Browse > Article

A Study on Models for Technical Security Maturity Level Based on SSE-CMM  

Kim, Jeom Goo (남서울대학교 컴퓨터학과)
Noh, Si Choon (남서울대학교 컴퓨터학과)
Publication Information
Abstract
The SSE-CMM model is how to verify the level of information protection as a process-centric information security products, systems and services to develop the ability to assess the organization's development. The CMM is a model for software developers the ability to assess the development of the entire organization, improving the model's maturity level measuring. However, this method of security engineering process improvement and the ability to asses s the individual rather than organizational level to evaluate the ability of the processes are stopped. In this research project based on their existing research information from the technical point of view is to define the maturity level of protection. How to diagnose an information security vulnerabilities, technical security system, verification, and implementation of technical security shall consist of diagnostic status. The proposed methodology, the scope of the work place and the current state of information systems at the level of vulnerability, status, information protection are implemented to assess the level of satisfaction and function. It is possible that measures to improve information security evaluation based on established reference model as a basis for improving information security by utilizing leverage.
Keywords
Evaluation Methodology; Maturity Level; Technical Security; SSE-CMM Network;
Citations & Related Records
연도 인용수 순위
  • Reference
1 CMMhttp://www.freesoft.or.kr/osd/html/software/introduction3.htm
2 SSE-CMM Org http://www.sse-cmm.org/
3 CCRA(Arrangement on the Recognition of Common Criteria Certificates) http://www.commoncriteria.org.
4 SSE-CMM, "Project, Systems Security Engineering Capability Maturity Model (SSE-CMM) - Model Description Document", V.2, http://www.sse-cmm.org, 1999. 4. 1.
5 CC, Common Criteria for Information Technology Security Evaluation, Version 2.1, CCIMB-99-031, August 1999,
6 British Standards Institution(BSI), "BS-7799", 1999.
7 정보통신부, 한국정보보호진흥원, 정보보호시스템 공통평가기준(정통부고시 제 2002-40), 2002.8.
8 한국정보보호진흥원, "공통평가기준 기반 평가기관 산정 방안 및 평가수수료 정책 연구," 수탁기관: 한국정보보호학회, 2003.11.
9 TTAS.KO-12.004, "네트워크 보안 장비에 대한 성능 측정 방법", 한국정보통신기술협회, 2006
10 류재철외 2명, "국외 민간평가기관 평가 동향", 한국정보보호학회 학회지 특집, 보안성 평가 및 시험, 제 13권 6호, 2003.12
11 오흥륭외 1명, "국제 공통평가기준(CC)의 교육 동향 및 평가된 정보보호 제품 분석", 한국정보보호학회 특집, 사이버 범죄와 프라이버시, 제 13권 5호, 2003.10
12 CC인증 제품 중 국제용은 15%에 불과, 보안뉴스 및 동향 2011.11.19