Вернуться к статье

Методология многоуровневой защиты данных для информационных систем «1С»

Comparison of methods

Direction

Goals and objectives

Advantages

Limitations

Main measures

Organizational

Establishing access regulations; defining procedures for interaction and response

A clear management structure; greater staff discipline and awareness

Dependence on the human factor; the need for regular training

Security policies; appointment of responsible persons; training sessions

Technical

Protecting information and preventing unauthorized access

A high degree of protection; the possibility of automation

Additional costs; the need for qualified maintenance

Encryption; access control; software updates

Monitoring and auditing

Detecting threats; analyzing anomalies; preventing attacks

Timely response; the possibility of incident analysis

Possible false positives; resource demands

Monitoring systems; action auditing; IDS/IPS