Asia pacific journal of information systems
- Volume 8 Issue 2
- /
- Pages.105-119
- /
- 1998
- /
- 2288-5404(pISSN)
- /
- 2288-6818(eISSN)
A Case Study on the Information Security Management System for Major Korean Businessn Groups
국내주요그룹의 정보보안관리 체계에 관한 사례 연구
Abstract
As the first step to information security, the security policy and organizational control need to be established. The purpose of this study is to investigate the policy and management of information security of five major Korean business groups. The results of case study on five giant groups can be summarized as follows. There exists a basic policy for information security. But it is outdated and not realistic in the present. The security audit and education need to be upgraded. It is also necessary to use security tools actively. The security level is low in companies which do not have independent information security divisions. Therefore, it is desirable to build information security teams. The number of security personnel is not enough for the task although there exist an information security team in the company. It is important to check if the team has the ability of perform information security task. The interview with security managers reveals that the total security management should be integrated with physical and computer security. It is suggested that an Information Security Center play the major role for information security. The study on the information security management for industry level is expected to be performed in the future.
Keywords