RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    검색결과 좁혀 보기

    선택해제
    • 좁혀본 항목 보기순서

      • 원문유무
      • 음성지원유무
      • 원문제공처
        펼치기
      • 등재정보
        펼치기
      • 학술지명
        펼치기
      • 주제분류
        펼치기
      • 발행연도
        펼치기
      • 작성언어
        펼치기

    오늘 본 자료

    • 오늘 본 자료가 없습니다.
    더보기
    • 무료
    • 기관 내 무료
    • 유료
    • KCI등재

      정보시스템 감리 보안점검 성숙도 모델

      이수현,박대하 보안공학연구지원센터(JSE) 2015 보안공학연구논문지 Vol.12 No.2

      본 논문에서는 정보시스템 감리 시 체계적인 보안 점검을 수행하고, 정보화 사업 수행 시 보안 측 면의 안정성 향상에 도움을 줄 수 있는 정보시스템 감리 보안점검 성숙도 모델과 그 활용 방안을 제 시하고자 한다. 보안 점검항목의 충분성과 일관성 결여 대한 문제를 해결하고자 성숙도 기반의 IT 국 제 기준인 ISM3와 SSE-CMM의 연구를 통해 충분성을 점검하고, 보안 점검항목의 일관성 확보를 위 해 정보시스템 감리 보안점검 성숙도 모델인 ISA-SCMM을 제안하였다. 본 모델은 정보시스템 계획, 설계, 구축, 운영 등의 과정에서 이뤄져야 할 보안 활동으로 10개 영역, 54개의 보안 점검항목으로 구 성하고, 정보화 사업의 특성과 비용 및 효율을 고려하여 3단계의 등급과 활용방안을 제시하고 있다. This paper proposes a security check maturity model and how to apply the model to support performing the effective security check for information system audit and improve the security stability of ICT business. ISA-SCMM is developed to solve the problem of lacking security check items in current Korean information system audit criteria and to guarantee the sufficient security check items consistent with maturity based global IT criteria such as ISM3 and SSE-CMM. ISA-SCMM is a security measure that be performed on several processes such as information system planning, designing, constructing, and operating. It is made up with 10 areas, 54 security check items and 3 steps of level, which can be applied for considering the characteristics and cost efficiency of ICT businesses and organizational requirements.

    • KCI등재

      인코텀즈 2010의 보안관련 전자정보 제공의무에 관한 연구-미국의 사전 전자정보제출에 관한 ISF 전송과의 관계를 중심으로-

      전순환 국제e-비즈니스학회 2011 e-비즈니스 연구 Vol.12 No.4

      The purpose of this article is to analyse the obligations for electronic submission of security information under importer security filing(ISF) in U.S. and Incoterms 2010. On January 26, 2010, Importer Security Filing(ISF) commonly known as “10+2” came into effect completely. According to this rules, the ISF importer is required to submit electronically the Import Security Filing. This program is applicable for the shipments arriving to the United States by vessel. In other words, ISF Importers and their agent must submit 10 data elements to CBP(U.S. Customs and Border Protection), and carrier must submit 2 data elements to CBP. Especially, ISF Importers and their agent must submit 8 data elements no later than 24 hours before the cargo is laden aboard a vessel destined to the United States. Amendments of Incoterms 2000 were made in 2010 in order to bring the rules in line with current international trade practices requiring the security information such as CSI, 24 hours rule, and ISF. This Incoterms 2010 came into effect on January 1, 2011. The A2/B2 and A10/B10 of all Incoterms 2010 rules provides that the seller must provide to or render assistance in obtaining for the buyer security-related information, and that the buyer must advise the seller of any security information requirements. Therefore, seller and buyer, parties to a trade contract, must fulfill their obligation to provide the security-related information or advise the any security information requirements under the ISF rule and the Incoterms 2010 rules. It should be noted that the failure to file results in liquidated damages in the $5,000 per violation. If inaccurate submission or late submission from the seller gives rise to the liquidated damages, the buyer will claim the damages to the seller. 본 논문은 2010년 10월 26일부터 전면 시행된 미국의 수입업자 보안정보전송(ISF) 관련규정과 이에 따른 보안관련 정보제공을 당사자의 의무로서 도입한 2011년 1월 1일부터 시행된 Incoterms 2010을 살펴보았다. 즉, 미국의 911 테러사건을 계기로 고조된 보안관련 규제는 2002년 컨테이너보안 이니셔티브(Container Security Initiative; CSI), 미국 테러행위방지를 위한 세관-산업계 협력(U.S. Customs-Trade Partnership Against Terrorism; C-TPAT), 24시간 규칙(24-Hour Rule)과 2002년 미국통상법 최종규칙(Trade Act of 2002 Final Rule), 수입업자 보안정보전송(Importer Security Filing; ISF)을 통하여 한층 강화되었다. 이러한 미국을 포함하는 선진국의 보안규제의 강화라는 무역관행을 반영한 Incoterms 2010 규칙에서도 매수인의 보안정보요건의 통지의무와 매도인의 보안관련 정보제공의 의무, 보안관련 정보제공에 따른 협조의무, 보안통관관련 정보제공의 의무를 신설하였다. 따라서, 무역계약의 당사자인 매도인과 매수인은 미국의 수입업자 보안정보전송(ISF)의 규정과 이러한 관행을 반영한 Incoterms 2010 규칙 상의 보안정보 관련 규정을 완전히 숙지하여 자신의 의무를 충실히 이행할 필요가 있다는 점에서 이러한 규칙에 대한 분석이 요구된다.

    • KCI등재

      정보보안정책 준수가 정보보안능력 및 행동에 미치는 영향 분석

      강다연(Dayeon Kang),장명희(Myunghee Chang) 한국항만경제학회 2014 한국항만경제학회지 Vol.30 No.1

      최근 발생한 고객정보유출사고는 조직의 정보보안 강화에 대한 관심과 전담조직의 중요성을 고조시키고 있다. 이에 따라 기업들은 정보보안 강화를 위해 정보보안정책을 마련하고 있으며, 조직구성원들로 하여금 보안정책을 준수하도록 권고하고 있다. 해운항만 조직에서도 정보보안을 위해 정보보안정책을 체계화시키고 조직구성원들의 정보보안능력과 정보보안행동을 평가할 필요성이 있다. 본 연구의 목적은 해운항만조직 구성원들을 대상으로 정보보안정책 준수 정도가 정보보안능력과 정보보안행동에 미치는 영향을 분석하는데 있다. 분석결과, 먼저 해운항만조직 구성원의 정보보안정책 준수에 영향을 미치는 요인으로 정보보안규범과 정보보안교육을 확인할 수 있었고, 정보보안처벌은 정보보안정책 준수에 유의한 영향을 미치지 않는 것으로 분석되었다. 해운항만조직 구성원의 정보보안정책 준수정도는 정보보안능력과 정보보안행동에 유의한 영향을 미치는 결과를 확인할 수 있었다. Recent accidents of customer information leakage increase the necessity of information security for organization and the importance of information security team for it. To strengthen information security, organizations make information security policy and ask the members to comply with it. In this regard, maritime organization also needs to structure information security policy and examine its ability and behavior. The purpose of this study is to analyze the effects of compliance with information security policy on the ability and behavior of workers in shipping and port organization. The results of investigation show that information security education and norm affect compliance with information security of the workers. On the contrary, the punishment of information security is insignificant. It is shown that the degree of compliance with information security significantly affects its ability and behavior of the workers in shipping and port organization.

    • KCI등재

      정보보안 위험 경험에 따른 대학생의 인식 변화와 행위의도 분석

      신호영,이영돈,김성용 한국산업경영학회 2026 경영연구 Vol.41 No.3

      본 연구는 대학생을 대상으로 정보보안 위험을 직접 경험하는 상황이 위협 인식과 정보보안 행위의도에 미치는 영향을 실험적으로 검증하였다. 이를 위해 정보보안 위험 경험 여부에 따라 통제집단과 실험집단을 구분하고, 보호 동기 이론을 바탕으로 지각된 심각성, 지각된 취약성, 반응효능감, 자기효능감, 정보보안 위협, 사회적 영향, 정보보안 행위의도 간의 관계를 분석하였다. 실험은 온라인 퀴즈 형식으로 진행되었으며, 위협을 암시하는 메시지를 통해 정보보안 위험을 체감하도록 설계하였다. 분석 결과, 통제집단에서는 지각된 심각성이 정보보안 위협 인식에 유의미한 영향을 미치지 않았으며, 자기효능감이 정보보안 행위의도를 설명하는 주요 요인으로 나타났다. 반면, 정보보안 위험을 직접 경험한 실험집단에서는 지각된 심각성과 지각된 취약성이 모두 정보보안 위협에 유의미한 영향을 미쳤고, 위협이 정보보안 행위의도를 설명하는 핵심 요인으로 작용하였다. 이는 정보보안 행동이 개인의 고정된 인식이나 역량에 의해 획일적으로 결정되는 것이 아니라, 실제 위험 경험이라는 상황적 요인에 따라 달라질 수 있음을 시사한다. 이러한 결과는 대학생 대상 정보보안 교육에서 지식 전달 중심의 접근을 넘어, 위험을 체감할 수 있는 경험 기반 교육 설계의 필요성을 실증적으로 보여준다. This study experimentally examined the effects of direct information security risk experience on threat perception and information security behavioral intention among university students. To this end, participants were divided into a control group and an experimental group based on whether they experienced information security risk, and the relationships among perceived severity, perceived vulnerability, response efficacy, self-efficacy, information security threat, social influence, and information security behavioral intention were analyzed based on Protection Motivation Theory. The experiment was conducted in the form of an online quiz, during which messages implying information security threats were presented to induce participants to experience a sense of risk. The results showed that, in the control group, perceived severity did not have a significant effect on information security threat perception, while self-efficacy emerged as the primary factor influencing information security behavioral intention. In contrast, in the experimental group that directly experienced information security risk, both perceived severity and perceived vulnerability had significant effects on threat perception, and information security threat was identified as the key determinant of behavioral intention. These findings suggest that information security behavior is not uniformly determined by individuals’ fixed perceptions or capabilities, but can vary depending on situational factors such as actual risk experience. Overall, this study empirically supports the need for experience-based educational approaches that allow learners to directly perceive security risks, rather than relying solely on knowledge-centered instruction in information security education for university students.

    • KCI등재

      정보보안 관련 스트레스와 개인조직 적합성이 정보보안 지식공유행동에 미치는 영향

      황인호 한국융합학회 2021 한국융합학회논문지 Vol.12 No.2

      최근 조직들은 조직원에게 엄격한 정보보안 수준을 요구하고 있다. 엄격한 정보보안 정책 및 기술은 정보보안 관련 스트레스를 유발할 수 있다. 연구 목적은 지식공유행동 및 개인조직 적합성을 감소시키는 정보보안 기술 및 업무 스트레스의 부정적 영향을 제시하는 것이다. 연구 대상은 정보보안 정책을 보유한 조직에서 근무하는 조직원이며, 연구 가설은 309개의 표본을 활용하여 구조방정식모델링으로 검증한다. 연구 결과, 개인조직적합성이 지식공유행동에 긍정 적 영향을 주었으나, 업무스트레스가 부정적 영향을 주었다. 또한, 기술스트레스가 개인조직 적합성에 부정적 영향을 미쳤다. 추가적으로, 업무모호성이 개인조직 적합성과 지식공유행동사이에 조절효과를 가졌다. 연구 시사점은 조직원의 정보보안 기술 및 업무 스트레스의 부정적 영향을 확인하였으며, 내부자의 부정적 행동 최소화를 위한 방향을 제시한다. Recently, organizations are demanding strict information security behavior from their employees. Strict information security policies and techniques can cause information security related stress. The purpose of this study is to present the negative effects of information security related techno stress and role stress that reduce knowledge sharing behavior and person-organization fit. The survey was conducted to people working in organizations with information security policies and system, and the research hypothesis was verified by structural equation modeling using 309 samples. As a result of the study, person-organization fit had a positive effect on knowledge sharing behavior, but role stress had a negative effect. And, techno-stress negatively affected the person-organization fit. Additionally, role ambiguity had a moderating effect between person-organization fit and knowledge sharing behavior. The implications of the study were to confirm the negative effects of information security related techno stress and role stress, and to suggest directions for minimizing negative behavior of insiders.

    • KCI등재

      금융기관의 정보보안 인식강화를 위한 정책적 제언

      임명성,정태석,이정민 보안공학연구지원센터(JSE) 2014 보안공학연구논문지 Vol.11 No.6

      본 연구의 목적은 금융기관에서 사용하는 여러 가지 정보보안 대책 중 보안인식 강화를 위해 가장 효과적인 방법을 제시하고, 현재의 문제점, 그리고 앞으로 나아가야 될 방향을 제시하는 것이다. 금융 기관에서 사용하는 정보보안 대책으로는 보안정책, 정보보안 교육 및 훈련 프로그램, 보안 교육 빈도, 준수 비용, 경영진의 관심 등이다. 조사결과 이중 정보보안 인식 교육 및 훈련이 정보보안인식 향상 을 위해 가장 효과적인 방법으로 드러났다. 본 연구에서는 효과적인 정보보안 인식 교육 및 훈련을 위한 정책적 제언 결론에서 제시하였다. The purpose of this study is to identify the most effective countermeasure for information security in organizations and to suggest ways to increase information security awareness using the countermeasure. Information security countermeasures include information security policy, information security education and training program, security education frequency, response cost, and management attention. We found that security awareness education and training is the most effective mean for information security in financial firms. Conclusions and implications are discussed for increasing the effective of security awareness education and training program.

    • KCI등재

      모의해킹 놀이 활동을 통한 초등 정보보호교육 STEAM 프로그램 개발 및 적용

      박남제 한국정보교육학회 2016 정보교육학회논문지 Vol.20 No.3

      본 논문에서 제안하는 신규 STEAM(Science, Technology, Engineering, Art, Mathematics) 프로그램 및 정보보안 모의해킹 놀이식 학습교구는 미래 유망 직업군인 정보보안전문가와 관련된 프로젝트를 수행해 정보보안전문가에 대한 학생들의 관심과 흥미를 높이고 창의적 진로설계를 할 수 있도록 도움을 주는 것을 목적으로 한다. 또한 프로그램을 활용하는 교사와 학생이 정보보안전문가 관련 프로젝트 지도 및 수행과정을 통해 정보보안전문가가 하는 일과 필요한 역량이 무엇인가를 자연스럽게 이해하도록 프로그램을 설계하였다. 본 논문에서 제안한 정보보안전문가 STEAM 학습 교구는 정보보안전문가의 기본 소양을 제안된 학습 교구를 응용하여 간접적으로 체험해보는 활동으로 설계하였다. 사이버 보안에 관련된 내용이 어렵고 낯설기 때문에 기술적인 부분보다는 해당 직업의 핵심 원리에 접근할 수 있도록 내용을 구성하였다. 이 프로그램을 통해 학생들은 문제를 해결하는 과정에서 서로 소통하고 정보보안전문가에 관심을 가지고 창의적으로 진로를 설계할 수 있을 것이다. The new STEAM program suggested in this paper aims at helping students to have interest in information security engineering experts and to design their career creatively through the project on future promising career. The program was designed to help teachers and students understand the jobs and capabilities required for information security experts through direction and execution of the information security expert project. Teaching tools of information security through simulation hacking play activities based on hexagon cell is designed to provide students with the chance to indirectly experience the job of a computer security expert through an unplugged education. Because the content of cyber security is unfamiliar and difficult to understand, the program is designed to allow students to access the key principle of the job, rather than to describe the technical part. Using this program, students will be able to communicate with each other to solve the problems, to have interest in computer security experts, and to design their careers in a creative manner.

    • KCI등재

      해운항만조직 구성원들의 정보보안정책 준수에 영향을 미치는 요인

      강다연(Dayeon Kang),장명희(Myunghee Chang) 한국항만경제학회 2012 한국항만경제학회지 Vol.28 No.1

      정보기술의 발전은 기업에게 많은 이익을 가져다주었지만, 정보유출이라는 심각한 문제를 야기하고 있다. 이에 따라 기업들은 정보보안을 위해 정보보안정책을 수립하고 조직구성원들이 정보보안정책을 준수할 것을 요구하고 있다. 본 연구에서는 해운항만조직 구성원들의 정보보안정책 준수에 영향을 미치는 요인들을 실증분석 하기 위해 정보보안인식, 정보보안태도, 자기효능감, 규범신념, 사회적 영향들을 영향요인으로 선정하였다. 분석결과에 따르면, 해운항만조직 구성원들의 정보보안인식과 정보보안태도와의 관계는 긍정적으로 나타났으며, 정보보안태도와 정보보안정책 준수와의 관계도 긍정적으로 나타났다. 그리고 자기효능감과 정보보안정책 준수와의 관계, 사회적 영향과 정보보안정책 준수의 관계도 긍정적으로 나타났다. 하지만 규범신념과 정보보안정책 준수와의 관계는 유의하지 않은 것으로 분석되었다. 본 연구의 결과는 정보유출문제가 발생할 가능성이 큰 해운항만조직의 구성원들이 정보보안정책의 준수사항을 어느 정도로 받아들이는 지를 확인함으로써 해운항만조직에서 정보보안과 관련된 정책을 수립하는데 기반을 제공할 것으로 기대한다. Advances in information technology has brought many benefits to businesses, but at the same time, businesses are facing serious problems caused by its use such as information leakage. In order to cope with problems, companies have established information security policies, demanding workers of a company to be compliant with the policies. This study proposes a research model that includes information security awareness, information security attitude, self-efficacy, standard belief and social influences as factors that affect the compliance of information security policy among the workers of shipping and port organization. The results of this study showed that there was a positive relationship not only between the information security awareness and the information security attitude, but also between the information security attitude and the information security policy among the workers of shipping and port organization. It was also found that there was a positive relationship between the self-efficacy and the compliance of information security policy, and between the social influence and the compliance of information security policy. However, there was no meaningful relationship between the standard belief and the compliance of information security policy. This study examined to what extent the workers of shipping and port organization that have a high possibility of the information leakage were compliant with the information security policy. The findings will contribute to organizations of shipping and port who attempt to establish strategies related to information security.

    • 정보보안정책태도와 준수행동의도성, 정보보안회피성이 정보보안위반행동에 미치는 영향 분석 -조절관점과 처벌관점을 중심으로-

      이려화,허성호 대전대학교 안보군사연구원 2021 국제군사안보연구(안보군사학연구) Vol.- No.20

      The aim of this study to assess the effectiveness of information security policy attitude, compliance behavioral intention, information security avoidance tendency on information security violation behavior The research method design is a cross-design of Regulation and Punishment. The measurement variables used in the investigation are information security policy attitude, compliance behavioral intention, information security avoidance tendency, and information security violation behavior. As a result, the Regulation had a significant effect on information security policy attitude, information security avoidance tendency, information security violation behavior, and it was found that influence of the promotion-based condition was greater than the prevention-based condition. The punishment had a significant effect on information security avoidance tendency, information security violation behavior, and it was found that influence of the clarity-based condition was greater than the severity-based condition. The resulting exploration model was verified as a complex mediation model. In addition, the discussion contains the appropriate implications for information security based on these research results 본 연구의 목적은 정보보안 정책의 특성이 정보보안과 관계되는 정보보안 과정에 미치는 영향을 이해하는 것이다. 연구 방법은 조절관점과처벌관점의 교차설계로 구성되었고, 정보보안 과정은 정보보안정책태도, 준수행동의도성, 정보보안회피성, 정보보안위반행동의 네 가지 변수로측정되었다. 연구 결과, 조절관점은 정보보안정책태도, 정보보안회피성, 정보보안위반행동에 유의미한 영향을 미치고 있었으며, 촉진 조건의 영향력이 예방 조건보다 더 큰 것으로 나타났다. 처벌관점은 정보보안회피성, 정보보안위반행동에 유의미한 영향을 미치고 있었으며, 명료성 조건의 영향력이 심각성 조건보다 더 큰 것으로 나타났다. 결과적으로 도출한 연구 모형은 측정변인으로 구조화된 복합 매개모형으로 확인되었다. 아울러, 논의점은 이러한 연구 성과를 반영하여 정보보안에 적합한시사점을 설명하고 있다

    • KCI등재

      정보보안과 개인정보보호 간의 이원화 보안범주의 상호연계 및 통합에 따른 보안성 증대에 대한 연구

      서우석(Woo Seok Seo) 한국전자통신학회 2018 한국전자통신학회 논문지 Vol.13 No.3

      공공기관 개인정보보호에 관한 법률이 제정되고 개정 되는 단계를 거치는 동안 정보보안에 관한 지침과 법률은 특정 기관에 중점적으로 반영되고 수축 및 실현되고 있었다. 상호 법률과 지침은 거시적인 정보라는 자산과 개인식별정보라는 자산에 대한 상호 다른 매체정보에 대한 보안을 목적으로 이원화 되어 적용되고 실현되어 왔다. 그러나 2017년 4차 산업혁명에 대한 정의와 방향 그리고 21세기 최고의 안전선을 확보하는 보안에 대한 다양한 제품과 솔루션 그리고 이런 모든 분야를 아우르는 제3의 기술을 제시하기 위해 IOT(: Internet of Things), ICT(Internet of Things), ICT Cloud, AI(: Artificial Intelligence) 등 마치 장난감 플라스틱 인형을 주물로 마구 만들어내 듯이 보안 시장에 쏟아져 들어오고 있는 상황이다. 이때 과거와는 다른 보안상의 범주에 두 가지 중요 영역에 준하는 정보보안과 개인정보보안 이라는 이원화된 물리적, 관리적, 논리적, 심리적 차이를 보이는 보안에 대한 상호연계성 보장과 통합적 관리 및 기술적용을 위한 보안성 증대에 대한 필요성이 대두되어짐에 따라 두 경우의 상호관계를 분석하고 이를 제안된 연구결과에 적용함으로써 최적의 보안성을 확보하는 연구를 하고자 한다. While the legislation on the protection of personal information in public institutions was enacted and amended, the guidelines and laws on information security were focused, contracted and realized with focus on specific institutions. Mutual laws and guidelines have been applied and realized for the dual purpose of securing both the asset of macroscopic information and the asset of personally identification information, which are mutually different media information. However, in a bid to present the definition and direction of the fourth industrial revolution in 2017, a variety of products and solutions for security designed to ensure the best safety line of the 21st century, and the third technology with the comprehensive coverage for all these fields, a number of solutions and technologies, including IOT(: Internet of Things), ICT Internet of Things(: ICT), ICT Cloud, and AI (: Artificial Intelligence) are pouring into the security market as if plastic doll toys were manufactured in massive scale into the market. With the rising need for guaranteeing the interrelation for securities with dualistic physical, administrative, logical and psychological differences, that is, information security and personal information security that are classified into two main categories and for the enhanced security for integrated management and technical application, the study aims to acquire the optimal security by analyzing the interrelationship between the two cases and applying it to the study results.

    연관 검색어 추천

    이 검색어로 많이 본 자료

    활용도 높은 자료

    해외이동버튼