• Title/Summary/Keyword: Audit Framework

Search Result 46, Processing Time 0.019 seconds

Developing a Real-time Cashflow Management System for National R&D Management (국가 연구 개발 프로젝트 실시간 자금 관리 시스템 개발에 관한 연구)

  • Han, Seung-Youp;Lee, Hyejung;Lee, Jungwoo
    • Journal of Information Technology Services
    • /
    • v.13 no.3
    • /
    • pp.343-357
    • /
    • 2014
  • As science and technology infiltrates every aspects of modern society in terms of economic and social growth and development, funding for research and development (R&D) is growing rapidly. Republic of Korea is not an exception in this trend and the R&D funding in Korea has been grown about 10% every year, recently. However, as the scope and size of funding grows exponentially, need for monitoring and managing these R&D projects becoming more and more imminent. Though different types of project management systems were developed by a variety of agencies and departments and used in monitoring and managing, these systems were developed as standalone silo type systems. These systems are not connected to each other while the same researchers may involved in different projects across agencies and department. Also, these management systems are not linked to the banking systems in which real transactions of funding occurs, such as cost reimbursement and financial audit of each R&D accounts. Historically, a few fraud and malappropriation cases were found and indicted. However, as the number of these incidents grows along with the growth of R&D funding, a large scale integration/linking of project management systems and banking systems. Realizing the importance of systems integration among agencies as well as with the banking systems, situational requirements analyses were conducted concerning the current state of R&D management system. As a results, a Real-time Case Management System (RCMS) was proposed as a solution to current problems. In this paper, the collected systems requirements were documents with analyses of the situation, the architecture of the integrated systems with more user-friendly technological alternatives. This large scale linkage requires interface standardization as well as modularization of interfaces. Proposed systems architecture is introduced here with technical details of Jex Framework used,, followed by resulting technical and economic performance of the Realtime Cashflow Management System (RCMS).

A Confirmatory Factor Analysis for Quality Competitiveness Excellence Company Evaluation Indicators (품질경쟁력 우수기업 평가지표의 확인적 요인분석)

  • Park, Dong Joon;Yun, Yeboon;Yoon, Min
    • Journal of Korean Society of Industrial and Systems Engineering
    • /
    • v.43 no.3
    • /
    • pp.101-111
    • /
    • 2020
  • Companies struggle to make their best products with high quality and service at a competitive price in global markets. However, customer needs and requirements keep changing with a variety of situations. Companies that face the changes can not stay the same and make an effort to adapt themselves to new circumstances. They would probably review the overall management system that is currently implementing to improve management efficiency. Among other things, quality might be considered to be a crucial element if they are manufacturing industries to be sustained in global markets. KSA (Korean Standards Association) is a government-affiliated organization under the Ministry of Trade, Infrastructure, and Energy. It is a Korean standards provider for quality and service industry. KSA confers national commendations for organizations, quality circles, artisans, QCEC (Quality Competitive Excellent Company), and the most honorable KNQA (Korean National Quality Award) every year. KSA established KNQA on the basis of Malcom Baldrige National Quality Award, Deming Prize, and European Quality Award. Research on quality awards shows that there are many similarities in the framework. Although KSA summarizes two factors for 13 evaluation indicators in the quality competitive excellent model of QCEC, the categorization is ambiguous to explain them according to earlier studies. We performed a deep analysis of foreign quality awards and background for KNQA and QCEC. We conducted a content analysis of KNQA and QCEC and matched evaluation items that were closely related. We proposed a quality competitiveness model with three factors, Technology, System, and Tools, summarizing 13 evaluation indicators in QCEC. Based on audit data for six years from 2012 to 2017 we carried out a confirmatory factor analysis for the proposed model by examining the model validity and fitness.

The Design and Implementation of Module supporting Trusted Channel in Secure Operating System Environment (보안운영체제 환경에서의 신뢰채널 지원을 위한 모듈의 설계 및 구현)

  • 유준석;임재덕;나재훈;손승원
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.14 no.3
    • /
    • pp.3-12
    • /
    • 2004
  • Secure operating system is a special operating system that integrates some security functions(i.e. access control, user authentication, audit-trail and etc.) with normal operating system in order to protect system from various attacks. But it doesn't consider my security of network traffic. To guarantee the security of the whole system, network traffic must be protected by a certain way and IPsec is a representative technology for network security. However, it requires administrator's carefulness in managing security policies and the key management mechanism is very heavy as well as complicated. Moreover, it doesn't have a suitable framework for delivery of security information for access control mechanism. So we propose a simple trusted channel mechanism for secure communication between secure operating systems. It provides confidentiality md authentication for network traffic and ability to deliver security information. It is implemented at the kernellevel of IP layer and the simplicity of the mechanism can minimize the overhead of trusted channel processing.

OHDSI OMOP-CDM Database Security Weakness and Countermeasures (OHDSI OMOP-CDM 데이터베이스 보안 취약점 및 대응방안)

  • Lee, Kyung-Hwan;Jang, Seong-Yong
    • Journal of Information Technology Services
    • /
    • v.21 no.4
    • /
    • pp.63-74
    • /
    • 2022
  • Globally researchers at medical institutions are actively sharing COHORT data of patients to develop vaccines and treatments to overcome the COVID-19 crisis. OMOP-CDM, a common data model that efficiently shares medical data research independently operated by individual medical institutions has patient personal information (e.g. PII, PHI). Although PII and PHI are managed and shared indistinguishably through de-identification or anonymization in medical institutions they could not be guaranteed at 100% by complete de-identification and anonymization. For this reason the security of the OMOP-CDM database is important but there is no detailed and specific OMOP-CDM security inspection tool so risk mitigation measures are being taken with a general security inspection tool. This study intends to study and present a model for implementing a tool to check the security vulnerability of OMOP-CDM by analyzing the security guidelines for the US database and security controls of the personal information protection of the NIST. Additionally it intends to verify the implementation feasibility by real field demonstration in an actual 3 hospitals environment. As a result of checking the security status of the test server and the CDM database of the three hospitals in operation, most of the database audit and encryption functions were found to be insufficient. Based on these inspection results it was applied to the optimization study of the complex and time-consuming CDM CSF developed in the "Development of Security Framework Required for CDM-based Distributed Research" task of the Korea Health Industry Promotion Agency. According to several recent newspaper articles, Ramsomware attacks on financially large hospitals are intensifying. Organizations that are currently operating or will operate CDM databases need to install database audits(proofing) and encryption (data protection) that are not provided by the OMOP-CDM database template to prevent attackers from compromising.

Management and Supervision Measures for Virtual Asset Ecosystem (가상자산 생태계 관리・감독 방안)

  • Sehyun Lee;Sangyeon Lee;Hee-Dong Yang
    • Knowledge Management Research
    • /
    • v.24 no.3
    • /
    • pp.73-94
    • /
    • 2023
  • With the virtual asset market's rapid growth, government regulations on listing and trading procedures are expected. However, specific measures are currently lacking. To ensure stable inclusion in the institutional framework, precise regulations are needed for market development and investor protection. This study compares self-regulatory guidelines of the top domestic virtual asset exchanges with Korea Exchange's Preliminary Listing Examination Standards (2022) to enhance timeliness and relevance. It defines IEO, IPO, and ICO concepts and addresses conflicts of interest in IEO. Analyzing delisted virtual assets, it categorizes issues and classifies listing examination guidelines into formal and qualitative requirements. The study examines self-regulatory guidelines based on continuity, transparency, stability, corporate characteristics, and investor protection criteria, along with five special requirements for virtual assets. Improvement measures include regular disclosures of governance structure, circulation volume, and the establishment of independent audit institutions. This research further analyzes delisting cases, classifies issues, and proposes solutions. Considering stock market similarities, it offers measures based on the institutional framework.

An improved methodology for estimating traffic accident cost savings in the (preliminary) feasibility study ((예비)타당성조사의 교통사고 감소편익 산정방안 보완 연구)

  • Jang, Su-Eun;Jeong, Gyu-Hwa
    • Journal of Korean Society of Transportation
    • /
    • v.25 no.5
    • /
    • pp.15-21
    • /
    • 2007
  • This paper proposes an improved methodology for estimating traffic accident cost savings in the transport appraisal. Four major problems from the existing framework are identified and their alternatives are suggested. First, casualties in the established approach are classified by just two types of 'killed' and 'injured'. This study supplies the indices of fatality further details. Namely, road victims are regrouped by 'killed', 'seriously injured', 'slightly injured', and 'accident reports'. Those of railways are similarly sorted by 'killed', 'seriously injured', and 'slightly injured'. Second, damage only accidents are not satisfactorily considered in the current arrangement. The accidents should be considered as one of the accident types and the social cost of them should also be evaluated. Third, the unit cost of accidents is given by the total value. The unit cost is consisted of several elements and each loss would be useful for a policy frame. This study breaks down the total figure into four pieces of costs, namely production loss, medical treatment, property loss, and administrative costs. Finally, there is inconsistency in the audit between roads and railways. Road accidents are analyzed by road types. On the other hand, patronage or others is the classification rule of rail accident costs. This paper suggests a way that the accident costs of two modes can be coherently estimated based on the level of services by each mode. The result of this study is expected to help frame more cautious social overhead capital investment policies.