• Title/Summary/Keyword: 비즈니스연속성 관리시스템

Search Result 3, Processing Time 0.017 seconds

A study on primary control area for information security management system (ISMS): focusing on the finance-related organizations (정보보호 관리체계를 위한 주요 통제영역 연구: 금융 관련 조직을 중심으로)

  • Kang, Youn-chul;Ahn, Jong-chang
    • Journal of Internet Computing and Services
    • /
    • v.19 no.6
    • /
    • pp.9-20
    • /
    • 2018
  • Financial service industry has introduced and operated management systems such as information security management system (ISMS), personal information security management system, business continuity management system to protect and maintain suitably customer's financial information and financial service. This study started that it's desirable financial industry takes consideration of ISMS and it can be different types among various organizations taking consideration of culture, practical work, and guideline of information security. The study derives primary control areas of ISMS through analyzing non-conformity trends and control factors according to certification audit for finance-related organizations introduced international ISMS of ISO27001 which is well known and commonly applicable irrespective of areas in financial service industry. Through case analyses for five finance-related organizations operating ISMS, this study analyzed improvement effects of ISMS. It has a meaning as an initial research though it was difficulty in acquiring data for empirical study because of rare organizations maintaining certification in financial sector. As a result, number of non-confirmity from the first audit to three years' elapse was decreased every year. Physical and environmental security, communication and operations management, and access control having the highest frequency of non-conformity each presented 23%, 19%, and 17%, which reached 59% in total and they are derived into primary control areas. ISMS can fulfill technical, managerial, physical security issues, which have not been treated importantly in financial industry. In addition, this study presented that ISMS can be an effective management system applicable for financial service industry.

A Study on the Establishment of Business Continuity Management Systems of the Organization During a Pandemic Outbreak (Focusing on the finance correspond case) (유행병 발병 시 조직의 비즈니스연속성 관리체계 구축에 관한 연구(금융회사 사례 중심으로))

  • Kim, Dae Jin;Yang, Seung Weon;Choi, Deok Jae;Kim, Gi Won;Jang, Hyun Min;Kim, Dong Heon;Eun, Min Gyun
    • Journal of Korean Society of Disaster and Security
    • /
    • v.9 no.2
    • /
    • pp.93-101
    • /
    • 2016
  • In recent years, epidemics have raged with a 6-7 years period such as SARS (2002), Swine Flu (2009), MERS (2015). When an epidemic arises, the first advice is the isolation of infected patients and disease areas. Because it appears after a certain incubation period, the peoples worked with Infected (infection cause) staff and the place are largely exposed to the epidemic Risk. If you have an epidemic in the workplace, even if you close it, the business plan should be ready to continue the safety and protection measures for employees and the organization's core business. In this study We present the corresponding measures to protect the safety of the employees and to continue the core business during a pandemic outbreak and the introduction of BCP mainly corresponding practices of financial companies.

A Study on Primary Control Area for Information Security Management System (ISMS): Focusing on the Domestic Three Industries (정보보호 관리체계를 위한 주요 통제영역에 대한 연구: 국내 3개 산업을 중심으로)

  • Kang, Youn-Chul;Ahn, Jong-Chang
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.22 no.4
    • /
    • pp.140-149
    • /
    • 2021
  • Most industries have introduced and operate an information security management system (ISMS) or a personal information security management system (PIMS) to suitably protect and maintain customer's information and company trade secrets. This study starts with the premise that it is desirable for every industry considering information security to maintain an ISMS. ISMS can be of different types among various organizations, taking into consideration culture, practical work procedures, and guidelines for information security. This study intends to derive primary control areas of an ISMS for each industry based on organizational size and audit type by analyzing non-conformity trends and control factors according to certification audits for organizations introduced for international ISMS under ISO27001. This study analyzed improvement effects of ISMS through case analyses. It is meaningful as exploratory research, although it was difficult to acquire data for empirical study because few organizations maintain certification in major industrial sectors. The requirements presented the highest frequency of non-conformity for each type from the 2013-initiated ISO27001; the years 2013 to 2020 were extracted as the primary control area. The study found that for primary control areas of ISMS for each of three industries, organizational size and audit type had differences.