<?xml version="1.0" encoding="UTF-8"?><xml><records><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>10</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Todor Tagarev</style></author><author><style face="normal" font="default" size="100%">George Sharkov</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Computationally intensive functions in designing and operating distributed cyber secure and resilient systems</style></title><secondary-title><style face="normal" font="default" size="100%">20th International Conference on Computer Systems and Technologies, CompSysTech 2019</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">agility</style></keyword><keyword><style  face="normal" font="default" size="100%">Cybersecurity</style></keyword><keyword><style  face="normal" font="default" size="100%">distributed systems</style></keyword><keyword><style  face="normal" font="default" size="100%">high-performance computing</style></keyword><keyword><style  face="normal" font="default" size="100%">operations</style></keyword><keyword><style  face="normal" font="default" size="100%">policy</style></keyword><keyword><style  face="normal" font="default" size="100%">resilience</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2019</style></year><pub-dates><date><style  face="normal" font="default" size="100%"> 21 June 2019</style></date></pub-dates></dates><publisher><style face="normal" font="default" size="100%">University of RuseRuse</style></publisher><pub-location><style face="normal" font="default" size="100%">Bulgaria</style></pub-location><volume><style face="normal" font="default" size="100%">ACM International Conference Proceeding Series</style></volume><pages><style face="normal" font="default" size="100%"> 8-18</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;Increasing incorporation of advanced information technologies makes business and public organisations more effective and efficient, while often introducing exploitable vulnerabilities. The efficient provision of security of interconnected, and interdependent, processes and sectors against cyberattacks requires deep understanding of vulnerabilities, exposure, potential negative impact, as well as the contribution existing and emerging organisational and technological solutions will potentially have on preventing attacks, reducing vulnerabilities, protecting digital infrastructures, response and recovery, and resilience. Such understanding will allow minimisation of risks against a spectrum of plausible cyber threats and reducing negative consequences of one or a series of cyberattacks.&lt;/p&gt;&lt;p&gt;Due to the complexity of the problem, the effective implementation of a number of functions and tasks in designing and operating distributed cyber secure and resilient systems require significant computational resources. This paper outlines six high-level, computationally demanding functions. The first three relate to the formulation and implementation of cybersecurity policy: understanding risk; planning and implementing cybersecurity measures; and continuous adaptation to the changing technological, threat and policy landscape. The other three functions are operational: situational awareness, including detection of cyberattacks and hybrid malicious activities; operational decision making, e.g. selecting a course of action under attack; and cyber forensics.&lt;/p&gt;</style></abstract></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Oleksandr Nepomnyashchyy</style></author><author><style face="normal" font="default" size="100%">Iryna Lahunova</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Methodology of Risk Management in Providing Sustainable Development of Settlements</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">construction</style></keyword><keyword><style  face="normal" font="default" size="100%">emergency situations</style></keyword><keyword><style  face="normal" font="default" size="100%">methodology</style></keyword><keyword><style  face="normal" font="default" size="100%">operation</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">technical regulation</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2018</style></year></dates><volume><style face="normal" font="default" size="100%">40</style></volume><pages><style face="normal" font="default" size="100%">100-104</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;In any activity, we deal with internal and external factors having a direct im&amp;not;pact on its results and which are determined as &amp;lsquo;risks.&amp;rsquo; Countries stand up to threats in economy, politics, environment, social risks, man-made disasters with the capacity to destabilize social and economic life. In Ukraine&amp;rsquo;s circumstances, these risks are compounded by geopolitical instability, the military conflict in the East of the country, a high level of corruption and a burden of the Soviet heritage of regulating the economy.&lt;/p&gt;&lt;p&gt;Construction and operation of real estate throughout its life cycle (from shaping investment intents, including design, construction, operation, repair, reconstruction, and up to demolition and reclamation of materials and waste) is a significant example for development and implementation of risk management models. Therefore, the elaboration of a methodology for risk management is of increasing significance for the policies and practices aiming to provide sustainable development of settlements by means of technical regulation in construction.&lt;/p&gt;</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Oksana Medvedchuk</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Self-regulation as a Risk Mitigation Tool in the Design and Construction of Critical Infrastructures</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">construction</style></keyword><keyword><style  face="normal" font="default" size="100%">Critical Infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">exploitation</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">security</style></keyword><keyword><style  face="normal" font="default" size="100%">self-regulation</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2018</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2018</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">40</style></volume><pages><style face="normal" font="default" size="100%">129-133</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">&lt;p&gt;Critical infrastructures are of strategic significance for the functioning of the economy, the security of a state, society and the population. Their breakdown or destruction has a considerable impact on the national security and defence, the natural environment, leads to material and financial losses and possibly casualties. Therefore, ensuring quality and reliability of such infrastructure is a priority of the state policy. The state policy in this regard is implemented through state regulation mechanisms aiming to protect life, health, property, and the environment, as well as by establishing ways of organizing or conducting activities, licensing rules, place and time of activities, volume of production or provision of services, etc. Control and supervisory functions are also important elements of the state regulation. In the Ukrainian experience, traditional mechanisms of state regulation do not ensure a relevant culture in construction. Thus, it is necessary to study and implement best international practices of avoiding risks in construction, in particular by self-regulation. This paper reviews approaches to self-regulation and the extent to which such practices contribute to risk mitigation in the design and construction of critical infrastructure assets, as currently implemented in Ukraine.&lt;/p&gt;</style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue><section><style face="normal" font="default" size="100%">129</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>27</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Venelin Georgiev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">A Two-Level Model for Describing the Risk Profile in Formulating Policy and Developing Security Capabilities</style></title><secondary-title><style face="normal" font="default" size="100%">IT4Sec Reports</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">context</style></keyword><keyword><style  face="normal" font="default" size="100%">Risk</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">risk profile assessment</style></keyword><keyword><style  face="normal" font="default" size="100%">scenario</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2015</style></year><pub-dates><date><style  face="normal" font="default" size="100%">June 2015</style></date></pub-dates></dates><number><style face="normal" font="default" size="100%">129</style></number><publisher><style face="normal" font="default" size="100%">Institute of Information and Communication Technologies</style></publisher><pub-location><style face="normal" font="default" size="100%">Sofia</style></pub-location><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The risk assessment/management concept is widely used in security research due to its universality, but also because of the active nature and sense of precautionary management, implemented on its basis. The security risk profile can be described and studied at different levels of security, which poses the question how researchers should choose the appropriate model for identifying, evaluating and developing strategies to mitigate the risk. The article raises the question whether the use risk profiles for the purposes of policy formulation, at one level of security, and capacity building at another, can introduce errors in decision making. As a possible tool to eliminate such errors the author proposes the use of a two-stage model for the description and study of the risk profile, which includes a contextual and a specific level of the discourse.</style></abstract></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">David López</style></author><author><style face="normal" font="default" size="100%">Oscar Pastor</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Comprehensive Approach to Security Risk Management in Critical Infrastructures and Supply Chains</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Comprehensive security</style></keyword><keyword><style  face="normal" font="default" size="100%">Critical Infrastructure Protection</style></keyword><keyword><style  face="normal" font="default" size="100%">DRA</style></keyword><keyword><style  face="normal" font="default" size="100%">DRM</style></keyword><keyword><style  face="normal" font="default" size="100%">dynamic risk assessment</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">supply chain protection.</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2013</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2013</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">29</style></volume><pages><style face="normal" font="default" size="100%">69-76</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The ability to assess and therefore react to risk exposure in critical infra¬structures and supply chains environments greatly contributes to reaching suitable protection levels and response mechanisms. Due to the unavoidable interdependen¬cies among those infrastructures, that allow disruptions to spread from one to an¬other and likely cause a great impact on society’s welfare state, risk management might be seen as a common and shared concern. The Comprehensive Risk Man¬agement approach tries to face this process by gathering information from a broad range of disciplines (physical and logical security, safety, environmental threats, etc.) while taking into account interdependencies of critical infrastructures and sup¬ply chains at different layers, going from critical infrastructure operators point of view, to sectoral, national and finally supranational levels. Besides, risk assessment and management processes rely on accurate and timely information to assist deci¬sion making, but this information (security holes, attacks or even disruptions suf¬fered by an infrastructure or supply chain)—due to its sensitiveness—does not eas¬ily flow between involved or interested parties. This paper provides an analysis of this situation and suggest future fields of action, supported by conclusions drawn from the FOCUS project.</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue><section><style face="normal" font="default" size="100%">69</style></section></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Alexander Ryazantsev</style></author><author><style face="normal" font="default" size="100%">Inna Skarga-Bandurova</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Establishing an Air Pollution Monitoring Network for Industrial Regions: A Probabilistic Approach</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Environmental safety</style></keyword><keyword><style  face="normal" font="default" size="100%">location</style></keyword><keyword><style  face="normal" font="default" size="100%">monitoring network</style></keyword><keyword><style  face="normal" font="default" size="100%">monitoring station</style></keyword><keyword><style  face="normal" font="default" size="100%">pollution detection.</style></keyword><keyword><style  face="normal" font="default" size="100%">probability of emission detection</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">unified information system</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2012</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2012</style></date></pub-dates></dates><number><style face="normal" font="default" size="100%">6</style></number><volume><style face="normal" font="default" size="100%">28</style></volume><pages><style face="normal" font="default" size="100%">79-86</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The paper examines the issue of establishing a monitoring network for regions with highly developed industrial infrastructure. The goal is to create a unified information and analytical system that would provide for efficient environmental risk management. These results are part of a multi-year research project pursuing the ultimate goal of enhanced ecological safety in industrialised regions. We build on studies initiated by the Canadian Institutes of Health Research   which, however, requires a large number of monitoring stations to measure the flows of pollutants with fine-scale spatial variability. In our approach we emphasise the power of the probabilistic approach to defining the location of monitoring stations and consequent efficient risk management.</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Dana Procházková</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Principles of Mitigating and Managing Human System Risks</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Disaster</style></keyword><keyword><style  face="normal" font="default" size="100%">Human System</style></keyword><keyword><style  face="normal" font="default" size="100%">Risk</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">Safety Management.</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2012</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2012</style></date></pub-dates></dates><number><style face="normal" font="default" size="100%">2</style></number><volume><style face="normal" font="default" size="100%">28</style></volume><pages><style face="normal" font="default" size="100%">21-36</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The security situation in a territory continuously evolves and, therefore, a new safety culture is formed that takes into account the actual knowledge and experience with interdependencies among public assets, including experience with extreme social crises. In dealing with disasters, historical development of human activities has included numerous preventive and mitigation measures applied according to legal rules, technical standards, norms and public instructions, response systems and ways of recovery. As a rule, these ensure protection against basic disasters and not to ‘calamities’ or random combinations of phenomena that may cause catastrophes. Problem solving the complex territory safety requires proactive, strategic risk management based on qualified data, methods, knowledge and good practices in their application. This paper summarizes the set of principles that ensures qualified decision-making for risk management, or ‘whole-of-life risk governance,’ directed at provision of human security and sustainable development. It addresses the key domains related to effective risk management.</style></abstract><issue><style face="normal" font="default" size="100%">1</style></issue></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Todor Tagarev</style></author><author><style face="normal" font="default" size="100%">Venelin Georgiev</style></author><author><style face="normal" font="default" size="100%">Valeri Ratchev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">A Taxonomy of Essential Services</style></title><secondary-title><style face="normal" font="default" size="100%">Radioelectronic and Computer Systems</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">Comprehensive approach</style></keyword><keyword><style  face="normal" font="default" size="100%">Critical Infrastructure</style></keyword><keyword><style  face="normal" font="default" size="100%">Planning</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">security policy</style></keyword><keyword><style  face="normal" font="default" size="100%">threats</style></keyword><keyword><style  face="normal" font="default" size="100%">Uncertainty</style></keyword><keyword><style  face="normal" font="default" size="100%">Vulnerabilities</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2012</style></year><pub-dates><date><style  face="normal" font="default" size="100%">May 2012</style></date></pub-dates></dates><publisher><style face="normal" font="default" size="100%">Radioelectronic and Computer Systems 6(58)</style></publisher><pub-location><style face="normal" font="default" size="100%">Sevastopol, Ukraine</style></pub-location><pages><style face="normal" font="default" size="100%">191-196</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Communities, countries and alliances cannot be efficient in preparing to meet diverse threats to their security within traditional organizational stovepipes. The boundaries between ‘internal’ and ‘external’ threats are getting fuzzier, and the vulnerabilities of governments, businesses and communities feed on each other, while the comprehensive approach is gaining traction in ever more security fields. The implementation of the comprehensive approach poses a number of methodological challenges. While it clearly requires coordination of various capabilities of a multitude of actors, it is less apparent which is the suitable organising concept. This paper takes as a starting point the concept of ‘essential services’ and suggests a taxonomy, that would allow to treat threats, vulnerabilities and risk in a common comprehensive framework. The taxonomy has been developed with a specific purpose in mind, and thus refers to European Essential Services (EES). We nevertheless reason that it can be replicated to support decision making at other levels, e.g. in national security policy making and planning. </style></abstract><issue><style face="normal" font="default" size="100%">58</style></issue></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Gueorgui Stankov</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">Risk as a Factor in Decision-Making</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">AHP</style></keyword><keyword><style  face="normal" font="default" size="100%">multi-criteria decision-making</style></keyword><keyword><style  face="normal" font="default" size="100%">Risk</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2009</style></year></dates><volume><style face="normal" font="default" size="100%">23</style></volume><pages><style face="normal" font="default" size="100%">224-233</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">Incorporating the problems of risk in the management of an organiza­tion is an important issue for any manager, especially for those in the security sec­tor. This article examines different approaches that enable taking into account the associated risks in decision-making. Considering a comprehensive understanding of risk, the transformation problems resolved in an organization and the types of fac­tors in decision-making, three different approaches are described. Based on the Analytic Hierarchy Process (AHP) methodology, an integral criterion for selection of an alternative could be developed.
</style></abstract><issue><style face="normal" font="default" size="100%">2</style></issue></record><record><source-app name="Biblio" version="7.x">Drupal-Biblio</source-app><ref-type>17</ref-type><contributors><authors><author><style face="normal" font="default" size="100%">Todor Tagarev</style></author><author><style face="normal" font="default" size="100%">Gueorgui Stankov</style></author><author><style face="normal" font="default" size="100%">Lozan Bizov</style></author><author><style face="normal" font="default" size="100%">Atanas Natchev</style></author></authors></contributors><titles><title><style face="normal" font="default" size="100%">A Framework Methodology to Support the Selection of a Multipurpose Fighter</style></title><secondary-title><style face="normal" font="default" size="100%">Information &amp; Security: An International Journal</style></secondary-title></titles><keywords><keyword><style  face="normal" font="default" size="100%">AHP</style></keyword><keyword><style  face="normal" font="default" size="100%">contract management</style></keyword><keyword><style  face="normal" font="default" size="100%">Decision Support</style></keyword><keyword><style  face="normal" font="default" size="100%">defense acquisition management</style></keyword><keyword><style  face="normal" font="default" size="100%">Defense procurement</style></keyword><keyword><style  face="normal" font="default" size="100%">DSS</style></keyword><keyword><style  face="normal" font="default" size="100%">risk management</style></keyword><keyword><style  face="normal" font="default" size="100%">Transparency</style></keyword></keywords><dates><year><style  face="normal" font="default" size="100%">2007</style></year><pub-dates><date><style  face="normal" font="default" size="100%">2007</style></date></pub-dates></dates><volume><style face="normal" font="default" size="100%">21</style></volume><pages><style face="normal" font="default" size="100%">82-91</style></pages><language><style face="normal" font="default" size="100%">eng</style></language><abstract><style face="normal" font="default" size="100%">The procurement of multipurpose fighter planes is one of the major procurement, or modernization projects, announced by Bulgaria’s Ministry of Defense in 2002, but a procurement case has not been initiated so far. This article calls for a transparent decision-making process within a rational framework, based on both qualitative and quantitative analysis, that would allow to select “the best” multipurpose fighter for the Bulgarian Air Force. After outlining the main assumptions, the authors examine the issue of identifying and structuring the criteria for selection of a multipurpose fighter, describe the main steps of a rational, quantitatively-based, transparent decision-making process and analyze the major decision support requirements, as well as methods and tools that may be used in providing analytical support to both the selection process and the follow-on contract and project management.</style></abstract></record></records></xml>