FUNCTIONAL MODEL OF SECURITY MANAGEMENT IN DATA WAREHOUSE INFRASTRUCTURE

Authors

DOI:

https://doi.org/10.31673/2409-7292.2026.035620

Abstract

The article considers the problem of ensuring information security of data warehouse infrastructure under
conditions of increasing information volumes, growing complexity of storage system architectures, and rising
requirements for ensuring data confidentiality, integrity, and availability. It is shown that modern data warehouses operate
in a complex information environment characterized by large volumes of structured and unstructured information,
distributed computing resources, cloud technologies, and multi-level access mechanisms, which necessitates the
development of a comprehensive information security management system. The limitations of traditional security
management approaches have been identified, as they do not provide a sufficient level of process formalization,
complicate the coordination of information flows, and do not allow full integration of international standard requirements
into the internal architecture of data warehouses. A systematic approach to the construction of a functional model for
information security management of data warehouse infrastructure based on the IDEF0 methodology is proposed.
Structured modeling was used to formalize functional processes, enabling the description of relationships between
information flows, security management mechanisms, and infrastructure components of the system. A top-level context
model was developed and decomposed according to the functional levels of the data warehouse architecture. For each
functional level, appropriate security mechanisms, access policies, infrastructure protection tools, and relationships with
regulatory requirements were identified. Particular attention was paid to the integration of the provisions of international
standards ISO/IEC 27001, ISO/IEC 27002, and the General Data Protection Regulation (GDPR) into the security
management processes of data warehouse infrastructure. It is shown that the use of the IDEF0 methodology makes it
possible to increase the level of process structuring in information security management, ensure formalization of security
procedures, and improve the controllability of information flows. The obtained results confirm the feasibility of using
structured functional modeling to improve the efficiency of information security management and ensure the resilience
of data warehouse infrastructure against modern cyber threats and information security violations.
Keywords: functional modeling, IDEF0, information security management, data warehouses, security policy,
decomposition, ISO/IEC 27001, GDPR, data architecture.

References
1. Singh, S. P., & Afzal, N. (2024). The MESA security model 2.0: A dynamic framework for mitigating stealth
data exfiltration. International Journal of Network Security & Its Applications, 16(3), 23–40.
https://doi.org/10.48550/arXiv.2405.10880.
2. Tran, K., Vasudevan, S., Desai, P., Gorelik, A., Ahuja, M., Venkateshababu, A. Y., Verma, M., Hu, D.,
Moustafa, W. E., Rajamani, V., Gupta, A., Buenrostro, I., & Raina, K. (2025). Data Guard: A fine-grained purpose-based
access control system for large data warehouses. Computer Science: Cryptography and Security, 2–13.
https://doi.org/10.48550/arXiv.2502.01998.
3. Fugkeaw, S., Suksai, P., & Hak, L. (2024). SSF-CDW: Achieving scalable, secure, and fast OLAP query for
encrypted cloud data warehouse. Journal of Cloud Computing, 13, Article 129. https://doi.org/10.1186/s13677-024-
00692-y.
4. Huang, J., & Yi, J. (2024). The key security management scheme of cloud storage based on blockchain and
digital twins. Journal of Cloud Computing, 13, Article 15. https://doi.org/10.1186/s13677-023-00587-4.
5. Alharbe, N., Aljohani, A., Rakrouki, M. A., & Khayyat, M. (2023). An access control model based on system
security risk for dynamic sensitive data storage in the cloud. Applied Sciences, 13(5), Article 3187.
https://doi.org/10.3390/app13053187.
6. Лєнков, С., Джулій, В., Муляр, І., & Димбовський, М. (2024). Модель визначення актуальних загроз
безпеки конфіденційних даних в розподіленій інформаційній системі. Pidvodni Tehnologii, 13, 45–59.
https://doi.org/10.32347/uwt.2023.13.1205.
7. Головацький, Н. Т. (2024). Питання захисту персональних даних при використанні хмарних технологій.
Аналітично-порівняльне правознавство, 5, 72–78. https://doi.org/10.24144/2788-6018.2024.05.72.
8. Фасій, Б. (2024). Національна безпека та захист персональних даних в епоху цифрових технологій.
Society and Security, 6(6), 76–82. https://doi.org/10.26642/sas-2024-6(6)-76-82.
9. Пристай, Р. А. (2023). Приватність за замовчуванням: Користувацька модель даних як основа захисту
приватності та персональних даних в соціальних мережах. Науковий вісник Ужгородського національного
університету. Серія: Право, 80(1), 84–89. https://doi.org/10.24144/2307-3322.2023.80.1.84.
10. European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April
2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such
data (General Data Protection Regulation). https://eur-lex.europa.eu/eli/reg/2016/679/oj.
11. International Organization for Standardization. (2022). ISO/IEC 27001:2022. Information security,
cybersecurity and privacy protection—Information security management systems—Requirements. https://www.iso.org/
standard/82875.html.
12. International Organization for Standardization. (2022). ISO/IEC 27002:2022. Information security,
cybersecurity and privacy protection—Information security controls. https://www.iso.org/standard/75652.html.
13. European Union Agency for Cybersecurity. (2021). Pseudonymisation techniques and best practices.
https://www.enisa.europa.eu/publications/pseudonymisation-techniques-and-best-practices.
14. European Data Protection Board. (2020). Guidelines 4/2019 on Article 25: Data protection by design and by
default. https: // edpb.europa.eu /our-work-tools/our-documents/guidelines/guidelines-42019-article-25-data-protectiondesign-and_en.
15. Костюк, Ю., Довженко, Н., Мазур, Н., Складанний, П., & Рзаєва, С. (2025). Методика захисту GRIDсередовища від шкідливого коду під час виконання обчислювальних завдань. Кібербезпека: освіта, наука,
техніка, 3(27), 22–40. https://doi.org/10.28925/2663-4023.2025.27.710.
16. Sarker, I. H. (2021). Data science and analytics: An overview from data-driven smart computing, decisionmaking and applications perspective. SN Computer Science, 2, Article 377. https://doi.org/10.1007/s42979-021-00765-
8.
17. Костюк, Ю., Хорольська, К., Бебешко, Б., Довженко, Н., Коршун, Н., & Пазинін, А. (2025).
Інструментальні засоби забезпечення інформаційної безпеки від прихованих загроз в інфраструктурі хмарних
обчислень. Кібербезпека: освіта, наука, техніка, 4(28), 633–655. https://doi.org/10.28925/2663-4023.2025.28.857.
18. Shah, J., & Baghela, V. (2025). Developing data governance frameworks for cloud-based platforms: Ensuring
data quality and security. International Journal of Research and Analytical Reviews, 12, 252–261.
19. Складанний, П. М., Машкіна, І. В., Рзаєва, С. Л., & Костюк, Ю. В. (2025). Методи GDPR для
забезпечення безпеки сховищ даних від витоків та загроз. Телекомунікаційні та інформаційні технології, 2, 59–
76. https://doi.org/10.31673/2412-4338.2025.027860.
20. Rafi, S., Yogesh, R., & Sriram, M. (2024). Optimized dual access control for cloud-based data storage and
distribution using global-context residual recurrent neural network. Computers & Security, 151, Article 104183.
https://doi.org/10.1016/j.cose.2024.104183.
21. Костюк, Ю., Складанний, П., Рзаєва, С., Самойленко, Ю., & Коршун, Н. (2025). Інтелектуальні системи
керування та захисту в кіберфізичних і хмарних середовищах Smart Grid. Кібербезпека: освіта, наука, техніка,
2(30), 125–156. https://doi.org/10.28925/2663-4023.2025.30.956.
22. Amaresam, R. K. (2025). Security and compliance in cloud-native data warehousing: A technical deep dive.
International Research Journal of Modernization in Engineering Technology & Science. https://doi.org/10.56726/
IRJMETS69854
23. Складанний, П., Костюк, Ю., & Рзаєва, С. (2026). Безперервна оцінка доступу в Zero Trust Access
Management на основі подієвих сигналів безпеки та динамічного керування сесіями. Математичні машини і
системи, 1, 29-46. https://doi.org/10.34121/1028-9763-2026-1-29-46.

Published

2026-09-15

Issue

Section

Articles