RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    금융기관의 개인정보 유출 방지를 위한 기술적 적용 방안 연구

    한글로보기

    https://www.riss.kr/link?id=T17264783

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    국문 초록 (Abstract) kakao i 다국어 번역

    금융기관은 고객의 금융거래 정보를 비롯한 민감한 개인정보를 대량으로 보유하고 있어 그 중요성은 매우 크다. 개인정보는 금융서비스 제공의 핵심 자원으로서, 이를 안전하게 보호하는 것은 금융기관의 책무이다. 개인정보를 보호하기 위한 수단으로 다양한 법률과 규제를 적용받고 있는 금융사에서 가장 큰 개인정보 유출 사건으로 2014년 사상 최대의 “카드 3사 개인정보 유출” 사건이 발생하였다. 이후 개인정보 보호 관련 제도들이 보완되었으며, 정보보호 관리체계를 강화하는 등 다양한 노력을 해온 결과 개인정보 유출 사고 건수는 이전보다 많이 줄어들었다.
    하지만 개인정보 유출 사고는 현재까지 지속적으로 발생하고 있다. 사례로는 1)외주 협력업체를 통한 유출, 2)내부 직원 및 시스템 오류에 의한 유출, 3)외부 공격자에 의한 유출 등이 있으며, 상대적으로 보안 수준이 낮은 저축은행에서 개인정보 유출 사고 빈도가 높지만 대기업에서도 예외 없이 발생하고 있다. 이처럼 충분한 테스트와 검증이 부족하거나 업무에 과도한 권한 부여로 개인정보 유출 사고가 발생하였으며, 정보보호 관리체계에 대한 지적을 피할 수 없게 되었다.
    이를 방지하기 위해서 관리적 체계 부분을 상호 보완하여 기술적으로 자동화 하는 방안을 검토할 필요성이 있다. 내부망 PC와 서버의 개인정보가 유출되지 않도록 기술적 보안 솔루션을 적용하고 주기적으로 점검하는 등 관리적 대책을 적용하고 있지만 적합한 승인 절차를 통해 유출된 개인정보에 대해서는 악의적인 목적으로 사용되더라도 뒤늦게 발견될 수밖에 없다. 마치 CCTV 사각지대에서 범죄가 일어났을 경우 경찰이 순찰을 주기적으로 하더라도 이미 범인은 사건 현장을 훼손하고 도주한다면 골든타임을 놓치게 되는 상황을 예시로 들 수 있다. 이를 예방하기 위해 사각지대 없이 CCTV를 설치하는 대응처럼 개인정보 보호 관련 보안 솔루션을 구축하고, 통합 모니터링 솔루션에 연동하여, 개인정보가 사용되는 기본 업무 외에 대량의 복호화나 반출이 수행되는 상황을 사각지대 없이 모니터링 되어야 한다. 개인정보가 유출되어 판매 또는 범죄에 이용된 후에 주기적인 점검이 수행되고 대응하더라도 골든타임이 지난 만큼 피해 규모는 커질 수 있다. 유출이 발생하는 즉시 개인정보보호 담당자에게 알람을 발생시키고, 골든타임 내에 상황을 해결하는 등 피해를 사전에 감지하고 대응하는 방안을 적용해야 한다.
    번역하기

    금융기관은 고객의 금융거래 정보를 비롯한 민감한 개인정보를 대량으로 보유하고 있어 그 중요성은 매우 크다. 개인정보는 금융서비스 제공의 핵심 자원으로서, 이를 안전하게 보호하는 ...

    금융기관은 고객의 금융거래 정보를 비롯한 민감한 개인정보를 대량으로 보유하고 있어 그 중요성은 매우 크다. 개인정보는 금융서비스 제공의 핵심 자원으로서, 이를 안전하게 보호하는 것은 금융기관의 책무이다. 개인정보를 보호하기 위한 수단으로 다양한 법률과 규제를 적용받고 있는 금융사에서 가장 큰 개인정보 유출 사건으로 2014년 사상 최대의 “카드 3사 개인정보 유출” 사건이 발생하였다. 이후 개인정보 보호 관련 제도들이 보완되었으며, 정보보호 관리체계를 강화하는 등 다양한 노력을 해온 결과 개인정보 유출 사고 건수는 이전보다 많이 줄어들었다.
    하지만 개인정보 유출 사고는 현재까지 지속적으로 발생하고 있다. 사례로는 1)외주 협력업체를 통한 유출, 2)내부 직원 및 시스템 오류에 의한 유출, 3)외부 공격자에 의한 유출 등이 있으며, 상대적으로 보안 수준이 낮은 저축은행에서 개인정보 유출 사고 빈도가 높지만 대기업에서도 예외 없이 발생하고 있다. 이처럼 충분한 테스트와 검증이 부족하거나 업무에 과도한 권한 부여로 개인정보 유출 사고가 발생하였으며, 정보보호 관리체계에 대한 지적을 피할 수 없게 되었다.
    이를 방지하기 위해서 관리적 체계 부분을 상호 보완하여 기술적으로 자동화 하는 방안을 검토할 필요성이 있다. 내부망 PC와 서버의 개인정보가 유출되지 않도록 기술적 보안 솔루션을 적용하고 주기적으로 점검하는 등 관리적 대책을 적용하고 있지만 적합한 승인 절차를 통해 유출된 개인정보에 대해서는 악의적인 목적으로 사용되더라도 뒤늦게 발견될 수밖에 없다. 마치 CCTV 사각지대에서 범죄가 일어났을 경우 경찰이 순찰을 주기적으로 하더라도 이미 범인은 사건 현장을 훼손하고 도주한다면 골든타임을 놓치게 되는 상황을 예시로 들 수 있다. 이를 예방하기 위해 사각지대 없이 CCTV를 설치하는 대응처럼 개인정보 보호 관련 보안 솔루션을 구축하고, 통합 모니터링 솔루션에 연동하여, 개인정보가 사용되는 기본 업무 외에 대량의 복호화나 반출이 수행되는 상황을 사각지대 없이 모니터링 되어야 한다. 개인정보가 유출되어 판매 또는 범죄에 이용된 후에 주기적인 점검이 수행되고 대응하더라도 골든타임이 지난 만큼 피해 규모는 커질 수 있다. 유출이 발생하는 즉시 개인정보보호 담당자에게 알람을 발생시키고, 골든타임 내에 상황을 해결하는 등 피해를 사전에 감지하고 대응하는 방안을 적용해야 한다.

    더보기

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Financial institutions have a large amount of sensitive personal information, including customer financial transaction information, so its importance is very significant. Personal information is a key resource in providing financial services, and it is the responsibility of financial institutions to protect it safely. As the largest personal information leakage incident in financial companies subject to various laws and regulations as a means of protecting personal information, the largest "personal information leakage of three card companies" occurred in 2014. Since then, personal information protection-related systems have been supplemented, and as a result of various efforts such as strengthening the information protection management system, the number of personal information leakage accidents has decreased more than before.
    However, personal information leakage accidents continue to occur to this day. Examples include 1) leakage through outsourced partners, 2) leakage by internal staff and system errors, and 3) leakage by external attackers. Although personal information leakage accidents are frequent in savings banks with relatively low security levels, they occur without exception in large companies. Personal information leakage accidents occurred due to insufficient testing and verification or excessive authorization of work, and it became inevitable to point out the information protection management system.
    To prevent this, it is necessary to consider ways to technically automate the management system by complementing each other. Management measures such as applying technical security solutions and periodically inspecting personal information of internal network PCs and servers are applied to prevent leakage, but personal information leaked through appropriate approval procedures is bound to be found late even if it is used for malicious purposes. For example, if a crime occurs in a blind spot of CCTV, even if the police patrol regularly, the criminal will already miss the golden time if he or she damages the scene of the incident and escapes. To prevent this, a security solution related to personal information protection should be established, linked to an integrated monitoring solution, and a situation in which a large amount of decryption or export is performed in addition to the basic tasks in which personal information is used should be monitored without blind spots. Even if periodic inspections are performed and responded after personal information is leaked and used for sale or crime, the scale of damage can increase as the golden time has passed. As soon as a leak occurs, it is necessary to apply measures to detect and respond to the damage in advance, such as generating an alarm to the person in charge of personal information protection and resolving the situation within golden time.
    번역하기

    Financial institutions have a large amount of sensitive personal information, including customer financial transaction information, so its importance is very significant. Personal information is a key resource in providing financial services, and it i...

    Financial institutions have a large amount of sensitive personal information, including customer financial transaction information, so its importance is very significant. Personal information is a key resource in providing financial services, and it is the responsibility of financial institutions to protect it safely. As the largest personal information leakage incident in financial companies subject to various laws and regulations as a means of protecting personal information, the largest "personal information leakage of three card companies" occurred in 2014. Since then, personal information protection-related systems have been supplemented, and as a result of various efforts such as strengthening the information protection management system, the number of personal information leakage accidents has decreased more than before.
    However, personal information leakage accidents continue to occur to this day. Examples include 1) leakage through outsourced partners, 2) leakage by internal staff and system errors, and 3) leakage by external attackers. Although personal information leakage accidents are frequent in savings banks with relatively low security levels, they occur without exception in large companies. Personal information leakage accidents occurred due to insufficient testing and verification or excessive authorization of work, and it became inevitable to point out the information protection management system.
    To prevent this, it is necessary to consider ways to technically automate the management system by complementing each other. Management measures such as applying technical security solutions and periodically inspecting personal information of internal network PCs and servers are applied to prevent leakage, but personal information leaked through appropriate approval procedures is bound to be found late even if it is used for malicious purposes. For example, if a crime occurs in a blind spot of CCTV, even if the police patrol regularly, the criminal will already miss the golden time if he or she damages the scene of the incident and escapes. To prevent this, a security solution related to personal information protection should be established, linked to an integrated monitoring solution, and a situation in which a large amount of decryption or export is performed in addition to the basic tasks in which personal information is used should be monitored without blind spots. Even if periodic inspections are performed and responded after personal information is leaked and used for sale or crime, the scale of damage can increase as the golden time has passed. As soon as a leak occurs, it is necessary to apply measures to detect and respond to the damage in advance, such as generating an alarm to the person in charge of personal information protection and resolving the situation within golden time.

    더보기

    목차 (Table of Contents)

    • 제1장 서 론 1
    • 제1절 연구의 배경 및 목적 1
    • 제2절 연구의 범위 및 방법 3
    • 1. 연구의 범위 3
    • 2. 연구의 방법 4
    • 제1장 서 론 1
    • 제1절 연구의 배경 및 목적 1
    • 제2절 연구의 범위 및 방법 3
    • 1. 연구의 범위 3
    • 2. 연구의 방법 4
    • 제2장 금융기관의 개인정보 기술적 보호조치 현황 5
    • 제1절 금융기관의 개인정보 정의 5
    • 1. 개인정보의 개념 5
    • 2. 개인정보의 종류 7
    • 3. 금융기관의 개인정보 개념 8
    • 제2절 금융기관의 개인정보 기술적 보호조치 9
    • 1. 개인정보의 기술적 보호조치 개념 9
    • 2. 개인정보 유출 방지 기술 10
    • 가. 서버 보안 솔루션 10
    • 나. 사용자PC 보안 솔루션 15
    • 3. 금융기관의 개인정보 기술적 보호조치 관련 규제 20
    • 제3장 금융기관의 개인정보 유출 문제점 24
    • 제1절 금융기관의 개인정보 유출 현황 연구 24
    • 1. 외주 협력업체를 통한 유출 25
    • 2. 내부 직원 및 시스템 오류에 의한 유출 26
    • 3. 외부 공격자에 의한 유출 28
    • 4. 해외 개인정보 유출(미국) 29
    • 제2절 금융기관의 개인정보 반출 현황 연구 30
    • 1. 금융기관의 개인정보 반출 현황 30
    • 2. 금융기관의 유형별 개인정보 반출 현황 31
    • 제4장 금융기관의 개인정보 유출 방지 방안 34
    • 제1절 개인정보 유출 실시간 탐지 방안 34
    • 제2절 외부 협력업체 안전한 통제 방안 40
    • 제3절 내부 직원의 보안 인식 강화 43
    • 제4절 안전한 출력물 관리 방안 44
    • 제5절 취약점 상시 관리 방안 45
    • 제5장 결 론 48
    • 참 고 문 헌 50
    • ABSTRACT 54
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼