본 연구는 공공기관 정보시스템 내에서 개인정보보호 영역을 중심으로, 운영감리체계를 검토하고, 문헌검토 및 실증적 방법을 통해 개선사항 및 추가사항을 파악하여, 개선된 공공기관 정...

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.
변환된 중국어를 복사하여 사용하시면 됩니다.
https://www.riss.kr/link?id=T13852180
서울 : 건국대학교 정보통신대학원, 2015
학위논문(석사) -- 건국대학교 정보통신대학원 , 정보시스템감리학과 정보시스템감리전공 , 2015. 8
2015
한국어
서울
97 ; 26 cm
지도교수: 김동수
0
상세조회0
다운로드본 연구는 공공기관 정보시스템 내에서 개인정보보호 영역을 중심으로, 운영감리체계를 검토하고, 문헌검토 및 실증적 방법을 통해 개선사항 및 추가사항을 파악하여, 개선된 공공기관 정...
본 연구는 공공기관 정보시스템 내에서 개인정보보호 영역을 중심으로, 운영감리체계를 검토하고, 문헌검토 및 실증적 방법을 통해 개선사항 및 추가사항을 파악하여, 개선된 공공기관 정보시스템의 개인정보보호 운영감리 모형을 제안하는데 목적을 두었다.
본 연구의 운영감리 개선방향은 공공기관 정보시스템의 개인정보보호에 있어서 내부정보유출 위험관리와 기술적 보호에 초점을 두었고, Von Solms et al.이 제시한 물리적, 관리적, 기술적 취약성 보안분류체계를 기초로 하여, 정보시스템 운영감리의 개인정보보호 점검항목 검토 및 PIMS, ISMS, ISO 27001 등에서 추출한 개인정보보호 관련 기준과 운영감리 관련 선행연구를 통하여 관리적, 물리적, 기술적 차원으로 구성된 공공기관 정보시스템의 개인정보보호 운영감리 개선모형 및 점검항목을 도출하였다.
이를 통해 공공기관 정보시스템의 개인정보보호 운영감리 개선모형의 3개 영역, 8개 점검항목, 52개의 세부검토항목을 얻을 수 있었다. 이러한 공공기관 정보시스템의 개인정보보호 운영감리 모형의 타당성과 적용가능성을 검증하고자, 실무전문가를 대상으로 설문조사 및 통계분석을 실시하였다. 그 결과 52개 항목 모두가 타당성과 신뢰성이 있는 것으로 판단되었다.
본 연구는 공공기관 정보시스템의 개인정보보호 운영감리 모형 개선에 관한 연구로서 차별성이 있으며, 본 연구를 통해 공공기관 정보시스템의 개인정보보호 운영감리 개선모형을 타당성 있게 개발하였고, 이를 통해 내부자의 고의나 실수로 국민의 소중한 개인정보가 유출될 수 있는 위험을 관리적, 물리적, 기술적 측면의 개인정보보호 운영감리를 활용하여 통제하고, 실효성 있는 정보시스템 환경을 구축하기 위한 방향성을 제시하였다는데 의의를 갖는다.
다국어 초록 (Multilingual Abstract)
This study reviewed operating supervision systems focused on the area of protection of personal information within information systems of public institutions, and identified matters to improve and additional matters via literature review and empirical...
This study reviewed operating supervision systems focused on the area of protection of personal information within information systems of public institutions, and identified matters to improve and additional matters via literature review and empirical methods. By doing so, the study aimed to propose an improved model of operating supervision for protection of personal information at information systems of public institutions.
The direction of the study towards improving operating supervision focused on risk management of leakage of internal information and technical protection in terms of protection of personal information at information systems of public institutions. And the study, based on security classification system of physical, managerial and technical vulnerability as suggested by Von Solms et al., reviewed items to be checked for protection of personal information in operating supervision of information system and conducted research on previous studies related with criteria of protection of personal information as derived from PIMS, ISMS, ISO 27001. By this methodology, the study drew a model to improve operating supervision for protection of personal information at information systems of public institutions in terms of physical, managerial and technical aspects, along with items to be checked.
Through this, the study was able to obtain 52 detailed items spanning three areas and eight checking items in the model to improve operating supervision for protection of personal information at information systems of public institutions. The study conducted a questionnaire survey and statistical analysis among experts working in actual fields in an attempt to verify validity and feasibility of the model of operating supervision for protection of personal information at information systems of public institutions. As a result, all of 52 items were found to have validity and reliability.
This study, which is differentiated in the aspect of improvement of model of operating supervision for protection of personal information at information systems of public institutions, was able to develop a valid model to improve operating supervision for protection of personal information at information systems of public institutions. Through this method, the study had the implications for that it proposed a direction to control risks of leakage of people's valuable personal information arising from purpose or errors of insiders as well as to establish effective information system environment, using operating supervision for protection of personal information in physical, managerial and technical aspects.
목차 (Table of Contents)