• Title/Summary/Keyword: Industrial Security Management

Search Result 588, Processing Time 0.03 seconds

A Study on the Effect of Institutionalization of the Security Education : Survey of National R&D Projects (국가연구개발사업 보안교육 실태조사를 통한 교육제도화에 관한 연구 -정부출연연구기관을 중심으로-)

  • Cho, Moo-Kwoan;Kim, Seong-Cheol;Hwang, Jeong-Mi;Kim, Seung-Chul
    • The Journal of Korean Association of Computer Education
    • /
    • v.17 no.2
    • /
    • pp.21-29
    • /
    • 2014
  • In spite of the R&D level of Korea, the efforts to protect the R&D results from outflowing has not been raised up. We investigated the current status of security education and the level of researcher's awareness for research security in the government-financed institutes. Also, we attempted to find out the needs for institutionalization of the security education. We conducted a survey and in-depth interviews of all the security officers in the thirty-seven government-financed institutes. The results show that the awareness level of the researchers for R&D security is below adequate level, and that security education is necessary in order to increase the security awareness. Also, it is necessary to institutionalize the security education.

  • PDF

A Study on Developing Assessment indicators for Cyber Resilience (사이버 레질리언스 평가지표 개발에 관한 연구)

  • Kim, Sujin;Kim, Jungduk
    • Journal of Digital Convergence
    • /
    • v.15 no.8
    • /
    • pp.137-144
    • /
    • 2017
  • Recently, cyber resilience has emerged as an important concept, recognizing that there is no perfect security. However, domestic researches on cyber resilience are insufficient. In this study, the 22 indicators for cyber resilience assessment were initially developed by the literature survey and discussions with security experts. The developed indicators are reviewed using the Focus Group Interview method in terms of materiality and feasibility of the indicators. This study derived meaningful and useful indicators for the assessment of cyber resilience, and it is expected to be used as a foundation for the future cyber resilience studies. In order to generalize and apply the results of this study in practice, it is necessary to carry out quantitative researches in the future.

Design of a Policy-based Security Mechanism for the Secure Grid Applications (안전한 그리드 응용을 위한 정책기반의 보안 기능 설계)

  • Cho, Young-Bok;You, Mi-Kyung;Lee, Sang-Ho
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.12 no.2
    • /
    • pp.901-908
    • /
    • 2011
  • For the available grid environmental realization, the resource supply PC must have to provide an appropriate security function of their operation environments. SKY@HOME is a kind of the grid computing environments. If this has not supervised by administrator handling smoothly, it is inherently vulnerable state to the security level of the grid environments, because the resource supply PC is not update a security function without delay. It is also have the troublesome problems which have to install of an additional security program for support the appropriate security. This paper proposes an integration security model on the policy-based that provides an update each level according to the situation of the resource supply PC for improving its problems as a security aspect of the SKY@HOME. This model analyzes the security state of the resource supply PC respectively, and then the result is available to provide an appropriate security of the resource supply PC using an integration security model. The proposed model is not need additionally to buy and install the software, because it is provided the security management server oriented service. It is also able to set up the suit security function of a characteristic of the each resource supply PC. As a result, this paper clearly show the participation of resource supply PC improved about 20%.

A Study on security characteristics and vulnerabilities of BAS(Building Automation System) (BAS의 보안 특성 및 취약점에 관한 연구)

  • Choi, Yeon-Suk
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.18 no.4
    • /
    • pp.669-676
    • /
    • 2017
  • Recently, due to the importance of information security, security vulnerability analysis and various information protection technologies and security systems are being introduced as a countermeasure against cyber-attacks in new as well as existing buildings, and information security studies on high-rise buildings are also being conducted. However, security system introduction and research are generally performed from the viewpoint of general IT systems and security policies, so there is little consideration of the infrastructure of the building. In particular, the BAS or building infrastructure, is a closed system, unlike typical IT systems, but has unique structural features that accommodate open functions. Insufficient understanding of these system structures and functions when establishing a building security policy makes the information security policies for the BAS vulnerable and increases the likelihood that all of the components of the building will be exposed to malicious cyber-attacks via the BAS. In this paper, we propose an architecture reference model that integrates three different levels of BAS structure (from?) different vendors. The architectures derived from this study and the security characteristics and vulnerabilities at each level will contribute to the establishment of security policies that reflect the characteristics of the BAS and the improvement of the safety management of buildings.

Design on Research Security Management Systems by the Research Development Process (연구개발 수행과정에 따른 연구보안 관리체계 설계)

  • Na, Onechul;Chang, Hang-Bae
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2015.10a
    • /
    • pp.754-755
    • /
    • 2015
  • 최근 국내에 연구개발을 하는 과정에서 발생하는 보유(연구성과물)기술의 유출 가능성이 증가하고 있다. 이러한 유출사고를 대비하기 위해 지속적으로 보안투자를 하고 있고, 보안 관리체계를 마련하여 시행하고 있다. 하지만 실질적으로 도움이 되는 연구보안을 위해서는 연구개발 과정의 특정부분이 아닌, 전체적인 연구개발 흐름을 대상으로 유기적으로 연결되는 연구보안 관리체계를 설계할 필요가 있다. 이 논문은 먼저, 일반적인 연구개발 프로세스를 파악하고, 연구개발에 필요한 보안활동을 알아본다. 다음, 조사한 보안활동을 연구개발 프로세스 흐름에 맞게 배치하여, 전체적인 관점에서의 연구보안 관리체계를 설계하고자 한다.

The Trends of Domestic and Overseas Cyber Security Training (국내외 사이버보안 훈련 동향)

  • Lee, Daesung
    • Journal of the Korea Institute of Information and Communication Engineering
    • /
    • v.25 no.6
    • /
    • pp.857-860
    • /
    • 2021
  • The 21st century society has entered the fourth industrial society of machine to machine from the information society of human to machine. Accordingly, countries around the world are always operating efficient crisis management systems that can quickly respond to disasters or crises. As cyber attacks such as cyber warfare are actually progressing, countries around the world are conducting defense training in response to cyber attacks, and reflecting the results of simulation attacks in improving or building security systems. In this paper, we would like to consider the future cyber training development guide by comparing and analyzing the trends of cyber training in domestic and foreign countries.

A Case Study on the Cost-Effectiveness Analysis for the Feasibility Study of Public Project Related to Personal Information Protection (개인정보보호 관련 공공사업의 타당성 조사를 위한 비용효과분석 사례 연구)

  • Jo, Illhyung;Kim, Jin;Yoo, Jinho
    • Knowledge Management Research
    • /
    • v.20 no.3
    • /
    • pp.91-106
    • /
    • 2019
  • In the era of the 4th Industrial Revolution, the importance of information protection is increasing day by day with the advent of the 'hyper-connection society', and related government financial investment is also increasing. The source of the government's fiscal investment projects is taxpayers' money. Therefore, the government needs to evaluate the effectiveness and feasibility of the project by comparing the public benefits created by the financial investment projects with the costs required for it. At present, preliminary feasibility study system which evaluates the feasibility of government financial investment projects in Korea has been implemented since 1994, but most of them have been actively carried out only in some fields such as large SOC projects. In this study, we discuss the feasibility evaluation of public projects for the purpose of information security. we introduce the case study of the personal information protection program of Korean public institutions and propose a cost-effectiveness analysis method that can be applied to the feasibility study of the information protection field. Finally, we presented the feasibility study and criteria applicable in the field of information security.

Performance Analysis of a Composite Service Providing System in a Context-Aware Computing Environment (상황인지 컴퓨팅 환경에서 복합서비스를 제공하는 서비스시스템의 성능분석)

  • Nam, Jin-Gyu;Hur, Sun;Joo, Kuk-Sun;Shin, Dong-Min
    • Journal of Korean Institute of Industrial Engineers
    • /
    • v.35 no.1
    • /
    • pp.51-57
    • /
    • 2009
  • There are a variety of users and devices in a context-aware computing environment. In this environment, the service provided to a user may be the composition of diverse services rather than one independent service. Before user's devices provide the composite service to the user, they should perceive user's needs by gathering related information segments from other surrounding devices and/or sensors. We consider a context-aware computing environment providing composite and adapted service to users and propose an information processing model that characterizes the device where the collected data should be processed through services and/or applications. Based on this model, we provide an analytical tool to obtain some performance measures of the context-aware computing environment.

Study for confidence security of certification of management system and validity examination (경영시스템 인증의 신뢰성 확보 및 유효성 심사에 관한 연구 -ISO 9001 인증을 중심으로-)

  • Lee, Eun-Sook;Kang, Kyung-Sik
    • Journal of the Korea Safety Management & Science
    • /
    • v.11 no.2
    • /
    • pp.127-135
    • /
    • 2009
  • In today's society it is often required to state objectively conformity of products (including services) to specified requirements. Conformity assessment bodies (CABs). can objectively state such conformity. These CABs perform conformity assessment activities that include certification, inspection, testing and calibration. A system to accredit CABs conformity assessment services should provide confidence to the purchaser and regulator. Certification of management system is one of means of providing assurance that the organization has implemented a system for the management of the relevant aspects of its activities, in line its policy.

The Comparison and Analysis on Students' Awareness of National Security -Focus on the students of military science established college and those of military science non-established college- (대학생들의 안보의식에 대한 비교·분석 -군사학과 설치 대학과 미설치 대학 대학생들을 중심으로-)

  • Lee, Sung Choon
    • Journal of the Korea Academia-Industrial cooperation Society
    • /
    • v.15 no.7
    • /
    • pp.4246-4257
    • /
    • 2014
  • The aim of this study was to search for a security strategy and security education program by analyzing the security awareness of universities with and without Department of Military Science. The results of university student's security awareness revealed a normal level of recognition and differences according to region and gender. The recognition of stability of current Korean national security is normally low on average, which suggests that students feel anxiety towards national security. In addition, the North Korea provocation influence on national security has been recognized highly (score of 4.33 on average). The national security awareness of university students in the case of whether establishing a Dept. of Military Science or not showed a normal level, which revealed a score of 3.44, and differed according to region, gender and recruitment, and had a relationship with the recognition of Dept. of Military Science management. Therefore, the political consideration of security authorities is in strong demand to improve the security awareness of general university students, and have an influx of great human resources by advertising the educational contents, advantages and future career of Dept. of Military Science students.