CONCEPTUAL FOUNDATIONS FOR BUILDING A SYSTEM OF ELECTRONIC TECHNICAL PASSPORTS OF INFORMATION SYSTEMS BASED ON BLOCKCHAIN TECHNOLOGY IN ORDER TO IMPROVE THE EFFICIENCY OF INFORMATION PROTECTION MEASURES AND ENSURE THE MANAGEMENT OF THE DEVELOPMENT OF COMPLEX SYSTEMS
Abstract and keywords
Abstract:
The article considers the possibility of using blockchain technology for automated maintenance of technical data sheets of information systems. An analysis of traditional documentation management methods has been carried out, and their disadvantages have been identified, including high time costs, audit complexity, and the risk of unauthorized data modification. The concept of an electronic technical passport system based on a decentralized registry and the use of smart contracts for automatic control of configuration changes and software updates is proposed. The simulation results showed that the introduction of blockchain technology reduces the processing time of changes from 4–6 hours with the traditional approach to 3–5 minutes, which is equivalent to speeding up the process by 50–100 times. The immutability of records, transparency of operations and automatic verification of data for compliance with security requirements are ensured. The developed system increases the efficiency of information security management, reduces the influence of the human factor and simplifies the audit process. The proposed solution is promising for implementation in mission-critical automated systems where strict control over the state and security of information resources is required. Further research may be aimed at integrating with threat monitoring systems and developing adaptive data access control mechanisms in the blockchain registry.

Keywords:
blockchain technology, technical data sheets, information systems, decentralized registry, smart contracts, change management, software configuration, data security, information security, process automation, immutability of records, audit control, threat monitoring, access control, management efficiency, automated systems, critical systems
Text
Text (PDF): Read Download
References

1. Ob utverzhdenii poryadka organizacii i provedeniya rabot po attestacii ob"ektov informatizacii na sootvetstvie trebovaniyam o zashchite informacii ogranichennogo dostupa, ne sostavlyayushchej gosudarstvennuyu tajnu: prikaz FSTEK Rossii ot 29 apr. 2021 g. № 77. URL: https://fstec.ru/dokumenty/vse-dokumenty/prikazy/prikaz-fstek-rossii-ot-29-aprelya-2021-g-n-77 (data obrashcheniya: 19.12.2025).

2. Losev V.S., Makarov A.E. Innovacionnoe znachenie primeneniya tekhnologii blokchejn v sisteme upravleniya // Vestnik Tihookeanskogo gosudarstvennogo universiteta. 2024. № 1 (72). S. 117–128.

3. Blockchain integration into electronic document management (EDM) system in construction common data environment / M.S. Kiu [et al.] // Smart and Sustainable Built Environment. 2024. Vol. 13. № 1. P. 117–132.

4. A cross-chain mechanism for agricultural engineering document management blockchain in the context of big data / L. Shi [et al.] // Big Data Research. 2024. Vol. 36. P. 100459.

5. Konceptual'nye osnovy ocenki urovnya zashchishchennosti avtomatizirovannyh sistem na osnove ih uyazvimosti / A.O. Efimov [i dr.] // Bezopasnost' informacionnyh tekhnologij. 2023. T. 30. № 2. S. 63–79. DOI:https://doi.org/10.26583/bit.2023.2.04

6. Komanov P.A., Revazov H.Yu., Tavasiev D.A. Issledovanie bezopasnosti smart-kontraktov Ethereum // Mezhdunarodnyj nauchno-issledovatel'skij zhurnal. 2021. № 1-1 (103). S. 80–83.

7. Yumasheva E.V., Yumashev D.V., Timonov D.A. Informacionnaya bezopasnost' v sistemah elektronnogo dokumentooborota s primeneniem tekhnologii blokchejn // Sovremennye naukoemkie tekhnologii. 2021. № 1. S. 63–68.

8. Klishin D.V., Chechulin A.A. Analiz standartov obespecheniya informacionnoj bezopasnosti // Sistemy analiza i obrabotki dannyh. 2023. № 1 (89). S. 37–54.

9. Livshic I.I., Baksheev A.S. Issledovanie metodik kontrolya urovnya zashchishchennosti informacii na ob"ektah kriticheskoj informacionnoj infrastruktury // Voprosy kiberbezopasnosti. 2022. № 6. S. 52.

10. Sirotskij A.A. Formalizovannaya model' audita informacionnoj bezopasnosti organizacii na predmet sootvetstviya trebovaniyam standartov // Bezopasnost' informacionnyh tekhnologij. 2021. T. 28. № 3. S. 103–117.

11. Information security and cybersecurity management: A case study with SMEs in Portugal / M. Antunes [et al.] // Journal of Cybersecurity and Privacy. 2021. Vol. 1. № 2. P. 219–238.

12. Effectiveness of cybersecurity audit / S. Slapničar [et al.] // International Journal of Accounting Information Systems. 2022. Vol. 44. P. 100548.

13. Shaikh F.A., Siponen M. Information security risk assessments following cybersecurity breaches: The mediating role of top management attention to cybersecurity // Computers & Security. 2023. Vol. 124. P. 102974.

14. IoT device security audit tools: A comprehensive analysis and a layered architecture approach for addressing expanded security requirements / A. Kumar [et al.] // International Journal of Information Security. 2025. Vol. 24. № 1. P. 1–22.

15. Osnovnye etapy proektirovaniya avtomatizirovannoj sistemy intellektual'nogo poiska mest narkoticheskih zakladok po otkrytym istochnikam / G.I. Zverev [i dr.] // Vestnik Voronezhskogo instituta MVD Rossii. 2024. № 4. S. 70–78.

16. Zverev G.I., Mishin S.A., Tuzhikova T.Yu. Osnovnye etapy razrabotki prototipa intellektual'noj sistemy detektirovaniya i klassifikacii ognestrel'nogo oruzhiya na fotoizobrazheniyah // Vestnik Voronezhskogo instituta MVD Rossii. 2025. № 1. S. 97–108.

Login or Create
* Forgot password?