A Study on an Audit Model for the Defense Information System security using BS7799

BS7799(정보보안관리 표준)를 적용한 국방정보체계 보안감사모델에 관한 연구

  • 최장욱 (국방대학교 국방관리대학원) ;
  • 남길현 (국방대학교 국방관리대학원)
  • Published : 2001.07.01

Abstract

Information technology has been made remarkable progress and most of computer systems are connected with internet over the world. We have not only advantages to access them easy, but also disadvantages to misuse information, abuse, crack, and damage privacy. We should have safeguards to preserve confidentiality, integrity and availability for our information system. Even tough the security is very important for the defense information system, we should not over limit users availability. BS7799, a British standard, is an evaluation criteria for information security management. In this paper we propose an audit model to manage and audit information security using control items of BS7799, which could be useful to mange the defence information system security. We standardize audit items, and classify them by levels, and degrees by using appropriate audit techniques / methods / processes.

Keywords