A Study on Establishing Guidelines for Information Protection and Security for Educational Institutes

학내 정보보호지침 수립에 관한 연구

  • Published : 2008.03.31

Abstract

Because IT security guidelines for universities and colleges mostly focus on hardware aspects, the problems such as security incidents by a user's mistake and personal information leakage by hacking are serious in our higher educational institutes. In order to solve these information protection and security problems in the educational institutes, realizable and implementable information protection and security guidelines which will contribute to escalate information protection level should be established and at the same time, specific guidelines should be provided to make the guidelines efficient. In this paper, the information security problems and cases are categorized to develop information security guidelines for the higher educational institutes in terms of short, mid, and long term aspects and the solutions to the problems are sought. In addition, a serious of approaches to the information security are proposed such as the improvement measures for the employees of the institute to have desirable security-minded, security problem prevention and resolving methods, developing conflict coordination procedure and law and regulation system establishment for making the educational institutes be information-oriented.

Keywords

References

  1. 최우혁, '정보보호 관리체계 인증심사 기준', 정보통신부고시, 제 2002-22호, 2002
  2. WPISP, 'OECD Guidelines for the Security of Information Systems and Networks: TOWARDS A CULTURE OF SECURITY', (2002), p.116
  3. Ralph Spencer Poore, 'Generally Accepted System Security Principles', 1999
  4. NIST, Table of Contents for Special Publication 800-12 Chapter 2, 2004
  5. 인터넷침해사고 대응지원센터(KrCERT/CC), http://www.krcert.or.kr
  6. 국가사이버안전센터(National Cyber Security Center), http://www.ncsc.go.kr
  7. 국가보안기술연구소(National Security Research Institute), http://www.nsri.re.kr
  8. 한국정보보호진흥원(Korea Information Security Agency), http://www.kisa.or.kr
  9. 경찰청 사이버테러 대응 센터(Cyber Terror Response Center), http://www.ctrc.go.kr
  10. CERT(Computer Emergency Response Team), http://www.cert.org