RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    사이버보안 리스크와 이사회의 역할 - 試論的 고찰 = Cybersecurity Risks and the Role of the Corporate Boards – An Initial Review

    한글로보기

    https://www.riss.kr/link?id=A108884747

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    Cybersecurity risks have emerged as a pivotal factor with the potential to significantly impact a companyʼs performance. Managing and mitigating such risks have gained prominence as a critical mission for corporate boards. Within the European Union (EU), NIS2 underscores the role of the board of directors in addressing cybersecurity risks. Drawing from the recent judicial trends emphasizing the duty of oversight in the state of Delaware, it is anticipated that legal precedents acknowledging board membersʼ breaches of duty due to inadequate internal control systems related to cyber security risks will soon materialize. In line with the proactive stance of Korean Supreme Court in recognizing directorsʼ liability for breaches of the duty of oversight, it is foreseeable that South Korea will follow a similar trajectory to the United States.
    In the context of cyber security risks, proactive risk management and the implementation of appropriate procedures hold more significance than retrospective accountability. The board should be cognizant of the importance of cybersecurity risks and devote attention to devising suitable procedures in light of the companyʼs operational circumstances for effectively managing such risks. However, as directors cannot become cybersecurity experts themselves, their role entails (i) posing pertinent questions to the management, thereby encouraging them to allocate the necessary resources for cybersecurity risk management, and (ii) securing the establishment of post-incident procedures aimed at minimizing damages in the event of a cyber security breach.
    번역하기

    Cybersecurity risks have emerged as a pivotal factor with the potential to significantly impact a companyʼs performance. Managing and mitigating such risks have gained prominence as a critical mission for corporate boards. Within the European Union (...

    Cybersecurity risks have emerged as a pivotal factor with the potential to significantly impact a companyʼs performance. Managing and mitigating such risks have gained prominence as a critical mission for corporate boards. Within the European Union (EU), NIS2 underscores the role of the board of directors in addressing cybersecurity risks. Drawing from the recent judicial trends emphasizing the duty of oversight in the state of Delaware, it is anticipated that legal precedents acknowledging board membersʼ breaches of duty due to inadequate internal control systems related to cyber security risks will soon materialize. In line with the proactive stance of Korean Supreme Court in recognizing directorsʼ liability for breaches of the duty of oversight, it is foreseeable that South Korea will follow a similar trajectory to the United States.
    In the context of cyber security risks, proactive risk management and the implementation of appropriate procedures hold more significance than retrospective accountability. The board should be cognizant of the importance of cybersecurity risks and devote attention to devising suitable procedures in light of the companyʼs operational circumstances for effectively managing such risks. However, as directors cannot become cybersecurity experts themselves, their role entails (i) posing pertinent questions to the management, thereby encouraging them to allocate the necessary resources for cybersecurity risk management, and (ii) securing the establishment of post-incident procedures aimed at minimizing damages in the event of a cyber security breach.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    사이버보안 리스크는 회사의 성과에 큰 영향을 미칠 수 있는 중요한 요소로 등장하고 있고, 그러한 리스크의 관리 및 방지는 이사회의 중대한 임무로 부각되고 있다. EU에서는 NIS2가 사이버보안 리스크에 관한 이사회의 역할을 강조하고 있다. 감시의무를 강조하는 미국 델라웨어주의 최근 판례 경향에 비추어보면, 사이버보안 리스크에 대한 내부통제시스템 미비를 이유로 이사의 의무위반을 인정하는 판례도 조만간 등장할 것으로 예상된다. 최근 감시의무 위반으로 인한 이사의 책임을 적극적으로 인정하는 우리 대법원의 경향에 비추어 보면, 우리나라도 미국과 유사한 경향을 보일 것이다.
    사이버보안 리스크에 대해서는 사후적인 책임추궁보다는 사전적인 리스크 관리 및 적정한 절차가 더 중요하다. 이사회는 사이버보안 리스크의 중요성을 인지하고, 회사의 영업실태에 비추어 그러한 리스크를 관리할 수 있는 적절한 절차를 마련하는 데 주의를 기울여야 한다. 다만 이사들이 직접 보안전문가가 될 수는 없으므로, 이사들의 역할은 직접 사이버보안 리스크 관리에 나서는 것이 아니라, (i) 경영진에게 적절한 질문을 던지고 주의를 환기함으로써 경영진으로 하여금 사이버보안 리스크 관리에 적절한 자원을 투입할 수 있도록 하고, (ii) 사고 발생시 피해 최소화를 위한 절차를 사전에 마련하도록 촉구하는 것이어야 한다.
    번역하기

    사이버보안 리스크는 회사의 성과에 큰 영향을 미칠 수 있는 중요한 요소로 등장하고 있고, 그러한 리스크의 관리 및 방지는 이사회의 중대한 임무로 부각되고 있다. EU에서는 NIS2가 사이버...

    사이버보안 리스크는 회사의 성과에 큰 영향을 미칠 수 있는 중요한 요소로 등장하고 있고, 그러한 리스크의 관리 및 방지는 이사회의 중대한 임무로 부각되고 있다. EU에서는 NIS2가 사이버보안 리스크에 관한 이사회의 역할을 강조하고 있다. 감시의무를 강조하는 미국 델라웨어주의 최근 판례 경향에 비추어보면, 사이버보안 리스크에 대한 내부통제시스템 미비를 이유로 이사의 의무위반을 인정하는 판례도 조만간 등장할 것으로 예상된다. 최근 감시의무 위반으로 인한 이사의 책임을 적극적으로 인정하는 우리 대법원의 경향에 비추어 보면, 우리나라도 미국과 유사한 경향을 보일 것이다.
    사이버보안 리스크에 대해서는 사후적인 책임추궁보다는 사전적인 리스크 관리 및 적정한 절차가 더 중요하다. 이사회는 사이버보안 리스크의 중요성을 인지하고, 회사의 영업실태에 비추어 그러한 리스크를 관리할 수 있는 적절한 절차를 마련하는 데 주의를 기울여야 한다. 다만 이사들이 직접 보안전문가가 될 수는 없으므로, 이사들의 역할은 직접 사이버보안 리스크 관리에 나서는 것이 아니라, (i) 경영진에게 적절한 질문을 던지고 주의를 환기함으로써 경영진으로 하여금 사이버보안 리스크 관리에 적절한 자원을 투입할 수 있도록 하고, (ii) 사고 발생시 피해 최소화를 위한 절차를 사전에 마련하도록 촉구하는 것이어야 한다.

    더보기

    참고문헌 (Reference)

    1 김인석, "전자금융보안론" IT포럼 2015

    2 송옥렬, "이사의 감시의무와 내부통제시스템 구축의무" 한국기업법학회 36 (36): 9-43, 2022

    3 윤상필, "사이버보안취약점의 법적 규제" 박영사 2022

    4 팔로알토 네트웍스, "디지털시대 사이버보안으로 항해하라" 화산미디어 2019

    5 전준영, "내부통제시스템 구축의무와 이사의 책임" 한국상사법학회 40 (40): 235-284, 2022

    6 폴 로마이어, "금융 사이버 보안 리스크 관리" 에이콘출판 2019

    7 Park, Sangchul, "Why Information Security Law Has Been Ineffective in Addressing Security Vulnerabilities" 58 : 2019

    8 Federal Office for Information Security, "The State of IT Security in Germany 2022" 2022

    9 Baker, Tom, "The Government behind Insurance Governance: Lessons for Ransomware" 17 : 2023

    10 Kempf, Mary Ellen, "The Duty to Monitor: How the Mission Critical Doctrine in Marchand Informs Directors Liability for Cybersecurity Breaches" 36 : 2022

    1 김인석, "전자금융보안론" IT포럼 2015

    2 송옥렬, "이사의 감시의무와 내부통제시스템 구축의무" 한국기업법학회 36 (36): 9-43, 2022

    3 윤상필, "사이버보안취약점의 법적 규제" 박영사 2022

    4 팔로알토 네트웍스, "디지털시대 사이버보안으로 항해하라" 화산미디어 2019

    5 전준영, "내부통제시스템 구축의무와 이사의 책임" 한국상사법학회 40 (40): 235-284, 2022

    6 폴 로마이어, "금융 사이버 보안 리스크 관리" 에이콘출판 2019

    7 Park, Sangchul, "Why Information Security Law Has Been Ineffective in Addressing Security Vulnerabilities" 58 : 2019

    8 Federal Office for Information Security, "The State of IT Security in Germany 2022" 2022

    9 Baker, Tom, "The Government behind Insurance Governance: Lessons for Ransomware" 17 : 2023

    10 Kempf, Mary Ellen, "The Duty to Monitor: How the Mission Critical Doctrine in Marchand Informs Directors Liability for Cybersecurity Breaches" 36 : 2022

    11 Logue, Kyle D., "The Case for Banning (and Mandating) Ransomware Insurance" 28 : 2021

    12 Morrison Foester, "Privacy Litigation 2022 Year in Review: Data Breach Litigation" 2023

    13 Pace, H. Justin, "Mission Critical: Caremark, Blue Bell, and Director Responsibility for Cybersecurity Governance" 2022 : 2022

    14 Evans, Ariel, "Managing Cyber Risk" Routledge 2019

    15 Ko, Haksoo, "How to De-Identify Personal Data in South Korea: an Evolutionary Tale" 10 (10): 2020

    16 Federation of European Risk Management Associations, "European Risk Manager Survey Report 2022" 2022

    17 US National Association of Corporate Directors, "Directorʼs Handbook on Cyber-Risk Oversight" 2023

    18 Edwards, Benjamin P., "Cybersecurity Oversight Liability" ʼ35 : 2019

    19 Klemash, Steve W., "Cybersecurity Disclosure Benchmarking" 2018

    20 Yar, Majid, "Cybercrime and Society" Sage 2013

    21 Trautman, Lawrence J., "Corporate Directorsʼ and Officersʼ Cybersecurity Standard of Care: the Yahoo Data Breach" 66 : 2017

    22 Ferrillo, Paul, "Boards Should Care More about Recent Caremark Claims and Cybersecurity" 2020

    더보기

    동일학술지(권/호) 다른 논문

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼