RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    보안사고 예방을 위한 인적취약점 분류 모형 및 측정지표 개발에 관한 연구

    한글로보기

    https://www.riss.kr/link?id=T17091423

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    The information security industry has experienced remarkable growth over the past few decades, particularly in presenting various solutions from technical, managerial, and institutional perspectives. Despite these advancements, security incidents continue to occur annually, highlighting a critical issue: existing security measures are overly focused on technology and prevention, failing to address the diverse business changes of the digital age. This has led to a rising interest in People-Centric Security(PCS), which seeks to overcome the limitations of traditional security approaches.
    This study aims to analyze fundamental causes of security incidents by categorizing human-induced vulnerabilities into five progressive expansion types based on the ethical perspective of value relation extension, further subdividing them into 20 detailed components. The research introduces the concept of information security violations, strategic principles of PCS, and employs Focus Group Interviews (FGI) with experts to evaluate the effectiveness of human vulnerability checklists.
    Human vulnerabilities are classified into five major categories: ‘personal vulnerability,’ which focuses on individual traits; ‘interpersonal relationships,’ concerning interactions between people; ‘Organizational Threats,’ related to intra-organizational dynamics; ‘sociality,’ arising from broader social interactions; and ‘ethicality,’ addressing universal ethical considerations. By defining these categories and their components, a comprehensive human vulnerability classification model is developed.
    The industry has continually evolved, offering diverse solutions and preventative measures, particularly on the technical front. However, the persistent occurrence of security incidents necessitates a reevaluation of overlooked areas beyond technological and managerial aspects. Despite the long-standing emphasis on human security, intensive research and investment have lagged. Consequently, the Zero Trust security model, which operates on the premise of trusting no one in cyberspace, has gained traction, naturally leading to a focus on people-centric security.
    Gartner's 2024 major cybersecurity trends underscore the importance of communication with management and the significance of security behavior and culture programs, highlighting the shift towards human-centric security strategies. This consensus acknowledges that relying solely on security solutions or policies is insufficient to combat increasingly sophisticated threats driven by IT advancements. In light of this, there is a growing need for in-depth research on human security. Similar to systematic vulnerability classifications for databases, networks, servers, and endpoints, establishing a fundamental classification model for human-induced vulnerabilities is a crucial starting point. This study leverages the principles of PCS, ISMS-P human security control standards, and a cybercrime profiling approach to analyze psychological aspects, conducting iterative FGIs and both qualitative and quantitative research to propose an optimized human vulnerability classification model.
    Furthermore, based on the proposed model, this study develops specific measurement indicators for each category, ultimately deriving 168 human security measurement items through phased research, expansion, and validation. The goal is to clarify and objectify abstract human security control standards. Given the novelty of developing classification models or measurement indicators for human-induced security vulnerabilities compared to technical perspectives, this research relied heavily on FGIs and Delphi surveys involving domain experts.
    In conclusion, considering the current state of human security research and the limitations of information security, the human vulnerability classification model and the development of specific measurement indicators presented in this study are expected to establish a new normal in human security within the complex and diverse IT environment.
    번역하기

    The information security industry has experienced remarkable growth over the past few decades, particularly in presenting various solutions from technical, managerial, and institutional perspectives. Despite these advancements, security incidents cont...

    The information security industry has experienced remarkable growth over the past few decades, particularly in presenting various solutions from technical, managerial, and institutional perspectives. Despite these advancements, security incidents continue to occur annually, highlighting a critical issue: existing security measures are overly focused on technology and prevention, failing to address the diverse business changes of the digital age. This has led to a rising interest in People-Centric Security(PCS), which seeks to overcome the limitations of traditional security approaches.
    This study aims to analyze fundamental causes of security incidents by categorizing human-induced vulnerabilities into five progressive expansion types based on the ethical perspective of value relation extension, further subdividing them into 20 detailed components. The research introduces the concept of information security violations, strategic principles of PCS, and employs Focus Group Interviews (FGI) with experts to evaluate the effectiveness of human vulnerability checklists.
    Human vulnerabilities are classified into five major categories: ‘personal vulnerability,’ which focuses on individual traits; ‘interpersonal relationships,’ concerning interactions between people; ‘Organizational Threats,’ related to intra-organizational dynamics; ‘sociality,’ arising from broader social interactions; and ‘ethicality,’ addressing universal ethical considerations. By defining these categories and their components, a comprehensive human vulnerability classification model is developed.
    The industry has continually evolved, offering diverse solutions and preventative measures, particularly on the technical front. However, the persistent occurrence of security incidents necessitates a reevaluation of overlooked areas beyond technological and managerial aspects. Despite the long-standing emphasis on human security, intensive research and investment have lagged. Consequently, the Zero Trust security model, which operates on the premise of trusting no one in cyberspace, has gained traction, naturally leading to a focus on people-centric security.
    Gartner's 2024 major cybersecurity trends underscore the importance of communication with management and the significance of security behavior and culture programs, highlighting the shift towards human-centric security strategies. This consensus acknowledges that relying solely on security solutions or policies is insufficient to combat increasingly sophisticated threats driven by IT advancements. In light of this, there is a growing need for in-depth research on human security. Similar to systematic vulnerability classifications for databases, networks, servers, and endpoints, establishing a fundamental classification model for human-induced vulnerabilities is a crucial starting point. This study leverages the principles of PCS, ISMS-P human security control standards, and a cybercrime profiling approach to analyze psychological aspects, conducting iterative FGIs and both qualitative and quantitative research to propose an optimized human vulnerability classification model.
    Furthermore, based on the proposed model, this study develops specific measurement indicators for each category, ultimately deriving 168 human security measurement items through phased research, expansion, and validation. The goal is to clarify and objectify abstract human security control standards. Given the novelty of developing classification models or measurement indicators for human-induced security vulnerabilities compared to technical perspectives, this research relied heavily on FGIs and Delphi surveys involving domain experts.
    In conclusion, considering the current state of human security research and the limitations of information security, the human vulnerability classification model and the development of specific measurement indicators presented in this study are expected to establish a new normal in human security within the complex and diverse IT environment.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    정보보안(Information Security) 산업은 지난 수십 년간 괄목할 만한 성장을 거듭해 왔다. 특히 기술적, 관리적, 제도적 측면에서 다양한 해법을 제시해 왔다. 그럼에도 불구하고 매년 보안 사고는 지속해서 발생하고 있는데 주목해야 한다. 이는 기존의 보안이 지나치게 기술 중심, 예방 중심의 정책으로 추진되고 있어서 디지털 시대의 다양한 비즈니스 변화에 한계가 있음을 증명하고 있다. 이러한 흐름에서 최근에 전통적인 보안 접근 방식의 한계를 벗어나고자 인간중심 보안(PCS, People-Centric Security)이 화두가 되고 있다. 본 연구에서는 정보보안 위반의 개념, PCS 전략적 원칙, 전문가 심층 인터뷰(FGI, Focus Group Interview)를 통해 인간이 유발할 수 있는 취약점을 가치관계 확장법의 윤리적 관점에 따라 크게 5가지의 점진적 확장 형태로 구분해서 20개의 세부 구성요소로 분류함으로써 근본적인 보안 사고 유발 요인을 분석하고 활용 방안을 제시하고자 한다. 즉, 사람 자체에 초점을 맞춘 개인의 성향이나 특성에 따른 인적취약점 유발 요인인 ‘개인취약성(personal vulnerability)’, 사람 간의 상호 작용에 따른 취약점 유발 요인인 ‘인간관계성(interpersonal relationships)’, 조직 전반의 업무적 관계에서 나타날 수 있는 인적취약점 유발 요인인 ‘조직위협성(org. threat)’ 그리고 사회 전반적 특성의 관계에서 유발될 수 있는 ‘사회성(sociality)’ 마지막으로 사회 보편적 가치에서 적용될 수 있는 윤리적인 측면의 인적취약점 유발 요인인 ‘윤리성(ethicality)’까지 크게 다섯 가지로 분류하고 유형별 구성요소를 정의함으로써 최종 인적취약점 분류 모형을 완성했다(박정준·안성진, 2023). 서두에서 언급한 바와 같이 정보보안 산업은 지난 수십 년간 지속적인 성장을 거듭해 왔고, 특히 기술적인 측면에서의 보안 수준은 한계에 다다를 만큼 대응 방안이나 예방에 있어서 다양한 해법을 충분히 제시해 주고 있다. 더불어 관련 법, 제도적인 측면에서의 정보보안 컨설팅도 이젠 정부 공공기관이나 기업에서는 매년 필수적인 업무로 자리매김해 오고 있다. 그런데도 매년 보안 사고는 지속적으로 발생하고 있는데 우리가 주목할 필요가 있다. 기술적, 관리적 측면의 보안 외에 우리가 간과하고 있었던 분야는 없었는지 되짚어 봐야 할 매우 중요한 시점이다. 인적보안은 오랫동안 강조됐던 보안의 한 분야임에도 불구하고 집중적인 연구나 투자가 지속해서 이루어지지 못했다. 이러한 흐름에서 사이버 공간에서 아무도 신뢰하지 않는 것을 전제로 한 이른바 제로 트러스트(Zero Trust) 보안 모델이 주목받고 있으며 자연스럽게 사람 중심 보안으로 귀결되고 있다. 또한 2024년 가트너(Gartner)가 발표한 주요 사이버보안 트렌드 6가지를 살펴보면 경영진과의 소통, 보안 행동 및 문화 프로그램의 중요성 등 사람 중심의 보안 전략을 제시하고 있다. 이는 더 이상 보안 솔루션이나 정책에 의존해서는 정보기술 변화에 따라 고도화되고 지능화되는 위협을 모두 방어할 수 없다는 공감대 때문일 것이다. 따라서 인적보안을 좀 더 심도 있게 다루는 연구가 필요해졌고, 시스템취약점과 같이 데이터베이스, 네트워크, 서버, 엔드포인트 등 영역별 체계적인 취약점 분류를 기반으로 대응 방안을 마련해 왔던 것처럼, 마찬가지로 인간이 유발할 수 있는 취약점의 유형에 대한 근본적인 분류 모형이 매우 중요한 출발점이 될 수 있을 것이다(정해인·김성준, 2018). 따라서 본 연구에서는 인간중심 보안의 취지와 ISMS-P의 인적보안 통제 기준, 인간의 심리적인 측면을 정보보안 범죄 프로파일링 관점에서 접근하여 분석하고, 반복적인 FGI 등 질적·양적 연구를 통해 인적취약점 분류에 대한 최적화된 분류 모형을 제시함으로써 보안 위협에 대한 좀 더 근본적인 접근을 시도해 보고자 노력했다. 또한 본 논문에서 제시한 인적취약점 분류 모형을 근거로 유형별 측정지표 개발을 진행했고 단계별 연구와 확장개발 및 검증을 통해서 최종 168개의 인적보안 측정지표 항목들을 도출함으로써 인적보안의 추상적인 통제 기준을 좀 더 명확하고 객관화시키고자 했다. 기존 기술적 관점의 취약점에 비해 사람 관점에서 유발할 수 있는 보안 취약점에 대한 분류 모형이나 측정지표 개발에 관한 선행 연구가 없었고 처음 시도되는 연구 분야인 만큼 관련분야 전문가 대상 FGI와 델파이 조사에 의존할 수밖에 없었다. 결론적으로 인적보안 연구 현황이나 정보보안의 한계점을 고려할 때 본 연구에서 제시하는 인적취약점 분류 모형 및 유형별 측정지표 개발은 다양하고 복잡한 정보기술 환경의 보안 위협 속에서 인적보안의 새로운 뉴노멀(New Normal)이 될 것으로 확신한다.
    번역하기

    정보보안(Information Security) 산업은 지난 수십 년간 괄목할 만한 성장을 거듭해 왔다. 특히 기술적, 관리적, 제도적 측면에서 다양한 해법을 제시해 왔다. 그럼에도 불구하고 매년 보안 사고는 ...

    정보보안(Information Security) 산업은 지난 수십 년간 괄목할 만한 성장을 거듭해 왔다. 특히 기술적, 관리적, 제도적 측면에서 다양한 해법을 제시해 왔다. 그럼에도 불구하고 매년 보안 사고는 지속해서 발생하고 있는데 주목해야 한다. 이는 기존의 보안이 지나치게 기술 중심, 예방 중심의 정책으로 추진되고 있어서 디지털 시대의 다양한 비즈니스 변화에 한계가 있음을 증명하고 있다. 이러한 흐름에서 최근에 전통적인 보안 접근 방식의 한계를 벗어나고자 인간중심 보안(PCS, People-Centric Security)이 화두가 되고 있다. 본 연구에서는 정보보안 위반의 개념, PCS 전략적 원칙, 전문가 심층 인터뷰(FGI, Focus Group Interview)를 통해 인간이 유발할 수 있는 취약점을 가치관계 확장법의 윤리적 관점에 따라 크게 5가지의 점진적 확장 형태로 구분해서 20개의 세부 구성요소로 분류함으로써 근본적인 보안 사고 유발 요인을 분석하고 활용 방안을 제시하고자 한다. 즉, 사람 자체에 초점을 맞춘 개인의 성향이나 특성에 따른 인적취약점 유발 요인인 ‘개인취약성(personal vulnerability)’, 사람 간의 상호 작용에 따른 취약점 유발 요인인 ‘인간관계성(interpersonal relationships)’, 조직 전반의 업무적 관계에서 나타날 수 있는 인적취약점 유발 요인인 ‘조직위협성(org. threat)’ 그리고 사회 전반적 특성의 관계에서 유발될 수 있는 ‘사회성(sociality)’ 마지막으로 사회 보편적 가치에서 적용될 수 있는 윤리적인 측면의 인적취약점 유발 요인인 ‘윤리성(ethicality)’까지 크게 다섯 가지로 분류하고 유형별 구성요소를 정의함으로써 최종 인적취약점 분류 모형을 완성했다(박정준·안성진, 2023). 서두에서 언급한 바와 같이 정보보안 산업은 지난 수십 년간 지속적인 성장을 거듭해 왔고, 특히 기술적인 측면에서의 보안 수준은 한계에 다다를 만큼 대응 방안이나 예방에 있어서 다양한 해법을 충분히 제시해 주고 있다. 더불어 관련 법, 제도적인 측면에서의 정보보안 컨설팅도 이젠 정부 공공기관이나 기업에서는 매년 필수적인 업무로 자리매김해 오고 있다. 그런데도 매년 보안 사고는 지속적으로 발생하고 있는데 우리가 주목할 필요가 있다. 기술적, 관리적 측면의 보안 외에 우리가 간과하고 있었던 분야는 없었는지 되짚어 봐야 할 매우 중요한 시점이다. 인적보안은 오랫동안 강조됐던 보안의 한 분야임에도 불구하고 집중적인 연구나 투자가 지속해서 이루어지지 못했다. 이러한 흐름에서 사이버 공간에서 아무도 신뢰하지 않는 것을 전제로 한 이른바 제로 트러스트(Zero Trust) 보안 모델이 주목받고 있으며 자연스럽게 사람 중심 보안으로 귀결되고 있다. 또한 2024년 가트너(Gartner)가 발표한 주요 사이버보안 트렌드 6가지를 살펴보면 경영진과의 소통, 보안 행동 및 문화 프로그램의 중요성 등 사람 중심의 보안 전략을 제시하고 있다. 이는 더 이상 보안 솔루션이나 정책에 의존해서는 정보기술 변화에 따라 고도화되고 지능화되는 위협을 모두 방어할 수 없다는 공감대 때문일 것이다. 따라서 인적보안을 좀 더 심도 있게 다루는 연구가 필요해졌고, 시스템취약점과 같이 데이터베이스, 네트워크, 서버, 엔드포인트 등 영역별 체계적인 취약점 분류를 기반으로 대응 방안을 마련해 왔던 것처럼, 마찬가지로 인간이 유발할 수 있는 취약점의 유형에 대한 근본적인 분류 모형이 매우 중요한 출발점이 될 수 있을 것이다(정해인·김성준, 2018). 따라서 본 연구에서는 인간중심 보안의 취지와 ISMS-P의 인적보안 통제 기준, 인간의 심리적인 측면을 정보보안 범죄 프로파일링 관점에서 접근하여 분석하고, 반복적인 FGI 등 질적·양적 연구를 통해 인적취약점 분류에 대한 최적화된 분류 모형을 제시함으로써 보안 위협에 대한 좀 더 근본적인 접근을 시도해 보고자 노력했다. 또한 본 논문에서 제시한 인적취약점 분류 모형을 근거로 유형별 측정지표 개발을 진행했고 단계별 연구와 확장개발 및 검증을 통해서 최종 168개의 인적보안 측정지표 항목들을 도출함으로써 인적보안의 추상적인 통제 기준을 좀 더 명확하고 객관화시키고자 했다. 기존 기술적 관점의 취약점에 비해 사람 관점에서 유발할 수 있는 보안 취약점에 대한 분류 모형이나 측정지표 개발에 관한 선행 연구가 없었고 처음 시도되는 연구 분야인 만큼 관련분야 전문가 대상 FGI와 델파이 조사에 의존할 수밖에 없었다. 결론적으로 인적보안 연구 현황이나 정보보안의 한계점을 고려할 때 본 연구에서 제시하는 인적취약점 분류 모형 및 유형별 측정지표 개발은 다양하고 복잡한 정보기술 환경의 보안 위협 속에서 인적보안의 새로운 뉴노멀(New Normal)이 될 것으로 확신한다.

    더보기

    목차 (Table of Contents)

    • 제 1 장 서 론 1
    • 제 2 장 이론적 배경 13
    • 제 1 절 인적보안 관련 현황 13
    • 1. 인적보안 연구 현황과 필요성 13
    • 2. 인간중심 보안 17
    • 제 1 장 서 론 1
    • 제 2 장 이론적 배경 13
    • 제 1 절 인적보안 관련 현황 13
    • 1. 인적보안 연구 현황과 필요성 13
    • 2. 인간중심 보안 17
    • 제 2 절 인적보안 관련 정책 동향 23
    • 1. 국내 인적보안 정책 동향 23
    • 2. 해외 인적보안 정책 동향 27
    • 제 3 절 인적보안 관련 선행연구 31
    • 1. 정보보호 관리체계 및 인적보안 관련 문헌분석 31
    • 2. 가치관계 확장법 42
    • 3. 기존 연구와의 차별성과 본 연구의 의의 44
    • 제 3 장 인적취약점 분류 모형 및 측정지표 개발 49
    • 제 1 절 인적취약점 분류 모형 및 구성요소 49
    • 1. 인적취약점 분류 모형 및 구성요소 개요 49
    • 2. 인적취약점 분류 모형 및 구성 요소별 조작적 정의 52
    • 3. 인적취약점 분류 모형 및 구성요소 연구 과정 55
    • 4. 인적취약점 분류 모형 및 구성요소 연구 결과 62
    • 제 2 절 인적취약점 분류 유형별 측정지표 개발 66
    • 1. 인적취약점 분류 유형별 측정지표 개요 66
    • 2. 인적취약점 유형별 측정지표 도출 68
    • 3. 인적취약점 유형별 측정지표 연구 과정 76
    • 4. 인적취약점 유형별 측정지표 연구 결과 79
    • 제 3 절 인적취약점 분류 모형 결과 및 유형별 측정지표 확장개발 85
    • 1. 인적취약점 분류 모형 결과 및 유형별 측정지표 개발 개요 85
    • 2. 인적취약점 분류 모형 및 구성 요소별 조작적 정의 86
    • 3. 인적취약점 유형별 측정지표 확장개발 과정 91
    • 4. 인적취약점 유형별 측정지표 확장개발 결과 93
    • 제 4 장 인적취약점 분류 모형 및 측정지표 분석 98
    • 제 1 절 인적취약점 분류 모형 상관관계 및 신뢰성 분석 98
    • 1. 분석 방법 및 절차 98
    • 2. 분석 결과 99
    • 3. 설문 대상 표본의 특성 102
    • 4. 기술 통계량 분석 103
    • 5. 신뢰도 분석 104
    • 6. 상관관계 분석 106
    • 제 2 절 인적취약점 유형별 측정지표 타당도 및 신뢰성 분석 115
    • 1. 분석 방법 및 절차 115
    • 2. 분석 결과 118
    • 3. 설문 대상 표본의 특성 132
    • 4. 타당도 및 신뢰도 분석 133
    • 제 3 절 인적취약점 위험도에 대한 수학적 모델링 및 정량적 범위 산정 139
    • 1. 인적취약점 분류 모형 및 측정지표 간 관계 설정 139
    • 2. 인적취약점 위험도에 대한 수학적 모델링 146
    • 3. 인적취약점 분류 모형 및 측정지표 활용을 위한 구조 분석 150
    • 제 5 장 결 론 157
    • 참 고 문 헌 163
    • 부 록 175
    • <부록 1> 인적취약점 분류 모형에 관한 연구 설문 조사지 175
    • <부록 2> 인적취약점 분류 모형 기반의 유형별 측정지표 연구(案) 182
    • <부록 3> 인적취약점 분류 모형 및 유형별 측정지표 확장개발 연구(案) 194
    • ABSTRACT 217
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼