년 - 년
신정보화 환경에서 중소기업 기술유출에 대한 인식과 관리 실태에 관한 연구 KCI 등재
한국디지털정책학회 디지털융복합연구 제11권 제11호 2013.11 pp.305-312
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
이 연구의 목적은 신정보화환경에서의 중소기업의 기술유출에 대한 보안인식 및 보안관리 실태를 측정하고, 대기업과 중소기업간의 수준비교분석을 통해 기술유출 방지대책을 위한 정책의 기초자료를 제시하고자 한다. 분석결 과 보안인식 및 보안관리실태 모두 중소기업은 대기업에 비해 열악한 것으로 나타났으며, 정보화환경의 급격한 발달 에 따른 부문별 관리가 필요한 상황인 것으로 보인다. 현재 중소기업의 신정보화환경 구축은 도입기에 있으므로, 구 축과 동시에 보안시스템을 함께 갖출 수 있는 지원이 필요하며, 동시에 중소기업 자체적 대응이 가능하도록 신정보 화환경에 맞는 보안시스템이 필요하다. 중소기업의 경우 급변하는 정보화환경의 변화에 따른 기술보호 역량을 갖추 기에는 한계가 있음으로 정부의 체계적인 보안관리 지원이 요구된다.
This research suggests the security countermeasures for solving technology outflow of small-medium companies in New IT Environment through level comparison of security cognition and security management between small-medium companies and major big companies. According to analysis results, it is poor for small-medium companies’ level of security cognition and security management compared with major big companies. Small-medium companies need to manage technology outflow to major big companies' level in New IT Environment. Small-medium companies has started to build New IT Environment recently and it must build the appropriate security system for small-medium companies at the same time. Small-medium company has more problem with budget and proffessionals to maintain the security of technology outflow. Therefore government has to support systematic management for the security of technology outflow to Small-medium companies
초불확실성 시대 일본의 게임체인저 전략 : 아베 독트린, 안보 넥서스, 가치 네트워크 KCI 등재
서울대학교 일본연구소 일본비평 제28호 2023.02 pp.268-300
※ 기관로그인 시 무료 이용이 가능합니다.
7,500원
본 연구는 국제질서가 불안정해지고 있는 상황 하에서 일본의 국가 안보 전략을 게임체인저(Game Changer) 개념을 접목하여 분석한다. 위협인식, 대외적 환경변화, 전략적 수단, 행위자로서의 게임체 인저 등 분야별 다양한 게임체인저들을 통해 일본의 국가전략을 분석하고 그 특징과 변화 양상에 대 해 논의한다. 초불확실성 시대, 국내외 정세가 급변하면서 일본은 ‘새로운 시대에 걸맞은 일본’을 창 조해 나가야 한다고 인식하고 적극적인 정책을 추진해 오고 있다. 전후 일본이라는 기존 질서를 변화 시키고자 했던 게임체인저 아베 신조와 아베 독트린에 대해 살펴보고, 일본 기시다 내각의 주요 정책 과 전략의 핵심 내용을 파악한다. 코로나 위기 극복과 미중 경쟁, 러시아의 우크라이나 침략과 같이 예측하기 어려운 변화에 대응하는 일본의 전략을 살펴보고, 경제, 기술, 사회가 가치와 연계하여 나타 나는 다층적인 국가안보 전략이 형성되는 가운데, 일본이 국제질서의 새로운 게임체인저가 되기 위해 어떠한 전략들을 구상하고 추진하고 있는지 확인할 수 있다.
This study analyzes Japan’s national security strategy by combining the concept of a game changer with a situation involving unstable international order. I discuss characteristics and changes in Japan’s national security strategy, considering aspects such as threat recognition, external environment change, strategic means, and the game changer as an actor. As the situations at home and abroad have changed rapidly in the era of hyper-uncertainty, Japan’s government has been pursuing proactive policies, recognizing that it should create a new and strong Japan. This paper explains game-changer Abe Shinzo and the Abe Doctrine that intended to change the existing order of post-war Japan, then identifies the core contents of Japan’s national strategy. This paper will help promote an understanding of Japan’s strategy to respond to unpredictable changes, such as the COVID-19 pandemic, U.S.–China competition, and Russia’s invasion of Ukraine, including an analysis of Japan’s strategy to emerge as a new game changer in international society.
BLOSOM : Blockchain Technology for Security of Medical Records
[NRF 연계] 한국통신학회 ICT Express Vol.8 No.1 2022.03 pp.56-60
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
Today, the world of information security is witnessing frequent attacks on electronic medical records by the naive and professional hackers, therefore security of the patient’s Electronic Medical Record (EMR) in Hospital Management System is of paramount importance. In the current research work Blockchain containers running on multiple ports are proposed to be used for holding patient’s medical records. To perform this task effectively, a Blockchain framework named as “Medichain” was developed from scratch with all the basic functionalities of a Blockchain to secure patient’s data. Each block of the Blockchain would contain a list of records of patient details as part of its data. Users would be provided with an option of uploading the file containing the list of records as a JSON file, in a decisive, distributed and decentralized network. The proposed Blockchain Algorithm consisting of cryptographic hash of the records, proof of work and a Merkle tree formulation were simulated in Python and the results have been positive and encouraging.
[Kisti 연계] 한국항공운항학회 한국항공운항학회지 Vol.31 No.3 2023 pp.172-177
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
The main purpose of the research was to review the global trends of airport's smart security technologies. Moreover, using the case studies of airport using smart security, this paper tried to propose the implication how the findings through the case studies may be important for airport policy and will impact the future research of airport operation. It is expected in the future the aviation security technology with biometric information evolves from single identification to multiple identification technology which has combined application of iris, vein and others. Facing post COVID-19 era, the number of passengers traveling through airports continues increase dramatically and the risks as well, the role of AI becomes even more crucial. With AI based automated security robotics airport operators could effectively handle the growing passenger and cargo volume and address the associated issues Smart CCTV analysis with A.I. and IoT applying solutions could also provide significant support for airport security.
Study on Improving Endpoint Security Technology KCI 등재
한국융합보안학회 융합보안논문지 제18권 제3호 2018.09 pp.19-25
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
엔드포인트 보안은 네트워크에 연결된 여러 개별 장치를 철저하게 보호함으로써 네트워크 보안을 보장하는 방법입니다. 본 연구에서는 엔드포인트 보안의 다양한 상용제품의 기능과 특․장점을 살펴본다. 그리고 클라우드, 모바일, 인공지능, 그리고 사물인터넷 기반의 초연결시대를 대비하여 날로 지능화되고 고도화되는 보안위협에 대응하기 위한 엔드포인트 보안의 중요성 을 강조하고, 그 개선방안으로서 선제적인 보안 정책 구현, 실시간 탐지 및 필터링, 탐지 및 수정 등의 정보보안의 생명주기의 개선방안을 제시한다.
Endpoint security is a method of ensuring network security by thoroughly protecting multiple individual devices connected to the network. In this study, we survey the functions and features of various commercial products of endpoint security. Also we emphasizes the importance of endpoint security to respond to the increasingly intelligent and sophisticated security threats against the cloud, mobile, artificial intelligence, and IoT based sur-connection era. and as a way to improve endpoint security, we suggest the ways to improve the life cycle of information security such as preemptive security policy implementation, real-time detection and filtering, detection and modification.
Technology Trends and Policies for IoT Security
ASCONS IJEMR VOLUME 4 Number 1 2020.03 pp.1-6
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
We are already living in the Internet of Things. The Internet of Things (IoT) refers to a networked state where things or humans can interact closely through embedded communication systems. As IoT technology is introduced into the industrial production sector, it is possible to visually check the production process and supply chain flow of factories and increase efficiency through integrated management that transcends the physical boundaries of factories and companies. Furthermore, IoT technology is also used for other areas, such as smart-factory, health-care, and vehicles, so the importance of the security is also receiving its attention as well. The network technology including IoT is getting more advanced, but the research for the security is incomplete. So, in this research, we have explored to the concept and the element of the IoT technology, and some attacking factors to the IoT security. Furthermore, we will look at some security technology and other supporting policies to suggest some solutions for the direction for the currently improving IoT security.
NFC Technology - bringing ease and security in our everyday lives
한국컴퓨터통신연구회 OSIA Standards & Technology Review Journal 제24권 제2호 2011.09 pp.28-37
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
How Facial Recognition Technology Impacts Resident Security KCI 등재
한국콘텐츠산업학회 콘텐츠와산업 제6권 제4호 2024.11 pp.23-28
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Through a survey of 229 users of Facial Recognition Technology(FRT) in Chongqing, China, this study examines residents' attitudes toward FRT and the changing status of their Sense of Security after using FRT. Rapid technological advances have brought about the convenience of social life, but they have also generated hidden concerns about violating personal privacy and increasing social inequality. This study found that knowledge of Facial Recognition Technology, Environmental Risks, and Technology Risks all reduce people's Sense of Security, while Legal Governance has a positive effect on residents' Sense of Security. The study suggests that while advancing the development of Facial Recognition Technology, it should strengthen legislation regulating the application of the technology, cautiously promote the development of FRT applications, and improve the path of remedies for FRT infringement, among other suggestions.
Anti-Drone Jamming Technology for Protecting Privacy and Physical Security
ASCONS IJASC Volume 2 Number 1 2020.03 pp.7-11
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Background/Objectives: Drones were originally developed for military use, and as their technology evolves, they can be said to be the new industrial sector of the 4th Industrial Revolution, which has unlimited possibilities. Methods/Statistical analysis: The first was a hot air balloon, which was actually used in the Battle of Austria in 1849 and subsequently as an important combat weapon in World Wars I and II. On the top of that, drone is unmanned, remote-controlled flight systems. Findings: It's widely used as an entertainment tool, but actually it's not only used for military purposes such as reconnaissance and surveillance, but also for transportation like Amazon Prime Air. Drones are vulnerable to hacking like GPS spoofing, control extortion, and jamming because they're wirelessly controlled. There are these various anti-drones technologies and there are grave risks to drone security. Improvements/Applications: Therefore, it is necessary to protect privacy from unwanted drone to use anti-drones technology.
Research on a New Approach to Enhance IoT Security Using Blockchain Technology KCI 등재
한국디지털정책학회 디지털융복합연구 제17권 제12호 2019.12 pp.235-241
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
IoT의 구조는 크게 디바이스, 게이트웨이, 서버로 나눌 수 있다. 먼저 디바이스로부터 게이트웨이는 데이터를 수집하고, 게이트웨이는 HTTP 프로토콜, 웹소켓 프로토콜, MQTT 프로토콜을 통해 서버로 데이터를 송신한다. 그 후 처리서버에서 데이터를 가공, 분석, 변환, 하며 데이터베이스는 이러한 데이터들을 저장하고 활용을 쉽게 한다. 이러 한 IoT 서비스는 기본적으로 서버가 있는 중앙 집중형 구조라는 특징 때문에 전체 플랫폼에 대한 공격이 중앙 서버로 만 집중되어 분산형 구조보다 해킹 성공 확률이 높다. 이를 해결하기 위한 하나의 방안으로 블록체인을 결합한 IoT가 개발되고 있다. 따라서, 제안하는 연구는 블록체인은 분산형 구조로 소규모 데이터들이 담긴 블록들이 체인 형식으로 연결되어 각 노드들이 서로 데이터를 합의, 검증하는 단계를 거쳐 신뢰성을 높이고 데이터 위변조 확률이 낮추는 방안 을 제안한다.
The structure of the IoT can be divided into devices, gateways, and servers. First, the gateway collects data from the device, and the gateway sends data to the server through HTTP protocol, Websocket protocol, and MQTT protocol. The processing server then processes, analyzes, and transforms the data, and the database makes it easy to store and use this data. These IoT services are basically centralized structures with servers, so attacks on the entire platform are concentrated only on the central server, which makes hacking more successful than distributed structures. One way to solve this problem is to develop IoT that combines blockchain. Therefore, the proposed research suggests that the blockchain is a distributed structure, in which blocks containing small data are connected in a chain form, so that each node agrees and verifies the data with each other, thereby increasing reliability and lowering the probability of data forgery.
Efficient Security Method Using Mobile Virtualization Technology And Trustzone of ARM KCI 등재
한국디지털정책학회 디지털융복합연구 제12권 제10호 2014.10 pp.299-308
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
최근, 스마트폰의 사용자 수는 스마트폰 성능 향상 및 다양한 서비스 제공으로 인해 매우 빠르게 증가하고 있다. 스마트폰 사용자들은 클라우드 서비스, 게임, 뱅킹 서비스, 모바일 서비스 등의 다양한 서비스를 사용한다. 오늘날의 모바일 보안 솔루션은 악성코드를 검출하거나 모바일 장치를 관리하는 수준에 그치고 있다. 이에 인증서, 법인 문서, 개인의 신용 카드 번호와 같은 보안에 민감한 정보에 대해 서비스 해킹 및 누설을 방지하는 기술이 필요하다. 모바일 보안 기술은 피해가 발생한 사례가 있었던 만큼 최근에 관심이 증가하고 있다. 이러한 문제를 해결하기 위해서 모바일 가상화, ARM Trustzone, Globalplatform과 같은 다양한 모바일 장치의 보안 기술이 연구되었다. 따라서 본 논문에서는 정보 유출 및 해킹을 방지하기 위한 인증, 보안 정책 및 액세스 제어, 암호/키 관리, 세이프 스토리지 등의 모바일 가상화 기술과 ARM의 Trustzone의 효율적인 방법을 제안한다.
Today, a number of users using smartphone is very rapidly increasing by development of smartphone performance and providing various services. Also, they are using it for enjoying various services(cloud service, game, banking service, mobile office, etc.). today's mobile security solution is simply to detect malicious code or stay on the level of mobile device management. In particular, the services which use sensitive information, such as certificate, corporation document, personal credit card number, need the technology which are prevented from hacking and leaking it. Recently, interest of these mobile security problems are increasing, as the damage cases been occurred. To solve the problem, there is various security research such as mobile virtualization, ARM trustzone, GlobalPlatform for mobile device. Therefore, in this paper, I suggested efficient method that uses the mobile virtualization techniques of certification, security policy and access control, password/key management, safe storage, etc. and Trustzone of ARM for preventing information leakage and hacking.
Autonomous Multi Drone Based Border Security Using Image Processing With 5G Technology
한국AI디지털융합학회(구 한국디지털융합학회) IJICTDC Vol 5 No 2 2020.12 pp.28-32
※ 기관로그인 시 무료 이용이 가능합니다.
4,000원
Today, there is a developing requirement for observation so as to keep up the dignity at a spot and guarantee the wellbeing and security of its kin. An airborne observation framework will be advantageous in such a manner. This paper depicts how an ethereal reconnaissance framework can be assembled utilizing an unmanned flying vehicle or an automaton. We start by depicting the highlights of our ethereal observation framework and afterward talk about a portion of the advances that we have utilized in building it. From that point onward, we notice how we have consolidated those innovations into an automaton and have made them cooperate amicably so as to accomplish our goal. This goal will be achieved with the help of cloud services and cellular service using 5G technology. It tends to be utilized in peacekeeping exercises and furthermore constant observing of a spot whenever of the day. The point is to give quick and productive reconnaissance at a moderate rate with the goal that it tends to be utilized broadly at the private, institutional and administrative levels.
[Kisti 연계] 한국항행학회 한국항행학회논문지 Vol.29 No.4 2025 pp.412-422
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 해상 사이버 사고 유형을 분석하고 선박 사이버 공격의 주를 이루는 엔드포인트 공격에 대한 대응 방안으로 선박용 엔드포인트 탐지 및 대응 기술을 제안하였다. EDR (endpoint detection and response)의 주요 기능인 탐지, 대응, 조사, 치료의 4가지 주요 기능을 기반으로 악성 행위 탐지를 위한 탐지 엔진과 이에 따른 유형별 대응을 탐지 정책으로 정의하고 이를 기반으로 선박에 탑재된 컴퓨터 기반 시스템의 사이버 위협에 대한 상태, 주요 경고 및 위협 정보를 모니터링하고 자동 대응이 가능하도록 선박용 엔드포인트 탐지 및 대응 기술을 개발하였다. 또한, 선박의 운영 환경에 맞추어 선박에 설치된 안티바이러스 솔루션과 상호 운영을 위해 바이러스 검사 시간, 시스템 자원 사용량을 비교하여 두 솔루션 간의 영향도 및 충돌, 간섭이 일어나지 않아 상호 운영이 가능함을 검증하였다.
In this paper, we analyzed the types of maritime cyber accidents and proposed endpoint detection and response technology for ships as a countermeasure against endpoint attacks, which are the main types of ship cyber attacks. Based on the main functions of EDR, which are detection, response, investigation, and treatment, we defined a detection engine for malicious behavior detection and a type-specific detection policy based on this, and developed endpoint detection and response technology for ships to monitor the status, major warnings, and threat information of cyber threats of computer-based systems installed on ships and enable automatic response. In addition, we compared the virus scan time and system resource usage to ensure interoperability with the antivirus solution installed on the ship according to the operating environment of the ship, and verified that the two solutions can interoperate without conflict or interference.
[Kisti 연계] 한국정보처리학회 정보처리학회논문지 Vol.7 No.s8 2000 pp.2597-2607
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
ATM은 고속통신 네트워크를 구현하기 위하여 요구에 따라 대역폭의 확장을 통한 망 자원의 효율성과 융통성을 제공한다. ATM은 서로 다른 서비스 품질을 필요로 하는 음성, 비디오, 이미지 및 데이터를 포함하는 다양한 응용을 지원한다. ATM Forum 보안 그룹은 ATM 네트워크에 대한 보안 서비스를 정의한 보안 규격을 발표하였다. 본 논문에서는 ATM 네트워크 보안 기술에 대한 일반적인 요구 사항과 ATM 네트워크에서 보안이 취약성을 분석하고, ATM Forum을 중심으로한 ATM 보안 모델을 소개하고, 초고속통신망(ATM-WAN)환경에 적용할 수 있는 ATM 네트워크 접속 모델 및 서비스 이용자 유형별 사용자 데이터 보호 모델을 소개하고 시뮬레이터를 이용하여 암호 알고리즘에 따른 데이터 전달 특성을 분석한다.
사이버전(Cyber Warfare)의 형태와 정보보호 기술
[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회지 Vol.11 No.4 2013 pp.41-44
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
새로운 신뢰 망 운영을 위한 가상화 및 보안 기술에 관한 연구
[Kisti 연계] 한국디지털콘텐츠학회 디지털콘텐츠학회 논문지 Vol.16 No.1 2015 pp.1-12
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
본 논문에서는 새로운 신뢰 망 운용에 가상화 기술을 적용하기 위하여 기존 가상화 기술 연구동향 및 문제점을 분석하고, 가장 적합한 가상화 기술을 제시하고자 한다. 가상화 기술을 통하여 자원의 활용률을 높이고 관리비용을 절감할 수 있는 장점이 있다. 한편 보안 측면에서는 가상화를 통한 보안의 장점도 있는 반면에, 가상화의 도입으로 인한 새로운 취약성이 발생하여 이 문제에 대한 분석 및 대책이 필요하다. 따라서 가상화 시스템의 보안 위협 요소들을 도출하고, 가상화 보안 정책에 대하여 분석하고 살펴본다.
In this paper, we analyze the research trend and problems of the existing virtualization technology and present the most applicable virtualization technology in order to apply the technology to the operation of novel reliable networks. By using the virtualization technology, there is advantage in that the utilization of resource becomes higher and maintenance cost goes down. While, from the security perspective, there exist advantage in using the virtualization, it also introduces new vulnerabilities due to the adoption. Thus it is necessary to analyze the problem and establish the strategy to solve it. Therefore we derive threat elements to the virtualized system, analyze and describe the virtualization security policy.
IOT(Internet of Things) 보안 기술 동향
[Kisti 연계] 한국콘텐츠학회 한국콘텐츠학회지 Vol.13 No.1 2015 pp.31-35
※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.
산업보안 기술보호활동이 보안인식과 보안성과에 미치는 영향 : 해외진출기업(베트남)을 중심으로 KCI 등재
한국산업안보학회(구 한국산업보안연구학회) 한국산업보안연구 제11권 제1호 통권 제20호 2021.04 pp.193-216
※ 기관로그인 시 무료 이용이 가능합니다.
6,100원
국내 중소기업에 대한 기술보호도 여전히 중요하지만 해외진출기업의 기술보호시스템은 열악 한 실정이다. 기술보호 관련 전문인력과 지원제도가 미흡한 해외진출기업은 손쉽게 기술탈취의 표적으로 일삼아지고 있다. 해외진출기업의 경쟁력을 강화하기 위해서는 보유기술 및 경영정보 에 대한 보호활동이 무엇보다 필요하며 현지기업에 다양한 기술보호서비스와 보안인력을 제공 할 필요가 있다. 이에 본 연구는 베트남의 해외진출기업을 중심으로 기술유출을 예방하고 보안 인식 및 보안성과를 제고하기 위한 방안을 제시하고자 하였다. 베트남 현지 기업의 대표자 및 관 리자들을 대상으로 기술보호활동 실태수준을 조사하고 기술보호역량점수와 보안인식 및 보안성 과를 측정함으로써 기술보호활동(보안정책, 자산분류, 관리보안, 물리보안, 기술보안)이 보안인 식과 보안성과에 어떠한 영향을 미치는 가를 분석하고자 하였다. 연구결과, 자산분류와 관리보 안은 보안성과에 정(+)의 영향을 미치는 것으로 나타났으며 보안정책과 관리보안, 기술보안은 보안인식에 정(+)의 영향을 미치는 것으로 나타났다. 보안인식은 보안성과에 정(+)의 영향을 미 치는 것으로 나타났으며 기술보호활동과 보안성과의 관계에서 매개하는 것으로 나타났다. 마지 막으로 보안담당자의 유무와 법률인지에 따라 기술보호활동과 보안인식, 보안성과에 차이가 있 는 것으로 나타났다. 따라서 베트남 현지 상황에 맞는 지역맞춤형 기술보호정책과 기술보호교육, 보안인력, 지원서비스를 제공하는 등의 보안인프라를 새롭게 구축하는 등의 노력과 정책이 마련 되어야 한다.
Technology protection for domestic SMEs(Small-Medium sized Enterprises) is also important, but the technology protection system of SMEs entering overseas is inferior. In the situation of overseas companies that do not have professional manpower and support system related to technology protection, overseas companies are easily targeting technology leakage. In order to reinforce the competitiveness of overseas companies, protection activities for possessed technologies and information are most important, and for this purpose, it is necessary to provide various technology protection information and security personnel to local companies. This study aims to present a plan to prevent technology leakage and improve security awareness and security performance based on the reality of SMEs that have entered Vietnam. This study was to investigate the actual level of technology protection activities for local business managers in Vietnam, measure the technology protection competency score, security awareness and security performance, and analyze how technology protection activities impact security awareness and security performance. As a result of the study, asset classification and management security had a positive (+) effect on security performance, and security policy, management security, and technical security had a positive (+) effect on security awareness. Security awareness was found to have a positive (+) effect on security performance. It was found that security awareness is mediated in the relationship between technology protection activities and security performance. Finally, it was found that there are differences in technology protection activities, security awareness, and security performance according to the presence or absence of a security officer and whether it is legal-know. Therefore, it is necessary to newly build a security infrastructure such as providing regionally tailored technology protection policies, technology protection education, security personnel, and support services suitable for the local situation in Vietnam.
업무-정보보안 기술 적합성이 정보보안 기술 스트레서 완화에 미치는 영향 KCI 등재
한국경영컨설팅학회 경영컨설팅연구 제21권 제3호 통권 제70호 2021.08 pp.31-43
※ 기관로그인 시 무료 이용이 가능합니다.
4,500원
조직의 정보 관리 중요성이 증가하면서, 정보보안 정책 및 기술에 대한 투자가 높아지고 있다. 더불어, 조직은 도입한 정보보안 정책 및 기술 을 구성원의 업무에 적용하는 것을 요구하고 있다. 하지만, 엄격하고 높은 수준의 정보보안 기술은 조직원의 스트레스를 유발하여 정보보안 행 동을 회피할 수 있다. 본 연구의 목적은 정보보안 준수 의도에 부정적 영향을 미치는 정보보안 기술 스트레서를 완화 방안을 제시하고 확인하는 것이다. 세부적으로, 정보보안 기술 스트레서가 개인의 내적 동기(가치 일치)와 정보보안 준수 의도에 미치는 부정적 영향을 업무-정보보안 기술 적합성이 조절하는 것을 확인한다. 본 연구는 정보보안 정책 및 기술을 도입한 조직에 근무하는 조직원들을 대상으로 설문을 하였으며, 확보된 표본을 활용하여 구조방정식 모 델링을 실시하여, 가설 검증을 하였다. 연구 결과, 정보보안 기술 스트레서가 정보보안 가치 일치를 부분 매개하여 정보보안 준수 의도를 감소시 키는 것을 확인하였으며, 업무-정보보안 기술 적합성이 정보보안 기술 스트레서와 가치 일치, 그리고 준수 의도 간의 부정적 영향 관계를 조절하 는 것을 확인하였다. 본 연구는 조직 내부의 정보보안 수준 달성을 위해 도입한 기술의 활용에 있어 발생 가능한 조직원의 정보보안 기술 관련 스 트레스 완화 방법을 제시하고, 내부 준수 수준 향상을 위한 방향을 제시한 측면에서 시사점을 가진다.
As the importance of organizational information management increases, organizations are increasing their investment in information security. Also, the organization requires its employees to apply the policies and technologies. However, strict information security technology induces stress on the employees, thereby avoiding information security behavior. The purpose of this study is to propose amethod tomitigate the techno-stress of information security that negatively affects the information security compliance intention. The subjects of this study are employees of the organization who have adopted information security policies and technologies, and hypotheses were verified through structural equation modeling using samples obtained through questionnaires. As a result of the study, it is confirmed that techno-stress has a negative effect on compliance intention by partially mediating value congruence, and it is confirmed that technical support increases compliance intention. And, the study confirmed that task-technology fit mediates the relationship between techno-stress and value congruence. The study presents implications in terms of suggesting directions for improving the level of internal information security through stressmitigation of employees.
안보기술 거버넌스의 국가간 비교분석 : 공식문헌 기반 기술범주 정규화 KCI 등재
한국보안관리학회(구 한국경호경비학회) 시큐리티 연구 제86호 2026.03 pp.97-126
※ 기관로그인 시 무료 이용이 가능합니다.
7,000원
국가안보의 위협이 군사⋅외교 영역을 넘어 디지털⋅공급망⋅물리보안이 융합된 복합 영역으로 확장됨에 따라, ‘무엇을 보호할 것인가’의 기술안보를 넘어 ‘무엇으로 안보를 지 킬 것인가’인 안보기술에 대한 거버넌스 정립이 시급해졌다. 본 연구는 안보기술(Security Technology)을 정책 분석의 대상으로 개념화하고, 공식 문헌 기반의 기술군을 도출하고 거 버넌스 분석틀(GAF)을 적용하여 미국⋅영국⋅EU⋅이스라엘과 한국의 운영 구조를 비교 분석하였다. 연구 결과, 비교대상 국가들은 안보기술을 단순한 산업 육성이 아닌 국가안보 임무와 결합해 관리하는 경향이 관찰되었으며, 특히 영국은 침해적 역량과 관련한 권한 행사를 법⋅코드로 규정하여 승인 요건과 감독 장치를 수렴시키는 결절점을 제도화하고 있음을 확인하였다. 반면 한국은 사이버 보안 분야를 제외하면 안보기술 전반을 포괄하는 컨트롤타워와 전주기 관리체계가 공식 문헌상 단일한 사슬로 수렴⋅가시화되지 않아, 수 행가능성(authorized capability)의 제도적 축적이 제한되는 한계가 드러났다. 본 연구는 이 러한 공백 해결을 위해 정책 과제를 ‘역량의 부재’가 아닌 ‘거버넌스 사슬의 불명확성’으로 재정의하고, 임무 기반 정렬 및 승인⋅감독 체계의 제도화 등 전주기 관리 설계 원칙을 제안하였다. 이러한 논의는 안보기술의 기술적 효용성과 민주적 통제 가능성을 동시에 확 보하는 이론적 분석 관점을 제공하며, 특히 기술안보에 편중된 기존 정책 담론을 안보기술 로 확장시켰다는 점에서 정책적 시사점이 크다.
As national security threats expand beyond military and diplomatic arenas into a converged space of digital risks, supply chains, and physical security, there is an urgent need for governance of security technology, not only “what to protect” (technology security) but also “what to protect security with.” This study conceptualizes security technology as a policy object, derives technology families from official documents, and applies the Governance Analytical Framework (GAF) to compare the governance structures of the United States, the United Kingdom, the European Union, Israel, and Korea. The findings show that some jurisdictions -most notably the UK- treat security technologies as mission-critical capabilities and maintain clear legal and normative nodal points to authorize and oversee intrusive capabilities. By contrast, beyond the cyber domain, Korea’s control-tower functions and lifecycle management remain fragmented, limiting the institutional accumulation of authorized capability. To resolve this gap, this study redefines the policy task not as a “lack of capability” but as an “ambiguity in the governance chain”. Accordingly, it proposes design principles for life-cycle management, including mission-based alignment and the institutionalization of approval and oversight systems. This discussion provides a theoretical analysis perspective for simultaneously ensuring the technical utility and democratic controllability of security technology. Furthermore, it offers significant policy implications by expanding the existing policy discourse, which has been biased toward technology security, into the realm of security technology.
0개의 논문이 장바구니에 담겼습니다.
선택하신 파일을 압축중입니다.
잠시만 기다려 주십시오.