RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    CVE와 STIG/STG 맵핑을 통한 NIST SP 800-53의 통제항목 중요도 연구 = A Study on the Importance of Control Items of NIST SP 800-53 by Mapping CVE and STIG/SRG

    한글로보기

    https://www.riss.kr/link?id=A109405915

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    The U.S. federal government has established NIST SP 800-53 in response to the need for vulnerability management, and MITRE manages security vulnerabilities through CVE numbers. Although the relationship between NIST SP 800-53 and CVE is a crucial factor in vulnerability management, it is not clearly defined, making it challenging for security managers to identify control items that address the latest vulnerabilities. This study aims to analyze the relationship between NIST SP 800-53 and CVE to establish prioritization for evaluating security control items. Controls that are frequently associated with CVE should be prioritized for evaluation and improvement. The study derived the relevance between NIST SP 800-53 security controls through mapping CVE to STIG/SRG and used SecBERT, CyBERT, and RankT5 models to automate this mapping. The results confirmed the need to prioritize the improvement of specific security controls.
    번역하기

    The U.S. federal government has established NIST SP 800-53 in response to the need for vulnerability management, and MITRE manages security vulnerabilities through CVE numbers. Although the relationship between NIST SP 800-53 and CVE is a crucial fact...

    The U.S. federal government has established NIST SP 800-53 in response to the need for vulnerability management, and MITRE manages security vulnerabilities through CVE numbers. Although the relationship between NIST SP 800-53 and CVE is a crucial factor in vulnerability management, it is not clearly defined, making it challenging for security managers to identify control items that address the latest vulnerabilities. This study aims to analyze the relationship between NIST SP 800-53 and CVE to establish prioritization for evaluating security control items. Controls that are frequently associated with CVE should be prioritized for evaluation and improvement. The study derived the relevance between NIST SP 800-53 security controls through mapping CVE to STIG/SRG and used SecBERT, CyBERT, and RankT5 models to automate this mapping. The results confirmed the need to prioritize the improvement of specific security controls.

    더보기

    참고문헌 (Reference)

    1 CVE Details, "Vulnerabilities By Types/Categories"

    2 Canonical Ltd, "Ubuntu OVAL Data"

    3 National Institute of Standards and Technology (NIST), "Security and Privacy Controls for Information Systems and Organizations:NIST Special Publication 800-53, Revision 5"

    4 Efense Information Systems Agency, "Security Technical Implementation Guides (STIGs)"

    5 "Security Requirements Guide"

    6 Red Hat, Inc, "OVAL Repository"

    7 ational Institute of Standards and Technology, "OVAL Language Specification, Version 5.11.3" MITRE Corporation

    8 National Institute of Standards and Technology, "National Checklist Program Repository"

    9 Hamdani, S. W., "Framework for Assessing Information System Security Posture Risks" The University of Western Ontario 2023

    10 "Control Correlation Identifier(CCI) Process, version 1 release 0.1"

    1 CVE Details, "Vulnerabilities By Types/Categories"

    2 Canonical Ltd, "Ubuntu OVAL Data"

    3 National Institute of Standards and Technology (NIST), "Security and Privacy Controls for Information Systems and Organizations:NIST Special Publication 800-53, Revision 5"

    4 Efense Information Systems Agency, "Security Technical Implementation Guides (STIGs)"

    5 "Security Requirements Guide"

    6 Red Hat, Inc, "OVAL Repository"

    7 ational Institute of Standards and Technology, "OVAL Language Specification, Version 5.11.3" MITRE Corporation

    8 National Institute of Standards and Technology, "National Checklist Program Repository"

    9 Hamdani, S. W., "Framework for Assessing Information System Security Posture Risks" The University of Western Ontario 2023

    10 "Control Correlation Identifier(CCI) Process, version 1 release 0.1"

    11 National Institute of Standards and Technology, "Control Correlation Identifier (CCI)" NIST Computer Security Resource Center

    12 "Control Correlation Identifier"

    13 Cui, Y, "Class-Balanced Loss Based on Effective Number of Samples"

    14 MITRE Corporation, "CVE Numbering Authorities (CNAs)"

    15 Branescu, I., "Automated Mapping of Common Vulnerabilities and Exposures to MITRE ATT&CK Tactics" 15 (15): 214-, 2024

    16 Haddad, A., "Automated Mapping of CVE Vulnerability Records to MITRE CWE Weaknesses"

    17 나현대 ; 정현수, "A Theoretical Comparative Study of Human Resource Security Based on Korean and Int'l Information Security Management Systems" 6 (6): 13-19, 2016

    18 김소정, "A Comparative Study on Information Security Management Activity of Public Sector in USA & Korea" 13C (13C): 69-74, 2006

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼