Browse > Article
http://dx.doi.org/10.13089/JKIISC.2008.18.5.161

A Study on the Development of Corporate Information Security Level Assessment Models  

Lee, Hee-Myung (Graduate School of Information Management and Security, Korea University)
Lim, Jong-In (Graduate School of Information Management and Security, Korea University)
Abstract
Despite the recent growth in size and frequency of damages caused by illegal information breaches, current business counter-measures and precautionary systems are greatly limited. Some major companies have developed Information Security Management Systems (ISMS) to safeguard their vital information; however, such measures are largely based on the ISO27001 and lacks in many aspects to grasp the holistic corporate security level and reinforce precautionary measures. The information protection level evaluation model introduced in this paper is a pragmatic evaluative tool that can be utilized to devise effective corporate information security precautionary measures and countermeasures, based on the BSC (Balanced ScoreCard) method for an actual and realistic corporate information security level evaluation possible.
Keywords
ISO 27001/27002/27004; BSC(Balanced Scorecard); ISMS;
Citations & Related Records
연도 인용수 순위
  • Reference
1 한국정보보호진흥원, 2007 정보시스템 해킹.바이러스 현황 및 대응, 한국정보보호진흥원 2007
2 ISO/IEC27001:2005(FDIS) Information Security Management System Requirements
3 최선태, 기업보안 관리전략, 인포더 2008
4 SP800-53(Rev.2):Recommended Security contorls for Federal Information Security, 2007. 10 NIST
5 SP800-55:Security Metrics Gudie for Information Technology Systems 2003, NIST
6 ISO/IEC 27004(Draft) Information Security Management measurement
7 concert, 2008 Security Forecast 발표자료, 2008. 3
8 ISO/IEC 27002(FDIS) The Code of Practice for Inforamtion Security Management
9 Robert S. Kaplan & David P. Norton, 전사적 전략경영(SEM)을 위한 SFO, 한언 2001. 8
10 첨단 산업기술 보호동향 (8호), 2007. 9 국가정보원
11 Robert S. Kaplan et. al., 가치실현을 위한 통합 경영지표 BSC, 한언 2007. 6