Organizational information systems operate through interdependent assets, services, and business functions; thus, the impact of a cyber incident affecting a specific asset can propagate across services and operations, requiring prompt and systematic response. However, conventional risk assessment is a predictive framework centered on pre-incident likelihood and potential impact, making it inadequate for directly explaining the actual scale of damage and financial loss after an incident has occurred. Accordingly, this study distinguishes qualitative pre-incident risk from quantitative post-incident severity and proposes a model for evaluating realized damage from a security perspective. Specifically, actual incident outcomes, including information leakage, data tampering, and service disruption, are quantified as Confidentiality, Integrity, and Availability (CIA) loss rates. The proposed model calculates severity by combining these CIA loss rates with asset importance derived from asset–service dependency structures. It also enables interpretation of the contribution of individual assets and security attributes, thereby supporting more efficient decision-making in response prioritization and resource allocation. Furthermore, the results can be fed back into the recalibration of risk management levels and the refinement of Degree of Assurance (DoA) criteria, contributing to improved organizational security management.
한국어
조직의 정보시스템은 자산, 서비스, 업무가 상호 의존하는 구조로 운영되므로, 특정 자산에서 발생한 침해사고의 영향이 서비스와 업무 전반으로 확산될 수 있어 신속하고 체계적인 대응이 요구된다. 그러나 기존 위험평가는 사고 이전의 가능성과 잠재적 영향을 중심으로 하는 예측적 평가 체계이므로, 사고 이후의 실제 피해 규모와 피해액을 직접적으로 설명하기 어렵다. 이에 본 연구는 정성적인 사전 위험도와 정량적인 사후 심각도를 구분하여 정의하고, 사고로 인해 실제 발생한 정보 유·노출, 데이터 변조, 서비스 중단을 각각 기밀성(C)·무결성(I)·가용성(A) 손실률로 정량화함으로써, 실현된 피해의 규모를 보안 관점에서 평가하는 모델을 제안한다. 제안 모델은 자산–서비스 의존 구조를 반영한 자산 중요도와 CIA 손실률을 결합하여 심각도를 산정하며, 자산별 및 보안 속성별 기여도를 해석할 수 있어 대응 과정에서의 우선순위 설정과 자원 배분 등 보다 효율적인 의사결정을 지원한다. 이는 향후 위험관리 수준의 재설정과 DoA 기준의 구체화에 반영되어 조직의 보안관리 체계 개선으로 환류될 수 있다.
목차
요약 ABSTRACT 1. 서론 2. 이론적 배경 및 관련 연구 2.1 사이버보안 위험평가 프레임워크 2.2 위험평가의 한계와 심각도 평가의 필요성 3. 침해사고 심각도 평가 모델 3.1 조직 구조 모델링 3.2 자산 중요도 산정 3.3 CIA 손실률 산정 3.4 최종 심각도 산정 4. 가상 시나리오 기반 적용 및 분석 4.1 가상 시나리오 설정 4.2 자산의 중요도 산정 결과 4.3 CIA 손실률 산정 결과 4.4 최종 심각도 산정 결과 및 해석 5. 결론 참고문헌