RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기
    KCI우수등재

    취약점 관리시스템을 이용한 주요정보통신기반시설 보안취약점 관리 방안 = Security Vulnerability Management Measures for Major Information and Communication Infrastructure using VMS

    한글로보기

    https://www.riss.kr/link?id=A106909210

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    The government is gradually improving the security vulnerabilities of the infrastructure by conducting vulnerability analysis and evaluation in order to secure the safety and reliability of the major information and communication infrastructure and establishing and implementing an implementation plan with necessary supplementary measures for the results. However, the vulnerability analysis and evaluation detailed guide, which is being used to analyze and evaluate infrastructure vulnerabilities, has not been updated since 2017, and management problems have also frequently occurred due to frequent changes in infrastructure managers. In this regard, it was intended to grasp the grievances of the person in charge of infrastructure information protection and to draw up management problems, and to propose ways to improve the technical and managerial tasks of major information and communication infrastructure through the vulnerability management system (VMS) presented in this paper. Unlike the previous ones where the vulnerability check was carried out manually, the work of the person in charge was reduced by converting it to a batch file and performing the check. It was difficult to secure continuity of work due to frequent changes in the personnel in charge due to the circular work system of public institutions, etc., but non-experts were also able to easily identify their work through the vulnerability management system, and the plan was to improve the management of infrastructure by securing reduction of work and continuity.
    번역하기

    The government is gradually improving the security vulnerabilities of the infrastructure by conducting vulnerability analysis and evaluation in order to secure the safety and reliability of the major information and communication infrastructure and es...

    The government is gradually improving the security vulnerabilities of the infrastructure by conducting vulnerability analysis and evaluation in order to secure the safety and reliability of the major information and communication infrastructure and establishing and implementing an implementation plan with necessary supplementary measures for the results. However, the vulnerability analysis and evaluation detailed guide, which is being used to analyze and evaluate infrastructure vulnerabilities, has not been updated since 2017, and management problems have also frequently occurred due to frequent changes in infrastructure managers. In this regard, it was intended to grasp the grievances of the person in charge of infrastructure information protection and to draw up management problems, and to propose ways to improve the technical and managerial tasks of major information and communication infrastructure through the vulnerability management system (VMS) presented in this paper. Unlike the previous ones where the vulnerability check was carried out manually, the work of the person in charge was reduced by converting it to a batch file and performing the check. It was difficult to secure continuity of work due to frequent changes in the personnel in charge due to the circular work system of public institutions, etc., but non-experts were also able to easily identify their work through the vulnerability management system, and the plan was to improve the management of infrastructure by securing reduction of work and continuity.

    더보기

    국문 초록 (Abstract) kakao i 다국어 번역

    정부는 주요정보통신기반시설의 안전성 및 신뢰성을 확보하기 위하여 취약점 분석·평가를 실시하고 그 결과에 대해 필요한 보완조치 사항으로 이행계획을 수립 및 시행하여 기반시설에 대한 보안취약점을 점차 개선해 나가고 있다. 그러나 기반시설 취약점 분석·평가 시 활용하고 있는 취약점 분석·평가 상세가이드는 2017년 이후 업데이트가 진행되지 않고 있으며, 기반시설 담당자의 잦은 변경으로 인한 관리적인 문제도 빈번하게 발생하고 있다. 이에 대한 기반시설 정보보호 담당자의 고충을 파악하고 관리의 문제점을 도출하고자 하였으며, 본 논문에서 제시하는 취약점 관리시스템을 통해 주요정보통신기반시설의 기술 및 관리적 업무 개선방안을 제시하고자 한다. 수동으로 취약점 점검을 진행했었던 기존과 다르게 배치파일로 변환하여 점검을 수행함으로써 담당자의 업무가 감소된 효과가 있었다. 공공기관의 순환근무제 등으로 인한 잦은 담당자의 변경으로 업무연속성을 확보하기 힘들었으나, 취약점 관리시스템을 통하여 비전문가도 쉽게 업무 파악이 가능하도록 하였으며 업무감소와 연속성을 확보하여 기반시설의 관리 방안을 개선하고자 하였다.
    번역하기

    정부는 주요정보통신기반시설의 안전성 및 신뢰성을 확보하기 위하여 취약점 분석·평가를 실시하고 그 결과에 대해 필요한 보완조치 사항으로 이행계획을 수립 및 시행하여 기반시설에 대...

    정부는 주요정보통신기반시설의 안전성 및 신뢰성을 확보하기 위하여 취약점 분석·평가를 실시하고 그 결과에 대해 필요한 보완조치 사항으로 이행계획을 수립 및 시행하여 기반시설에 대한 보안취약점을 점차 개선해 나가고 있다. 그러나 기반시설 취약점 분석·평가 시 활용하고 있는 취약점 분석·평가 상세가이드는 2017년 이후 업데이트가 진행되지 않고 있으며, 기반시설 담당자의 잦은 변경으로 인한 관리적인 문제도 빈번하게 발생하고 있다. 이에 대한 기반시설 정보보호 담당자의 고충을 파악하고 관리의 문제점을 도출하고자 하였으며, 본 논문에서 제시하는 취약점 관리시스템을 통해 주요정보통신기반시설의 기술 및 관리적 업무 개선방안을 제시하고자 한다. 수동으로 취약점 점검을 진행했었던 기존과 다르게 배치파일로 변환하여 점검을 수행함으로써 담당자의 업무가 감소된 효과가 있었다. 공공기관의 순환근무제 등으로 인한 잦은 담당자의 변경으로 업무연속성을 확보하기 힘들었으나, 취약점 관리시스템을 통하여 비전문가도 쉽게 업무 파악이 가능하도록 하였으며 업무감소와 연속성을 확보하여 기반시설의 관리 방안을 개선하고자 하였다.

    더보기

    참고문헌 (Reference)

    1 민소연, "시스템 취약점 개선의 필요성에 따른 효율적인 점검 방법을 통한 종합 보안 취약성 분석 시스템 설계" 한국산학기술학회 18 (18): 1-8, 2017

    2 J. I. Kim, "Strengthening protection of information and communication infrastructure"

    3 P. S. Kim, "Measures to Improve Civil Service Circulation"

    4 Ministry of Legislation, "Information and Communication Infrastructure Protection Act"

    5 Korea Information Security Agency, "Establishment of improvement scheme for information security consulting company designation system"

    6 MSIT, "Detailed guide on the analysis and evaluation of technical vulnerabilities in major information and communication infrastructure"

    7 MOIS, "Criteria for analyzing and evaluating vulnerabilities in major information and communications infrastructure" 2012

    8 S. T. Park, "A study on the vulnerability analysis and assessment management for the protection of major information and communication infrastructures" 19 (19): 32-40, 2009

    9 D. H. Jang, "A research on quality improvement methods for the scan items of WINDOWS security vulnerability in critical IT infrastructure" Sungkyunkwan University 2018

    10 NIS, "2019 national information protection white paper" 2019

    1 민소연, "시스템 취약점 개선의 필요성에 따른 효율적인 점검 방법을 통한 종합 보안 취약성 분석 시스템 설계" 한국산학기술학회 18 (18): 1-8, 2017

    2 J. I. Kim, "Strengthening protection of information and communication infrastructure"

    3 P. S. Kim, "Measures to Improve Civil Service Circulation"

    4 Ministry of Legislation, "Information and Communication Infrastructure Protection Act"

    5 Korea Information Security Agency, "Establishment of improvement scheme for information security consulting company designation system"

    6 MSIT, "Detailed guide on the analysis and evaluation of technical vulnerabilities in major information and communication infrastructure"

    7 MOIS, "Criteria for analyzing and evaluating vulnerabilities in major information and communications infrastructure" 2012

    8 S. T. Park, "A study on the vulnerability analysis and assessment management for the protection of major information and communication infrastructures" 19 (19): 32-40, 2009

    9 D. H. Jang, "A research on quality improvement methods for the scan items of WINDOWS security vulnerability in critical IT infrastructure" Sungkyunkwan University 2018

    10 NIS, "2019 national information protection white paper" 2019

    11 H. K. Noh, "(A)study on the improvement of the vulnerability management system in the information and communications infrastructure : vulnerability analysis and evaluation for major information and communications infrastructure" Soongsil University 2013

    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    인용정보 인용지수 설명보기

    학술지 이력

    학술지 이력
    연월일 이력구분 이력상세 등재구분
    2023 평가 계속평가 신청대상 (등재유지)
    2018-01-01 등재 우수등재학술지 선정 (계속평가)
    2015-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2014-12-11 학술지명변경 외국어명 : journal of The Institute of Electronics Engineers of Korea -> Journal of the Institute of Electronics and Information Engineers KCI등재
    2014-01-21 학회명변경 영문명 : The Institute Of Electronics Engineers Of Korea -> The Institute of Electronics and Information Engineers KCI등재
    2011-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2009-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2007-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2005-10-17 학술지명변경 한글명 : 대한전자공학회 논문지 -> 전자공학회논문지 KCI등재
    2005-05-27 학술지등록 한글명 : 대한전자공학회 논문지
    외국어명 : journal of The Institute of Electronics Engineers of Korea
    KCI등재
    2005-01-01 등재 등재학술지 유지 (등재유지) KCI등재
    2002-07-01 등재 등재학술지 선정 (등재후보2차) KCI등재
    2000-01-01 등재 등재후보학술지 선정 (신규평가) KCI등재후보
    더보기

    학술지 인용정보

    학술지 인용정보
    기준연도 WOS-KCI 통합IF(2년) KCIF(2년) KCIF(3년)
    2016 0.27 0.27 0.25
    KCIF(4년) KCIF(5년) 중심성지수(3년) 즉시성지수
    0.22 0.19 0.427 0.09
    더보기

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼