• 제목/요약/키워드: Vendor Risk

검색결과 25건 처리시간 0.019초

축제방문자의 먹거리 구매행동 예측에 대한 계획행동이론의 적용 (Applying the Theory of Planned Behavior to Forecast the Food Purchase in Festivals)

  • 이준엽;안태기
    • 한국콘텐츠학회논문지
    • /
    • 제8권2호
    • /
    • pp.116-124
    • /
    • 2008
  • 축제에서 제공되는 먹거리는 그 자체가 축제매력요소로 작용하게 되며, 다양한 먹거리는 축제평가에서도 중요한 부분으로 평가되고 있다. 한정된 축제 기간에 지역주민, 축제방문자 그리고 상인들의 과대 유입으로 인하여 축제성공에 반하는 사고와 여러 문제점들이 나타날 수 있다. 본 연구에서는 축제방문자가 축제먹거리를 어떻게 지각하고 있으며, 먹거리 구매 행위와의 인과관계를 계획행동이론을 적용해 규명하고자 하였다. 실증분석결과, 행동의도에는 신념, 주관적 규범, 지각된 행동조절 모두가 영향을 미치는 것으로 나타났으며, 최종 먹거리구매에 대한 영향 관계에서는 행동의도가 정의 영향을 미치는 것으로 나타났으며, 지각된 행동조절은 유의수준 p<.05에서 유의하지 않은 것으로 나타났다. 축제장은 일탈성을 강하게 강조되는 장소이므로, 먹거리에 대한 축제방문자 각 개인의 능력보다 축제의 매력과 흥미에 의하여 소비가 일어나고 있다고 볼 수 있으므로, 축제 먹거리에 대한 체계적인 위생관리가 필요하다.

클라우드 컴퓨팅 환경을 위한 기존 시스템의 이전 방안 연구 (A Study on the method of existing system migration for Cloud computing)

  • 박성희;양해술
    • 디지털융복합연구
    • /
    • 제12권10호
    • /
    • pp.271-282
    • /
    • 2014
  • 최근 클라우드 컴퓨팅이라는 패러다임의 기술과 개념은 사실상 거대한 자원의 활용과 다양한 서비스를 시간과 장소의 구애 없이 효율적인 비용으로 제공된다는 장점으로 기업들의 도입이 점차 늘어가고 있다. 하지만, 보안, 호환성, 통제력 상실, 보안, 데이터보호, 성능과 업타임, 클라우드 컴퓨팅 서비스의 벤더 종속에 대한 위험성, 기존 시스템과 호환성, 이식성에 대한 불안으로 국내에 클라우드 도입은 아직 미미한 상태이다. 특히 기존 시스템의 이전에 관심과 이슈는 높지만, 그에 따른 연구가 아직은 부족한 상황이다. 본 논문에서는 클라우드 도입사례와 클라우드 컴퓨팅 환경으로의 기존 시스템 이전에 관련한 방법론과 방안에 대해 연구하고 한계점을 도출하고 클라우드 컴퓨팅을 위한 기존 시스템의 현대화에 대해 방안을 제시하였다.

발전소 주제어시스템 모의해킹을 통한 취약점 분석 및 침해사고 대응기법 연구 (A study on vulnerability analysis and incident response methodology based on the penetration test of the power plant's main control systems)

  • 고호준;김휘강
    • 정보보호학회논문지
    • /
    • 제24권2호
    • /
    • pp.295-310
    • /
    • 2014
  • 발전소 주제어시스템(DCS, Distributed Control System)은 원격지의 설비를 계통현황에 따라 실시간 조작, 감시 및 운전 효율성을 향상시키기 위해 튜닝을 하도록 구현된 자동화 시스템이다. DCS는 IT 기술의 발전과 함께 점차 지능화, 개방화되고 있다. 많은 전력회사들이 DCS에 설비 관리용 패키지 시스템을 접목하여 예측진단을 통한 유지 보수 및 Risk Management를 실현시키기 위한 투자를 확대하고 있다. 하지만, 최근 해외사례에서 보듯이 원전 전력망 등 국가 주요기반 시설인 산업 제어시스템(ICS)을 마비시키고 파괴할 목적으로 개발된 최초의 사이버 전쟁무기인 스턱스넷이 출현하는 등, 폐쇄형 시스템으로 구성된 발전소 주제어시스템도 점차 외부 공격으로부터 위협의 대상이 되고 있음을 알 수 있다. 높은 수준의 가용성(낮은 고장빈도와 신속한 복구)과 운영 신뢰성의 이유로 10년 이상 장기 사용이 요구되는 발전소 주제어시스템의 경우 전적으로 해외 기술에 의존하고 있고 패치 업데이트 등 주기적 보안관리가 이뤄지지 못해 잠재된 취약점이 노출될 경우 심각한 우려가 예상된다. 본 논문에서는 국내 발전회사에서 사용 중인 Ovation 1.5 버전의 간이 시뮬레이터 환경에서 범용 취약점 분석툴인 NESSUS를 활용하여 인가된 내 외부 사용자의 악의적 행위(모의해킹)를 수행하였다. 이를 통해 취약점 탐지 및 발전소 제어시스템 내 사이버 침해사고 발생 시 효과적으로 대응 할 수 있는 취약점 분석 및 로그분석 방안을 제시하고자 한다.

CMIT/MIT 함유 가습기 살균제 제품의 제조 및 판매기업 형사판결 1심 재판 판결문에 대한 과학적 고찰 (I) - 제품 위험성과 노출평가 측면에서 (A Scientific Critique of a Korean Court's Acquittal for Involuntary Manslaughter Related to 5-chloro-2-methylisothiazol-3(2H)-one/2-methylisothiazol-3(2H)-one (CMIT/MIT), a Humidifier Disinfectant (HD) Part I: Material safety, exposure and delivery to target organ from an HD perspective)

  • 박동욱;조경이;김지원;최상준;권정환;전형배;김성균
    • 한국환경보건학회지
    • /
    • 제47권2호
    • /
    • pp.111-122
    • /
    • 2021
  • Objectives: There was a judgment of acquittal for the manufacturer SK Chemical and the vendor Aekyung regarding humidifier disinfectant (HD) containing 5-chloro-2-methylisothiazol-3(2H)-one/2-methylisothiazol-3(2H)-one (CMIT/MIT). The rationale used in this judgement is discussed here in the light of scientific consideration. Methods: The sentencing document for the judgements was obtained from the Korea Supreme Court Service. In particular, the judgements made by the court related to the risk of HD and external and internal exposure to CMIT/MIT are discussed based on scientific evidence. Results: Rendering a determination in a criminal trial of insufficient evidence of causation, the court dismissed the prosecution's motion that humidifier disinfectant-associated lung injuries (HDLI) and asthma were associated with the utilization of these products. However, CMIT/MIT, a strong sensitizing and corrosive substance, has been reported to be associated with brain toxicity, allergic contact dermatitis, and asthma. Furthermore, the judgment did not consider total consumption amounts or the cumulative dose of CMIT/MIT in the humidifier. Lastly, there are several cases supporting the fact that exposure to water-soluble substances including CMIT/MIT can cause lower respiratory tract diseases. In addition to cases of asthma among the workers exposed to CMIT/MIT, we identified lung injury victims who were exposed to HDs exclusively containing CMIT/MIT. Conclusions: We conclude that there is sufficient evidence supporting the assertion that HDs containing CMIT/MIT cause lung injuries, including asthma, contrary to the court's judgement.

조직의 정보 니즈와 ERP 기능과의 불일치 및 그 대응책에 대한 이해: 조직 메모리 이론을 바탕으로 (Understanding the Mismatch between ERP and Organizational Information Needs and Its Responses: A Study based on Organizational Memory Theory)

  • 정승렬;배억호
    • Asia pacific journal of information systems
    • /
    • 제22권2호
    • /
    • pp.21-38
    • /
    • 2012
  • Until recently, successful implementation of ERP systems has been a popular topic among ERP researchers, who have attempted to identify its various contributing factors. None of these efforts, however, explicitly recognize the need to identify disparities that can exist between organizational information requirements and ERP systems. Since ERP systems are in fact "packages" -that is, software programs developed by independent software vendors for sale to organizations that use them-they are designed to meet the general needs of numerous organizations, rather than the unique needs of a particular organization, as is the case with custom-developed software. By adopting standard packages, organizations can substantially reduce many of the potential implementation risks commonly associated with custom-developed software. However, it is also true that the nature of the package itself could be a risk factor as the features and functions of the ERP systems may not completely comply with a particular organization's informational requirements. In this study, based on the organizational memory mismatch perspective that was derived from organizational memory theory and cognitive dissonance theory, we define the nature of disparities, which we call "mismatches," and propose that the mismatch between organizational information requirements and ERP systems is one of the primary determinants in the successful implementation of ERP systems. Furthermore, we suggest that customization efforts as a coping strategy for mismatches can play a significant role in increasing the possibilities of success. In order to examine the contention we propose in this study, we employed a survey-based field study of ERP project team members, resulting in a total of 77 responses. The results of this study show that, as anticipated from the organizational memory mismatch perspective, the mismatch between organizational information requirements and ERP systems makes a significantly negative impact on the implementation success of ERP systems. This finding confirms our hypothesis that the more mismatch there is, the more difficult successful ERP implementation is, and thus requires more attention to be drawn to mismatch as a major failure source in ERP implementation. This study also found that as a coping strategy on mismatch, the effects of customization are significant. In other words, utilizing the appropriate customization method could lead to the implementation success of ERP systems. This is somewhat interesting because it runs counter to the argument of some literature and ERP vendors that minimized customization (or even the lack thereof) is required for successful ERP implementation. In many ERP projects, there is a tendency among ERP developers to adopt default ERP functions without any customization, adhering to the slogan of "the introduction of best practices." However, this study asserts that we cannot expect successful implementation if we don't attempt to customize ERP systems when mismatches exist. For a more detailed analysis, we identified three types of mismatches-Non-ERP, Non-Procedure, and Hybrid. Among these, only Non-ERP mismatches (a situation in which ERP systems cannot support the existing information needs that are currently fulfilled) were found to have a direct influence on the implementation of ERP systems. Neither Non-Procedure nor Hybrid mismatches were found to have significant impact in the ERP context. These findings provide meaningful insights since they could serve as the basis for discussing how the ERP implementation process should be defined and what activities should be included in the implementation process. They show that ERP developers may not want to include organizational (or business processes) changes in the implementation process, suggesting that doing so could lead to failed implementation. And in fact, this suggestion eventually turned out to be true when we found that the application of process customization led to higher possibilities of failure. From these discussions, we are convinced that Non-ERP is the only type of mismatch we need to focus on during the implementation process, implying that organizational changes must be made before, rather than during, the implementation process. Finally, this study found that among the various customization approaches, bolt-on development methods in particular seemed to have significantly positive effects. Interestingly again, this finding is not in the same line of thought as that of the vendors in the ERP industry. The vendors' recommendations are to apply as many best practices as possible, thereby resulting in the minimization of customization and utilization of bolt-on development methods. They particularly advise against changing the source code and rather recommend employing, when necessary, the method of programming additional software code using the computer language of the vendor. As previously stated, however, our study found active customization, especially bolt-on development methods, to have positive effects on ERP, and found source code changes in particular to have the most significant effects. Moreover, our study found programming additional software to be ineffective, suggesting there is much difference between ERP developers and vendors in viewpoints and strategies toward ERP customization. In summary, mismatches are inherent in the ERP implementation context and play an important role in determining its success. Considering the significance of mismatches, this study proposes a new model for successful ERP implementation, developed from the organizational memory mismatch perspective, and provides many insights by empirically confirming the model's usefulness.

  • PDF