IMPROVEMENT OF THE LOGISTICS RISK MANAGEMENT PROCESS FOR CRITICAL INFRASTRUCTURE ENTERPRISES
DOI:
https://doi.org/10.36910/p22jya05Keywords:
Keywords: ISO 28000, critical infrastructure, logistics risk management, supply chain resilience, integrated management systems, cyber physical convergence, infrastructure decentralization, business continuity.Abstract
Supply chains of critical infrastructure enterprises under contemporary conditions are characterized by high complexity, digitalization, and an increasing level of hybrid threats, which necessitates a transition from reactive to proactive approaches to logistics risk management. The purpose of this article is to improve the logistics risk management process within supply chain security management systems of critical infrastructure facilities through the implementation of the requirements of the international standard ISO 28000:2022.
The study employs systems analysis to examine supply chains as complex, interconnected ecosystems, as well as methods of mathematical and logical modeling to formalize risk assessment as a function of the probability of threat realization and the severity of its consequences. An improved logistics risk management process is proposed, based on the integration of the requirements of ISO 28000:2022, ISO 31000:2018, and ISO/IEC 27001:2022, with mandatory consideration of risks associated with the use of artificial intelligence in accordance with ISO/IEC 42001.
The improved process includes context definition and supply chain mapping using artificial intelligence tools; identification of assets and sources of threats with consideration of AI models and datasets; vulnerability analysis and assessment of incident probability; consequence analysis taking into account ethical and social AI risks; scenario simulation; development of security plans and risk treatment; as well as continuous system improvement considering the evolution of digital technologies. Practical implementation of the proposed approach is aimed at enhancing the resilience of critical infrastructure supply chains under conditions of dynamic risks and accelerated digitalization.