<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">accounting</journal-id><journal-title-group><journal-title xml:lang="ru">Учет. Анализ. Аудит</journal-title><trans-title-group xml:lang="en"><trans-title>Accounting. Analysis. Auditing</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2408-9303</issn><issn pub-type="epub">2619-130X</issn><publisher><publisher-name>Financial University under The Government of Russian Federation</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.26794/2408-9303-2016--6-102-110</article-id><article-id custom-type="elpub" pub-id-type="custom">accounting-129</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>АНАЛИЗ ПРАКТИКИ</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>PRACTICE ANALYSIS</subject></subj-group></article-categories><title-group><article-title>ОРГАНИЗАЦИЯ АУДИТА ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ</article-title><trans-title-group xml:lang="en"><trans-title>The Organization of Auditing of Information Security</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Ситнов</surname><given-names>Алексей Александрович</given-names></name><name name-style="western" xml:lang="en"><surname>Sitnov</surname><given-names>A. A.</given-names></name></name-alternatives><email xlink:type="simple">55st@mail.ru</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Финансовый университет</institution><country>Россия</country></aff><aff xml:lang="en"><institution>Financial University</institution><country>Russian Federation</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2016</year></pub-date><pub-date pub-type="epub"><day>17</day><month>01</month><year>2019</year></pub-date><volume>0</volume><issue>6</issue><fpage>102</fpage><lpage>110</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Ситнов А.А., 2019</copyright-statement><copyright-year>2019</copyright-year><copyright-holder xml:lang="ru">Ситнов А.А.</copyright-holder><copyright-holder xml:lang="en">Sitnov A.A.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://accounting.fa.ru/jour/article/view/129">https://accounting.fa.ru/jour/article/view/129</self-uri><abstract><p>В предлагаемой статье отражены и систематизированы взгляды на аудит информационной безопасности экономических субъектов. В результате проведенного исследования автор обобщил современное состояние указанной предметной области аудита и обозначил свою точку зрения на возможности его применения при перманентном влиянии внутренней среды и внешнего окружения на экономические субъекты, раскрыл его существенные преимущества для системы управления этим субъектом. В статье автором обозначены основные этапы организации процесса проведения аудита информационной безопасности в рамках аудита бизнеса как современной концепции на аудит в целом. Раскрыты особенности каждого из обозначенных этапов, и даны рекомендации по их осуществлению. Результатом предложенного автором подхода к аудиту информационной безопасности является комплексная модель аудиторского цикла в рамках аудита бизнеса, позволяющая осуществлять исследования указанной предметной области, что служит основой подготовки информации для принятия оптимальных управленческих решений.</p></abstract><trans-abstract xml:lang="en"><p>The article generalizes and systematizes the views of the auditing of information security of the economic subjects. As a result of this research, the author summarized the contemporary condition of the specified subject areas of the auditing and outlined his views regarding the possibility of its application in the condition of permanent influence of the internal environment and the external surroundings on the economic entities, discovered its significant advantages for the system management of this entity. In the article the author outlines the main organizational stages of the processes of information security auditing within the auditing of the business as a modern concept of auditing in general. The features of each of the above mentioned stages as well as the recommendations for their implementation are discovered in the article. The result of the proposed by the author industry approach to the information security auditing is a comprehensive model of the auditing cycle within the auditing of the business which in turn allows to carry out the research of this subject area, which serves as the basis for the preparation of the information for making best and optimal management decisions.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>оценка ресурсов</kwd><kwd>анализ угроз</kwd><kwd>анализ уязвимостей</kwd><kwd>оценка эффективности контрмер</kwd><kwd>анализ рисков</kwd><kwd>экономический субъект</kwd><kwd>бизнес-системы</kwd><kwd>assets and resources evaluation</kwd><kwd>threat assessment</kwd><kwd>vulnerability assessment</kwd><kwd>control evaluation</kwd><kwd>counter-measures efficiency evaluation</kwd><kwd>risk assessment</kwd><kwd>the economic subject</kwd><kwd>business-systems</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Ситнов А.А., Уринцов А.И. Аудит информационных систем: монография для магистров. М.: Юнити-Дана, 2014. 239 с.</mixed-citation><mixed-citation xml:lang="en">Ситнов А.А., Уринцов А.И. Аудит информационных систем: монография для магистров. М.: Юнити-Дана, 2014. 239 с.</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Булыга Р.П., Мельник М.В. Аудит бизнеса. Практика и проблемы развития: монография / под ред. Р.П. Булыги. М.: Юнити-Дана, 2013. 263 с.</mixed-citation><mixed-citation xml:lang="en">Булыга Р.П., Мельник М.В. Аудит бизнеса. Практика и проблемы развития: монография / под ред. Р.П. Булыги. М.: Юнити-Дана, 2013. 263 с.</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Ситнов А.А. Особенности аудита информационной безопасности бизнес-систем // Аудитор. 2015. № 9 (247). С. 14-22.</mixed-citation><mixed-citation xml:lang="en">Ситнов А.А. Особенности аудита информационной безопасности бизнес-систем // Аудитор. 2015. № 9 (247). С. 14-22.</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
