본 과제(결과물)는 2023년도 교육부의 재원으로 한국연구재단의 지원을 받아 수행된 지자체-대학협력기반 지역혁신 사업의 결과입니다(2021RIS-001).
- 공희경, 전효정, 김태성, "AHP를 이용한 정보보호투자 의사결정에 대한 연구", Journal of Information Technology Applications and Management, 제15권, 제1호, pp. 139-152, 2008.
- 국가종합 전자조달청, "나라장터 종합 쇼핑몰, 2023, 1, 20, Available at
- 이경율, 이선영, 임강빈, "기반시설 보안위협분류 및 분석", 한국통신학회논문지, 제43권, 제3호, 2018, pp. 572-579.
- 이상훈, 김태성, "정보보호 대책의 성능을 고려한 투자 포트폴리오의 게임 이론적 최적화", 지능정보연구, 제26권, 제3호, 2020, pp. 37-50.
- 임정현, 김태성, "침해사고 통계 기반 정보보호 투자 포트폴리오 최적화 : 유전자 알고리즘 접근법", Information Systems Review, 제22권, 제2호, 2020, pp. 201-217.
- 한국인터넷진흥원, "정보보호 공시 현황", 2022, 12, 1, Available at
- 허진, 이애리, "스마트팩토리의 주요 보안요인 연구: AHP를 활용한 우선순위 분석을 중심으로", Information Systems Review, 제22권, 제4호, 2020, pp. 185-203.
- Armenia, S., M. Angelini, F. Nonino, G. Palombi, and M. F. Schlitzer, "A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs", Decision Support Systems, Vol.147, 2021, p. 113580.
- Bodin, L. D., L. A. Gordon, and M. P. Loeb, "Evaluating information security investments using the analytic hierarchy process", Communications of the ACM, Vol.48, No.2, 2005, pp. 78-83.
- Bodin, L. D., L. A. Gordon, and M. P. Loeb, "Information security and risk management", Communications of the ACM, Vol.51, No.4, 2008, pp. 64-68.
- Cavusoglu, H., S. Raghunathan, and W. T. Yue, "Decision-theoretic and game-theoretic approaches to IT security investment", Journal of Management Information Systems, Vol.25, No.2, 2008, pp. 281-304.
- Fielder, A., E. Panaousis, P. Malacaria, C. Hankin, and F. Smeraldi, "Decision support approaches for cyber security investment", Decision Support Systems, Vol. 86, 2016, pp. 13-23.
- Gartner, "Gartner Identifies Three Factors Influencing Growth in Security Spending", 2022, 10, 13, Available at
- Gordon, L. A. and M. P. Loeb, "The economics of information security investment", ACM Transactions on Information and System Security, Vol.5, No.4, pp. 438-457, 2002.
- Gordon, L. A., M. P. Loeb, W. Lucyshyn, and L. Zhou, "Externalities and the magnitude of cyber security underinvestment by private sector firms: A modification of the Gordon-Loeb model", Journal of Information Security, Vol.6, No.1, 2014, pp. 24-30.
- Gupta, M., J. Rees, A. Chaturvedi, and J. Chi, "Matching information security vulnerabilities to organizational security profiles: A genetic algorithm approach", Decision Support Systems, Vol.41, No.3, 2006, pp. 592-603.
- Heidt, M., J. P. Gerlach, and P. Buxmann, "Investigating the security divide between SME and large companies: How SME characteristics influence organizational IT security investments", Information Systems Frontiers, Vol. 21, 2019, pp. 1285-1305.
- IBM Security, "Cost of a Data Breach Report 2022", 2022. 11. 7., Available at
- Kaspersky, "SMBs and Enterprise plan to increase IT security budgets equally up to 14% in the next three years", 2023. 2. 8., Available at
- Kumar, R. L., S. Park, and C. Subramaniam, "Understanding the value of countermeasure portfolios in information systems security", Journal of Management Information Systems, Vol.25, No.2, 2008, pp. 241-280.
- Miaoui, Y. and N. Boudriga, "Enterprise security investment through time when facing different types of vulnerabilities", Information Systems Frontiers, Vol.21, 2019, pp. 261-300.
- NSS Labs., "NSS Labs Announces 2019 Next Generation Intrusion Prevention Systems (NGIPS) Group Test Results", PR Newswire, 2019.
- Ponemon Institute, "Closing the IT Security Gaps 2020 Global Study by the Ponemon Institute", HPE Inc., 2020.
- Sawik, T., "Selection of optimal countermeasure portfolio in IT security planning", Decision Support Systems, Vol.55, No.1, 2013, pp. 156-164.
- Skybakmoen, T., "Next Generation Firewall Comparative Analysis", Media Zones, 2022.
- Sonmez, F. O. and B. G. Kilic, "A decision support system for optimal selection of enterprise information security preventative actions", IEEE Transactions on Network and Service Management, Vol.18, No.3, 2020, pp. 3260-3279.
- Von Solms, R., "Information security management: The second generation", Computers and Security, Vol.15, No.4, 1996, pp. 281-288.
- Whitman, M. E. and H. J. Mattord, "Threats to information protection-industry and academic perspectives: An annotated bibliography", Journal of Cybersecurity Education, Research and Practice, Vol.2016, No.2, Article 4.