PUKYONG

M-ISMS 모델 기반의 군(軍) 보안감사 설계에 관한 연구

Metadata Downloads
Abstract
Abstract

In recent, the levels of military information protection has been currently remained through very powerful legal systems such as Military Secret Protection Act and Military security operational defense minister instructions and regular and non-scheduled security inspection by considering the specialization of military.
However, the changes of information speed of military are required because of a relative lower level compared to the developing speed of the private_based ICT(Information Communication Technology). Therefore, the military also needs to adopt management systems of information security based on KISA ISMS(Korea Internet & Security Agency Information Security Management System) following Korean standards for Information Security.
We propose an improved M-ISMS(Military-ISMS) model for the characteristics of the military and management systems of information security based on the existing ISMS model. Our improved model focuses on 'internal security audit' and 'management of external activity' by considering military characteristics that have not been conducted in ISMS.
Therefore, we added the six control items regarding confidentiality to internal security audits because the confidentiality is more important in militaries than fusibility which is importantly handled in private sectors.
We also recommend some control items regarding standards establishment and level maintain for security management in the external activity management parts because its value for secrecy is disappeared in case militaries reveal information or their external activities such as national defense white papers.
The proposed M-ISMS model in this thesis has an effect on preventing a rapid and future-oriented security intrusion incident in advance by considering a variety of its advantages and case studies of private intrusion incident collected from existing ISMS. However, specific guidelines and technologies of multiple control items in our proposed model will be studied in detail.
Author(s)
김대규
Issued Date
2014
Awarded Date
2014. 2
Type
Dissertation
Publisher
부경대학교
URI
https://repository.pknu.ac.kr:8443/handle/2021.oak/1390
http://pknu.dcollection.net/jsp/common/DcLoOrgPer.jsp?sItemId=000001966799
Affiliation
대학원
Department
대학원 정보시스템협동과정
Advisor
김창수
Table Of Contents
1. 서론 1
1.1 연구배경 및 필요성 1
1.2 연구방법 및 구성 3
2. 이론적 배경 4
2.1 국내 정보통신기반 보호법 4
2.2 국내외 정보보호관리 인증제도 6
2.2.1 ISMS(정보보호 관리체계) 6
2.2.2 BS7799 7
2.2.3 ISO/IEC 27001 9
2.2.4 KISA ISMS 14
3. 군 특수성을 고려한 ISMS 분석 24
3.1 ISMS 기반의 군(軍)보안적용 문제점 분석 24
3.1.1 보안감사의 현실적인 문제 24
3.2 IT기반의 ISMS와 보안규정 25
3.2.1 거버넌스 개념의 ISMS 검토 25
3.2.2 효율적인 ISMS의 성과 및 영향 29
3.3 선행 연구 검토결과 30
4. 군 특수성을 고려한 M-ISMS 모델 제안 31
4.1 M-ISMS 모델 제안 31
4.1.1 M-ISMS 개념 31
4.1.2 M-ISMS 정보보호 관리과정(5단계) 31
4.1.3 M-ISMS 통제항목 33
4.1.4 KISA ISMS와 M-ISMS 비교 분석 38
4.2 M-ISMS 효과성 43
5. 결론 및 향후 연구 방향 46
5.1 결론 46
5.2 향후 연구방향 48
참고문헌 49
Degree
Master
Appears in Collections:
대학원 > 정보시스템협동과정
Authorize & License
  • Authorize공개
Files in This Item:

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.