/10.28925/2663-4023.2026.34.1311

Keywords:

cyber incident, military command authorities, adaptive decision-making, decision context, decision factors, response loop, artefact, threat intelligence, critical infrastructure

Abstract

Cyber incident response in the interests of the military command authorities (MCA) of the Armed Forces of Ukraine takes place under time pressure, data incompleteness and mandatory coordination among several subjects of the national response system. For the MCA, the outcome is not the recording of an event's technical indicators but a prepared response decision that defines permitted and prohibited actions, their time windows, priorities and constraints. The current normative framework (Law of Ukraine No. 2163-VIII, the Cybersecurity Strategy of Ukraine, Resolutions of the Cabinet of Ministers of Ukraine No. 1471 and No. 1533 of November 2025) and international process models (NIST CSF 2.0, NIST SP 800-61 Rev. 3, the ISO/IEC 27035 series) regulate the response sequence in detail but do not treat the conditions of decision-making as a distinct object of description. As a result, different units may rely on divergent assumptions about constraints, priorities and consequences, which reduces the comparability of decisions even for technically similar incidents. The paper proposes a taxonomy of internal and external factors influencing decisions and a structure of the decision context as a consistent input-data package decomposed into mission context, policy constraints, asset context and threat intelligence. To reduce uncertainty, a status attribute (known, assumed, unknown) and artefact-based confirmation of key parameters are introduced, and traceability is supported by a role framework of subjects who form and approve context elements. A correspondence matrix "factor — context element — decision consequence" and a minimal artefact checklist are constructed as a practical instrument for preparing a decision within the response loop. The results separate the incident description from the decision-making conditions, improve the comparability of decisions for typical incident classes and form a terminological and conceptual basis for the subsequent justification of an assessment system of indicators and criteria. The proposed apparatus does not duplicate prioritization or alternative-selection models but precedes them by fixing the input conditions on which such models rely.

Downloads

Download data is not yet available.

References

Verkhovna Rada of Ukraine. (2017). On the basic principles of ensuring cybersecurity of Ukraine: Law of Ukraine No. 2163-VIII dated October 5, 2017. https://zakon.rada.gov.ua/go/2163-19

President of Ukraine. (2021). On the Cybersecurity Strategy of Ukraine: Decree of the President of Ukraine No. 447/2021 dated August 26, 2021. https://www.president.gov.ua/documents/4472021-40013

Cabinet of Ministers of Ukraine. (2025). On approval of the procedure for interaction between entities of the national cyber incident, cyberattack, and cyberthreat response system and entities responsible for cybersecurity, law enforcement, counterintelligence and intelligence agencies, and entities carrying out operational-search activities: Resolution of the Cabinet of Ministers of Ukraine No. 1471. https://zakon.rada.gov.ua/laws/show/1471-2025-п

Cabinet of Ministers of Ukraine. (2025). Certain issues of responding to cyber incidents, cyberattacks, and cyberthreats: Resolution of the Cabinet of Ministers of Ukraine No. 1533. https://zakon.rada.gov.ua/laws/show/1533-2025-п

Cabinet of Ministers of Ukraine. (2019). On approval of the general requirements for cyber protection of critical infrastructure facilities: Resolution of the Cabinet of Ministers of Ukraine No. 518. https://zakon.rada.gov.ua/laws/show/518-2019-п

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.29

Nelson, A., Rekhi, S., Souppaya, M., & Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile (NIST SP 800-61 Rev. 3). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r3

International Organization for Standardization. (2023). Information technology—Information security incident management—Part 1: Principles and process (ISO/IEC Standard No. 27035-1:2023).

International Organization for Standardization. (2023). Information technology—Information security incident management—Part 2: Guidelines to plan and prepare for incident response (ISO/IEC Standard No. 27035-2:2023).

International Organization for Standardization. (2020). Information technology—Information security incident management—Part 3: Guidelines for ICT incident response operations (ISO/IEC Standard No. 27035-3:2020).

International Organization for Standardization. (2024). Information technology—Information security incident management—Part 4: Coordination (ISO/IEC Standard No. 27035-4:2024).

European Union Agency for Cybersecurity. (2020). How to set up CSIRT and SOC: Good practice guide. ENISA.

Joint Task Force. (2018). Risk management framework for information systems and organizations: A system life cycle approach for security and privacy (NIST SP 800-37 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-37r2

Johnson, C., Badger, L., Waltermire, D., Snyder, J., & Skorupka, C. (2016). Guide to cyber threat information sharing (NIST SP 800-150). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-150

Schroeder, K., Trinh, H., & Pillitteri, V. (2024). Measurement guide for information security: Volume 1—Identifying and selecting measures (NIST SP 800-55 Vol. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-55v1

Schroeder, K., Trinh, H., & Pillitteri, V. (2024). Measurement guide for information security: Volume 2—Developing an information security measurement program (NIST SP 800-55 Vol. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-55v2

Cybersecurity and Infrastructure Security Agency. (2020). CISA national cyber incident scoring system (NCISS).

Kertzner, P., Carter, C., & Hahn, A. (2022). Crown jewels analysis for industrial control systems. The MITRE Corporation.

Uzlov, D., Yakovlev, S., Tolstoluzka, O., Kopytsia, O., & Burchenko, S. (2025). Integrating CVSS, national criticality levels, and MCDA for multi-factor cyber incident prioritization. Radioelectronic and Computer Systems, 4, 220–235. https://doi.org/10.32620/reks.2025.4.15

Downloads


Abstract views: 4

Published

2026-09-24

How to Cite

Rybachok, H., & Mykus, S. (2026). DECISION FACTORS AND DECISION CONTEXT FOR MILITARY COMMAND AUTHORITIES DURING CYBER INCIDENTS. Electronic Professional Scientific Journal «Cybersecurity: Education, Science, Technique», 2(34), 318–326. https://doi.org/10.28925/2663-4023.2026.34.1311