OPTIMIZATION OF CONTROL AND MANAGEMENT PROCESSES IN THE ACCESS CONTROL AND MANAGEMENT SYSTEM OF THE AULIE-ATA CONGRESS HALL
https://doi.org/10.53360/2788-7995-2026-1(21)-15
Abstract
The article discusses the task of improving the efficiency and reliability of control and management processes in the access control and management system (ACMS) using the example of a public facility, the Congress Hall "Aulie-Ata". The article provides an overview of typical ACMS architectures and regulatory requirements for information security and engineering security systems. It has been shown that at facilities with a high density of visitors and mixed access scenarios (employees, contractors, guests, and mass events), the key problems are decision delays, inconsistent rules, insufficient integration with video surveillance and fire automation, and limited event analytics. A set of optimization measures is proposed: transition to eventoriented processing (event-driven), server offloading due to local controllers and rule caching, application of a hybrid RBAC+ABAC access control model with adaptive risk assessment, unification of logging and integration via API/bus.
Keywords
About the Authors
B. S. SarsenovKazakhstan
Batyrkhan Samatuly Sarsenov – Master's student
010000, Astana, Alexander Pushkin St., 11
D. Zhamangarin
Kazakhstan
Dusmat Zhamangarin — PhD
010000, Astana, Alexander Pushkin St., 11
References
1. Security Industry Association (SIA). Open Supervised Device Protocol (OSDP) v2.2 – Technical Specification. Silver Spring, MD: SIA, 2017. (In English).
2. Role-Based Access Control Models / R.S. Sandhu et al // IEEE Computer. – 1996. – Vol. 29, № 2. – P. 38-47. (In English).
3. Hu V.C. Assessment of Access Control Systems / V.C. Hu, D. Ferraiolo, R. Kuhn // NIST Interagency Report 7316. Gaithersburg, MD: NIST, 2006. (In English).
4. McGraw R. Risk-Adaptable Access Control (RAdAC) / R. McGraw // Security and Privacy in Dynamic Environments. IEEE, 2009. (In English).
5. Goncharov A.V. Sistemy kontrolya i upravleniya dostupom: proektirovanie i ehkspluatatsiya / A.V. Goncharov. – M.: INFRA-M, 2021. (In Russian).
6. Sidorov N.N. Intellektual'nye sistemy bezopasnosti: metody analiza sobytii i predotvrashcheniya intsidentov / N.N. Sidorov. – SPb.: Piter, 2020. (In Russian).
7. Zhang H. Event-Driven Architectures for Security Monitoring: A Survey and Practical Considerations / H. Zhang, J. Li // IEEE Access. – 2021. – Vol. 9. – P. 102340-102356. (In English).
8. Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications / A. Al-Fuqaha et al // IEEE Communications Surveys & Tutorials. – 2015. – Vol. 17, № 4. – P. 2347-2376. (In English).
9. Chen X. Integrating Access Control Events with Video Analytics for Incident Response / X. Chen, Y. Zhang // Journal of Security and Networks. – 2022. – Vol. 17, № 3. – P. 145-158. (In English).
10. Kent K. Guide to Computer Security Log Management / K. Kent, M. Souppaya // NIST Special Publication 800-92. Gaithersburg, MD: NIST, 2006. – 72 p. (In English).
11. ISO/IEC 27001:2022. Information security, cybersecurity and privacy protection – Information security management systems – Requirements. Geneva: ISO, 2022. (In English).
12. ISO/IEC 27002:2022. Information security, cybersecurity and privacy protection – Information security controls. Geneva: ISO, 2022. (In English).
13. IEC 60839-11-1:2013. Alarm and electronic security systems – Part 11-1: Electronic access control systems – System and components requirements. Geneva: IEC, 2013. (In English).
14. National Institute of Standards and Technology. Security and Privacy Controls for Information Systems and Organizations. NIST Special Publication 800-53 Rev. 5. Gaithersburg, MD: NIST, 2020. (In English).
Review
For citations:
Sarsenov B.S., Zhamangarin D. OPTIMIZATION OF CONTROL AND MANAGEMENT PROCESSES IN THE ACCESS CONTROL AND MANAGEMENT SYSTEM OF THE AULIE-ATA CONGRESS HALL. Bulletin of Shakarim University. Technical Sciences. 2026;1(1(21)):135-145. (In Russ.) https://doi.org/10.53360/2788-7995-2026-1(21)-15
JATS XML















