금융기관은 고객의 금융거래 정보를 비롯한 민감한 개인정보를 대량으로 보유하고 있어 그 중요성은 매우 크다. 개인정보는 금융서비스 제공의 핵심 자원으로서, 이를 안전하게 보호하는 ...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T17264783
서울: 동국대학교 국제정보보호대학원, 2025
학위논문(석사) -- 동국대학교 국제정보보호대학원 , 정보보호학과 정보보호전공 , 2025. 8
2025
한국어
금융기관의 개인정보 ; 개인정보 유출 ; 기술적 적용
005.8 판사항(22)
서울
A Study on Technical Implementation Measures to Prevent Personal Information Leakage in Financial Institutions
iv, 56 p.: 삽도; 26 cm.
동국대학교 논문은 저작권법에 의해 보호받습니다
지도교수: 이재우
I804:11020-000000092044
0
상세조회0
다운로드금융기관은 고객의 금융거래 정보를 비롯한 민감한 개인정보를 대량으로 보유하고 있어 그 중요성은 매우 크다. 개인정보는 금융서비스 제공의 핵심 자원으로서, 이를 안전하게 보호하는 ...
금융기관은 고객의 금융거래 정보를 비롯한 민감한 개인정보를 대량으로 보유하고 있어 그 중요성은 매우 크다. 개인정보는 금융서비스 제공의 핵심 자원으로서, 이를 안전하게 보호하는 것은 금융기관의 책무이다. 개인정보를 보호하기 위한 수단으로 다양한 법률과 규제를 적용받고 있는 금융사에서 가장 큰 개인정보 유출 사건으로 2014년 사상 최대의 “카드 3사 개인정보 유출” 사건이 발생하였다. 이후 개인정보 보호 관련 제도들이 보완되었으며, 정보보호 관리체계를 강화하는 등 다양한 노력을 해온 결과 개인정보 유출 사고 건수는 이전보다 많이 줄어들었다.
하지만 개인정보 유출 사고는 현재까지 지속적으로 발생하고 있다. 사례로는 1)외주 협력업체를 통한 유출, 2)내부 직원 및 시스템 오류에 의한 유출, 3)외부 공격자에 의한 유출 등이 있으며, 상대적으로 보안 수준이 낮은 저축은행에서 개인정보 유출 사고 빈도가 높지만 대기업에서도 예외 없이 발생하고 있다. 이처럼 충분한 테스트와 검증이 부족하거나 업무에 과도한 권한 부여로 개인정보 유출 사고가 발생하였으며, 정보보호 관리체계에 대한 지적을 피할 수 없게 되었다.
이를 방지하기 위해서 관리적 체계 부분을 상호 보완하여 기술적으로 자동화 하는 방안을 검토할 필요성이 있다. 내부망 PC와 서버의 개인정보가 유출되지 않도록 기술적 보안 솔루션을 적용하고 주기적으로 점검하는 등 관리적 대책을 적용하고 있지만 적합한 승인 절차를 통해 유출된 개인정보에 대해서는 악의적인 목적으로 사용되더라도 뒤늦게 발견될 수밖에 없다. 마치 CCTV 사각지대에서 범죄가 일어났을 경우 경찰이 순찰을 주기적으로 하더라도 이미 범인은 사건 현장을 훼손하고 도주한다면 골든타임을 놓치게 되는 상황을 예시로 들 수 있다. 이를 예방하기 위해 사각지대 없이 CCTV를 설치하는 대응처럼 개인정보 보호 관련 보안 솔루션을 구축하고, 통합 모니터링 솔루션에 연동하여, 개인정보가 사용되는 기본 업무 외에 대량의 복호화나 반출이 수행되는 상황을 사각지대 없이 모니터링 되어야 한다. 개인정보가 유출되어 판매 또는 범죄에 이용된 후에 주기적인 점검이 수행되고 대응하더라도 골든타임이 지난 만큼 피해 규모는 커질 수 있다. 유출이 발생하는 즉시 개인정보보호 담당자에게 알람을 발생시키고, 골든타임 내에 상황을 해결하는 등 피해를 사전에 감지하고 대응하는 방안을 적용해야 한다.
다국어 초록 (Multilingual Abstract)
Financial institutions have a large amount of sensitive personal information, including customer financial transaction information, so its importance is very significant. Personal information is a key resource in providing financial services, and it i...
Financial institutions have a large amount of sensitive personal information, including customer financial transaction information, so its importance is very significant. Personal information is a key resource in providing financial services, and it is the responsibility of financial institutions to protect it safely. As the largest personal information leakage incident in financial companies subject to various laws and regulations as a means of protecting personal information, the largest "personal information leakage of three card companies" occurred in 2014. Since then, personal information protection-related systems have been supplemented, and as a result of various efforts such as strengthening the information protection management system, the number of personal information leakage accidents has decreased more than before.
However, personal information leakage accidents continue to occur to this day. Examples include 1) leakage through outsourced partners, 2) leakage by internal staff and system errors, and 3) leakage by external attackers. Although personal information leakage accidents are frequent in savings banks with relatively low security levels, they occur without exception in large companies. Personal information leakage accidents occurred due to insufficient testing and verification or excessive authorization of work, and it became inevitable to point out the information protection management system.
To prevent this, it is necessary to consider ways to technically automate the management system by complementing each other. Management measures such as applying technical security solutions and periodically inspecting personal information of internal network PCs and servers are applied to prevent leakage, but personal information leaked through appropriate approval procedures is bound to be found late even if it is used for malicious purposes. For example, if a crime occurs in a blind spot of CCTV, even if the police patrol regularly, the criminal will already miss the golden time if he or she damages the scene of the incident and escapes. To prevent this, a security solution related to personal information protection should be established, linked to an integrated monitoring solution, and a situation in which a large amount of decryption or export is performed in addition to the basic tasks in which personal information is used should be monitored without blind spots. Even if periodic inspections are performed and responded after personal information is leaked and used for sale or crime, the scale of damage can increase as the golden time has passed. As soon as a leak occurs, it is necessary to apply measures to detect and respond to the damage in advance, such as generating an alarm to the person in charge of personal information protection and resolving the situation within golden time.
목차 (Table of Contents)