The purpose of the research is to develop a solution that allows optimizing the number and functionality of information security specialists involved in ensuring the information security of an automated system in a secure execution of the organization. The methods used in the article include a description and analysis of various governing documents, professional standards and regulations of the Russian Federation, and a number of scientific author's works that disclose the requirements for the functionality and qualifications of information security specialists. As a result of the work carried out, significant shortcomings were identified in the current regulatory and methodological documents describing the labor actions of personnel ensuring the protection of the facility's information, and a tendency to reduce the number of positions and simultaneously expand the functionality of the remaining employees. The need to comply with the qualification requirements for the reliable functioning of an automated system in a secure design and the exclusion of the "human" factor in information security incidents is emphasized. A new, optimal organizational structure of the department responsible for monitoring the protection of information circulating in an automated system is proposed, and the job responsibilities and areas of responsibility of the automated system administrator and the information security administrator are specified in detail. The solution presented in this paper can be used for daily information security in any automated system for various organizations. It emphasizes the importance of improving the skills and unifying the competencies of information security workers to ensure their interchangeability and reduce the risks associated with lack of control if highly specialized employees are excluded, which will increase the stability and effectiveness of the information security system at the enterprise.
Keywords: information security, administrator, staffing, functionality of information security personnel, automated system in a secure design