In industrialized countries, such facilities are organized into an interconnected system — critical infrastructure in various fields of activity of states, and the information systems and telecommunications networks that support them into a critical information infrastructure. Purpose: The article examines the changing requirements for information security: from the requirements of maximum security to the more "lenient" requirements of the acceptable risk concept. The expediency of returning to the concept of maximizing security for critical information infrastructures is substantiated. Methods: As a model of the objective function of the protection system, the asymptotic information security management is considered, which makes it possible to gradually bring the required security values closer to the "ideal" ones during the operation of the control system. Results: The possibilities of implementing an asymptotic approach to information security management for various management system models developed in different countries are considered. The article analyzes the features of the implementation of the object and subject model of information security management systems in different operating conditions of the CII. The principal difference between the properties of these two models is the possibility of external control, which is typical for strict regulatory management (object model). Another (subject-based) model allows for flexibility and responsiveness in security management. In particular, the ability of the CI subject to promptly make independent decisions and take into account interactions with other CI (the subject model) reduces the response time of the management system to external influences. .When analyzing the prospects for the development of information security requirements, it is proposed to take into account not only national, but also international mechanisms for improving security. It is proposed to take into account for such mechanisms the threats and conditions that arise during hostilities or in the case of a terrorist threat. Practical relevance: The transition to the subject model when changing the target management paradigm within the framework of asymptotic management meets the requirements not only to reduce the hierarchy of management, but also to accelerate responses and. e their duplication.
Erokhin et al. (Wed,) studied this question.