• Title/Summary/Keyword: Information Security Budget

Search Result 122, Processing Time 0.025 seconds

Developing a Classification of Vulnerabilities for Smart Factory in SMEs: Focused on Industrial Control Systems (중소기업용 스마트팩토리 보안 취약점 분류체계 개발: 산업제어시스템 중심으로)

  • Jeong, Jae-Hoon;Kim, Tae-Sung
    • Journal of Information Technology Services
    • /
    • v.21 no.5
    • /
    • pp.65-79
    • /
    • 2022
  • The smart factory has spread to small and mid-size enterprises (SMEs) under the leadership of the government. Smart factory consists of a work area, an operation management area, and an industrial control system (ICS) area. However, each site is combined with the IT system for reasons such as the convenience of work. As a result, various breaches could occur due to the weakness of the IT system. This study seeks to discover the items and vulnerabilities that SMEs who have difficulties in information security due to technology limitations, human resources, and budget should first diagnose and check. First, to compare the existing domestic and foreign smart factory vulnerability classification systems and improve the current classification system, the latest smart factory vulnerability information is collected from NVD, CISA, and OWASP. Then, significant keywords are extracted from pre-processing, co-occurrence network analysis is performed, and the relationship between each keyword and vulnerability is discovered. Finally, the improvement points of the classification system are derived by mapping it to the existing classification system. Therefore, configuration and maintenance, communication and network, and software development were the items to be diagnosed and checked first, and vulnerabilities were denial of service (DoS), lack of integrity checking for communications, inadequate authentication, privileges, and access control in software in descending order of importance.

A Study on Converting the Data of Probability of Hit(Ph) for OneSAF Model (OneSAF 모델을 위한 명중률 데이터 변환 방법)

  • Kim, Gun In;Kang, Tae Ho;Seo, Woo Duck;Pyun, Jae Jung
    • Journal of the Korea Society for Simulation
    • /
    • v.29 no.3
    • /
    • pp.83-91
    • /
    • 2020
  • To use the OneSAF model for the analysis of Defence M&S, the most critical factor is the acquisition of input data. The model user is hard to determine the input data such as the probability of hit(Ph) and the probability of kill(Pk). These data can be obtained directly by live fire during the development test and the operational test. Therefore, this needs more time and resources to get the Ph and Pk. In this paper, we reviewed possible ways to obtain the Ph and Pk. We introduced several data producing methodologies. In particular, the error budget method was presented to convert the Ph(%) data of AWAM model to the error(mil) data of OneSAF model. Also, the conversion method which can get the adjusted results from the JMEM is introduced. The probability of a hit was calculated based on the error budget method in order to prove the usefulness of the given method. More accurate data were obtained when the error budget method and the projected area from the published photo were used simultaneously. The importance of the Ph calculation was demonstrated by sensitivity analysis of the Ph on combat effectiveness. This paper emphasizes the importance of determining the Ph data and improving the reliability of the M&S system though steady collection and analysis of the Ph data.

Design of the PHY Structure of a Voice and Data Transceiver with Security (보안성을 갖는 음성 및 데이터 트랜시버의 물리 계층 구조 설계)

  • Eun, Chang-Soo;Lom, Sun-Min;Lee, Kyoung-Min
    • Journal of the Institute of Electronics Engineers of Korea TC
    • /
    • v.43 no.10 s.352
    • /
    • pp.46-54
    • /
    • 2006
  • In this paper, we propose a digital transceiver that can overcome the problems which current analog transceivers have. For the proposed transceiver, we assumed a frequency resource that consists of discrete and narrow channels. We also assumed that person-to-group, group-to-group, as well as person-to-person, voice and data communications with moderate security should be devisedand the data rate is 1 Mbps with simultaneous voice and data. Frequency hewing spread spectrum (FH-SS) and differential 8-PSK (D8PSK) were adopted for security reasons and bandwidth constraints, and for the reduction of implementation complexity, respectively. For the carrier and the symbol timing recovery, the structure of the preamble was proposed based on the IEEE 802.11 FHSS frame format to improve detection probability. The computer simulation results and power budget analysis implies that the proposed system can be usedin simple wireless communications in place of such as analog walkie-talkies.

A Study on Parent's Consciousness in regard to School-based Comprehensive Oral Health Care Program (학부모의 학교계속구강건강관리사업에 관한 의식조사 연구)

  • Kim, Soo-Kyung
    • Journal of Korean society of Dental Hygiene
    • /
    • v.3 no.2
    • /
    • pp.117-125
    • /
    • 2003
  • This study was pursued for the sake of gathering fundamental information to implement school-based comprehensive oral health care program and for planning oral health care program in consideration of parents. The following results were obtained by investigation of consciousness and favor level of 215 parents, who have elementary school children, regarding school-based comprehensive oral health care program. 1. It appears that many parents are not knowledgeable about school-based comprehensive oral health care program. There were significant differences between recognition level of school-based comprehensive oral health care program and age(PE0.05). 2. The parents acquired information about school-based comprehensive oral health care program; 58.7% by their children, 11.2% by mass-media, 10.0% by dentists and 3.7% by dental hygienists. 3. Most parents are in favor of school-based comprehensive oral health care program (96.7%). 4. Many parents(63.7%) prefer that social security law should budget for oral health care program. There were significant differences by sex(PE0.05) and age(PE0.01) As most parents are not so conscious of school-based comprehensive oral health care program, appropriate education program for dentists, dental hygienists and parents should be developed urgently.

  • PDF

Efficient Operation Model for Effective APT Defense (효율적인 APT 대응 시스템 운영 모델)

  • Han, Eun-hye;Kim, In-seok
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.27 no.3
    • /
    • pp.501-519
    • /
    • 2017
  • With the revolution of IT technology, cyber threats and crimes are also increasing. In the recent years, many large-scale APT attack executed domestically and internationally. Specially, many of the APT incidents were not recognized by internal organizations, were noticed by external entities. With fourth industrial revolution(4IR), advancement of IT technology produce large scale of sensitive data more than ever before; thus, organizations invest a mount of budget for various methods such as encrypting data, access control and even SIEM for analyzing any little sign of risks. However, enhanced intelligent APT it's getting hard to aware or detect. These APT threats are too much burden for SMB, Enterprise and Government Agencies to respond effectively and efficiently. This paper will research what's the limitation and weakness of current defense countermeasure base on Cyber Kill Chain process and will suggest effective and efficient APT defense operation model with considering of organization structure and human resources for operation.

A Study on the Improvements through the Analysis of Information Disclosure System and the Disclosure of Academic Libraries (대학도서관의 정보공개 및 공시 실태분석을 통한 개선방안에 관한 연구)

  • Gu, Jung-Eok
    • Journal of Korean Library and Information Science Society
    • /
    • v.40 no.4
    • /
    • pp.327-351
    • /
    • 2009
  • In this study, the actual condition in operating Information Disclosure System and University Information Disclosure was investigated and analyzed for 413 universities which had their own homepages out of the total 414 universities, which were the targets of university information disclosure in 2008. To activate Information Disclosure System of the academic library, how to use Korea Library Statistics Items and National Libraries Operation Assessment Index as the standard of information disclosure, and how to use a national library statistics system effectively were suggested. In addition, to make University Information Disclosure efficient, the amendments about the status of books holdings and library budget were respectively suggested so that the items and contents of disclosure about the status of library support might be disclosed by focusing on the security of finance and the improvement of the academic library. In order to enhance the interest of universities and in society and policy, it is necessary for the academic library to make use of Information Disclosure System and University Information Disclosure as a major means.

  • PDF

A Study on Developing the Model of Reasonable Cost Calculation for Privacy Impact Assessment of Personal Information Processing System in Public Sector (공공기관 개인정보 처리시스템의 개인정보 영향평가를 수행하기 위한 합리적인 대가 산정 모델 개발에 관한 연구)

  • Shin, Young-Jin
    • Informatization Policy
    • /
    • v.22 no.1
    • /
    • pp.47-72
    • /
    • 2015
  • According to the progress of national informatization throughout the world, infringement and threaten of privacy are happening in a variety of fields, so government is providing information security policy. In particular, South Korea has enhanced personal impact assessment based on the law of personal information protection law(2011). But it is not enough to effect the necessary cost calculation standards and changeable factors to effect PIA. That is, the budgets for PIA was calculated lower than the basic budget suggested by Ministry of Government Administration Home affairs(2011). Therefore, this study reviewed the cost calculation basis based on the literature review, cost basis of similar systems, and reports of PIA and obtained to the standard with Delphi analysis. As a result, the standards of PIA is consisted to the primary labors and is utilized to how the weights by division of target system, construction and operating costs of target system, type of target systems, etc. Thus, the results of this study tried to contribute to ensure the reliability of PIA as well as the transparency of the budget for privacy in public sector.

Hospital Cost Analysts' Perception on Prime Cost of Medical Services and Future Direction to Establish a Cost Accounting system (병원 원가관리자의 원가인식 및 원가체계 구축 방향)

  • Noh, Jin-Won;Lee, Hae-Jong;Park, Hyun-Chun
    • Korea Journal of Hospital Management
    • /
    • v.19 no.1
    • /
    • pp.32-42
    • /
    • 2014
  • It is necessary to calculate prime cost of medical services accurately in order to evaluate the adequacy of medical fee. This paper aims to identify cost analysts' perception on prime cost of medical services and needs in establishing a cost accounting system in hospitals, proposing future directions and guidelines for the calculation of medical fee. A self-administered questionnaire and telephone survey on operation of a hospital cost-accounting system was conducted in November, 2012, among cost analysts currently working in the hospitals and hospital administrators planning to implement the hospital cost-accounting system. Our study shows that most of the cost analysts were aware of the importance of calculating prime cost and responded that collection of the prime cost data from government is necessary although they are less likely to provide the data in the future concerning the risk of data misuse and data security. They also responded that lack of budget allocation and excessive workload were the main reasons for not estimating the prime cost and operating cost management information system. Results show that hospital cost analysts considered the data accuracy is the most critical factor in calculating prime costs of medical services. However, there was no investment budget allocated in some hospitals or limited to less than 100 million, indicating that hospitals are reluctant to invest on implementing the cost accounting system. Respondents stated the organization that collects the prime cost of medical services among hospitals should display strong analytical capabilities, ensure data security, and maintain independence, which is most demanded. There are 57 hospitals that calculated the prime cost of medical services for 2012 by each medical department and 20 hospitals that calculated the prime cost by fee-for-services, aiming to establish a cost accounting system. Our results indicate that hospitals should voluntarily provide the accurate prime cost for medical services in order to properly evaluate the adequacy of medical fee. Consequently, it is critical to establish an independent organization to collect and appraise the data. It is also recommended that government should implement various policies to encourage hospitals to participate in the data collection to achieve the data accuracy and representativeness.

  • PDF

A study on role of ROK Escort Task Gruop according to recently Pirate Conducting Trend and Anti-Piracy Operation in Indian Ocean (최근 인도양 해적활동과 대해적작전 변화에 따른 한국 청해부대 역할 연구)

  • Choi, Hyoung-Min
    • Strategy21
    • /
    • s.32
    • /
    • pp.192-221
    • /
    • 2013
  • In order to deal with the current economic crisis, the U.S. government, as a part of its austerity fiscal policy, implemented a budget sequester. The sequester will hit the U.S. defense budget the hardest, and as a result will most likely put the security of the international community in jeopardy. The U.S. will have to cut 46 billion dollars from its original 525 billon defense spending in 2013. And by the year 2022, will have to cut 486.9 billion dollars. Such an astronomical decrease in the U.S. defense spending will inevitably burden the friendly nations. According to recent studies, pirate related incidents in Somalia, where piracy is most active, has declined from its 226 incidents to 76 incidents per year in 2012, a 66% drop from previous years'. However, piracy threats as well as those related to firearms still remain and thus participants of anti-piracy operations, namely the U.S., U.K., France, Canada, NCC, EUNAVFOR, and NATO, are facing a problem of declining forces. Considering the current situation as well as rising expectations from the international community, Republic of Korea, a supporter of NCC's maritime security operation, not to mention its foremost duty of securing its sea, is at a stage to re-examine its operational picture. Such action will be a good opportunity for Republic of Korea to build the trust and live up to the international community's expectation. To quote from the network theory, although in relation to other friendly nations participating in the anti-piracy operation, Republic of Korea currently remains at a single cell level, this opportunity will certainly develop Korea to a 'node' nation in which power and information would flow into. Through this expansion of operational capability, Republic of Korea will be able to exert more influence as a more developed nation. Currently however, not only is the single 4,500 ton class destroyer deployed in Somalia a limited unit to further expand the scale and amount of force projection in the area, but also the total of six 4,500 ton class destroyers ROK feet possess is at a high fatigue degree due to standard patrolling operations, midshipman cruise and the RIMPAC exercise. ROK fleet therefore must consider expanding the number of ships deployed along with either deploying combat support ships or constructing logistics support site in the African region. Thus, by expanding its operational capabilities and furthermore by abiding to the rightful responsibilities of a middle power nation, Republic of Korea will surely earn its respect among the members of the international community.

  • PDF

Influencing Factors on Outsourcing Success in the Defense Sector (국방부문의 아웃소싱 성공도에 영향을 미치는 요인에 관한 연구)

  • Yu, Dae Beom;Oh, Jay In
    • Information Systems Review
    • /
    • v.18 no.1
    • /
    • pp.79-103
    • /
    • 2016
  • The Korean Army has to construct a system that will enable it to cope immediately with the flexible military relationships in Northeast Asia by systematizing and improving the efficiency of operations. These improvements include building a smart and strong army, concentrating on cost-effective combat skills, maximizing the utilization of private resources, and establishing a military structure based on information and technology. Accordingly, this study proposes solutions to solve the problems affecting the success of outsourcing in the defense industry. Unlike outsourcing in other government ministries, outsourcing in the national defense sector may be unrealistic because this strategy is related to the renovation project of the Ministry of the National Defense. In general, the objective of outsourcing in the defense industry, similar to other businesses, is to improve efficiency and not to reduce troops and national defense budget. Several factors, such as identification and security guarantee, risk reduction, cost saving, quality improvement, the reliability of enterprise, and professional technology, are necessary to ensure outsourcing success in the national defense sector. In terms of effectiveness, the improvement in service quality significantly influences outsourcing success in the national defense sector. Eventually, the national defense forces must be strengthened to prevent the provocative actions of North Korea and other threats by improving identification, sense of national security, and quality unlike the current outsourcing of the government, as well as emulating German GEBB or PMC, which utilizes social capital.