UDC 004.056
The active implementation of electronic document management systems in the activities of organizations of various profiles necessitates the provision of a high level of security for processed information resources. The paper presents the development of the methodological foundations of organizational and technological management of the subsystem for the protection of information resources in electronic document management systems. A conceptual model is proposed that describes a two-circuit control structure, including a control loop for a set of software protection tools and a control loop for the protection subsystem itself. The task of management optimization is formulated, the criterion of which is the maximization of an integral indicator of the effectiveness of the information resource protection subsystem, combining qualitative and quantitative characteristics. The indicator of temporary non-conflict is described in detail, for the assessment of which the apparatus of semi-Markov processes is used. A methodology has been developed for organizational and technological management of the effectiveness of the subsystem for the protection of information resources based on a purposeful change in key controlled parameters that affect the dynamics of the subsystem's functioning. An appropriate algorithm has been created to search for optimal values of the controlled parameters of the information resources protection subsystem of the electronic document management system. The results of computational experiments are presented, demonstrating the nature of the influence of various parameters on the resulting efficiency. The proposed solutions form the basis for the creation of automated decision support systems for managing the information security of electronic document management systems.
Organizational and technological management, electronic document management system, information security, operational efficiency, optimization, semi-Markov model, temporary non-conflict
1. GOST R ISO/IEC 15408-1-2012. The national standard of the Russian Federation. Information technology. Methods and means of ensuring safety. Criteria for assessing the security of information technologies. Part 1. Introduction and general model. (approved and put into effect by Rosstandart Order No. 814-st dated 11/15/2012).
2. GOST R ISO/IEC 15408-2-2013. The national standard of the Russian Federation. Information technology. Methods and means of ensuring safety. Criteria for assessing the security of information technologies. Part 2. Functional Safety Components" (approved and put into effect by Rosstandart Order No. 1339-st dated 11/08/2013).
3. GOST R 50922-2006. Information protection. Basic terms and definitions. – M.: Standartinform, 2007. – 8 p.
4. Guidance document. Automated systems. Protection against unauthorized access to information. Classification of automated systems and information protection requirements. Moscow: State Technical Commission of Russia, 1992. 42 p.
5. Novikov, D. A. Theory of management of organizational systems. 4th ed., ispr. and supplement– Moscow: LENAND, 2022. 500 p
6. Zastrozhnov, I.I. Methodological foundations of the safety of using information technologies in electronic document management systems: monography / I.I. Zastrozhnov, E.A. Rogozin, M.A. Bagaev. – Voronezh: CPI "Scientific Book", 2011. – 252 p.
7. Melnikov, V.P. Information security and information protection: a textbook for students. institutions of higher Prof. education / V.P. Melnikov, S.A. Kleimenov, A.M. Petrakov. – M.: Publishing center "Academy", 2012. – 336 p.
8. Domarev, V.V. Security of information technologies. A systematic approach / V.V. Domarev. – K.: OOO "TID "DS", 2004. – 992 p.
9. Khoroshko, V.A. Methods and means of information protection / V.A. Khoroshko, A.A. Chekatkov. – K.: Publishing house "Junior", 2003. – 504 p.
10. Zegzhda, D.P. Fundamentals of information systems security / D.P. Zegzhda, A.M. Ivashko. Moscow: Goryachaya liniya – Telecom, 2000. 452 p.
11. Belov, E.B. Fundamentals of information security: a textbook for universities / E.B. Belov, V.P. Los, R.V. Meshcheryakov, A.A. Shelupanov. Moscow: Goryachaya liniya – Telecom, 2011. 548 p.
12. Shangin, V.F. Information security and information protection / V.F. Shangin. Saratov: Vocational Education, 2017. 277 p.
13. Shcherbakov, A.Y. Modern computer security. Theoretical foundations. Practical aspects / A.Y. Shcherbakov, Moscow: Knizhny Mir Publ., 2021, 352 p.
14. Kort, S.S. Theoretical foundations of information protection / S.S. Kort. – M.: Helios ARV, 2004. – 240 p.
15. Ryabko, B.Ya. Cryptographic methods of information protection / B.Ya. Ryabko, A.N. Fionov. Moscow: Hotline - Telecom, 2012. 229 p.
16. Malyuk, A.A. Information security: conceptual and methodological foundations of information protection / A.A. Malyuk. Moscow: Hotline - Telecom, 2004. 280 p.
17. Galatenko, V. A. Fundamentals of information security: a textbook / V. A. Galatenko. — 4th ed. — Moscow: Internet University of Information Technologies (INTUIT), AI Art Media, 2024. — 266 p. — ISBN 978-5-4497-3316-0. — Text: electronic // Electronic resource of the digital educational environment of vocational education: [website]. — URL: https://profspo.ru/books/142285 (date of request: 03/26/2026). — Access mode: for authorization. Polovateleykhorev, P.B. Methods and means of information protection in computer systems / P.B. Khorev. Moscow: Academia, 2021. 256 p.
18. Platonov, V.V. Software and hardware for ensuring information security of computational networks: a textbook / V.V. Platonov. Moscow: INFRA-M, 2006. 240 p.
19. Proskurin V. G. Protection in operating systems / V.G. Proskurin. - Moscow: Hotline–Telecom, 2014. - 192 p. - ISBN 978-5-9912-0379-1. - URL: https://ibooks.ru/bookshelf/344419/reading (date of notification: 03/26/2026). - Text: electronic.
20. Korolyuk, V.S. Semimarkov processes and their applications / V.S. Korolyuk, A.F. Turbin. Kiev: Naukova Dumka Publ., 1976. 184 p.



