RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI등재

    새로운 사이버보안 위협에 대응한 정보보호 법제도 개선방안 연구 = Research on Improving Information Protection Laws and Systems to respond to new Cybersecurity Threats

    한글로보기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    New cybersecurity threats in the AI transformation (AX) era include hacking of autonomous systems, AI model theft and manipulation, IoT vulnerability attacks, deepfake-based crimes, ransomware, and supply chain attacks. Accordingly, the European Union (EU) NIS-2 Act is a comprehensive law to strengthen cybersecurity and aims to improve the level of cybersecurity across the European Union. The NIS-2 Act applies to Essential Entities and Important Entities. The NIS-2 Act requires cybersecurity risk management measures and strengthens reporting obligations. An early warning must be issued within 24 hours of becoming aware of a major incident, an initial assessment must be submitted within 72 hours of becoming aware of the incident, and a final report on incident handling and recovery efforts must be submitted within one month.
    As a way to improve the Information and Communications Network Act, first, we can pursue the integration and unification of laws related to personal information protection. Second, we must establish a legal system that can flexibly respond to the development of new technologies. Third, the procedures for ensuring the speed of blocking and deleting illegal information should be simplified, and the authority and responsibility of related organizations should be clarified. Fourth, reporting obligations and procedures in the event of a breach should be clarified, and the support system for rapid response and recovery should be strengthened. Fifth, in the event of user damage due to cyberattacks, a simple and quick procedure for receiving relief must be established.
    As a way to improve the Information and Communications Infrastructure Protection Act, first, the scope of designation should be expanded to include private digital services, platforms, and cloud-based services that have a significant impact on national security and the lives of citizens as “Important information and communications infrastructure,” and clear legal standards should be established. Second, we must make threat information sharing mandatory or activate it by establishing and operating an information sharing platform between major information and communication infrastructures and between the government and private companies. Third, we must establish legal grounds and guidelines for new security challenges resulting from the introduction of new technologies, such as distribution of security responsibilities in cloud computing environments, vulnerability analysis and evaluation methods for AI-based systems, and IoT device security. Fourth, since cybersecurity is a national task that the government must shoulder in order to ensure the stability of the people's lives, the government must bear the costs related to cyber risks.
    As a way to improve the Information Protection Industry Act, first, the legal system should be reorganized to eliminate duplication and fill in the gaps between laws related to information protection. Second, practical incentives that can encourage companies to invest in information protection, such as expanded tax benefits, financial support, and financial assistance, should be strengthened. Third, there is a need to encourage information and communication-related companies to comply with laws and regulations regarding information protection and to strengthen the effectiveness of the disclosure system.
    번역하기

    New cybersecurity threats in the AI transformation (AX) era include hacking of autonomous systems, AI model theft and manipulation, IoT vulnerability attacks, deepfake-based crimes, ransomware, and supply chain attacks. Accordingly, the European Union...

    New cybersecurity threats in the AI transformation (AX) era include hacking of autonomous systems, AI model theft and manipulation, IoT vulnerability attacks, deepfake-based crimes, ransomware, and supply chain attacks. Accordingly, the European Union (EU) NIS-2 Act is a comprehensive law to strengthen cybersecurity and aims to improve the level of cybersecurity across the European Union. The NIS-2 Act applies to Essential Entities and Important Entities. The NIS-2 Act requires cybersecurity risk management measures and strengthens reporting obligations. An early warning must be issued within 24 hours of becoming aware of a major incident, an initial assessment must be submitted within 72 hours of becoming aware of the incident, and a final report on incident handling and recovery efforts must be submitted within one month.
    As a way to improve the Information and Communications Network Act, first, we can pursue the integration and unification of laws related to personal information protection. Second, we must establish a legal system that can flexibly respond to the development of new technologies. Third, the procedures for ensuring the speed of blocking and deleting illegal information should be simplified, and the authority and responsibility of related organizations should be clarified. Fourth, reporting obligations and procedures in the event of a breach should be clarified, and the support system for rapid response and recovery should be strengthened. Fifth, in the event of user damage due to cyberattacks, a simple and quick procedure for receiving relief must be established.
    As a way to improve the Information and Communications Infrastructure Protection Act, first, the scope of designation should be expanded to include private digital services, platforms, and cloud-based services that have a significant impact on national security and the lives of citizens as “Important information and communications infrastructure,” and clear legal standards should be established. Second, we must make threat information sharing mandatory or activate it by establishing and operating an information sharing platform between major information and communication infrastructures and between the government and private companies. Third, we must establish legal grounds and guidelines for new security challenges resulting from the introduction of new technologies, such as distribution of security responsibilities in cloud computing environments, vulnerability analysis and evaluation methods for AI-based systems, and IoT device security. Fourth, since cybersecurity is a national task that the government must shoulder in order to ensure the stability of the people's lives, the government must bear the costs related to cyber risks.
    As a way to improve the Information Protection Industry Act, first, the legal system should be reorganized to eliminate duplication and fill in the gaps between laws related to information protection. Second, practical incentives that can encourage companies to invest in information protection, such as expanded tax benefits, financial support, and financial assistance, should be strengthened. Third, there is a need to encourage information and communication-related companies to comply with laws and regulations regarding information protection and to strengthen the effectiveness of the disclosure system.

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼