Browse > Article

The Study on Corporate Information Security Governance Model for CEO  

Kim, Do Hyeong ((주)대구은행 정보보호부)
Publication Information
Abstract
The existing enterprise information security activities were centered on the information security organization, and the top management considers information security and enterprise management to be separate. However, various kinds of security incidents are constantly occurring. In order to cope with such incidents, it is necessary to protect information in terms of business management, not just information security organization. In this study, we examine the existing corporate governance and IT governance, and present an information security governance model that can reflect the business goals of the enterprise and the goals of the management. The information security governance model proposed in this paper induces the participation of top management from the planning stage and establishes information security goals. We can strengthen information security activities by establishing an information security plan, establishing and operating an information security system, and reporting the results to top management through compliance audit, vulnerability analysis and risk management.
Keywords
Information Security Governance; Information Security Management; Security Management;
Citations & Related Records
Times Cited By KSCI : 2  (Citation Analysis)
연도 인용수 순위
1 이성일, "정보보호 거버넌스 프레임워크에 관한 연구", 동국대학교 대학원 경영정보학과, 2011.
2 ISO/IEC 38500, "Corporate Governance of Information Technology", 2008.
3 ISACA, "COBIT 5 Framework", 2012.
4 조희준, "COBIT 5와 거버넌스 프레임워크", 한국정보시스템감사통제협회, 2012.
5 김귀남, 김민준, "정보보안 거버넌스 프레임워크에 관한 연구", 융합보안논문지, 제10권, 제4호, pp. 14-19, 2010.
6 한국정보보호진흥원, 정보보호관리체계, 2002.
7 ISO, ISO27001:2013, 2013.
8 정대령, "전자정부 정보보호관리체계(G-ISMS)를 활용한 공공기관 정보보호 거버넌스 수립방안에 관한 연구", 배재대학교 대학원 컴퓨터공학과, 2012.
9 한국인터넷진흥원, 정보보호관리체계 인증, 2016.
10 이창훈, 하옥현, "기밀유출방지를 위한 융합보안 관리 체계", 융합보안논문지, 제10권, 제4호, pp. 61-67, 2010.