CRITERIA FOR STRATEGIC ASSESSMENT OF STATE CYBER SECURITY: CYBER DIPLOMATIC ASPECT

DOI: 10.31673/2409-7292.2025.032375

Authors

  • В. П. Шульга, (Shulga V.P.) State University of Information and Communication Technologies, Kyiv
  • О. Г. Корченко, (Korchenko O.H.) State University of Information and Communication Technologies, Kyiv
  • Є. В. Іванченко, (Ivanchenko Ye.V.) State University of Information and Communication Technologies, Kyiv
  • C. В. Казмірчук, (Kazmirchuk S.V.) State University of Information and Communication Technologies, Kyiv
  • С. В. Кондратюк, (Kondratyuk S.V.) State University of Information and Communication Technologies, Kyiv

DOI:

https://doi.org/10.31673/2409-7292.2025.032375

Abstract

For Ukraine, which is in a state of armed aggression and systemic pressure in cyberspace, the issue of cyber defense is
gaining critical importance, especially in the context of integration into the European and Euro-Atlantic security space. This
requires not only technological readiness to repel an attack, but also the creation of a stable, comprehensive cyber defense
system capable of effectively interacting with international partners and integrating into the global security space. In this context,
the production of this system becomes colored by the cyber diplomatic aspect. The implementation of effective cyber diplomacy requires clear tools for monitoring and assessing the state of cyber defense of the country in order to: identify the strengths and
weaknesses of national cybersecurity; adjust the policy and development program; ensure transparency and accountability to
society and international partners, etc. In view of this, there is a need to develop appropriate criteria for evaluating the
components of cyber diplomacy adapted to Ukrainian realities, combining the best global practices taking into account the
modern unique challenges of the state. The method of this study is to form criteria for assessing the country's cybersecurity
within the framework of the components of cyber diplomacy strategies using the best global practices. To form such criteria, at
the initial stage of the study, we analyze internationally recognized approaches developed by governments, intergovernmental
organizations and industry experts. The formed set of 11 criteria, by which it is possible to assess the level of cybersecurity in
Ukraine within the framework of the implementation of the cyber diplomacy strategy, have a sufficient level of detail, which
allows: to comprehensively assess the state of cyber defense in a wide range of areas; to effectively plan the development of
institutional, technological and legal mechanisms; to strengthen Ukraine's position in cyberspace.
Keywords: cyber diplomacy, cybersecurity, criteria for strategic assessment of state cybersecurity, state cyber defense,
cyber threats.

References
1. Global Cybersecurity Index, About International Telecommunication Union (ITU), веб-сайт. URL:
https://www.itu.int/hub/publication/d-hdb-gci-01-2024/ (дата звернення: 08.08.2025).
2. Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures
for a high common level of cybersecurity across the Union. URL: https://eur-lex.europa.eu/eli/dir/2022/2555/oj (дата
звернення: 08.08.2025).
3. Joint Communication To The European Parliament And The Council The EU's Cybersecurity Strategy for the
Digital Decade. URL: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52020JC0018 (дата звернення: 08.08.
2025).
4. OECD Policy Framework on Digital Security Cybersecurity For Prosperity. URL: https://www.oecd.org/
content/dam/oecd/en/publications/reports/2022/12/oecd-policy-framework-on-digital-security_a0b1d79c/a69df866-
en.pdf (дата звернення: 08.08.2025).
5. Global Cybersecurity Index 2024. URL: https:// www.itu.in t/en / ITU-D / Cybersecurity / pages/globalcybersecurity-index.aspx (дата звернення: 08.08.2025).
6. The National Cyber Security Index 3.0. URL: https: // ega.ee / wp-content / upload s/ 2023 / 08/NCSI3.0_Methodology.pdf (дата звернення: 08.08.2025).
7. Information security, cybersecurity and privacy protection – Information security management systems –
Requirements: ISO/IEC 27001:2022: Technical Committee: ISO/IEC JTC 1/SC 27, ICS : 35.030 03.100.70, Р. 19.
8. Information security, cybersecurity and privacy protection – Guidance on managing information security risks:
ISO/IEC 27005:2022: Technical Committee : ISO/IEC JTC 1/SC 27, ICS : 35.030, Р. 64.
9. Information security, cybersecurity and privacy protection – Information security controls: ISO/IEC
27002:2022: Technical Committee : ISO/IEC JTC 1/SC 27, ICS : 35.030 03.100.70, Р. 152.
10. Security and resilience – Business continuity management systems – Requirements: ISO 22301:2019:
Technical Committee : ISO/TC 292, ICS : 03.100.01 03.100.70, Р. 21.
11. The NIST Cybersecurity Framework (CSF) 2.0: National Institute of Standards and Technology URL:
https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf (дата звернення: 12.08.2025).
12. Cybersecurity Capacity Maturity Model for Nations (CMM) Global Cyber Security Capacity Centre URL:
https://gcscc.ox.ac.uk/files/cmm2021editiondocpdf (дата звернення: 12.08.2025).
13. CYBERSECURITY CAPACITY REVIEW Republic of Cyprus September 2021 URL:
https://dsa.cy/images/pdf-upload/cmm_cyprus_report_2021_final.pdf (дата звернення: 12.08.2025).
14. CMM Reviews Around the World. URL: https://gcscc.ox.ac.uk/cmm-reviews (дата звернення: 12.08.2025).

Published

2025-10-26

Issue

Section

Articles