
http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
김영화 목원대학교 산업정보대학원 2008 국내석사
Development strategies of military information protection in order to cope with the cyber war and terror are very essential in new military environment. Therefore, we have to consider new paradigm war patterns based on new developed IT(Information Technology). The threats are very critical to new environment including wire and wireless equipment. Nowadays, many researcher concentrate on new technology to solve the threats due to changed war patterns in ubiquitous environment. We have to make new plan for improving overall military information protection at the level of the Ministry of National Defense/Joint Chiefs of Staff with regard to "improvement in the information protection policy/institution", "the strengthening of information protection and organizations/human resources for conducting the cyber-war", "the construction of the information protection system", and "the securing of core technology". To provide policy and establishment of institution, we should establish multi-level and multi-stratum information protection promotion strategies. Also, we have to construct the technological structure in order to implement the strategies, establish high technology protection policies and countermeasures against cyber war. In terms of organizations and human resources, we should strengthen organizations with powerful responsibility for information protection and increase professional staffs and educate them by considering quality and quantity. With regard to the construction of the national information protection system, we should follow many rules according to military information protection technology structure. The order to secure mutual management between network timing systems, and expand the application of electronic data drain prevention systems, we need to strengthen the cyber war simulation training system and education for training actively to cope with treats to the systems. Development strategy of national defense information security in ubiquitous environment is presented in this dissertation. Specially, in air force, requirements to construct and management to protect the information system against cyber war are focus on the headquarter control to concentrate their command. This leads to requirement of information security technology in order to protect outside intrusion and threats. 본 논문에서는 정보통신기술 발전에 따라 변화된 전쟁양상과 이로 인한 정보보호 위협의 변화, 그리고 이러한 위협에 효과적으로 대처하기 위한 정보보호 발전방안에 대한 고찰을 통하여 사이버전 대응능력 완비를 위한 국방정보보호 발전 방향을 도출하였다. 우선 전쟁양상 변화에 따른 위협의 변화를 파악하고 군의 전체적인 차원에서 취할 수 있는 국방부/합참 차원의 군 전반적인 국방 정보보호 발전 방향에 대하여 ‘정보보호 정책/제도 발전’, ‘정보보호 및 사이버전 수행 조직/인력 강화’, ‘정보보호체계 구축’, 그리고 ‘핵심기술 확보’ 측면에서 주요 내용을 도출하였다. 정책/제도 측면에서는 날로 고도화되는 사이버위협에 대응하기 위한 다수준?다계층 정보보호 추진전략을 정립 및 이를 수행하기 위한 기술구조 수립과 첨단 IT 기술 보호정책 수립, 그리고 사이버전 대응정책 및 수행절차 수립을 하여야 하며, 조직/인력 측면에서는 정보보호 전담조직을 강화하고 정보보호 전문 인력의 선발 확대 및 교육을 강화해야 한다. 정보보호체계 구축 측면에서는 각 체계의 네트워크화 구성시 각 체계간 상호운용성 보장을 위하여 국방정보체계 기술구조를 준수하고 또한 전자자료 유출 방지체계의 적용을 확대하며 체계에 대한 테스트 및 위협에 대한 능동적 대응을 위한 사이버전 모의 훈련체계 구축 및 교육훈련을 강화해야 하며, 마지막으로 이를 지원할 수 있도록 사이버전 수행을 위한 방호 빛 대응능력 및 정보보호 기반 기술의 핵심기술을 확보하여야 한다. 또한 공군 차원에서는 미래 사이버 전장공간에서 실제 정보보호체계를 구축하고 운영하는데 있어서 필요한 중앙 부서로서 착안사항 및 각 제대별로 작전 수행시 겪게 되는 한계를 극복하고 현 능력을 보완하기 위해 필요한 요구사항을 도출하였다.
금융기관의 개인정보 유출 방지를 위한 기술적 적용 방안 연구
김준호 동국대학교 국제정보보호대학원 2025 국내석사
금융기관은 고객의 금융거래 정보를 비롯한 민감한 개인정보를 대량으로 보유하고 있어 그 중요성은 매우 크다. 개인정보는 금융서비스 제공의 핵심 자원으로서, 이를 안전하게 보호하는 것은 금융기관의 책무이다. 개인정보를 보호하기 위한 수단으로 다양한 법률과 규제를 적용받고 있는 금융사에서 가장 큰 개인정보 유출 사건으로 2014년 사상 최대의 “카드 3사 개인정보 유출” 사건이 발생하였다. 이후 개인정보 보호 관련 제도들이 보완되었으며, 정보보호 관리체계를 강화하는 등 다양한 노력을 해온 결과 개인정보 유출 사고 건수는 이전보다 많이 줄어들었다. 하지만 개인정보 유출 사고는 현재까지 지속적으로 발생하고 있다. 사례로는 1)외주 협력업체를 통한 유출, 2)내부 직원 및 시스템 오류에 의한 유출, 3)외부 공격자에 의한 유출 등이 있으며, 상대적으로 보안 수준이 낮은 저축은행에서 개인정보 유출 사고 빈도가 높지만 대기업에서도 예외 없이 발생하고 있다. 이처럼 충분한 테스트와 검증이 부족하거나 업무에 과도한 권한 부여로 개인정보 유출 사고가 발생하였으며, 정보보호 관리체계에 대한 지적을 피할 수 없게 되었다. 이를 방지하기 위해서 관리적 체계 부분을 상호 보완하여 기술적으로 자동화 하는 방안을 검토할 필요성이 있다. 내부망 PC와 서버의 개인정보가 유출되지 않도록 기술적 보안 솔루션을 적용하고 주기적으로 점검하는 등 관리적 대책을 적용하고 있지만 적합한 승인 절차를 통해 유출된 개인정보에 대해서는 악의적인 목적으로 사용되더라도 뒤늦게 발견될 수밖에 없다. 마치 CCTV 사각지대에서 범죄가 일어났을 경우 경찰이 순찰을 주기적으로 하더라도 이미 범인은 사건 현장을 훼손하고 도주한다면 골든타임을 놓치게 되는 상황을 예시로 들 수 있다. 이를 예방하기 위해 사각지대 없이 CCTV를 설치하는 대응처럼 개인정보 보호 관련 보안 솔루션을 구축하고, 통합 모니터링 솔루션에 연동하여, 개인정보가 사용되는 기본 업무 외에 대량의 복호화나 반출이 수행되는 상황을 사각지대 없이 모니터링 되어야 한다. 개인정보가 유출되어 판매 또는 범죄에 이용된 후에 주기적인 점검이 수행되고 대응하더라도 골든타임이 지난 만큼 피해 규모는 커질 수 있다. 유출이 발생하는 즉시 개인정보보호 담당자에게 알람을 발생시키고, 골든타임 내에 상황을 해결하는 등 피해를 사전에 감지하고 대응하는 방안을 적용해야 한다. Financial institutions have a large amount of sensitive personal information, including customer financial transaction information, so its importance is very significant. Personal information is a key resource in providing financial services, and it is the responsibility of financial institutions to protect it safely. As the largest personal information leakage incident in financial companies subject to various laws and regulations as a means of protecting personal information, the largest "personal information leakage of three card companies" occurred in 2014. Since then, personal information protection-related systems have been supplemented, and as a result of various efforts such as strengthening the information protection management system, the number of personal information leakage accidents has decreased more than before. However, personal information leakage accidents continue to occur to this day. Examples include 1) leakage through outsourced partners, 2) leakage by internal staff and system errors, and 3) leakage by external attackers. Although personal information leakage accidents are frequent in savings banks with relatively low security levels, they occur without exception in large companies. Personal information leakage accidents occurred due to insufficient testing and verification or excessive authorization of work, and it became inevitable to point out the information protection management system. To prevent this, it is necessary to consider ways to technically automate the management system by complementing each other. Management measures such as applying technical security solutions and periodically inspecting personal information of internal network PCs and servers are applied to prevent leakage, but personal information leaked through appropriate approval procedures is bound to be found late even if it is used for malicious purposes. For example, if a crime occurs in a blind spot of CCTV, even if the police patrol regularly, the criminal will already miss the golden time if he or she damages the scene of the incident and escapes. To prevent this, a security solution related to personal information protection should be established, linked to an integrated monitoring solution, and a situation in which a large amount of decryption or export is performed in addition to the basic tasks in which personal information is used should be monitored without blind spots. Even if periodic inspections are performed and responded after personal information is leaked and used for sale or crime, the scale of damage can increase as the golden time has passed. As soon as a leak occurs, it is necessary to apply measures to detect and respond to the damage in advance, such as generating an alarm to the person in charge of personal information protection and resolving the situation within golden time.
정보보호 교육을 위한 정보보호 지식체계 프레임워크에 關한 硏究
This Study presents requirement, framework, practice program, Management program of Information Security Knowledge System. Information Security Knowledge System Framework for Information Security Education is constructed by Knowledge subject and Knowledge unit. It practicable for books, learning data, digital contents, courseware for education. It should be generating and maintaining by communication with information security expert and user.
유럽의 GDPR대응을 위한 ISMS-P 관리체계 개선에 관한 연구
현재 우리가 사는 제4차 산업혁명 시대는 기술의 발전과 더불어, 정보가 자원이 되고 권력이 되는 시대라 할 수 있다. 그리고 이러한 시대의 흐름 속에 개인정보는 중요한 축으로 발생하였다. 국내에서는 기관 및 기업이 개인정보보호 관리체계를 갖추고 체계적 • 지속적으로 보호 업무를 수행하는지에 대해 객관적으로 심사하여 기준 만족 시 인증을 부여하는 개인정보보호 관리체계(PIMS)를 발표하여 시행하고 있다. 최근 방송 통신위원회에서는 개인정보보호 관리체계 인증( PIMS )과 유사한 특성을 갖고 있는 정보보호 관리체계 인증(ISMS)과 통합한 ISMS-P 인증체계를 도입할 것을 발표 하였다. 국내와 마찬가지로, 유럽에서는 국내의 개인정보보호법 격인 EU-GDPR 을 공표하였다. 2018년 5월 부터 유럽의 개인정보보호법 격인 EU-GDPR이 엄격하게 적용된다. 엄격한 개인정보보호 기준에 따라, 유럽의 고객들을 유치하는 기업들은 반드시 GDPR을 준수해야 하며, 위반 시 막대한 벌금을 부과하게 된다. 따라서 유럽을 대상으로 하는 국내 기업들은 유럽의 정보보호 기준인 GDPR에 대응할 방법을 마련해야 한다. 이에 이 논문은 개인정보보호법과 GDPR에 대해 비교하여, 합리적인 결론을 낼 수 있도록 한다. The era of the 4th Industrial Revolution we live in today is a time when information becomes a resource and power with the development of technology. In this age of personal information, personal information has emerged as an important axis. In Korea, we introduced an information protection and privacy management system (ISMS-P) that inspects objectively whether institutions and companies have system of personal information protection management, and performs systematic and continuous protection work. As in Korea, in Europe, the EU-GDPR, the privacy protection law of Korea, has been announced. From May 2018, EU-GDPR, the European privacy policy, is strictly enforced. Under strict privacy standards, companies that attract customers in Europe must comply with the GDPR and impose significant penalties for violations. Therefore, domestic companies targeting Europe should have a way to respond to the GDPR, the European information protection standard. Therefore, this paper compares the Privacy Act and the GDPR to make a reasonable conclusion.
현대 기업 경영에서 IT 인프라에 대한 의존도가 심화됨에 따라 기업의 중요 정보 자산에 대한 불법적인 정보 유출과 악의적인 해킹공격으로 인한 피해가 급증하고 있으며, 기업 경영관리자들의 정보보호 중요성에 관한 인식도 높아지고 있다. 그러나 외부 공격 위험에 대비한 기업 정보보호 수준 평가 항목 및 세부 지표가 부재하며 정보보호 투자 타당성 분석 및 투자 포트폴리오를 측정하기 위한 기업들의 정보보호 전략과 정책이 미흡한 실정이다. 외국의 여러 나라에서는 COBIT, NIST, SSE-CMM, ISO27001, ISO27002 을 통하여 정보보호 관리체계를 진단, 운영하여 국제환경에 적응하도록 했으며, 국내에서는 “정보통신망 이용촉진 및 정보보호 등에 관한 법률”제47조, “정보통신망 이용촉진 및 정보보호 등에 관한 법률 시행령”제50조에 의거 국내 평가 및 인증제도가 구축되어 운영되고 있다. 대부분의 중소기업에서는 관리 체계 평가 비용의 부담을 갖고 있다. 또한, 조직에 맞는 평가 지표나 기준이 미비하거나, 외부의 기관에서 만들어진 기준을 통하여 평가할 수밖에 없는 현실이다. 기업에서 정보보호 수준을 종합적으로 평가하기 위해서는 현실적이고, 종합적인 평가체계의 개발이 필요하다. 따라서 본 논문은 중소기업 실태에 맞도록 IT 취약점, 보안관리 체계, 보안 이행 점검의 3개 카테고리로 구분하여 핵심지표를 구성하며, 이를 통해 중소기업들이 비용 효과적으로 정보보호 수준을 종합적으로 평가할 수 있는 객관적인 자가 측정 평가모형을 제시한다.
김성용 성균관대학교 정보통신대학원 2011 국내석사
우정사업본부는 전국 3,600여개 우체국을 통해 국민에게 예금, 보험, 우편서비스를 제공하는 공공기관이다. 여느 민간기업과 다를 바 없이 날로 정보시스템의 활용도가 증가하고 있으며, 이로 인해 사이버테러의 위협에도 항시 노출되어 있다. 따라서 우정사업본부에서는 정보보호를 위해 매년 소속기관에 대하여 정보보호 수준 평가를 실시하고 있다. 그러나 기존 정보보호 수준평가는 모든 소속기관에 동일한 평가 지표를 적용하여 평가함으로써 비효율적인 정보보호 활동으로 이어지는 한계가 발생하고 있다. 따라서 본 연구에서는 정보보호 수준평가 지침, 제도, 논문, 보고서 등 다양한 평가 사례를 분석하여 우정사업본부 소속기관별 정보보호 수준 등급과 평가 지표를 제시 하였다. 소속기관별 평가지표는 총212개 항목 중 우정사업본부 131개, 우정사업정보센터 207개, 체신청 등 직할관서 119개, 총괄우체국 77개, 소속우체국 46개로 조사되었다. 이를 검증하기 위해 평가 지표로 제시한 점검 항목에 대하여 관련분야 전문가 설문을 통해 해당 지표의 적정성을 확보하였다. 또한 새로운 정보보호 수준평가 지표를 적용하여 체신청 및 총괄우체국을 평가함으로써 평가지표의 활용 가능성을 검증하였다. Korea Post is a public institution that provides banking, insurance, and postal services through its 3,600 post offices nationwide. Like in all the other corporations, usage of IT system has been increasing, and by that, it's exposed to cyber-terror threat, all the time. Korea Post makes IT security level assessment to its branches every year. However, current assessment system applies the same index to all the different branch offices, and that leads to inefficient endeavors of IT workforce. Therefore, this research, by analyzing diverse cases such as IT Security Assessment Guide, regime, theses, reports, etc, suggests appropriate level of IT security and assessment indexes, classified by different types of its internal organizations. Among a total of 212 indexes for each organization, there are 131 for KP headquarters, 207 for KP Information Center, 119 for regional main and direct offices, 123 for post offices. Appropriateness of the indexes is secured by surveys conducted to specialists in the related fields. Also, assessing regional communications office and post offices with the new assessment indexes, proves its potential usability.
개인정보보호 인식 수준 제고 방안 연구 : 20·30대 정보주체의 인식 수준을 바탕으로
김수정 동국대학교 국제정보보호대학원 2023 국내석사
In the country, In accordance with the Personal Information Protection Act, the personal information controller is allowed to make efforts for the safety of the personal information of the information subject in handling personal information, and the information subject is protected by the relevant law. However, it is difficult to safely protect the personal information of the information subject only with the technical, physical, and administrative measures and efforts of the personal information controller. Therefore, in this paper, the subject of information subjects is to recognize the importance of personal information on their own and to study ways to increase the awareness of personal information so that they can protect it safely. Based on the results of this study, I would like to suggest the following as a measure to improve the level of personal information protection awareness of information subjects in their 20s and 30s. First, by establishing a customized personal information education system, information subjects should actively perform requests for access, correction, deletion, and suspension of processing of their personal information. and A customized education system on how to take damage relief measures after personal information leakage damage should be gradually activated. Second, it is necessary to provide a service that can add and receive personal information education to the notification service currently operated by the country. and And it is necessary to make it possible for the target person who needs customized education to recognize it. Through this, an environment in which data subjects can carry out personal information protection activities on their own should be prepared. Lastly, it is necessary for the government to prepare a system for compulsory personal information education so that not only the obligations of the personal information manager but also the data subject themselves can safely protect and manage their personal information.
유동화 고려대학교 정보보호대학원 2005 국내석사
정보통신의 눈부신 발전으로 향후 사회는 많은 물리적인 프로세스와 개인들의 접촉이 가상화, 개인화, 디지털 모바일화되는 사회적인 패러다임의 변화가 가속될 것이고 그에 따라 개인정보의 신속한 유통과 활용이 필수불가결한 시대가 되고 있다. 본 논문에서는 이러한 변화 속에서 개인의 위엄과 프라이버시를 지키기 위한 노력들의 한 분야로 민간기업에서 개인정보 보호관리 체계를 효과적으로 내재화할 수 있는 방안에 대하여 고찰해 보았다. 우선 개인정보보호라는 주제가 가지는 의미와 일반적인 사회적 환경에 대하여 파악하고, 국내외의 법제도의 변화를 살펴보았다. 또한 OECD의 개인정보보호 기준에 대하여 민간부문 측면으로 검토하고, 실제 사례로 국내 한 민간기업의 개인정보 관리실태를 분석하여 실질적인 개인정보 관리상의 문제점과 개선점을 분석, 도출하여 향후 일반기업이 개인정보보호를 위한 대응 방향성을 갖추는데 도움이 될 수 있는 정책적, 기술적 방향을 제시하고자 한다.