1 한국정보보호진흥원, "정보보호시스템 평가인증 가이드"
2 김종기, "시스템 보안공학 능력 성숙도 모델 고찰" (6) : 2001
3 Anderson,R, "Why information Security Is Hard(An Economic Perspective)" 2001
4 Mouratidis,H., "When Security Meets Software Engineering: a Case of Modelling Secure Information Systems" 30 (30): 609-629, 2005
5 Massacci,F., "Using a Security Requriements Engineering Methodology in Practice:The Compliance with the Italian Data Protection Legislation" 27 (27): 445-455, 2005
6 Department of Defense, "Trusted Computer System Evaluation Criteria" Department of Defense 1985
7 Shin,S.M., "Trade-off Studies on Process Parameters:A Robust Design Perspective" 2000
8 Godrdon,L., "The Economics of Information Security Investment" 5 (5): 438-457, 2002
9 Baskerville,R, "The Developmental Duality of Information Systems Security" 4 (4): 1-12, 1992
10 ISO/IEC, "TR13335, Guideline for the Management of IT Security, ISO/IEC JTC1 SC27/WG1" ISO/IEC 1996
1 한국정보보호진흥원, "정보보호시스템 평가인증 가이드"
2 김종기, "시스템 보안공학 능력 성숙도 모델 고찰" (6) : 2001
3 Anderson,R, "Why information Security Is Hard(An Economic Perspective)" 2001
4 Mouratidis,H., "When Security Meets Software Engineering: a Case of Modelling Secure Information Systems" 30 (30): 609-629, 2005
5 Massacci,F., "Using a Security Requriements Engineering Methodology in Practice:The Compliance with the Italian Data Protection Legislation" 27 (27): 445-455, 2005
6 Department of Defense, "Trusted Computer System Evaluation Criteria" Department of Defense 1985
7 Shin,S.M., "Trade-off Studies on Process Parameters:A Robust Design Perspective" 2000
8 Godrdon,L., "The Economics of Information Security Investment" 5 (5): 438-457, 2002
9 Baskerville,R, "The Developmental Duality of Information Systems Security" 4 (4): 1-12, 1992
10 ISO/IEC, "TR13335, Guideline for the Management of IT Security, ISO/IEC JTC1 SC27/WG1" ISO/IEC 1996
11 John Leach, "TBSE-an Engineering Approach to the Design of Accurate and Reliable Security Systems" 23 : 63-76, 2004
12 Hefner,R., "System Security Engineering Capability Mutu1rity Model" 1997
13 Wood,C.C., "Shifting IS Security Responsibility from User Organization to Vendor/ Publisher Organizations" 14 (14): 283-284, 1995
14 Gentile,F., "Security Evaluation in Information Technology Standards" 13 (13): 647-650, 1994
15 Strous,L., "Security Evaluation Criteria" 13 (13): 379-384, 1994
16 John Leach, "Security Engineering and Security Rol" 22 (22): 482-486, 2003
17 "SSE-CMM Project, Systems SE Capability Maturity Model Version 2.0 April" Systems SE Capability Maturity Model Version 2.0 April
18 Lee,Y., "Integrating Software Lifecycle Process Standards with Security Engineering" 21 (21): 345-355, 2002
19 Higginbothan, M. D., "Integrating Information SE with Systems Engineering with System Engineering Tools" 320-326, 1998
20 European Commission, "Information Technology Security Evaluation Criteria(ITSEC)"
21 Finne,T., "Information Systems Risk Management: Key Concepts and Business Process" 19 (19): 234-240, 2000
22 Eloff,M., "Information Security Management, An Hierachical Framework for Various Approaches" 19 (19): 243-256, 2000
23 Eloff, M., "Information Security Management, An Approach to Combine Process Certification And Product Evaluation" 19 (19): 698-709, 2000
24 GISA, "IT Baseline Protection Manual (ITBPM)" BSI 1995
25 Pijl,G., "ISO 9000 versus CMM: Standardization and Certification of IS Development" 32 : 267-274, 1997
26 Wood,C.C., "ISO 9000 and information, Security" 14 (14): 287-288, 1995
27 Wood,C.C., "ISO 9000 and Information Security" 14 : 287-288, 1995
28 Wood,C.C., "How to Achieve a Clear Definition of Responsibilities for Information Security, DATAPRO" Information Security 1993
29 Zuccato,A., "Holistic Security Requirement Engineering for Electronic Commerce" 23 (23): 63-76, 2004
30 Horman, T. P., "Evaluation of Certification Validation Mechanisms" 29 (29): 2006
31 Stallings,W., "Cryptography and Network Security:Principles and Practice, Second Ed." Prentice-Hall, Englewood Cliffs 1999
32 Qadeer,S., "Context-Bounded Model Checking of Concurrent Software" 3440 : 93-107, 2005
33 A.Purse,S., "Computers and Security" 23 (23): 542-546, 2004
34 Hankcock,B., "Computer and Security" 19 (19): 2-5, 2000
35 Watt,S., "Computer Security Manager" Elsevier Science Publishers Ltd. 1989
36 Robinson,J., "Computer Security Evaluation :Developments in the European ITSEC Programme" 11 (11): 518-524, 1992
37 ISO/IEC, "Common Methodology for Information Technology Security Evaluation Part 2:Evaluation Methodology Version 1.0"
38 ISO/IEC(c), "Common Criteria for Information Technology Security Evaluation Part 3:Security Assurance Requirements Version 2.1" 1999
39 ISO/IEC(b), "Common Criteria for Information Technology Security Evaluation Part 2:Security Functional Requirements Version 2.1"
40 ISO/IEC(a), "Common Criteria for Information Technology Security Evaluation Part 1:Introduction and General Model, Version 2.1"
41 Piazzal,C., "CoPSChecker of Persistent Security" 2988 : 93-107, 2004
42 Software Engineering Institute, "Carnegie Mellon Univ.:SSE-CMM Appraisal Method, V.2.0"
43 Mark,P., "Capability Maturity Model for Software version 1.1" Pittsburgh, Pa, Software Engineering Institute, Carnegie Mellon University 1993
44 CSE, "Canadian Handbook on Information Technology Security, Communications Security Establishment" Government of Canada 1998
45 ISACA, "COBIT, Framework, 2nd Edition" ISACA 1998
46 Steve,M., "CMM Appraisal Framework, Version 1.0" Carnegie Mellon University 1995
47 Herbsleb, J., "Benefits of CMMBased Software Process Improvement: Initial Results" Software Engineering Institute, Carnegie Mellon University 1994
48 Purse,S.A., "Balancing Opportunity and Risk" 9 (9): 2004
49 British Standard Institute, "BS 7799:Code of Practice for Information Security Management( CoP), PD0003"
50 Schneier,B., "Applied Cryptography" John Wiley and Sons INC. 1993
51 Mecuri,RT., "Analyzing Security Costs" 46 (46): 2003
52 Konard,M.D., "An Overview of SPICE’s Model for Process Management" 291-301, 1995
53 NIST, "An Introduction to Computer Security: The NIST Handbook, National Institute of Standards and Technology, U.S." Department of Commerce 1995
54 Lee,S.Y., "An Empirical Study of Quality and Cost Based Security Engineering" 3903 : 2006
55 Fung,A.R.W., "A Study on the Certification of the Information Security Management Systems" 25 (25): 447-461, 2003
56 Purse,S.A., "A Practical Guide to Managing Information Security" Artech House 2004
57 Avusoglu, H., "A Model for Evaluating IT Security Investments" 24 (24): 2004
58 Brink,D., "A Guide to Determining Return on Investment for e-Security"
59 Pfleeger,S.L., "A Framework for Security Requirements" 10 (10): 515-523, 1991
60 Barnard,L., "A Formalized Approach to the Effective Selection and Evaluation of Information Security Controls" 19 (19): 185-194, 2000