Abstract

Uzbekistan's rapid digital transformation has increased the dependence of public administration, finance, energy and healthcare on state information systems, while cyber threats against government information resources have grown. The Cybersecurity Strategy for 2026–2030 prioritizes the protection of critical information infrastructure, yet existing legislation does not provide clear, measurable criteria for deciding which systems qualify as critical. This paper aims to develop a practical, criteria-based methodology for identifying critical information infrastructure objects among state information systems and classifying them into tiers. Drawing on international risk-based practice (ISO/IEC 27001, NIST SP 800-53 and the EU's EPCIP programme), the methodology has three steps: compiling a unified register of information systems; scoring each system from 1 to 5 against six weighted criteria (socio-economic impact, national-security impact, interdependency, redundancy, threat exposure and recovery time objective); and classifying it by its total weighted score. Weights are to be set by an expert panel through a Delphi-style consensus process. The model separates systems into Tier I (critical, 4.00–5.00), Tier II (significant, 2.50–3.99) and Tier III (limited, 1.00–2.49), each linked to a proportionate level of oversight, from mandatory audits to baseline self-assessment. Unlike general impact-categorization schemes, it explicitly accounts for interdependency and national-security considerations. The proposed weights and thresholds remain a methodological proposal requiring empirical validation and sensitivity analysis. The methodology gives agencies a transparent, shared framework for directing limited resources to the systems that matter most

Keywords
information security critical information infrastructure state information systems risk assessment classification methodology