Browse > Article
http://dx.doi.org/10.7838/jsebs.2011.16.2.159

Developing the Assessment Method for Information Security Levels  

Oh, Nam-Seok (방송통신위원회)
Han, Young-Soon (연세대학교 정보대학원)
Eom, Chan-Wang (연세대학교 정보대학원)
Oh, Kyeong-Seok (연세대학교 정보대학원)
Lee, Bong-Gyou (연세대학교 정보대학원)
Publication Information
The Journal of Society for e-Business Studies / v.16, no.2, 2011 , pp. 159-169 More about this Journal
Abstract
In order for agencies and companies at the IT service industry to check as well as to upgrade the current status of their information security programs, this paper suggests the assessment method for information security levels. The study developed 12 assessment fields and 54 assessment items derived from domestic and foreign cases including SP800-26, SP800-53, ISMS, and ISO27001. It categorized 54 assessment items into 5 levels for determining information security levels. Also, the study presents 7 strategies for performing their efficient evaluations. The proposed method and process in this paper can be useful guidelines for improving the national information security level.
Keywords
Assessment Method for Information Security Levels; Assessment Indicator; Information Security; Security Maturity;
Citations & Related Records
연도 인용수 순위
  • Reference
1 Carnegie Mellon University, "The SSE-CMM Appraisal Method (SSAM)-Capability Maturity Model," 1999.
2 강신원, "국가정보화지수 측정을 위한 가중치 연구:RCSS를 중심으로", 정보통신정책연구, 제6권, 제2호, pp. 47-64, 1999.
3 황종성, "국가정보화종합지수 모델개발 연구", 한국전산원, 2005.
4 Swanson, M., "Security Self-Assessment Guide for Information Technology System," NIST, SP800-26, 2001.
5 김진영, 정보보호수준 평가 방법론 개발에 관한 연구, 석사학위논문, 2003.
6 이강신, "정보보호관리체계 인증가이드", 한국정보보호진흥원, 2002.
7 ISO/IEC, Information Security Management System Part 2:Specification for Information Security Management System, 2005.
8 Carnegie Mellon University, "SSE-CMM Model Decripton Document," SSE-CMM, 2003.
9 Carley, M., Social Measurement and Social Indicators, George Allen and Unwin, Ltd., London, 1981.
10 한근식, "정보보호 수준평가에서의 표본설계방법에 따른 허용오차", 정보보호 심포지움, 2009. 6.
11 정경호, 민경식, "국가 정보보호수준 평가 모델 개발", 한국정보보호진흥원, 2001.
12 Ross, R., "Guide for Assessing the Security Controls in Federal Information Systems:Building Effective Security Assessment Plans," NIST, Special Publications 800-53A, 2008.
13 한국인터넷진흥원, 정보보호 수준평가 방법론 안내서, 2010. 3.