RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    품질과 비용을 고려한 프로세스 기반의 보안공학방법론에 관한 연구 = A Study on a Security Engineering Methodology for Information Security Systems Considering Quality and Cost

    한글로보기

    https://www.riss.kr/link?id=A77051070

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    For reliability and confidentiality of information security systems, the security engineering methodologies are accepted in many organizations. To improve the effectiveness of security engineering, this paper suggests a security methodology ISEM, which considers both product assurance and production processes, takes advantages in terms of quality and cost. To verify the effectiveness of ISEM, this paper introduces the concepts of quality loss, and compares the development costs and quality losses between ISEM and CC through the development of VPN system.
    번역하기

    For reliability and confidentiality of information security systems, the security engineering methodologies are accepted in many organizations. To improve the effectiveness of security engineering, this paper suggests a security methodology ISEM, whic...

    For reliability and confidentiality of information security systems, the security engineering methodologies are accepted in many organizations. To improve the effectiveness of security engineering, this paper suggests a security methodology ISEM, which considers both product assurance and production processes, takes advantages in terms of quality and cost. To verify the effectiveness of ISEM, this paper introduces the concepts of quality loss, and compares the development costs and quality losses between ISEM and CC through the development of VPN system.

    더보기

    목차 (Table of Contents)

    • Abstract
    • 1. 서론
    • 2. 보안공학방법론 고찰
    • 3. 프로세스기반의 ISEM 방법론
    • 4. ISEM 방법론과 CC 적용 비교 분석
    • Abstract
    • 1. 서론
    • 2. 보안공학방법론 고찰
    • 3. 프로세스기반의 ISEM 방법론
    • 4. ISEM 방법론과 CC 적용 비교 분석
    • 5. 결론
    • 참고문헌
    • 저자소개
    더보기

    참고문헌 (Reference)

    1 한국정보보호진흥원, "정보보호시스템 평가인증 가이드"

    2 김종기, "시스템 보안공학 능력 성숙도 모델 고찰" (6) : 2001

    3 Anderson,R, "Why information Security Is Hard(An Economic Perspective)" 2001

    4 Mouratidis,H., "When Security Meets Software Engineering: a Case of Modelling Secure Information Systems" 30 (30): 609-629, 2005

    5 Massacci,F., "Using a Security Requriements Engineering Methodology in Practice:The Compliance with the Italian Data Protection Legislation" 27 (27): 445-455, 2005

    6 Department of Defense, "Trusted Computer System Evaluation Criteria" Department of Defense 1985

    7 Shin,S.M., "Trade-off Studies on Process Parameters:A Robust Design Perspective" 2000

    8 Godrdon,L., "The Economics of Information Security Investment" 5 (5): 438-457, 2002

    9 Baskerville,R, "The Developmental Duality of Information Systems Security" 4 (4): 1-12, 1992

    10 ISO/IEC, "TR13335, Guideline for the Management of IT Security, ISO/IEC JTC1 SC27/WG1" ISO/IEC 1996

    1 한국정보보호진흥원, "정보보호시스템 평가인증 가이드"

    2 김종기, "시스템 보안공학 능력 성숙도 모델 고찰" (6) : 2001

    3 Anderson,R, "Why information Security Is Hard(An Economic Perspective)" 2001

    4 Mouratidis,H., "When Security Meets Software Engineering: a Case of Modelling Secure Information Systems" 30 (30): 609-629, 2005

    5 Massacci,F., "Using a Security Requriements Engineering Methodology in Practice:The Compliance with the Italian Data Protection Legislation" 27 (27): 445-455, 2005

    6 Department of Defense, "Trusted Computer System Evaluation Criteria" Department of Defense 1985

    7 Shin,S.M., "Trade-off Studies on Process Parameters:A Robust Design Perspective" 2000

    8 Godrdon,L., "The Economics of Information Security Investment" 5 (5): 438-457, 2002

    9 Baskerville,R, "The Developmental Duality of Information Systems Security" 4 (4): 1-12, 1992

    10 ISO/IEC, "TR13335, Guideline for the Management of IT Security, ISO/IEC JTC1 SC27/WG1" ISO/IEC 1996

    11 John Leach, "TBSE-an Engineering Approach to the Design of Accurate and Reliable Security Systems" 23 : 63-76, 2004

    12 Hefner,R., "System Security Engineering Capability Mutu1rity Model" 1997

    13 Wood,C.C., "Shifting IS Security Responsibility from User Organization to Vendor/ Publisher Organizations" 14 (14): 283-284, 1995

    14 Gentile,F., "Security Evaluation in Information Technology Standards" 13 (13): 647-650, 1994

    15 Strous,L., "Security Evaluation Criteria" 13 (13): 379-384, 1994

    16 John Leach, "Security Engineering and Security Rol" 22 (22): 482-486, 2003

    17 "SSE-CMM Project, Systems SE Capability Maturity Model Version 2.0 April" Systems SE Capability Maturity Model Version 2.0 April

    18 Lee,Y., "Integrating Software Lifecycle Process Standards with Security Engineering" 21 (21): 345-355, 2002

    19 Higginbothan, M. D., "Integrating Information SE with Systems Engineering with System Engineering Tools" 320-326, 1998

    20 European Commission, "Information Technology Security Evaluation Criteria(ITSEC)"

    21 Finne,T., "Information Systems Risk Management: Key Concepts and Business Process" 19 (19): 234-240, 2000

    22 Eloff,M., "Information Security Management, An Hierachical Framework for Various Approaches" 19 (19): 243-256, 2000

    23 Eloff, M., "Information Security Management, An Approach to Combine Process Certification And Product Evaluation" 19 (19): 698-709, 2000

    24 GISA, "IT Baseline Protection Manual (ITBPM)" BSI 1995

    25 Pijl,G., "ISO 9000 versus CMM: Standardization and Certification of IS Development" 32 : 267-274, 1997

    26 Wood,C.C., "ISO 9000 and information, Security" 14 (14): 287-288, 1995

    27 Wood,C.C., "ISO 9000 and Information Security" 14 : 287-288, 1995

    28 Wood,C.C., "How to Achieve a Clear Definition of Responsibilities for Information Security, DATAPRO" Information Security 1993

    29 Zuccato,A., "Holistic Security Requirement Engineering for Electronic Commerce" 23 (23): 63-76, 2004

    30 Horman, T. P., "Evaluation of Certification Validation Mechanisms" 29 (29): 2006

    31 Stallings,W., "Cryptography and Network Security:Principles and Practice, Second Ed." Prentice-Hall, Englewood Cliffs 1999

    32 Qadeer,S., "Context-Bounded Model Checking of Concurrent Software" 3440 : 93-107, 2005

    33 A.Purse,S., "Computers and Security" 23 (23): 542-546, 2004

    34 Hankcock,B., "Computer and Security" 19 (19): 2-5, 2000

    35 Watt,S., "Computer Security Manager" Elsevier Science Publishers Ltd. 1989

    36 Robinson,J., "Computer Security Evaluation :Developments in the European ITSEC Programme" 11 (11): 518-524, 1992

    37 ISO/IEC, "Common Methodology for Information Technology Security Evaluation Part 2:Evaluation Methodology Version 1.0"

    38 ISO/IEC(c), "Common Criteria for Information Technology Security Evaluation Part 3:Security Assurance Requirements Version 2.1" 1999

    39 ISO/IEC(b), "Common Criteria for Information Technology Security Evaluation Part 2:Security Functional Requirements Version 2.1"

    40 ISO/IEC(a), "Common Criteria for Information Technology Security Evaluation Part 1:Introduction and General Model, Version 2.1"

    41 Piazzal,C., "CoPSChecker of Persistent Security" 2988 : 93-107, 2004

    42 Software Engineering Institute, "Carnegie Mellon Univ.:SSE-CMM Appraisal Method, V.2.0"

    43 Mark,P., "Capability Maturity Model for Software version 1.1" Pittsburgh, Pa, Software Engineering Institute, Carnegie Mellon University 1993

    44 CSE, "Canadian Handbook on Information Technology Security, Communications Security Establishment" Government of Canada 1998

    45 ISACA, "COBIT, Framework, 2nd Edition" ISACA 1998

    46 Steve,M., "CMM Appraisal Framework, Version 1.0" Carnegie Mellon University 1995

    47 Herbsleb, J., "Benefits of CMMBased Software Process Improvement: Initial Results" Software Engineering Institute, Carnegie Mellon University 1994

    48 Purse,S.A., "Balancing Opportunity and Risk" 9 (9): 2004

    49 British Standard Institute, "BS 7799:Code of Practice for Information Security Management( CoP), PD0003"

    50 Schneier,B., "Applied Cryptography" John Wiley and Sons INC. 1993

    51 Mecuri,RT., "Analyzing Security Costs" 46 (46): 2003

    52 Konard,M.D., "An Overview of SPICE’s Model for Process Management" 291-301, 1995

    53 NIST, "An Introduction to Computer Security: The NIST Handbook, National Institute of Standards and Technology, U.S." Department of Commerce 1995

    54 Lee,S.Y., "An Empirical Study of Quality and Cost Based Security Engineering" 3903 : 2006

    55 Fung,A.R.W., "A Study on the Certification of the Information Security Management Systems" 25 (25): 447-461, 2003

    56 Purse,S.A., "A Practical Guide to Managing Information Security" Artech House 2004

    57 Avusoglu, H., "A Model for Evaluating IT Security Investments" 24 (24): 2004

    58 Brink,D., "A Guide to Determining Return on Investment for e-Security"

    59 Pfleeger,S.L., "A Framework for Security Requirements" 10 (10): 515-523, 1991

    60 Barnard,L., "A Formalized Approach to the Effective Selection and Evaluation of Information Security Controls" 19 (19): 185-194, 2000

    더보기

    동일학술지(권/호) 다른 논문

    동일학술지 더보기

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    인용정보 인용지수 설명보기

    학술지 이력

    학술지 이력
    연월일 이력구분 이력상세 등재구분
    2026 평가 재인증평가 신청대상 (재인증)
    2020-04-01 학회명변경 한글명 : 한국데이타베이스학회 -> 한국데이터전략학회
    영문명 : 미등록 -> Korea Data Strategy Society
    KCI등재
    2020-01-01 등재 등재학술지 유지 (재인증) KCI등재
    2017-01-01 등재 등재학술지 유지 (계속평가) KCI등재
    2013-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2010-06-22 학술지명변경 한글명 : Journal of Information Technology Applications & Menagement -> Journal of Information Technology Applications & Management
    외국어명 : Journal of Information Technology Applications & Menagement -> Journal of Information Technology Applications & Management
    KCI등재
    2010-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2008-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2005-01-01 등재 등재학술지 선정 (등재후보2차) KCI등재
    2004-01-01 등재 등재후보 1차 PASS (등재후보1차) KCI등재후보
    2002-01-01 등재 등재후보학술지 선정 (신규평가) KCI등재후보
    더보기

    학술지 인용정보

    학술지 인용정보
    기준연도 WOS-KCI 통합IF(2년) KCIF(2년) KCIF(3년)
    2016 0.39 0.39 0.48
    KCIF(4년) KCIF(5년) 중심성지수(3년) 즉시성지수
    0.59 0.56 0.673 0.18
    더보기

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼