Method of assesing damage in case of leakage of official information

Authors

DOI:

https://doi.org/10.18372/2225-5036.31.21166

Keywords:

protection of restricted information, official information, damage assessment, information leak, negative consequences, losses

Abstract

Based on the previously developed basic tuple model of a set of parameters for assessing the consequences of a leak of official information of a critical infrastructure facility, a method for assessing damage in the event of its leak has been developed, which allows estimating the amount of predicted significant damage by determining the parameters of economic losses (as damage from the publication of this information, which is subject to examination for classification as official information) and damage from the possible occurrence of other serious ones. This method has the ability to calculate the amount of this predicted significant damage depending on the type of violation committed in the event of disclosure of official information and/or in the event of loss of its material media. The method provides conditions for determining the possible obsolescence of information, its importance among other available official information and material media, the amount of funding for measures to protect them and its effectiveness. The developed method meets the requirements of existing legislation in terms of the application of norms to restrict access to public information. The method has been tested and the results obtained for a real subject of authority (object of critical infrastructure) are presented based on its current list of official information and certain assumptions. Its use will be useful when implementing a comprehensive information protection system at the stage of developing an information security policy when assessing risks (including losses) of loss of information assets for their timely minimization and elimination, as a way to prevent, identify, prevent and neutralize threats to the security of a critical infrastructure object (and/or subject of authority) and maintain the security of its critical information infrastructure objects at a level that ensures the continuity of operation and stability of the provision of basic services and/or vital functions.

Published

2025-12-25

How to Cite

Dreis , Y. (2025). Method of assesing damage in case of leakage of official information. Ukrainian Scientific Journal of Information Security, 31(3), 190–206. https://doi.org/10.18372/2225-5036.31.21166

Issue

Section

Cybersecurity & Critical Information Infrastructure Protection (CIIP)