• Title/Summary/Keyword: Security Maturity

Search Result 56, Processing Time 0.026 seconds

Determinants of ASP Effectiveness in Small-Medium Enterprises (중소기업 ASP 효과의 결정요인에 관한 연구)

  • Mun, Yong-Eun
    • Journal of Digital Convergence
    • /
    • v.4 no.1
    • /
    • pp.93-109
    • /
    • 2006
  • Several studies have investigated the success of ASP from various perspectives. This study, thus, investigated factors affecting ASP effectiveness in various literature relevant ASP and outsourcing. By applying the basic ideas of the IS success model, this study proposes a research model of the factors affecting the success of ASP, in term of internal factors(Top Management Involvement, User Participation, Size of Organization, IS Maturity) and Reliability factors(Transaction Reliability, After-Sale Reliability, System Reliability, Security). The proposed model is expected to provide a guideline to researchers and practitioners extend their understanding of the success factors of the ASP effectiveness.

  • PDF

A Framework of Factors Affecting ASP Effectiveness (ASP 효과에 영향을 미치는 요인)

  • Moon Yong-Eun
    • The Journal of Information Systems
    • /
    • v.15 no.2
    • /
    • pp.227-245
    • /
    • 2006
  • Several studies have investigated the success of ASP(Application Service Provider) from various perspectives. This study, thus, investigated factors affecting ASP effectiveness in various literature relevant ASP and outsourcing. By applying the basic ideas of the IS success model, this study proposes a research model of the factors affecting the success of ASP, in term of internal factors(Top Management Involvement, User Participation, IS Maturity) and external factors(Transaction Reliability, Service Reliability, System Trust Security). The proposed model is expected to help both researchers and practitioners extend their understanding of the success factors of the ASP effectiveness.

  • PDF

Developing the Assessment Method for Information Security Levels (정보보호 수준평가 방법 개선에 관한 연구)

  • Oh, Nam-Seok;Han, Young-Soon;Eom, Chan-Wang;Oh, Kyeong-Seok;Lee, Bong-Gyou
    • The Journal of Society for e-Business Studies
    • /
    • v.16 no.2
    • /
    • pp.159-169
    • /
    • 2011
  • In order for agencies and companies at the IT service industry to check as well as to upgrade the current status of their information security programs, this paper suggests the assessment method for information security levels. The study developed 12 assessment fields and 54 assessment items derived from domestic and foreign cases including SP800-26, SP800-53, ISMS, and ISO27001. It categorized 54 assessment items into 5 levels for determining information security levels. Also, the study presents 7 strategies for performing their efficient evaluations. The proposed method and process in this paper can be useful guidelines for improving the national information security level.

Analyzing the Practice and Relationship of the onfiguration Management among International Standards (국제 표준간 형상관리 공정의 활동 및 관계 분석)

  • 황선명;김혜미;김태훈;노병규
    • Convergence Security Journal
    • /
    • v.3 no.1
    • /
    • pp.85-94
    • /
    • 2003
  • The Configuration management process is to establish and maintain the integrity of all the work products of a process or project. This paper discusses the similarities and differences between ISO/IEC 12207 and ISO/IEC 15846. The most widely used models for software process assesment, ISO/IEC 15504, CMM and CMMI can rate maturity of processes. We analyze and compare the practices for measuring Configuration process and propose metric for quantitative measure.

  • PDF

A Study on the Information Disclosure of Financial services Using Content Analsysis (금융상품정보제공 실태파악을 위한 금융상품팜플렛 내용분석)

  • 허은영;최현자
    • Journal of the Korean Home Economics Association
    • /
    • v.38 no.11
    • /
    • pp.63-75
    • /
    • 2000
  • To identify the actual situation of financial information disclosure, a content analysis was performed on pamphlets of a time deposit and a new reserve trust offered by banks and other financial institutes. Although consumers required information on interest rate, tax favor, loan service, protection of brink depositors and bank security to select a financial service account, informations offered on pamphlets are not sufficient. Therefore concrete way of information offer system shoed be developed. In offering interest rate, interest rate after tax deduction or payment at maturity should be also mentioned. Information on tax favor, protection of bank depositors and bank security should be contained in pamphlets as well. Use of easy terms and notes are recommended for developing pamphlets for financial products.

  • PDF

Developing the Stage Evaluation Model for e-Business Company using Analytic Hierarchy Process (분석적 계층기법을 활용한 e-Business 기업의 초기투자단계 및 성장단계별 평가모형의 개발)

  • Choi, Hye-Jin;Han, In-Goo;Oh, Kyong-Joo
    • Asia pacific journal of information systems
    • /
    • v.15 no.1
    • /
    • pp.45-61
    • /
    • 2005
  • This study develops the evaluation model for e-Business company using analytic hierarchy process. As the first step of this study, we derived the appraisal standards based on the previous literature and the knowledge of experts from venture capitalists, security companies, credit evaluation companies, and consulting firms. In order to validate the evaluating factors in the models, this study was supported by analysts of top ranked venture capitalists in Korea. Through their assistance, this study can determine necessary evaluating factors that refined and deepened the models. Four expert groups, such as venture capitalists, credit analysts, analysts of security company and e-Business consultants, provide their knowledge for the determination of the weights of evaluating factors in the hierarchical model through the questionnaires and interviews. The results show that the weights of the evaluating factors differed by the maturity of e-Business company.

The ISO the research also the ISMS security maturity of 27001 regarding a measurement modeling (ISO 27004 information security management measurement and metric system) (ISO 27001의 ISMS 보안성숙도 측정 모델링에 관한 연구 (ISO 27004 정보보호관리 측정 및 척도 체계))

  • Kim, Tai-Dal
    • Journal of the Korea Society of Computer and Information
    • /
    • v.12 no.6
    • /
    • pp.153-160
    • /
    • 2007
  • Recently, the demand against the system risk analysis and security management from the enterprises or the agencies which operate a information system is increasing even from domestic. The international against the standardization trend of information protection management system it investigates from the dissertation which it sees. It analyzed and against information property information protection management system integrated it will be able to manage a danger modeling it did it proposed. Having analyzed as well as compared the matureness of security-measurement models in regard to the global standard of proposal system, the administrative presentation for various IT technology resources. which have been managed singly so far, is now well applied under the united control of the company itself, and enabled the automated management of authentication support and renewal for ISO 27001, ISO 9000, ISO 14000, resulting in much advanced operation for both material and human resources.

  • PDF

Influence Factors and the Introducing Outcomes over IT Outsourcing in the Government Offices (공공기관의 정보시스템 아웃소싱에 미치는 영향 요인과 도입 성과)

  • Jun, Je-Man;Yi, Seon-Gyu
    • The Journal of the Korea Contents Association
    • /
    • v.13 no.3
    • /
    • pp.339-351
    • /
    • 2013
  • In this research, we analyzed the influence factors and introducing outcomes empirically. The influencing factors over IT Outsourcing set up organizational factors(maturity of information system, the support of CEO), dealing factors(asset speciality, uncertainty, degree of using of information system), and risk factors(risk of safety/security. cost increase, loss of autonomy). The result of this study are as follows. In the organizational factors, degree of a maturity of the information system and the support of CEO were analyzed as the variables affecting the introducing outcomes positively. In the dealing factors, however, the degree of using information system was only analyzed as the variables affecting the introducing outcomes positively, while the speciality of asset and the uncertainty factors were analyzed as the variables not affecting the introducing outcomes. In the risk factors, the risk of safety/security and the increase of cost were only analyzed as the variables affecting the introducing outcomes positively, therefore loss of autonomy, was not analyzed as the affecting variables.

The Process of Occupational Socialization of Special Guard Firstly Appointed (초임 특수경비원의 직업사회화 과정 분석)

  • Park, Ok-Cheol;Kim, Tae-Hwan
    • Journal of the Society of Disaster Information
    • /
    • v.7 no.4
    • /
    • pp.316-327
    • /
    • 2011
  • The purposes of this study are to investigate various experience factors that special guards firstly appointed calculate during the occupational socialization and suggest the preliminary data which is necessary to the establishment of educational service strategy of preliminary special guard and security guard. So, in-depth interviewing and ethnographic study were conducted for 4 special guards firstly appointed. As the result, the occupational socialization process of special guards firstly appointed are quickening period, preparatory period, adaptation period and conflict/maturity period. The first, quickening period is a decision of family background, exercise experience and university entrance. The second, preparatory period is certificates and mentor of department vision, university curriculum and occupational preparation. The third, adaptation period is occupational specialty, occupational professionalism, occupational satisfaction, motivation and company colleagues. The forth, conflict/maturity period is job stress, turnover, conflict in company, efforts for self-development and prospect of job. Therefore, this study will be able to be applied as a guide for special guard's performance improvement and provide educational preliminary data for following-up studies.

How to Cope with Ransomware in the Healthcare Industry (의료산업에서의 랜섬웨어 대응 방법)

  • Jeon, In-seok;Kim, Dong-won;Han, Keun-hee
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.28 no.1
    • /
    • pp.155-165
    • /
    • 2018
  • As medical healthcare industry is growing up rapidly these days, providing various new healthcare service is considered carefully. Health information is considered to be more important than financial information; therefore, protecting health information becomes a very significant task. Ransomware is now targeting industry groups that have high information value. Especially, ransomware has grown in various ways since entering maturity in 2017. Healthcare industry is highly vulnerable to ransomeware since most healthcare organizations are configured in closed network with lack of malware protection. Only meeting the security criteria is not the solution. In the case of a successful attack, restoration process must be prepared to minimize damages as soon as possible. Ransomware is growing rapidly and becoming more complex that protection must be improved much faster. Based on ISO 27799 and 27002 standard, we extract and present security measures against advanced ransomware to maintain and manage healthcare system more effectively.