Russia, lastly, has a well-established system of information security standards. A system used to handle nuclear material data is expected to satisfy to the criteria required by these standards. This conformity is subject to verification by qualification tests. There are also industry standards and guides in effect at the enterprise level. These contain requirements to be also taken into account.
Therefore, a secure information processing system [2], specifically a computerized NM A&C system, should satisfy to the following three requirements and, subject to these, is expected to:
∙automate confidential data handling processes, including all aspects thereof involved in ensuring security of the data processed;
∙counter security threats that act in a particular environment;
∙meet the requirements and criteria of security information standards.
Secure information processing systems should ensure information security. Information security, as viewed by the expert community, is security of the information environment that supports its formation and evolution in the interests of an organization or the state. Prevention of information security threats and response to these is achieved through a combination of organizational, legal, technical and technological measures known, collectively, as information protection features.
8.2. Information protection in accounting and control of nuclear material
In recent years, security of information technologies has been the cause of an increasingly growing concern, while analytical surveys show a yearly increasing damage from security violations. Here are some figures to illustrate the level of damage from computer viruses for the several past years. The virus-caused damage was about 13 billion US dollars in 2001 and 20 to 30 billion in 2002 reaching, a year later, 55 billion. Nearly the same was the damage, as some estimates show, from the Mydom virus in January 2004. Therefore, there is every reason to speak about a crisis in the field of IT security.
The security crisis has its roots in the rapidly evolving information technologies and the security provisions lagging behind the technological advances both in theoretical and practical terms. The huge computational capabilities of modern computer systems are combined with the handiness of these. The formation of the global information environment makes information resources accessible to a great number of differently skilled users. Most users are not competent enough to keep security of their