METHODOLOGY FOR DEVELOPING A SECURITY PROFILE AND AUTHORIZING SYSTEMS THAT PROCESS RESTRICTED INFORMATION
DOI:
https://doi.org/10.31673/2409-7292.2026.034811Abstract
The article develops a methodological approach to creating a security profile and authorizing systems that process
state information resources or restricted information. The transition from one-time project-based conformity confirmation
to a risk-oriented profile model requiring continuous management of requirements, evidence, risks, and changes is
substantiated. The relationships among baseline, sectoral, and target security profiles are clarified, together with the
responsibilities of the system owner or administrator, the procedure for assessing compliance with the target profile, and
the types of authorization. The proposed sequence covers determination of the legal regime of information, definition of
system boundaries, decomposition of requirements into verifiable outcomes, development of an evidence base,
conformity assessment, and maintenance of the profile throughout the system life cycle. A set of internal indicators is
introduced to characterize confirmation of applicability, weighted coverage of requirements, completeness of verified
evidence, and authorization readiness. Particular attention is paid to management responsibility, supplier governance,
cloud services, architectural changes, and transition from legacy comprehensive information protection projects. The
practical value of the approach lies in establishing traceability between regulatory requirements, implemented security
measures, responsible roles, control parameters, and current evidence of effective operation. The methodology may be
used to plan the transition to the profile model, identify blocking gaps, and prepare an authorization package without
replacing independent assessment or the authorization decision.
Keywords: restricted information, security profile, target profile, system authorization, conformity assessment,
cybersecurity, risk-oriented approach.
References
1. Закон України «Про внесення змін до деяких законів України щодо удосконалення правових засад
забезпечення кіберзахисту державних інформаційних ресурсів та інформації, вимога щодо захисту якої
встановлена законом» від 27.03.2025 № 4336-IX. https://zakon.rada.gov.ua/laws/show/4336-20#Text.
2. Закон України «Про захист інформації в інформаційно-комунікаційних системах» від 05.07.1994 №
80/94-ВР. https://zakon.rada.gov.ua/laws/show/80/94-%D0%B2%D1%80#Text.
3. Постанова Кабінету Міністрів України «Деякі питання захисту інформаційних, електронних
комунікаційних, інформаційно-комунікаційних і технологічних систем» від 18.06.2025 № 712.
https://zakon.rada.gov.ua/laws/show/712-2025-%D0%BF#Text.
4. Закон України «Про основні засади забезпечення кібербезпеки України» від 05.10.2017 № 2163-VIII.
https://zakon.rada.gov.ua/laws/show/2163-19#Text.
5. Закон України «Про доступ до публічної інформації» від 13.01.2011 № 2939-VI.
https://zakon.rada.gov.ua/laws/show/2939-17#Text.
6. Закон України «Про Державну службу спеціального зв’язку та захисту інформації України» від
23.02.2006 № 3475-IV. https://zakon.rada.gov.ua/laws/show/3475-15#Text.
7. Указ Президента України «Про Положення про технічний захист інформації в Україні» від 27.09.1999
№ 1229/99. https://zakon.rada.gov.ua/laws/show/1229/99#Text.
8. Базовий профіль безпеки системи, де обробляється відкрита або конфіденційна інформація: наказ
Адміністрації Держспецзв’язку від 30.06.2025 № 409.
9. Базовий профіль безпеки системи, де обробляється службова інформація: наказ Адміністрації
Держспецзв’язку від 02.07.2025 № 419.
10. Порядок ведення переліку авторизованих систем з безпеки: наказ Адміністрації Держспецзв’язку від
11.07.2025 № 434.
11. Вимоги до суб’єктів оцінювання: наказ Адміністрації Держспецзв’язку від 11.07.2025 № 438.
12. Постанова Кабінету Міністрів України «Про внесення змін до постанов Кабінету Міністрів України від
18 червня 2025 р. № 712 і від 31 грудня 2025 р. № 1799» від 10.04.2026 № 493. https://zakon.rada. gov.ua
/laws/show/493-2026-%D0%BF#Text.
13. Постанова Кабінету Міністрів України «Про затвердження Порядку оцінювання стану кіберзахисту»
від 31.12.2025 № 1799. https://zakon.rada.gov.ua/laws/show/1799-2025-%D0%BF#Text.
14. Порядок підтвердження постачальниками відповідності впроваджених заходів безпеки інформації:
наказ Адміністрації Держспецзв’язку від 17.12.2025 № 836.
15. Вимоги з кіберзахисту об’єктів критичної інфраструктури: наказ уповноваженого органу від 07.10.2025
№ 403.
16. ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection — Information security
management systems — Requirements. https://www.iso.org/standard/27001.
17. ISO/IEC 27002:2022. Information security, cybersecurity and privacy protection — Information security
controls. https://www.iso.org/standard/75652.html.
18. ISO/IEC 27005:2022. Information security, cybersecurity and privacy protection — Guidance on managing
information security risks. https://www.iso.org/standard/80585.html.
19. NIST. (2024). The NIST Cybersecurity Framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29.
20. NIST. (2020). Security and Privacy Controls for Information Systems and Organizations (Special Publication
800-53 Rev. 5). https://doi.org/10.6028/NIST.SP.800-53r5.