<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Sergiy Dotsenko</style></author><author><style face="normal" font="default" size="100%">Oleg Illiashenko</style></author><author><style face="normal" font="default" size="100%">Sergii Kamenskyi</style></author><author><style face="normal" font="default" size="100%">Vyacheslav Kharchenko</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Integrated Model of Knowledge Management for Security of Information Technologies: Standards ISO/IEC 15408 and ISO/IEC 18045</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Information Security</style></keyword><keyword><style  face="normal" font="default" size="100%">information technologies</style></keyword><keyword><style  face="normal" font="default" size="100%">IT security</style></keyword><keyword><style  face="normal" font="default" size="100%">knowledge management</style></keyword><keyword><style  face="normal" font="default" size="100%">security standards</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year></dates><volume><style face="normal" font="default" size="100%">43</style></volume><pages><style face="normal" font="default" size="100%">305-317</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The paper presents analysis of existing knowledge management models and justification for introducing an integrated model of knowledge management for both industry and academia. It is proposed to build such a model using well-known standards of IT security – common criteria and methodology for IT security evaluation. The model of knowledge management is elaborated by analysing the content of the relevant elements of standards and establishing the knowledge content that determines the forms of relations between them. The authors propose the application of an architecture of four-factor models towards the formation of knowledge management models in the organization of the information security management system in accordance with the standards of the series ISO/ IEC 27000.</style></abstract><issue><style face="normal" font="default" size="100%">3</style></issue><section><style face="normal" font="default" size="100%">305</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Todor Tagarev</style></author><author><style face="normal" font="default" size="100%">Venelin Georgiev</style></author><author><style face="normal" font="default" size="100%">Petya Ivanova</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Analytical Support to Critical Infrastructure Protection Policy and Investment Decision-Making</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">CASoS</style></keyword><keyword><style  face="normal" font="default" size="100%">CIP</style></keyword><keyword><style  face="normal" font="default" size="100%">complex adaptive systems</style></keyword><keyword><style  face="normal" font="default" size="100%">Decision Support</style></keyword><keyword><style  face="normal" font="default" size="100%">ECI</style></keyword><keyword><style  face="normal" font="default" size="100%">EU Directive 114/2008</style></keyword><keyword><style  face="normal" font="default" size="100%">interdependency</style></keyword><keyword><style  face="normal" font="default" size="100%">knowledge management</style></keyword><keyword><style  face="normal" font="default" size="100%">knowledge portal</style></keyword><keyword><style  face="normal" font="default" size="100%">method</style></keyword><keyword><style  face="normal" font="default" size="100%">security policy</style></keyword><keyword><style  face="normal" font="default" size="100%">tool</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2012</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2012</style></date></pub-dates></dates><number><style face="normal" font="default" size="100%">1</style></number><volume><style face="normal" font="default" size="100%">28</style></volume><pages><style face="normal" font="default" size="100%">13-20</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Critical infrastructures are complex, interlinked socio-technical systems, with impact often crossing state borders. Their protection involves governments and business organisations, interacting in the application of a broad variety of measures to provide safety and security while investing a considerable amount of public and private resources. This paper examines the challenge of making respective policy and investment decisions transparent, and a sample of methods and tools used to facilitate decision making. It also calls for contributions to a knowledge portal on security and safety of critical infrastructures. </style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record></records></xml>