년 - 년
소프트웨어 보안 테스트에 관한 연구 : 방법론 중심으로 KCI 등재후보
제주대학교 융합과학기술사회연구소 융합과학기술사회연구 제3권 2호 2024.12 pp.21-26
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
본 논문은 소프트웨어 테스트와 보안 점검의 통합적 중요성을 다루고 있다. 우선 소프트웨어 테스트는 내부적 결함을 발견하고 품질을 보장하기 위한 필수 절차이며, 이를 통해 소프트웨어의 안정성과 신뢰성을 높일 수 있다 고 강조한다. 동시에 현대 소프트웨어 환경에서의 보안 위협은 기능적 결함 이상의 심각한 위험을 초래할 수 있 기에, 보안 점검 역시 소프트웨어 개발 생명주기(SDLC) 전체에 걸쳐 수행되어야 함을 주장한다. 특히 AI 기반 코 드 생성 도구가 널리 도입됨에 따라, 개발 프로세스에 환경에 변화가 생기있어 예측하기 어려운 결함이 나타날 가능성이 커졌다. 이에 따라 전통적 테스트 기법을 넘어, AI가 생성한 코드를 검증하고 보안 취약점을 사전에 식별ㆍ차단하는 접근이 요구된다. 이에 취약점 진단, 모의해킹, 시큐어코딩 점검 등 다양한 보안 점검 기법의 특징과 수행 시점을 구분하고, 이를 기존 테스트 프로세스에 병행ㆍ통합하여 적용하는 방법론적 방향을 제시한다. 이를 통해 통합된 품질 보증(Integrated Quality Assurance) 목적으로 소프트웨어 신뢰성과 보안성을 동시에 달성할 수 있는 방법론을 제안한다.
This paper emphasizes the importance of combining software testing and security checks. Software testing is a key process for finding and fixing internal defects, which improves the stability and reliability of the software. At the same time, today’s software faces security threats that can be more serious than typical functional errors, meaning security checks should happen throughout the entire Software Development Life Cycle (SDLC). AI-based code generation tools have become common, and they can lead to new and unpredictable defects in development. Therefore, it is necessary to move beyond traditional testing methods by verifying AI-generated code and detecting security risks early. This paper outlines various security approaches, including vulnerability assessments, penetration testing, and secure coding reviews, and explains how to integrate them into existing testing processes. By using this combined method—called Integrated Quality Assurance—software teams can achieve both reliability and security at the same time.
국가첨단전략기술 보호를 위한 보안시스템 소프트웨어 테스트 시나리오 평가체계 연구 KCI 등재
한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제15권 3호 2025.12 pp.201-225
※ 기관로그인 시 무료 이용이 가능합니다.
6,300원
국가첨단전략기술은 반도체, 이차전지, 방위산업, 첨단소재 등 국가 경쟁력과 직결되는 자산 으로, 기술 유출 위협이 심화됨에 따라 보안성 검증의 중요성이 높아지고 있다. 그러나 기존 대 응은 제도적 규제 중심에 머물러 실제 보안시스템 소프트웨어의 사전 검증 체계는 미흡하다. 본 연구는 이러한 한계를 극복하기 위해 보안시스템 소프트웨어 테스트 시나리오의 평가체계를 구 축하고, 델파이(Delphi)와 계층적분석기법(AHP)을 활용해 항목의 타당성과 상대적 중요도를 검 증하였다. 연구 결과, 상위 영역에서는 ‘시나리오 구조 타당성’과 ‘위협 기반 대응성’이 높은 중요 도를 보였으며, 세부 항목에서는 ‘시나리오 단계구성의 논리성’과 ‘위협 시나리오 구성의 현실성’ 이 핵심 요인으로 도출되었다. 이는 구조적 완성도와 위협 대응 현실성이 보안성 평가의 핵심 기 준임을 시사한다. 본 연구는 정량화된 평가체계를 제시함으로써 학술적 토대를 확장하고, 실무 적 활용 가능성과 정책적 기여 가능성을 동시에 확보한 점에서 실무적 의의가 있다.
National core strategic technologies, such as semiconductors, secondary batteries, defense systems, and advanced materials, face increasing risks of technology leakage, highlighting the need for reliable security verification. However, current measures remain regulationcentered and lack systematic pre-verification of protective software. This study proposes an evaluation framework for security system software test scenarios and validates its indicators using the Delphi method and Analytic Hierarchy Process (AHP). The results show that “Scenario Structural Validity” and “Threat-Response Effectiveness” are the most critical domains, while “Logical Structure of Scenario Phases” and “Realism of Threat Scenarios” emerged as key factors. These findings suggest that structural completeness and realistic threat modeling are essential criteria in security evaluations. By presenting a quantitative, weight-based framework, this study provides both academic contributions and practical implications for technology protection policy and practice.
동중앙아시아경상학회 동중앙아시아연구(구 한몽경상연구) 제22권 제3호 2011.12 pp.5-14
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
The objective of the household livelihood determination using PMT methodology is to use variables that can represent household income in situations where there is no data, methods and methodology to directly determine household income and evaluate household livelihood and on the outcome determine target group in need for social welfare assistances and create nationwide electronic database of the target groups The database created using this methodology can be used in policy development, determination of target groups of certain social assistances and services, implementation of appropriate policies of determination of form and amount of assistances and services
동중앙아시아경상학회 동중아시아경상학회 학술대회 한국-몽골 협력에 관한 이슈와 주변국 사례 활용 2011.07 pp.75-82
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
웹 서비스 보안 성능 평가 테스트 방법론 연구 KCI 등재후보
한국융합보안학회 융합보안논문지 제10권 제4호 2010.12 pp.31-37
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
IT에서 보안은 위험 및 위협으로부터 시스템을 보호하고, 피해를 방지하며 Risk를 최소화해야 한다. 이와 같은 맥락으로 정보보안 제품의 정보가 처리, 저장, 전달되는 과정에서 정보와 시스 템의 보안기준, 즉 기본적인 기밀성, 가용성, 무결성과 부차적인 명확성, 증명가능성, 감지, 경보 및 방어능력 등이 충분히 보장될 수 있도록 하여야 한다. 웹 서비스에서 보안은 가장 중요한 요 소이며, 웹 특성상 서비스를 위해 80번 포트 같은 통로를 열어놔야 하는 구조로서, 웹 어플리케 이션, 웹 소스 및 서버, 네트워크 모든 요소가 근본적인 취약점을 안고 있다. 이에 따라 이런 요 소를 통해 웹 프로그램의 설정오류나 개발 오류 및 웹 애플리케이션 자체의 취약점을 이용한 홈페이지 와 웹 서버 해킹을 방지하며, 효율성을 높이는 웹서비스 보안 BMT 수행 방법론을 제 시하고자 한다.
The risks and threats in IT security systems to protect, prevent damage and Risk should be minimized. Context of information security products such as information processing, storage, delivery, and in the process of information system security standards, That is the basic confidentiality, availability, integrity and secondary clarity, potential evidence, detection, warning and defense capabilities, to ensure sufficient and should be. Web services are the most important elements in the security, the web nature of port 80 for the service to keep the door open as a structure, Web applications, web sources and servers, networks, and to hold all the elements are fundamental weaknesses. Accordingly, these elements through a set of Web application development errors and set-up errors and vulnerabilities in Web applications using their own home pages and web servers to prevent hacking and to improve the efficiency of Web services is proposed methodology performs security BMT.
외주 개발 웹 어플리케이션 테스팅의 보안성 강화 방안 KCI 등재
한국융합보안학회 융합보안논문지 제15권 제4호 2015.06 pp.3-9
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
웹 서비스를 가능하게 하는 웹 어플리케이션은 내부 개발자가 보안 의식을 갖고 만든다면 일정 수준 이상의 안전성을 보여준다. 하지만 외주 개발의 경우, 품질의 우수성보다는 요구 사항을 충족하고 요청 받은 기능을 실행시키는데 주안점이 있기 때문에 안전성이 우선되지 못한다. 따라서, 본 논문에서는 소프트웨어에 대한 객관적이고도 독립적인 시각으로의 평가를 가능하게 해주는 소프트웨어 테스트 절차를 보안 중심으로 개선하였다. 제안된 모델은 웹 어플리케이션의 외주 개발 시에도 초기부터 보안을 고려할 수 있게 해주며, 특히 보안 인식이 부족한 상황에서 작성된 프로그램의수정 소요 발생으로 인한 개발 일정 지연 사태를 미연에 방지할 수 있는 효과가 있음을 확인하였다. 이러한 결과는 자원관리체계를 중심으로 웹 어플리케이션에 대한 소요가 증가하고 있는 국방 분야에서도 엄격한 테스트를 토대로 보안취약점을 지닌 채 서비스되는 것을 방지할 수 있기에 활용이 가능할 것으로 판단된다.
A web application that allows a web service created by a internal developer who has security awareness show certain level of security. However, in the case of development by outsourcing, it is inevitable to implement the development centered on requested function rather than the issue of security. Thus in this paper, we improve the software testing process focusing on security for exclusion the leakage of important information and using an unauthorized service that results from the use of the vulnerable web application. The proposed model is able to consider security in the initial stage of development even when outsourced web application, especially, It can prevent the development schedule delay caused by the occurrence of modification for program created by programer who has low security awareness. This result shows that this model can be applied to the national defense area for increasing demand web application centered resource management system to be able to prevent service of web application with security vulnerability based on high test.
4,000원
웹 보안 강화를 위한 생성형 AI 기반 취약점 분석 프레임워크 - Nmap 기반 하이브리드 테스트 KCI 등재
대한산업경영학회 산업융합연구(구 대한산업경영학회지) 제23권 제11호 2025.11 pp.53-60
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근 웹 애플리케이션의 복잡성 증가와 함께 새로운 보안 취약점이 지속적으로 발생하고 있으나, 기존 알려진 정적 분석 도구는 취약점(CVE) 데이터베이스에 의존적으로 제로데이 공격 및 복합적인 위협에 대응이 어려운 한계를 지니고 있 다. 따라서, 본 연구는 Nmap 기반 정적 분석과 생성형 AI를 결합한 하이브리드 웹 보안 프레임워크를 제안한다. 기본 정적 도구는 단계에서 알려진 취약점(CVE) 매핑을 수행한 후, AI 기반으로 동적 테스트 케이스(SQLi/XSS 페이로드 등)를 실시간 으로 스캐닝한다. 취약점 패턴 분석 결과, 기존 정적 분석 대비 40% 향상된 탐지율(F1-Score 0.91)과 AI의 문맥 이해 능력을 활용해 오탐지율을 25% 감소시켰다. 본 연구는 향후 오픈소스(Nmap)와 클라우드 기반 ChatGPT API의 연동을 통해 저비 용·고효율 보안 솔루션 개발을 위한 기초연구로서 의의가 있다.
The increasing complexity of modern web applications has led to the continuous emergence of new security vulnerabilities. However, existing static analysis tools rely heavily on vulnerability (CVE) databases, limiting their ability to effectively counter zero-day attacks and complex threats. Therefore, this study proposes a hybrid web security framework that combines Nmap-based static analysis with generative AI. The basic static tool performs known vulnerability (CVE) mapping in a step, and then AI-based dynamic test cases (SQLi/XSS payloads, etc.) are scanned in real-time. Analysis of vulnerability patterns showed a 40% improvement in detection rate (F1-Score 0.91) compared to existing static analysis, while leveraging AI's contextual understanding capability reduced false positive rates by 25%. This research holds significance as foundational work for developing low-cost, high-efficiency security solutions through future integration with open-source tools (Nmap) and cloud-based ChatGPT APIs.
A Study on The Information Gathering Method for Penetration Testing
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.5 No.5 2008.10 pp.411-418
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Information gathering is the initial stage of any information security audit, which many people tend to overlook. When performing any kind of test on an information system, information gathering and is essential and provides the testers with all possible information about the target to continue with the test. Information gathering methodology in penetration testing is given in this paper.
Implementation and Automatic Testing for Security Enhancement of Linux Based on Least Privilege SCOPUS
보안공학연구지원센터(IJSIA) International Journal of Security and Its Applications Vol.2 No.3 2008.07 pp.93-100
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
Nowadays, technologies of information security have been attached more and more importance to and it's a critical problem to take measures to ensure the reliability of related trustworthy software such as secure operating systems (SOSs). Thereafter, it's always necessary for such systems to be taken complete and rigorous security test and evaluation among development team and/or by third-party security certification organization. However, such software testing is usually time consuming, cost consuming and boresome and thus technologies of software testing automation have alluring application foreground in that field. In this paper, methods and technologies about how to test a SOS automatically are discussed in breadth and in depth at first. Then least privilege is studied and the corresponding modules of security enhancement are added to Linux based on Linux Kernel Modules (LKM). Finally, a prototype of automatic security testing as to such least privilege mechanism is implemented and the results are analyzed.
클라우드 서비스 사업자를 위한 보안 자가 측정 시스템(CssT v1.0) 개발 KCI 등재
보안공학연구지원센터(JSE) 보안공학연구논문지 Vol.10 No.6 2013.12 pp.621-630
※ 원문제공기관과의 협약기간이 종료되어 열람이 제한될 수 있습니다.
클라우드 컴퓨팅은 하드웨어, 소프트웨어 등 IT 자원을 필요한 만큼 빌려 쓰고 사용한 만큼만 요금을 지불하는 서비스로서 전 세계적으로 IT 시스템 도입 비용을 절감하고 신속한 IT 시스템 구축 및 제공 등의 장점으로 부각되고 있다. 이와 같이 국내의 클라우드 컴퓨팅 보급 초기에는 IT 자원 활용의 극대화와 비용절감의 측면에서 접근하였으나, 현재 국내 의 클라우드 시장은 클라우드 컴퓨팅에 대한 보안 문제로 인해 실제 도입이 미비한 실정이다. 본 논문에서는 클라우드 서비스 도입 및 이용에 대한 막연한 불안감을 해소하고, 국내의 클라우드 서비스 활성화를 위해 클라우드 서비스 사업자의 보안 수준을 제고하기 위한 “클라우드 서비스 보안 자가 측정 시스템(CssT v1.0)”을 제시하고 자 한다.
Cloud Computing is a technology that uses the internet and central remote servers to maintain data and applications. Cloud computing allows consumers and businesses to use applications without installation and access their personal files at any computer with internet access. This technology allows for much more efficient computing by centralizing data storage, processing and bandwidth. Initially, the domestic supply of cloud computing to maximize IT resource utilization and costs were approaching. However, the current domestic market for cloud due to security concerns about cloud computing is a real lack of adoption. In this paper, the use of cloud services to relieve anxiety, and improve the level of security in the cloud service providers(i.e., CSPs) for "The Cloud Service Security Self-Testing System"(CssT v1.0) is presented.
[Kisti 연계] 한국정보과학회 정보과학회지 Vol.30 No.2 2012 pp.9-21
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
패킷 필터링 보안 정책을 테스트하기 위한 테스트 베드 구축
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2006 pp.250-252
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
패킷 필터링은 잠재적으로 악의 있는 네트워크 패킷을 필터링하는 것이다. 패킷 필터링의 기능을 테스트하기 위해서 우리는 보안 시스템에 설정된 보안 정책이 의도한 대로 수행되는지 검증해야 한다. 그러나 기존에 이러한 기능을 테스트하기 위한 도구가 거의 없으며, 존재하는 도구는 테스트의 수행 시 테스트 케이스 선정과 테스트 결과의 판단에 있어 많은 사용자의 판단을 요구한다. 대부분의 보안 시스템 운영자는 새로운 보안 정책을 설립할 때 이를 테스트하는데 많은 부담감을 갖는다. 이에 본 논문에서는 사용자의 판단을 최소화 할 수 있는 새로운 테스트 베드를 제안하고 구현한다. 본 논문의 테스트 베드는 테스트 케이스와 테스트 오라클을 자동으로 생성한다. 그리고 생성된 테스트 오라클을 기반으로 테스트 결과를 사용자의 참여 없이 자동으로 판단한다.
보안취약점 테스트를 위한 IPv4/IPv6 혼재 네트워크 구축 방법
[Kisti 연계] 한국정보보호학회 한국정보보호학회 학술대회논문집 2006 pp.477-480
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
IPv6는 IPv4의 주소 부족을 해결하기 위해 1998년 IETF에서 표준화된 프로토콜이다. 현재 IPv4가 수축으로 되어 있는 인터넷을 동시에 IPv6로 전환하는 것은 불가능하므로 IPv4/IPv6 혼재네트워크를 거쳐 IPv6 순수 망으로 전환될 것이다. 본 논문에서는 혼재네트워크에서 IPv4 망과 IPv6 망간의 통신을 가능하게 해주는 IPv6 전환 메커니즘 중 터널링 방식에 대해 기술하고, 보안 취약성을 테스트하기 위해 동일한 보안 취약성에 대해 각각 IPv4 패킷, IPv6 패킷, 터널링된 패킷을 캡쳐할 수 있는 구축방안을 제안한다. 제안된 방식은 IPv4, IPv6, 터널링 패킷에 대한 분석이 가능하므로 IPv6 지원을 계획하는 침입탐지, 침입차단 시스템에 활용이 가능하다.
Terraform 기반 IaC 보안성 검증을 위한 확장형 테스트 프레임워크
[Kisti 연계] 한국정보처리학회 정보처리학회논문지 Vol.15 No.5 2026 pp.383-392
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
클라우드 환경에서 인프라의 구성 및 설정을 코드 형태로 관리하는 코드형 인프라(Infrastructure as Code, IaC) 기술은 DevSecOps 구현의 핵심 요소이지만, 잘못된 설정이 자동으로 배포될 위험이 존재한다. 본 연구는 Terraform 기반 IaC 보안 감사 도구의 플랫폼 간 탐지 일관성 한계를 분석하고, 이에 대응하기 위한 확장형 테스트 프레임워크를 제안한다. 실험 결과, 운용 환경이 상이한 Terraform 공급자(provider)에 대해 동일한 IaC 구성임에도 취약점 탐지 결과가 다르게 나타남을 확인하였다. 제안하는 프레임워크는 퍼블릭 클라우드, 쿠버네티스, 온프레미스 환경을 대상으로 공급자별 커스터마이징과 취약성 주입을 통해 tfsec 기반 보안 평가를 자동화한다. 이를 통해 IaC 정적분석의 한계를 실증적으로 제시하고, 다양한 클라우드 운용 환경에서의 보안 감사 일관성 확보 방안을 제시한다.
Infrastructure as Code (IaC) is a key component for implementing DevSecOps in cloud. However, IaC misconfigurations can be automatically propagated to production systems, introducing significant security risks. This study analyzes the inconsistency of vulnerability detection across platforms in Terraform-based IaC security auditing tools and proposes an extensible test framework to address this issue. Experimental results show that even with identical IaC configurations, vulnerability detection outcomes differ across Terraform providers with distinct operational environments. The proposed framework automates tfsec-based security evaluation by injecting predefined vulnerabilities and customizing configurations for public-cloud, Kubernetes, and on-premises environments.
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2010 pp.1024-1026
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
IT 기술의 발달로 자료의 대형화, 통신의 초고속 광역화가 이루어짐에 따라 우리 실생활과 비즈니스에 밀접하게 연관되어있을 뿐 만 아니라, 분산서비스거부(DDos)공격과 대규모 개인정보 유출사례 등은 데이터베이스(DB) 보안의 중요성은 한층 높아지고 있다. 본 논문에서는 대형 개인 정보 유출사고의 가능성을 안고 있는 기업에서 DB 암호화 구축 이후 발생할 수 있는 장애요소를 최소화 할 수 있도록 DB 보안 요구사항에 기반한 점검 항목을 도출하고 테스트 방안을 제시하였다.
[Kisti 연계] 한국정보처리학회 한국정보처리학회 학술대회논문집 2010 pp.1024-1026
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
IT 기술의 발달로 자료의 대형화, 통신의 초고속 광역화가 이루어짐에 따라 우리 실생활과 비즈니스에 밀접하게 연관되어있을 뿐 만 아니라, 분산서비스거부(DDos)공격과 대규모 개인정보 유출사례 등은 데이터베이스(DB) 보안의 중요성은 한층 높아지고 있다. 본 논문에서는 대형 개인 정보 유출사고의 가능성을 안고 있는 기업에서 DB 암호화 구축 이후 발생할 수 있는 장애요소를 최소화 할 수 있도록 DB 보안 요구사항에 기반한 점검 항목을 도출하고 테스트 방안을 제시하였다.
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2004 pp.259-261
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
정보의 불법적 유출 및 해킹 등과 같은 정보화 역기능을 해결하기 위해서 안전성과 신뢰성이 검증된 정보보호시스템을 사용하여 정보보호 수준 강화가 요구되고 있다. 우리나라를 비롯한 각 국에서는 안정성과 신뢰성 평가를 위한 ITSEC, CC 등과 같은 평가기준들이 개발되어 평가를 시행중이며 이러한 평가기준들에 현존하는 보안위협에 정보보호시스템이 잘 대처하고 있는지를 평가하는 침투시험 항복이 공통적으로 존재한다. 본 논문에서는 정보보호시스템 개발자 및 평가자의 이해를 돕기 위하여 침투시험을 이용한 평가방법론에 대하여 기술한다.
[Kisti 연계] 한국정보과학회 한국정보과학회 학술대회논문집 2004 pp.259-261
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
정보의 불법적 유출 및 해킹 등과 같은 정보화 역기능을 해결하기 위해서 안전성과 신뢰성이 검증된 정보보호시스템을 사용하여 정보보호 수준 강화가 요구되고 있다. 우리나라를 비롯한 각 국에서는 안정성과 신뢰성 평가를 위한 ITSEC, CC 등과 같은 평가기준들이 개발되어 평가를 시행중이며 이러한 평가기준들에 현존하는 보안위협에 정보보호시스템이 잘 대처하고 있는지를 평가하는 침투시험 항복이 공통적으로 존재한다. 본 논문에서는 정보보호시스템 개발자 및 평가자의 이해를 돕기 위하여 침투시험을 이용한 평가방법론에 대하여 기술한다.
사회 내 보안처분의 집행과정에서 거짓말탐지기 검사의 적정성 검토
[NRF 연계] 법조협회 법조 Vol.75 No.1 2026.02 pp.142-172
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
우리나라에서 성폭력범죄는 보안처분의 주요 대상이 되고 있다. 전자장치부착법 제정 당시부터 성폭력범죄자는 부착명령의 대상이었고, 성충동약물치료법도 성폭력범죄를 저지른 성도착증 환자가 성폭력범죄라는 동종범죄의 재범위험성이 있다고 인정되는 경우에 치료명령을 부과할 수 있다. 이런 개별 보안처분에 보호관찰이 필요적으로 병과되어 있다. 전자장치부착법과 성충동약물치료법은 준수사항위반죄를 규정하고 있다. 이러한 처분의 집행과정에서 거짓말탐지기 검사가 활용되고 있으며, 집행과 관련한 보호관찰관 외에 신속수사팀 보호관찰관에게는 특사경이 인정된다. 신속수사팀 보호관찰관은 부착명령 및 치료명령의 개별 준수사항을 포함하여 보호관찰법 준수사항 위반에 대해서도 수사를 할 수도 있다. 이러한 과정에서 지도·감독절차와 수사절차가 혼재될 가능성이 있다. 가석방 등 주 처분이 있는 개별 처분의 유형은 그 집행 중에 준수사항을 위반하는 경우에 주 처분이 취소되면 다시 원래의 시설 수용상태로 돌아간다. 그럼에도 부착명령과 치료명령은 준수사항을 위반하는 경우에 준수사항위반죄로 처벌하는 것과 별개로 주 처분 취소나 기간연장 및 준수사항 추가 또는 변경 등의 절차가 중복해서 이루어질 수 있다. 따라서 거짓말탐지기 검사가 지도·감독의 일환인지 수사절차의 일환인지 명확하게 구분되지 않아서 적법절차원칙 준수에 대한 관심이 요구된다. 개별 보안처분 집행절차에서 준수사항 위반에 대한 증거를 이미 확보하여 거짓말탐지기 검사가 무용한 준수사항이 있다. 또한 법령의 준수사항을 그대로 부과할 경우 예컨대, ‘나쁜 습관’, ‘선행을 하며’, ‘범죄를 저지를 염려가 있는 자’, ‘노력할 것’ 등의 추상적이고 불명확한 개념을 사용하고 있어서 거짓말탐지기 검사에서 허위진술 여부를 정확하게 측정할 수 있을지 의문이다. 거짓말탐지기 검사를 실시하는 계기가 준수사항을 위반하였거나 위반의 혐의가 있는 때라면 지도·감독을 빙자하여 증거확보를 위한 수사절차가 진행될 수 있다. 따라서 대상자의 진술거부권, 변호인의 조력을 받을 권리 등을 보장하기 위한 조치가 법령에 규정될 필요가 있다. 사회 내 보안처분의 집행에서 거짓말탐지기 검사는 적법절차원칙의 준수라는 대원칙에 입각하여 보다 신중한 접근이 요구된다는 결론을 도출하였다.
Sexual violence crimes are a major target of security measures in our country. Since the enactment of Act on Electronic Monitoring sexual violence offenders have been subject to attachment orders, and the Act on Pharmacologic Treatment of sex offenders sex impulse can also impose such orders on patients with sexual perversion who have committed sexual crimes and are deemed to have a recidivism risk of re-offending the same type of crime, such as sexual violence. Probation is necessarily imposed in conjunction with these individual security measures. Act on Electronic Monitoring and Act on Pharmacologic Treatment of sex offenders sex impulses stipulate the crime of violations of observance. It is said that polygraph testing is used in the process of enforcing these dispositions. In addition to the probation officer involved in the execution of the attachment order, the probation officer of the rapid investigation team is also recognized as a special judical police officer. The rapid investigation team probation officer may also investigate violations of the Act on Probation observance requirements, including observance requirements for attachment orders and drug treatment orders. In this process, there is a possibility that guidance & surveillance procedures and investigation procedures will be mixed. In the case of individual security measures such as parole, if observance requirements are violated during execution, the main disposition is revoked and the inmate returns to the original facility confinement status. Nevertheless, the attachment order and drug treatment order can have procedures for cancellation of the main disposition, extension of the period, and addition or modification of observance requirements which can take place in addition to the punishment for violating observance requirements. Therefore attention is required to comply with the principle of due process of law, as it is not clearly distinguished whether the polygraph testing is part of guidance & surveillance or part of the investigative procedure. In the procedure for executing individual security measures, there are observance requirements for which evidence of violation has already been obtained, rendering a polygraph testing ineffective. Furthermore, if observance requirements are imposed according to the wording of the law, using abstract and ambiguous concepts such as ‘bad habits’, ‘doing good deeds’, ‘those who may commit crimes’, and ‘make an effort’, it raises doubts about whether the polygraph testing can accurately measure the truthfulness of statements. If the occasion for conducting a polygraph testing is a violation of observance requirements, it is necessary to stipulate in the law measures to guarantee the right to refuse to testify and the right to receive assistance from an lawyer, taking into account that investigative procedures for securing evidence may be conducted under the guise of guidance & surveillance. Through above review we concluded that polygraph testing require a more cautious approach based on the fundamental principle of compliance with the principle of due process of law.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.