<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.3 20210610//EN" "JATS-journalpublishing1-3.dtd">
<article article-type="research-article" dtd-version="1.3" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xml:lang="ru"><front><journal-meta><journal-id journal-id-type="publisher-id">kaz44</journal-id><journal-title-group><journal-title xml:lang="ru">Вестник Университета Шакарима. Серия технические науки</journal-title><trans-title-group xml:lang="en"><trans-title>Bulletin of Shakarim University. Technical Sciences</trans-title></trans-title-group></journal-title-group><issn pub-type="ppub">2788-7995</issn><issn pub-type="epub">3006-0524</issn><publisher><publisher-name>«Шәкәрім университеті» КеАҚ</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.53360/2788-7995-2026-1(21)-15</article-id><article-id custom-type="elpub" pub-id-type="custom">kaz44-2302</article-id><article-categories><subj-group subj-group-type="heading"><subject>Research Article</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="ru"><subject>АВТОМАТИЗАЦИЯ И ИНФОРМАЦИОННЫЕ ТЕХНОЛОГИИ (ОРИГИНАЛЬНАЯ СТАТЬЯ)</subject></subj-group><subj-group subj-group-type="section-heading" xml:lang="en"><subject>AUTOMATION AND INFORMATION TECHNOLOGY (ORIGINAL ARTICLE)</subject></subj-group></article-categories><title-group><article-title>ОПТИМИЗАЦИЯ ПРОЦЕССОВ КОНТРОЛЯ И УПРАВЛЕНИЯ В СИСТЕМЕ КОНТРОЛЯ И УПРАВЛЕНИЯ ДОСТУПОМ КОНГРЕСС-ХОЛЛА «АУЛИЕ-АТА»</article-title><trans-title-group xml:lang="en"><trans-title>OPTIMIZATION OF CONTROL AND MANAGEMENT PROCESSES IN THE ACCESS CONTROL AND MANAGEMENT SYSTEM OF THE AULIE-ATA CONGRESS HALL</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><contrib-id contrib-id-type="orcid">https://orcid.org/0009-0003-5491-2160</contrib-id><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Сарсенов</surname><given-names>Б. С.</given-names></name><name name-style="western" xml:lang="en"><surname>Sarsenov</surname><given-names>B. S.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Батырхан Саматұлы Сарсенов – магистрант </p><p>010000, г. Астана, ул. Александра Пушкина, 11</p></bio><bio xml:lang="en"><p>Batyrkhan Samatuly Sarsenov – Master's student </p><p>010000, Astana, Alexander Pushkin St., 11</p></bio><email xlink:type="simple">batyr.sarsenov@gmail.com</email><xref ref-type="aff" rid="aff-1"/></contrib><contrib contrib-type="author" corresp="yes"><name-alternatives><name name-style="eastern" xml:lang="ru"><surname>Жамангарин</surname><given-names>Д.</given-names></name><name name-style="western" xml:lang="en"><surname>Zhamangarin</surname><given-names>D.</given-names></name></name-alternatives><bio xml:lang="ru"><p>Дусмат Жамангарин – PhD </p><p>010000, г. Астана, ул. Александра Пушкина, 11</p></bio><bio xml:lang="en"><p>Dusmat Zhamangarin — PhD </p><p>010000, Astana, Alexander Pushkin St., 11</p></bio><email xlink:type="simple">Dusmat_zhamangarin@vk.com</email><xref ref-type="aff" rid="aff-1"/></contrib></contrib-group><aff-alternatives id="aff-1"><aff xml:lang="ru"><institution>Евразийский национальный университет имени Л.Н. Гумилева</institution><country>Казахстан</country></aff><aff xml:lang="en"><institution>L.N. Gumilyov Eurasian National University</institution><country>Kazakhstan</country></aff></aff-alternatives><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>25</day><month>05</month><year>2026</year></pub-date><volume>1</volume><issue>1(21)</issue><fpage>135</fpage><lpage>145</lpage><permissions><copyright-statement>Copyright &amp;#x00A9; Сарсенов Б.С., Жамангарин Д., 2026</copyright-statement><copyright-year>2026</copyright-year><copyright-holder xml:lang="ru">Сарсенов Б.С., Жамангарин Д.</copyright-holder><copyright-holder xml:lang="en">Sarsenov B.S., Zhamangarin D.</copyright-holder><license xml:lang="ru" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>Данная работа распространяется под лицензией Creative Commons Attribution 4.0.</license-p></license><license xml:lang="en" license-type="creative-commons-attribution" xlink:href="https://creativecommons.org/licenses/by/4.0/" xlink:type="simple"><license-p>This work is licensed under a Creative Commons Attribution 4.0 License.</license-p></license></permissions><self-uri xlink:href="https://tech.vestnik.shakarim.kz/jour/article/view/2302">https://tech.vestnik.shakarim.kz/jour/article/view/2302</self-uri><abstract><p>В статье рассматривается задача повышения эффективности и надёжности процессов контроля и управления в системе контроля и управления доступом (СКУД) на примере объекта общественного назначения – Конгресс-Холла «Аулие-Ата». Выполнен обзор типовых архитектур СКУД и нормативных требований к информационной безопасности и инженерным системам безопасности. Показано, что на объектах с высокой плотностью посетителей и смешанными сценариями доступа (сотрудники, подрядчики, гости, массовые мероприятия) ключевыми проблемами являются задержки принятия решений, несогласованность правил, недостаточная интеграция с видеонаблюдением и пожарной автоматикой, а также ограниченная аналитика событий. Предложен комплекс оптимизационных мер: переход к событийно-ориентированной обработке (event-driven), разгрузка сервера за счёт локальных контроллеров и кэширования правил, применение гибридной модели управления доступом RBAC+ABAC с адаптивной оценкой риска, унификация журналирования и интеграция через API/шину сообщений с СВН, ОПС и системами учёта. Сформулирован алгоритм обработки события доступа и представлена структурная схема интеграций. Эффективность решений оценивалась моделированием потоков запросов и сравнением с базовым вариантом: достигнуто снижение среднего времени обработки события на 25-35%, уменьшение доли отказов из-за «таймаутов» и повышение полноты протоколирования инцидентов. Результаты могут быть использованы при проектировании и модернизации СКУД объектов массового пребывания людей.</p></abstract><trans-abstract xml:lang="en"><p>The article discusses the task of improving the efficiency and reliability of control and management processes in the access control and management system (ACMS) using the example of a public facility, the Congress Hall "Aulie-Ata". The article provides an overview of typical ACMS architectures and regulatory requirements for information security and engineering security systems. It has been shown that at facilities with a high density of visitors and mixed access scenarios (employees, contractors, guests, and mass events), the key problems are decision delays, inconsistent rules, insufficient integration with video surveillance and fire automation, and limited event analytics. A set of optimization measures is proposed: transition to eventoriented processing (event-driven), server offloading due to local controllers and rule caching, application of a hybrid RBAC+ABAC access control model with adaptive risk assessment, unification of logging and integration via API/bus.</p></trans-abstract><kwd-group xml:lang="ru"><kwd>СКУД</kwd><kwd>контроль доступа</kwd><kwd>оптимизация</kwd><kwd>RBAC</kwd><kwd>ABAC</kwd><kwd>оценка риска</kwd><kwd>интеграция</kwd><kwd>event-driven</kwd><kwd>аудит</kwd></kwd-group><kwd-group xml:lang="en"><kwd>access control</kwd><kwd>ACMS</kwd><kwd>optimization</kwd><kwd>RBAC</kwd><kwd>ABAC</kwd><kwd>risk scoring</kwd><kwd>integration</kwd><kwd>event-driven</kwd><kwd>audit</kwd></kwd-group></article-meta></front><back><ref-list><title>References</title><ref id="cit1"><label>1</label><citation-alternatives><mixed-citation xml:lang="ru">Security Industry Association (SIA). Open Supervised Device Protocol (OSDP) v2.2 – Technical Specification. Silver Spring, MD: SIA, 2017.</mixed-citation><mixed-citation xml:lang="en">Security Industry Association (SIA). Open Supervised Device Protocol (OSDP) v2.2 – Technical Specification. Silver Spring, MD: SIA, 2017. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit2"><label>2</label><citation-alternatives><mixed-citation xml:lang="ru">Role-Based Access Control Models / R.S. Sandhu et al // IEEE Computer. – 1996. – Vol. 29, № 2. – P. 38-47.</mixed-citation><mixed-citation xml:lang="en">Role-Based Access Control Models / R.S. Sandhu et al // IEEE Computer. – 1996. – Vol. 29, № 2. – P. 38-47. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit3"><label>3</label><citation-alternatives><mixed-citation xml:lang="ru">Hu V.C. Assessment of Access Control Systems / V.C. Hu, D. Ferraiolo, R. Kuhn // NIST Interagency Report 7316. Gaithersburg, MD: NIST, 2006.</mixed-citation><mixed-citation xml:lang="en">Hu V.C. Assessment of Access Control Systems / V.C. Hu, D. Ferraiolo, R. Kuhn // NIST Interagency Report 7316. Gaithersburg, MD: NIST, 2006. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit4"><label>4</label><citation-alternatives><mixed-citation xml:lang="ru">McGraw R. Risk-Adaptable Access Control (RAdAC) / R. McGraw // Security and Privacy in Dynamic Environments. IEEE, 2009.</mixed-citation><mixed-citation xml:lang="en">McGraw R. Risk-Adaptable Access Control (RAdAC) / R. McGraw // Security and Privacy in Dynamic Environments. IEEE, 2009. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit5"><label>5</label><citation-alternatives><mixed-citation xml:lang="ru">Гончаров А.В. Системы контроля и управления доступом: проектирование и эксплуатация / А.В. Гончаров. – М.: ИНФРА-М, 2021.</mixed-citation><mixed-citation xml:lang="en">Goncharov A.V. Sistemy kontrolya i upravleniya dostupom: proektirovanie i ehkspluatatsiya / A.V. Goncharov. – M.: INFRA-M, 2021. (In Russian).</mixed-citation></citation-alternatives></ref><ref id="cit6"><label>6</label><citation-alternatives><mixed-citation xml:lang="ru">Сидоров Н.Н. Интеллектуальные системы безопасности: методы анализа событий и предотвращения инцидентов / Н.Н. Сидоров. – СПб.: Питер, 2020.</mixed-citation><mixed-citation xml:lang="en">Sidorov N.N. Intellektual'nye sistemy bezopasnosti: metody analiza sobytii i predotvrashcheniya intsidentov / N.N. Sidorov. – SPb.: Piter, 2020. (In Russian).</mixed-citation></citation-alternatives></ref><ref id="cit7"><label>7</label><citation-alternatives><mixed-citation xml:lang="ru">Zhang H. Event-Driven Architectures for Security Monitoring: A Survey and Practical Considerations / H. Zhang, J. Li // IEEE Access. – 2021. – Vol. 9. – P. 102340-102356.</mixed-citation><mixed-citation xml:lang="en">Zhang H. Event-Driven Architectures for Security Monitoring: A Survey and Practical Considerations / H. Zhang, J. Li // IEEE Access. – 2021. – Vol. 9. – P. 102340-102356. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit8"><label>8</label><citation-alternatives><mixed-citation xml:lang="ru">Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications / A. Al-Fuqaha et al // IEEE Communications Surveys &amp; Tutorials. – 2015. – Vol. 17, № 4. – P. 2347-2376.</mixed-citation><mixed-citation xml:lang="en">Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications / A. Al-Fuqaha et al // IEEE Communications Surveys &amp; Tutorials. – 2015. – Vol. 17, № 4. – P. 2347-2376. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit9"><label>9</label><citation-alternatives><mixed-citation xml:lang="ru">Chen X. Integrating Access Control Events with Video Analytics for Incident Response / X. Chen, Y. Zhang // Journal of Security and Networks. – 2022. – Vol. 17, № 3. – P. 145-158.</mixed-citation><mixed-citation xml:lang="en">Chen X. Integrating Access Control Events with Video Analytics for Incident Response / X. Chen, Y. Zhang // Journal of Security and Networks. – 2022. – Vol. 17, № 3. – P. 145-158. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit10"><label>10</label><citation-alternatives><mixed-citation xml:lang="ru">Kent K. Guide to Computer Security Log Management / K. Kent, M. Souppaya // NIST Special Publication 800-92. Gaithersburg, MD: NIST, 2006. – 72 p.</mixed-citation><mixed-citation xml:lang="en">Kent K. Guide to Computer Security Log Management / K. Kent, M. Souppaya // NIST Special Publication 800-92. Gaithersburg, MD: NIST, 2006. – 72 p. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit11"><label>11</label><citation-alternatives><mixed-citation xml:lang="ru">ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection – Information security management systems – Requirements. Geneva: ISO, 2022.</mixed-citation><mixed-citation xml:lang="en">ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection – Information security management systems – Requirements. Geneva: ISO, 2022. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit12"><label>12</label><citation-alternatives><mixed-citation xml:lang="ru">ISO/IEC 27002:2022. Information security, cybersecurity and privacy protection – Information security controls. Geneva: ISO, 2022.</mixed-citation><mixed-citation xml:lang="en">ISO/IEC 27002:2022. Information security, cybersecurity and privacy protection – Information security controls. Geneva: ISO, 2022. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit13"><label>13</label><citation-alternatives><mixed-citation xml:lang="ru">IEC 60839-11-1:2013. Alarm and electronic security systems – Part 11-1: Electronic access control systems – System and components requirements. Geneva: IEC, 2013.</mixed-citation><mixed-citation xml:lang="en">IEC 60839-11-1:2013. Alarm and electronic security systems – Part 11-1: Electronic access control systems – System and components requirements. Geneva: IEC, 2013. (In English).</mixed-citation></citation-alternatives></ref><ref id="cit14"><label>14</label><citation-alternatives><mixed-citation xml:lang="ru">National Institute of Standards and Technology. Security and Privacy Controls for Information Systems and Organizations. NIST Special Publication 800-53 Rev. 5. Gaithersburg, MD: NIST, 2020.</mixed-citation><mixed-citation xml:lang="en">National Institute of Standards and Technology. Security and Privacy Controls for Information Systems and Organizations. NIST Special Publication 800-53 Rev. 5. Gaithersburg, MD: NIST, 2020. (In English).</mixed-citation></citation-alternatives></ref></ref-list><fn-group><fn fn-type="conflict"><p>The authors declare that there are no conflicts of interest present.</p></fn></fn-group></back></article>
