Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 35
No
1

6,100원

네트워크의 활용 범위가 의료 기관 내에서의 보험청구 처리나 전자차트에 머 물지 않고 지역에서의 의료 기관 간의 네트워크의 구축까지 확대되면, 의료기관 내에서의 관계자뿐만이 아니라 외부의 행정기관이나 환자의 이용도 상정할 필요 가 있다. 여러 입장의 사용자가, 안심하고 안전하게 이용할 수 있는 네트워크 환 경을 고려할 때 제일 첫째 조건으로서 제시되는 명제는 보안일 것이다. 이에 따 라 본 논문에서는 원격진료의 안전한 서비스를 위한 기존의 정보보호기술에 대 한 심도 깊은 고찰을 수행하였다.

Once the application range of the network is expended to build a network of medical facilities in the region in stead of staying in insurance claims processing or electronic chart in the medical institution, external use of government agencies and patients as well as officials in the medical institutions should be assumed. The first proposition would be security considering the network environment multiple positions of users can safely use. Thereby, in this paper we performed a deep discussion about the existing information security technologies for secure services of Telecare.

2

특허지표를 이용한 우리나라 정보보안기술의 R&D 특성분석 KCI 등재

오종학, 나관식

한국지식재산학회 산업재산권 제62호 2020.01 pp.251-281

※ 기관로그인 시 무료 이용이 가능합니다.

7,200원

본 연구에서는 먼저 정보보안기술을 대상으로 선진국과 신흥기술 국의 R&D특성에 영향을 미치는 요인을 파악하고자 한다. 분석결과, 선진국 R&D는 특허의 질적 수준을 의미하는 인용율과 관련된 특허 지표에 영향을 받고, 신흥기술국 R&D는 특허의 양적 수준을 의미하 는 출원수와 관련된 특허지표에 영향을 받는 것으로 나타났다. 또한 정보보안 분야의 28개 세부기술 중 10개가 신흥기술국 R&D에 가까 운 형태를 보인 반면에, 18개 기술은 선진국 R&D에 가까운 형태를 보이는 것으로 예측되었다. 하지만 파급효과가 큰 5개 기술(암호기 술, 인증기술, 클라우드/빅데이터 보안, 개인정보보호, IoT 보안)은 신흥기술국 R&D에 가까운 특성을 보이는 것으로 예측되어서, 향후 이러한 기술에 대한 우선적인 지원과 특허전략이 필요하다고 볼 수 있다.

In this study, we first examine the factors affecting R&D characteristics of developed and developing countries in information security technology. As a result, developed country R&D is influenced by patent index related to the quotation rate, which means the quality level of the patent, and R&D of developing country is influenced by the patent index related to the number of patent, which means the quantity of patent. In addition, ten of the 28 detailed technologies in the field of information security were close to R&D in developing countries, while 18 technologies were expected to be close to R&D in developed countries. However, five technologies with high ripple effects (encryption technology, authentication technology, cloud / big data security, privacy protection, and IoT security) are expected to show characteristics close to R&D in emerging technologies. Therefore, it is necessary to provide priority support and patent strategy for these technologies.

3

정보보호 기술 개발 및 표준화 현황 분석 KCI 등재

장희선

한국융합보안학회 융합보안논문지 제13권 제4호 2013.09 pp.53-59

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

컴퓨터와 정보통신 기술의 발전으로 사이버테러 및 금융사기를 위한 해킹 기술도 진화하고 있으며 이를 대비하기위한 선진국 수준의 표준화된 정보보호 기술의 연구․개발이 어느 때보다 중요해지고 있다. 본 논문에서는 주요 정보보호 기술에 대한 국외대비 국내의 기술 및 표준화 수준을 진단함으로서 개선점을 제안하며, 시장․기술적 파급효과와 정부 정책 추진과의 부합성을 분석하여 향후 연구개발 방향을 제시한다. 정보보호 기술은 정보보호기반 및 이용자 보호,네트워크 및 시스템 보안, 응용보안 및 평가인증의 세 가지로 분류하고 세부적으로 OTP기반 인증, 스마트폰앱 보안, 모바일 전자금융 등 9가지로 구분하여 각각의 세부 기술에 대한 현황을 분석한다. 분석 결과, 전반적으로 국외 대비 표준화 및 기술개발 역량이 다소 부족한 것으로 평가되며, 특히 시장․기술적 파급효과가 큰 스마트폰앱 보안 및 모바일 전자금융에 대한 국제적 수준의 기술개발과 표준화 역량이 강화되어야 하고, 미래인터넷에서의 정보보호 기술에 대한 정부의 지원 정책이 시급한 것으로 평가된다.

As the hacking technology for cyber-terror and financial fraud evolves, the research and development for advanced and standardized information security technology is growing to be more and more important. In this paper, the domestic level of technology and standardization for information security as compared to advanced country is diagnosed, and future policy is presented by analyzing the influence effect for market and technology. The information security is classified into information security-based & user protection, network & system security,and application security & evaluation validation with details of OTP-based validation, smart-phone app security,and mobile electronic finance, etc. The analytic results indicate that domestic level is some poor for advanced country, the technological development and standardization capability for smart-phone app security and mobile electronic finance is needed, and finally the government's supporting policy for the future Internet is urgently needed.

4

4,500원

조직의 정보 관리 중요성이 증가하면서, 정보보안 정책 및 기술에 대한 투자가 높아지고 있다. 더불어, 조직은 도입한 정보보안 정책 및 기술 을 구성원의 업무에 적용하는 것을 요구하고 있다. 하지만, 엄격하고 높은 수준의 정보보안 기술은 조직원의 스트레스를 유발하여 정보보안 행 동을 회피할 수 있다. 본 연구의 목적은 정보보안 준수 의도에 부정적 영향을 미치는 정보보안 기술 스트레서를 완화 방안을 제시하고 확인하는 것이다. 세부적으로, 정보보안 기술 스트레서가 개인의 내적 동기(가치 일치)와 정보보안 준수 의도에 미치는 부정적 영향을 업무-정보보안 기술 적합성이 조절하는 것을 확인한다. 본 연구는 정보보안 정책 및 기술을 도입한 조직에 근무하는 조직원들을 대상으로 설문을 하였으며, 확보된 표본을 활용하여 구조방정식 모 델링을 실시하여, 가설 검증을 하였다. 연구 결과, 정보보안 기술 스트레서가 정보보안 가치 일치를 부분 매개하여 정보보안 준수 의도를 감소시 키는 것을 확인하였으며, 업무-정보보안 기술 적합성이 정보보안 기술 스트레서와 가치 일치, 그리고 준수 의도 간의 부정적 영향 관계를 조절하 는 것을 확인하였다. 본 연구는 조직 내부의 정보보안 수준 달성을 위해 도입한 기술의 활용에 있어 발생 가능한 조직원의 정보보안 기술 관련 스 트레스 완화 방법을 제시하고, 내부 준수 수준 향상을 위한 방향을 제시한 측면에서 시사점을 가진다.

As the importance of organizational information management increases, organizations are increasing their investment in information security. Also, the organization requires its employees to apply the policies and technologies. However, strict information security technology induces stress on the employees, thereby avoiding information security behavior. The purpose of this study is to propose amethod tomitigate the techno-stress of information security that negatively affects the information security compliance intention. The subjects of this study are employees of the organization who have adopted information security policies and technologies, and hypotheses were verified through structural equation modeling using samples obtained through questionnaires. As a result of the study, it is confirmed that techno-stress has a negative effect on compliance intention by partially mediating value congruence, and it is confirmed that technical support increases compliance intention. And, the study confirmed that task-technology fit mediates the relationship between techno-stress and value congruence. The study presents implications in terms of suggesting directions for improving the level of internal information security through stressmitigation of employees.

5

ICT 융합서비스 제공을 위한 정보보호 기술개발 현황분석 KCI 등재

김동철

한국융합보안학회 융합보안논문지 제15권 제4호 2015.06 pp.33-39

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

본 논문에서는 최근 국내외적으로 많은 이슈가 되고 있는 사물인터넷, 빅데이터, 클라우드 융합 서비스들에 대한 정보 보호 기술 개발 현황을 분석하고 특허 및 표준화 분야에서 우리나라가 선도적인 위치를 차지하기 위한 세부 전략을 제 시한다. 이를 위하여, ICT 융합의 개념을 살펴보고 주요 융합 기술이 제공하는 서비스와 시장 현황을 진단하며, 기술별 로 주요 기능과 보안대상을 제시한다. 그리고 국외대비 국내 기술 및 표준화 수준을 진단하기 위한 평가기준을 설정하 고 이에 대한 평가 결과와 지적재산권의 보유 현황을 분석한다. 모든 분야에서 아직은 국외 선진국의 수준에 크게 미치 지 못하나 빅데이터 및 클라우드 분야에서의 국내 역량을 활용한 선도 전략의 마련과 시장기술적 파급효과가 높은 사물 인터넷과 클라우드 서비스에 대한 우선적인 기술 개발이 요구된다. 그리고 사물인터넷 분야에서의 M2M 보안 프레임워 크, 빅데이터에서의 데이터 보안 기술 및 클라우드에서의 보안관리 및 신뢰 클라우드 연동 보안 기술 개발 및 표준화 추진이 우선적으로 요구된다.

In this paper, the development level of information security technology for internet of things(Iot), big data and clo ud services is analyzed, and the detail policy is proposed to be leader in area of patents and ICT standard. The conc ept of ICT convergence is defined frist, market and current state of technology for three convergence services is the n analyzed, and finally main function and security target for each technology are presented. The evaluation criteria a nd IPR are analyzed to diagnose the level of patent and standard for the technology. From the results, even though the domestic competence is inferior compared to other advanced country, the efficient policy should be presented by using our capability for the big data and cloud. Furthermore, the technology development for the IoT and cloud is ne eded in advance considering the market-technology influence effects. In addition to, M2M security framework in IoT, data security in big data and reliable networking in cloud should be developed in advance.

6

IT 시스템의 다중 수준 보안을 위한 관리 환경 연구 KCI 등재후보

김점구

한국융합보안학회 융합보안논문지 제10권 제4호 2010.12 pp.39-48

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

복잡한 환경에서 안전한 IT환경은 하나이상으로 분리된 데이터의 그룹으로 나뉘어 같은 시스 템에 상주하지 않게 함으로서 그 목적을 얻을 수 있다. 이러한 시스템의 사용자는 특정 데이터 에 접근하는 방법과 등급을 다르게 하여야 한다. 정보구조, 물리적 구조, 사용자 권한 및 응용 프로그램 보안 정책을 위한 유지 보수 등은 이러한 환경 관리를 더욱 복잡하게 하고 보안 관리 자의 수의 증가를 가져온다. 본 논문은 이러한 환경관리를 위한 CM 툴을 시스템 공학의 CASE 툴을 모델로 하여 제안하 고자 한다. 시스템 공학의 모델링 기법은 다중 정보 보안을 처리하는 데 사용할 수 있다. SE의 CASE 툴 모델은 동일 시스템에 대한 논리와 물리적인 관리를 쉽게 할 수 있는 중요한 구성 요 소를 가지게 된다. CASE 툴의 확장된 영역은 물리적인 CM 툴을 사용자 친화적이고 안전한 IT 시스템의 관리 환경의 문제점을 해결하는 기본을 제공하게 될 것이다.

In a complex, secure IT system environment there will be groups of data that be segregated from one another, yet reside on the same system. Users of the system will have varying degrees of access to specific data. The Configuration Management(CM) of the information architecture, the physical architecture, user privileges and application security policies increases the complexity for operations, maintenance and security staff. This pager describes(current work to merge the capabilities of a network CM toll with those of a Computer Aided System Engineering(CASE) tool. The rigour of Systems Engineering(SE) modelling techniques can be used to deal with the complexities of multi-level information security. The SE logical and physical models of the same system are readily tailorable to document the critical components of both the information architecture and physical architecture that needs to be managed. Linking a user-friendly, physical CM tool with the extended capabilities of a CASE tool provide the basis for improved configuration management of secure IT systems.

7

7,800원

정보보호 요구가 고도화되는 금융산업 환경에서, 기존 정보보호 공시제도의 정보 비대칭성과 정성 중심의 공시구조로 인해 기업 간 보안 수준을 객관적으로 비교하기 어렵다는 한계를 지닌다. 또한 정보보호 공시제도는 금융권의 특수성을 충분히 반영하지 못한다. 이에 본 논문에서 금융권을 기반으로 기존 정보보호 공시제도의 구조적 문제를 규범적으로 분석하고, 금융권에 적합한 정보보호 공시항목의 표준화, 보안 공시 등급체계, 인센티브 구조를 결합하여 이러한 한계를 보완하기 위한 제도적 개선안을 제시한다. 이를 구현하기 위한 방법으로, 공시정보의 위·변조를 방지하고 이력의 신뢰성을 확보하기 위한 블록체인 기반 무결성 보장기술과, 공시항목의 이상징후를 탐지하고 점검의 효율성을 높이기 위한 인공지능 기반 이상탐지기법을 결합한 새로운 공시체계 모델을 제안한다. 이러한 공시 모델은 정보의 접근성을 높여 모든 이해관계자에게 동등하게 알 권리를 보장함으로써, 정보의 공공성과 투명성을 한층 강화하는 데 기여할 수 있다. 이를 통해 정보보호 공시제도의 실효성을 제고하고 참여자 간 신뢰를 체계화함으로써 국내 금융 생태계의 신뢰 기반 형성에 기여하고자 한다.

As information security requirements in the financial sector become increasingly sophisticated, the existing information security disclosure system faces significant limitations. In particular, information asymmetry and a qualitative-oriented disclosure structure make it difficult to objectively compare security levels across firms. Furthermore, the current system fails to sufficiently reflect the unique characteristics and regulatory environment of the financial sector. Accordingly, this study conducts a normative analysis of the structural limitations of the existing information security disclosure system and proposes institutional improvements tailored to the financial industry. These improvements include the standardization of disclosure items, a security disclosure rating system, and an incentive-based framework. To support implementation, this study further proposes a new disclosure system model that integrates blockchain-based integrity assurance technology—to prevent tampering and ensure the reliability of historical records—with AI-based anomaly detection techniques to identify irregularities and improve audit efficiency. This model enhances information accessibility by ensuring equal access for all stakeholders, thereby strengthening the public nature and transparency of disclosed information. Ultimately, this study aims to improve the effectiveness of the information security disclosure system, foster trust among participants, and contribute to the establishment of a robust, trust-based domestic financial ecosystem.

8

정보보호 산업의 기술성숙도에 따른 비즈니스 모델 상관성 분석 KCI 등재

임헌욱

한국융합보안학회 융합보안논문지 제19권 제4호 2019.10 pp.165-171

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

국내 정보보호 시장이 급성장하고 있어 정보보호 산업의 발전을 위해 성장성이 우수한 비즈니스 모델을 찾아 보안산 업의 발전방안을 제시하고자 하였다. 이를 위해 정보보호 산업의 주요 생산품을 유사한 업종별로 구분하여 종속변수로 정하고 전문가 인터뷰를 통해 기술성숙도에 따라 구분하였으며, 독립변수는 매출액, 사원수, 업력을 대상으로 하였다. 조 사결과 86개 기업 대상 평균 매출액은 87.98억원, 업력은 13.51년, 사원수는 64.3명 이었으며, SPSS 통계분석 결과 기술 성숙도에 따른 업종과 매출액의 상관관계는(r = -.729) 유의수준 5%이내에서 상관이 있으며, 회귀분석 결과 (p=.047 < 0.05)는 유의미하였다. 따라서 기술성숙도에 따른 업종 분류와 매출액은 관련이 있다고 할 수 있다.

The domestic information security market is booming, For the development of the information security industry. I wanted to suggest a strategy for finding and developing a good business model. So the main products were classified by similar industries. And The sector was selected as the dependent variable. Expert interviews were conducted and classified according to technical maturity. Independent variables were sales, number of employees, and performance. Average analysis result, sales amounted to 8.798 billion won, 13.51 years in industry, and 64.3 employees. As a result of SPSS statistical analysis, the correlation between industry type and sales according to technical maturity (r = -.729) was within 5% of significance level. The regression results were significant. (p= .047<0.05) Therefore, industry classification and sales are related to technological maturity.

9

4,000원

급격한 정보통신기술의 발달은 경찰에게 새로운 도전이자 기회가 되고 있다. 이 연구는 국내외 치안분야의 ICT기 술 활용사례를 검토하고, 그 시사점을 확인하는 것을 목적으로 한다. 이를 위해 정보통신기술 활용에 관한 경찰활동의 근거이론으로 정보주도 경찰활동(intelligence-led policing), 예측적 경찰활동(predictive policing), 증거기반 경찰활동 (evidence-based policing)의 개념에 대해 소개하였다. 또, 빅데이터 기반 범죄분석과 예측기술 활용방안과 경찰의 정보 통신체계 및 지휘통제기술의 고도화방안에 대해 논의하였다. 이 연구를 통해 확인한 시사점으로 ① 기본데이터의 확 보, ② 활용가능한 통합D/B의 구축, ③ 정책결정자의 활용성 증대, ④ 유관기관 사이의 교류협력, ⑤ 전문가집단의 양 성, ⑥ 통합 D/B구축의 법적 근거와 실무적 가이드라인 마련을 제안한다.

Rapid advances in information and communications technology are new challenges and also opportunities for the police. For the purpose of identifying its implications, this study reviews utilization cases of information and communications technology in the field of public security in South Korea and other countries. As theoretical basis for utilization of information and communications technology, this study introduces intelligence-led policing, predictive policing and evidence-based policing. Also, utilization of big-data based crime analysis and crime prediction technology, as well as advancement of information and communications system and command and control technology of the police, are discussed. Based on the identified implications in this study, the following proposals are made. They are ① procuring basic data, ② creating an integrated database, ③ increasing utilization of policy decision-makers, ④ exchange and cooperation between related institutions, ⑤ training professional analyzers, ⑥ establishing legal basis and practical guidelines for an integrated database.

10

4,800원

현재, 스마트폰 보급이 시작된 이후 스마트폰 사용이 보편화되어 대다수의 사람들이 사용하고 있다. 스마트폰 사용이 대중화됨에 따라 과거에는 문자메시지(SMS), 통화, 이메일 등을 통해 타 인과 소통하는 방식으로 교류되고 있었지만, 오늘날에는 모바일 인스턴트 메신저 서비스(MIM)를 통해 연락하고 있다. 모바일 메신저 앱 서비스를 사용하는 주된 이유는 가족과 지인과의 개인적 인 접촉, 사내 비즈니스, 외부 거래처 서비스 등의 순으로 높았다. 외부 거래처 서비스의 경우 거 래처에서 모바일 인스턴트 메신저 서비스를 사용으로 응대와 업무용 컨퍼런스콜 목적으로 사용 하고 있다. 업무 특성상 고객 서비스(응대)에 사용되는 인스턴트 메신저 서비스(MIM)의 경우 DLP가 애플리케이션 실행 정책을 통해 인스턴트 메신저 서비스(MIM)을 통제할 수 있지만 업무 용으로 허용될 경우 인스턴트 메신저 서비스(MIM) 특성상 내부정보 유출의 잠재적 위험요인이 잔재한다. 따라서 인스턴트 메신저 서비스인 카카오톡을 통해 내부정보가 유출될 경우 디지털포 렌식 기법을 통한 보안감사 방법을 제안 한다.

Today, After the spread of smartphones began in earnest in 2009, the use of smartphones has become so common that the majority of the people use them. As the use of smartphones has become popular, in the past, ways of communicating with others through text messages (SMS), calls, and e-mails have been exchanged, but today they are contacting them through a mobile instant messenger service (MIM). The main reasons for using the mobile messenger app service were in the order of personal contact with family and acquaintances, in-house business, and external customer service. In the case of external customer service, a mobile instant messenger service is used by the customer for response and business conference calls. In the case of instant messenger service (MIM), which is being used for customer service due to its nature of work, DLP can control instant messenger service (MIM) through application execution policies, but if it is to be allowed for business purposes, potential risks of internal information leakage exist due to the nature of instant messenger service (MIM). Therefore, when internal information is leaked through KakaoTalk, an instant messenger service, we propose a security audit methodology through digital forensics.

11

User Behavior Research of Information Security Technology Based on TAM SCOPUS

Wang Cheng, Wang Shi-bo

보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.8 No.2 2014.03 pp.203-210

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

By analyzing the present applying situation and influential factors of the information security technology, considering technological utility, cognitive cost, social impact, individual innovation, computer self-efficacy and other external variables, this paper constructs a model of user behavior of information security technology based on TAM. Through questionnaire to collect data and SPSS to perform reliability analysis, validity analysis, correlation analysis and regression analysis, the model in this paper is verified to be effective. Finally, some relative recommendations for the development of Chinese information security technology are put forward.

12

정보 보안을 위한 데스크탑 가상화 기술 동향 KCI 등재후보

배유미, 정성재

보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.8 No.2 2011.04 pp.255-264

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

기업이나 학교의 컴퓨터 사용 현황을 살펴보면 개인별로 PC(Personal Computer)나 노트북(Notebook)을 지급받아 사용하고 있다. 기업은 이동성, 편의성, 공간의 활용이라는 측면에서 노트북이 많이 사용되고 있고, 학교는 공용 PC실을 구축하여 다수의 클래스(Class)들이 사용하는 경우가 많아 데스크탑 PC를 주로 사용한다. 기업 입장에서 보면 기업 정보 유출의 위험에 노출되어 있고, 학교 입장에서 보면 다수의 사용자가 공동으로 사용함으로서 웜이나 바이러스에 노출되어 시스템을 사용할 수 없는 상황이 많이 발생한다. 이러한 문제점을 해결할 방안으로 대두되고 있는 기술이 데스크탑 가상화(Desktop Virtualization)이다. 본 논문에서는 현재의 PC 사용 환경과 데스크탑 가상화 환경에 대해 알아보고, 데스크탑 가상화기반 기술인 가상화 프로그램과 로컬 장치(Local Device)에 대해 분석한다. 이러한 분석을 토대로 데스크탑 가상화의 장단점을 파악하고 결론을 맺는다.

As we are examining corporate's and school computer usages of today, Desktop(Personal Computer) or Laptop(Portable Computer) is offered to each individuals. Laptop is widely used on company for the purpose of mobility, convenience and practical space usage and desktop is mainly used in school to share PC room by the number of classes. Companies are on the verge of security data exposure by the Portable Computer and School desktop is vulnerable to worm and virus by sharing PC and resulted out of order frequently. For those problems, we focus into uprising technology solution that is Desktop Virtualization. This paper will look into current PC use and Desktop Virtualization environments, analyze Virtualization software that is Desktop Virtualization base technology and Local Device. By the foundation of this analysis, we will understand pro and con of Desktop Virtualization and have a finishing conclusion.

13

특허지표가 선진국과 개발도상국의 기술수준에 미치는 영향 : 정보보안기술을 중심으로 KCI 등재

오종학, 나관식

한국창업학회 한국창업학회지 제13권 제3호 2018.06 pp.75-93

※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.

본 연구는 한국과 중국을 중심으로 하는 개발도상국과 선진 8개국(미국, 일본, 영국, 프랑스, 독일, 이탈리아, 네덜란드, 스웨덴) 등 10개국의 특허지표들을 수집하여 다중회귀분석을 통해 그 영향도를 실증분석 하였다. 결론적으로 개발도상국에서는 특허의 양적 지표에 해당하는 특허활동도와 특허집중도만 유의한 것으로 나타났으나, 선진국에서는 이들 양적 지표들 뿐만 아니라 질적인 지표(특허시장력과 특허영향력)도 유의한 것으로 나타났다. 따라서 우리나라와 같은 개발도상국에서는 관련 기술분야가 선진국 수준으로 발전하기 위해서는, 특허의 수에 영향을 받는 양적 지표뿐만 아니라 질적지표의 개선을 위해서 전략적으로 많은 노력을 기울여야할 것이다.

In this paper, four patent indices of developing countries (Korea and China) and developed countries (USA, Japan, UK, France, Germany, Italy, Netherlands and Sweden) were collected and analyzed through multiple regression analysis. In conclusion, only quantitative indicators of patents (patent activity and patent concentration) significantly affected technology levels in the developing countries. In the developed countries, however, not only these quantitative indicators but also qualitative indicators (patent market power and patent influence) were significant in influencing the technology level. Therefore, in developing countries such as Korea, in order to develop related technologies to the level of developed countries, strategic efforts should be made not only for quantitative indicators affected by the number of patents but also for improvement of qualitative indicators.

14

ISO/IEC JTC1/SC27의 국제표준소개(4) : 정보기술- 보안기술-메세지 복원형 디지탈서명 방식 [Information technology - Security techniques - Digital signature scheme giving message recovery]

이필중

[Kisti 연계] 한국정보보호학회 정보보호학회지 Vol.4 No.2 1994 pp.74-99

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

ISO와 IEC가JTC1 을 만들기 이전인 1984년 'Digital Signature'를 만들기위한 과제가 시작되었다, 그후 3개의 과제로 세분되고 그중 첫번째의 과제로 본 문서가 가장 먼저 국제표준이 되었다. 1989년에 제목이 지금과 같이 바뀌었고, 1990년 DIS를 거쳐 1991년에 IS가 되었다. 1996년에 재검토될 예정이다.

15

웹서비스 보안을 위한 XML 기반 정보 보호 기술 연구

박병철, 성백호, 차무흥, 신동일, 신동규

[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2003 pp.778-780

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

웹서비스는 최근 들어 e-business에서 가장 주목받고 있는 신기술이다. 웹서비스는 기존 웹 기반의 디스플레이에 그쳤던 단순정보 교환을 애플리케이션 차원에서 데이터를 통신할 수 있어 개발 가능성이 무한한 프레임 워크로 각광받고 있다. 그러나 보안에 취약성을 가지고 있어 웹서비스의 도입과 활성화가 되지 못하고 있는 실정이다. 따라서 본 논문에서는 웹서비스에서 통신에 있어 반드시 지켜져야 할 메시지 무결성, 기밀성, 부인 방지 등의 신뢰성 보장 기법이 어떻게 적용될 수 있는지를 살펴보고, XML 기반의 보안 기술 및 적용 분야 분석을 통해 웹서비스에서의 확장성 및 상호운용성을 보장하는 보안 취약성 해결책을 제시한다.

16

사이버전(Cyber Warfare)의 형태와 정보보호 기술

박호균

[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회지 Vol.11 No.4 2013 pp.41-44

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

17

정보보안 기술 스트레서의 완화- 기술적 지원과 개인 조직 적합성의 역할

황인호

[Kisti 연계] 한국전자통신학회 The Journal of the Korean institute of electronic communication sciences Vol.20 No.3 2025 pp.585-594

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사회적으로, 조직이 보유한 정보 자원에 대한 보호가 중요해지면서, 조직들은 정보보안 기술에 대한 투자를 강화하고 있다. 본 연구는 보안 기술의 도입이 역설적으로 조직원에게 스트레스 원인으로 작용할 수 있음을 고려하였으며, 기술 스트레서(과부하, 복잡성)의 부정적 영향을 완화하기 위한 조직 조건(기술적 지원)과 개인 조건(개인 조직 적합성)을 통합적으로 제시하였다. 보안 및 조직 행동 관련 선행연구에서 연구모델을 도출하였으며, 정보보안 정책과 기술을 운용하는 조직의 직원에게 설문을 통해 313건의 표본을 확보하였다. AMOS 22.0과 Process 3.1을 활용한 가설 검증 결과, 기술 과부하와 복잡성이 준수 의도를 감소시키는 관계에서, 조직의 기술적 지원과 조직원의 개인 조직 적합성이 조절된 조절 효과가 있음을 확인하였다. 연구 결과는 보안 기술로 인해 발생 가능한 스트레스 완화 조건을 제시함으로써, 조직의 보안 목표 달성을 위한 내부자 관리 전략을 수립 및 운영하는 데 도움을 준다.

As the protection of organizations' information resources becomes increasingly important, organizations are enhancing their investment in information security (IS) technology. This study posited that adopting IS technology could paradoxically serve as a source of stress for employees and integratively presented the technical support of the organization and the person-organization fit of employees to mitigate the negative effects of IS stressors, including overload and complexity. This study developed a research model based on previous studies on IS and organizational behavior, collecting 313 samples through a survey of employees in organizations implementing IS policies and technologies. The study, employing AMOS 22.0 and Process 3.1 for hypothesis testing, confirmed that technical support and personal-organizational fit exert a moderated moderation effect in the relationship where IS technological overload and complexity reduce IS compliance intention. These findings contribute to establishing and operating insider management strategies to achieve the organization's IS objectives by presenting conditions for alleviating stress.

18

정보보안기술 사용의 영향요인에 관한 실증적 연구

김상훈, 이갑수

[Kisti 연계] 한국전자거래학회 한국전자거래학회지 Vol.20 No.4 2015 pp.151-175

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

조직의 정보보안을 위해서는 세 가지 유형의 정보보안(기술적, 물리적 및 관리적 보안) 모두가 중요하며 병행 추진되어야 할 것이지만, 본 연구는 관리적 보안대책의 수립 및 추진의 효과성을 보다 높이기 위한 이론적 근거를 확보하는데 연구목표를 설정하였다. 즉, 기술적 및 물리적 보안대책이 철저하게 정비되고 추진된다고 하더라도 이를 준수하고 실행하는 주체는 결국 조직구성원들이므로 기술적 및 물리적 보안대책이 소기의 성과를 이루기 위해서는 이에 부응한 관리적 보안대책이 균형 있게 추진되는 것이 필수적이기 때문에 관리적 보안을 보다 효과적으로 수행할 수 있기 위한 이론적 근거를 확보하는 것은 매우 중요한 의미를 지닌다고 본다. 특히, 본 연구에서는 효과적인 관리적 보안대책의 수립 추진의 핵심과제라고 할 수 있는 조직구성원들의 정보보안기술 사용의도를 향상시키기 위한 방안 마련 시에 적용될 수 있는 이론적 모형을 개발 제시하고자 하였다. 이를 위해 정보보안기술 사용의도에 영향을 미치는 요인들을 주요 관련 이론 및 선행연구들에 대한 체계적 고찰을 통해 도출하고 이들 간의 인과적 관계를 논리적으로 추론함으로써 연구모형 및 가설을 도출하였다. 실증분석을 위해서는 국내 대기업들의 직원들을 대상으로 현장서베이를 통한 자료수집을 하였고 부분최소자승법(PLS: Partial Least Squares)기법에 의한 구조방정식 모형분석을 실시하였다. 본 연구의 유의한 결과는 이론적인 측면에서 관리적 정보보안 분야 연구의 외연을 확대하는데 기여할 수 있다고 보며, 실무적인 측면에서는 제반 조직들이 관리적 정보보안 방안 및 대책 수립을 함에 있어서 업무지침의 일부로 적용될 수 있을 것으로 예상된다.

Although three types of the information security measures (technical, physical and managerial ones) are all together critical to maintaining information security in the organizations and should be implemented at the same time, this study aims at providing theoretical basis of establishing and implementing effective managerial security measures. The rationale behind this research objective is that it is very important to effectively perform the managerial security measures to achieve the target performance level of the technical and the physical security measures because main agents of practicing the information security measures in the organizations are staff members even though the technical and the physical ones are well constructed and implemented. In particular, this study intends to develop and propose the theoretical model applicable to providing the way of improving organizational members' intention to use information security technologies since the very intention to use them is essential to effectively establishing and promoting managerial security measures. In order to achieve the objective of this study, the factors critical to influencing upon the intention to use information security technologies are derived through systematically reviewing related theories and previous studies, and then the research model and hypotheses are proposed by logically reasoning the casual relationship among the these factors. Also, the empirical analyses are performed by conducting the survey of the organization members of domestic large companies and analyzing the structural equation model by PLS (Partial Least Squares) method. The significant results of this study can contribute to expanding the research area of managerial information security and can be applied to suggesting the practical guidelines for effectively establishing and implementing the managerial security measures in various organizations.

19

정보통신 기술개발계획 추진과정 분석 : 정보보호 분야의 사례연구

한상영, 유영신

[Kisti 연계] 한국해양정보통신학회 한국해양정보통신학회 학술대회논문집 2002 pp.710-714

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

한정된 자원과 인력을 보다 효율적으로 사용하기 위하여 정부는 정보통신 각 분야의 기술개발계획을 수립하고 이에 기반한 기술개발 정책을 집행한다. 본 논문은 정보보호 분야의 사례분석을 통하여 정부의 정보보호 기술개발 계획 수립 과정을 분석하고, 이것이 정보보호 기술개발 정책의 효율적인 집행에 갖는 함의를 찾는다 정부가 수립하는 기술개발 계획은 국가가 나서서 반드시 수행하여야 하는 분야, 사업의 경쟁력을 높일 수 있는 분야에 집중하는 것이 기본이다. 이 기본이 기술개발 계획의 수립과정에서 어떻게 반영되고 있으며, 이것이 정책적으로 어떤 과정을 거쳐 반영되고 있는 가를 분석한다.

20

정보보안 정책, 기술, 그리고 커뮤니케이션 불확실성의 영향: 정보보안 역할 정체성의 역할

황인호

[Kisti 연계] 한국전자통신학회 The Journal of the Korean institute of electronic communication sciences Vol.19 No.1 2024 pp.241-248

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사회적으로, 조직이 보유한 정보 자원에 대한 엄격한 관리를 요구하고 있다. 조직들은 기술적으로 외부 정보 침입에 대처해야 할 뿐 아니라, 내부자에 의한 정보 노출 가능성까지 관리해야 하는 상황에 직면해 있다. 하지만, 조직이 도입한 정보보안 정책, 기술 등은 조직 내부의 보안 수준 달성에 도움을 주지만, 과도하거나 체계적이지 못한 보안 구조는 조직원의 불확실성을 높일 수 있다. 본 연구는 정보보안 관련 조직의 구조적인 불확실성 요인을 제시하고 행동에 미치는 영향을 제시한다. 즉, 정보보안 정책, 기술, 그리고 커뮤니케이션 불확실성이 구조적으로 존재할 수 있음을 밝힌다. 정보보안 환경 관련 선행연구를 통해 연구 모델과 가설을 제시하였으며, 구조방정식 모델링을 적용하여 가설을 검정하였다. 가설 검정 결과, 정보보안 정책, 기술, 그리고 커뮤니케이션 불확실성이 조직원의 역할 정체성과 준수 의도를 감소시켰다. 연구 결과는 조직 내 정보보안 관련 구조적인 불확실성 개선 조건을 제시하였기 때문에, 조직 내부의 정보보안 목표 달성을 위한 환경 전략 방향을 제언한다.

Socially, organizations are required to effectively manage their information resources, both in terms of acquiring information from external sources and safeguarding against potential breaches by insiders. While information security policies and technologies implemented by organizations contribute to achieving internal security, an overly complex or disorganized security structure can create uncertainty among employees. In this study, we identify factors of structural information security (IS)-related uncertainty within organizations and propose that they contribute to non-compliance. We develop a research model and hypotheses based on previous studies on the information security environment and test these hypotheses using structural equation modeling. Our findings indicate that uncertainties related to IS policy, technology, and communication decrease employees' IS role identity and their intention to comply with IS measures. By addressing these uncertainties, organizations can improve their IS environment and work towards achieving there IS goals.

 
1 2
페이지 저장