A METHODOLOGY FOR IDENTIFYING AND CLASSIFYING CRITICAL INFORMATION INFRASTRUCTURE OBJECTS
- Authors
-
-
Makhmudov Mirshod Bahodir ugli
Leading specialist, Angren University; applicant for the basic doctoral program (PhD)
-
- Keywords:
- information security critical information infrastructure state information systems risk assessment classification methodology
- Abstract
-
Uzbekistan's rapid digital transformation has increased the dependence of public administration, finance, energy and healthcare on state information systems, while cyber threats against government information resources have grown. The Cybersecurity Strategy for 2026–2030 prioritizes the protection of critical information infrastructure, yet existing legislation does not provide clear, measurable criteria for deciding which systems qualify as critical. This paper aims to develop a practical, criteria-based methodology for identifying critical information infrastructure objects among state information systems and classifying them into tiers. Drawing on international risk-based practice (ISO/IEC 27001, NIST SP 800-53 and the EU's EPCIP programme), the methodology has three steps: compiling a unified register of information systems; scoring each system from 1 to 5 against six weighted criteria (socio-economic impact, national-security impact, interdependency, redundancy, threat exposure and recovery time objective); and classifying it by its total weighted score. Weights are to be set by an expert panel through a Delphi-style consensus process. The model separates systems into Tier I (critical, 4.00–5.00), Tier II (significant, 2.50–3.99) and Tier III (limited, 1.00–2.49), each linked to a proportionate level of oversight, from mandatory audits to baseline self-assessment. Unlike general impact-categorization schemes, it explicitly accounts for interdependency and national-security considerations. The proposed weights and thresholds remain a methodological proposal requiring empirical validation and sensitivity analysis. The methodology gives agencies a transparent, shared framework for directing limited resources to the systems that matter most
- References
-
[1] President of the Republic of Uzbekistan, “On defining the Cybersecurity Strategy of the Republic of Uzbekistan and improving the system for preventing cybercrime,” Decree No. PF-38, Mar. 10, 2026. [Online]. Available: https://lex.uz/
[2] Republic of Uzbekistan, “On cybersecurity,” Law of the Republic of Uzbekistan. [Online]. Available: https://lex.uz/
[3] International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 27001:2022: Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements, 3rd ed. Geneva, Switzerland: ISO, 2022.
[4] National Institute of Standards and Technology, Security and Privacy Controls for Information Systems and Organizations, NIST Special Publication 800-53, Rev. 5. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2020.
[5] C. Pascoe, S. Quinn, and K. Scarfone, The NIST Cybersecurity Framework (CSF) 2.0, NIST Cybersecurity White Paper 29. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2024, doi: 10.6028/NIST.CSWP.29.
[6] European Commission, “European Programme for Critical Infrastructure Protection (EPCIP),” Directorate-General for Migration and Home Affairs, Brussels, Belgium. [Online]. Available: https://eur-lex.europa.eu/.
[7] Ministry of Digital Technologies of the Republic of Uzbekistan, “Digital Uzbekistan—2030 strategy.” [Online]. Available: https://digital.gov.uz/.
[8] European Commission, “Critical infrastructure resilience at EU-level,” Directorate-General for Migration and Home Affairs, Jan. 13, 2026. [Online]. Available: https://home-affairs.ec.europa.eu/.
[9] European Commission, “On a European Programme for Critical Infrastructure Protection,” COM(2006) 786 final, Dec. 12, 2006. [Online]. Available: https://eur-lex.europa.eu/.
[10] P. Cichonski, T. Millar, T. Grance, and K. Scarfone, Computer Security Incident Handling Guide, NIST Special Publication 800-61, Rev. 2. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2012. [Online]. Available: https://csrc.nist.gov/.
[11] K. Rigopoulos, S. Quinn, C. Pascoe, J. Marron, A. Mahn, and D. Topper, NIST Cybersecurity Framework 2.0: Resource & Overview Guide, NIST Special Publication 1299. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2024, doi: 10.6028/NIST.SP.1299.
[12] National Institute of Standards and Technology, Cybersecurity Framework 2.0. Gaithersburg, MD, USA: National Institute of Standards and Technology, 2024. [Online]. Available: https://www.nist.gov/cyberframework.
[13] B. N. Tahirov, Fundamentals of Information Security: A Textbook. Bukhara, Uzbekistan: Fan va Ta'lim, 2022, 156 p.
[14] President of the Republic of Uzbekistan, “On the strategy ‘Uzbekistan—2030’,” Presidential Decree. [Online]. Available: https://president.uz/.
[15] European Commission, “Commission issues guidance to strengthen resilience of critical infrastructure,” Directorate-General for Migration and Home Affairs, Jul. 10, 2026. [Online]. Available: https://home-affairs.ec.europa.eu/
