• 제목/요약/키워드: management information system

검색결과 18,230건 처리시간 0.047초

보안성숙도 모델을 활용한 정보보호 관리수준 점검방법에 관한 연구 (A Study on the Method of Checking the Level of Information Security Management Using Security Maturity Model)

  • 이상규;김인석
    • 정보보호학회논문지
    • /
    • 제28권6호
    • /
    • pp.1585-1594
    • /
    • 2018
  • 데이터 주도 시대가 형성되면서 경제적 활용가치가 높은 정보의 수집과 분석, 생산과 유통에 관한 안전성 확보를 위한 정보보호 관리의 중요성이 날로 높아지고 있다. 이러한 환경에서 기업은 정보보호 관리체계(ISMS) 인증을 통해 정보보안에 대한 신뢰를 보장받고 있으나 관리체계를 구성하는 세부영역에 대한 수준 평가와 활용은 제한적이다. 이에 반해 보안 성숙도 모델은 기업의 정보보호 수준을 단계적으로 진단할 수 있고 시급히 개선해야 할 영역을 판단할 수 있음은 물론 기업의 특성과 수준에 맞는 목표 설정을 지원하는 도구가 된다. 본 논문에서는 성숙도 모델을 바탕으로 정보보호 분야에 특화되어 개발, 활용되고 있는 보안 성숙도 모델의 사례인 C2M2를 국내 ISMS인증과 비교, 분석하여 정보보호 관리 수준을 점검하기 위한 모형을 벤치마크 하고 ISMS인증의 정보보호대책 세부영역을 구성하는 점검항목 간 우선순위를 도출하여 단계적으로 정보보호 관리수준을 점검하고 구축을 지원할 수 있는 방법을 살펴본다.

ISO 27001의 ISMS 보안성숙도 측정 모델링에 관한 연구 (ISO 27004 정보보호관리 측정 및 척도 체계) (The ISO the research also the ISMS security maturity of 27001 regarding a measurement modeling (ISO 27004 information security management measurement and metric system))

  • 김태달
    • 한국컴퓨터정보학회논문지
    • /
    • 제12권6호
    • /
    • pp.153-160
    • /
    • 2007
  • 국내에서도 이제 정보시스템을 운영하고 있는 기업이나 기관들에서 체계적인 위험분석 및 보안관리에 대한 요구가 늘어나고 있다. 본 논문에서는 국제적인 정보보호관리시스템의 표준화 동향에 대해 조사, 분석하여 정보자산에 대해 통합적으로 위험을 관리 할 수 있는 정보보호관리시스템을 모델링하여 제안하였다. 제안시스템과 관련된 국제적인 표준에 대해 보안측정모델의 성숙도를 비교 분석한 결과, 개별 관리되던 각종 정보기술자원에 대한 보안관리를 전사차원에서 통합적으로 관리할 수 있게 되었고, ISO 27001, ISO 9000, ISO 14000인증지원 및 인증수준 유지를 자동화 관리하게 함으로서 인적, 물적 자원의 효율적 운영이 가능한 것을 보여주고 있다.

  • PDF

Integration of Strategic Issue Management and Knowledge Management in View of Strategic Information Process

  • 염지환
    • 한국디지털정책학회:학술대회논문집
    • /
    • 한국디지털정책학회 2004년도 춘계학술대회
    • /
    • pp.383-400
    • /
    • 2004
  • Knowledge management is an essential part for gaining competitive advantage. The knowledge management system deals with information gathering, process, and implementation for the organizational performance advantage. The study integrates knowledge management in view of an internal organizational information processing structure and external strategic issue management system. This means that the coordination between internal systematic process and external scanning mechanism is essential for organizational success.

  • PDF

형상관리 절차 및 정보시스템 개발환경 (Configuration Management Processes and Its Information Systems Development Environments)

  • 김선호;김태환;김철환;정석찬
    • 한국전자거래학회지
    • /
    • 제2권2호
    • /
    • pp.1-30
    • /
    • 1997
  • In this research, the concept of CM (configuration management) is introduced for proper applications to the life-cycle product data management. In addition, the activities for CM - CM management and planning, configuration identification, configuration control, configuration status accounting, and configuration verification and audit - are described in detail. For the management of distributed configuration data among governments, prime contractors, and subcontractors, development environments and functions for the configuration management information system (CMIS) are proposed.

  • PDF

Client/server 환경 하에서의 도면 및 부품 정보통합관리 시스템 개발

  • 신동일;김선호
    • 한국경영과학회:학술대회논문집
    • /
    • 대한산업공학회/한국경영과학회 1996년도 춘계공동학술대회논문집; 공군사관학교, 청주; 26-27 Apr. 1996
    • /
    • pp.341-345
    • /
    • 1996
  • We have developed the drawing and part information management system that could integrate drawing information with corresponding part information in design process. The modules developed include the drawing information management (DIM) and the part information management(PIM). DIM consist of processing drawing management, approved drawing management, disused drawing management, and drawing print management. PIM consist of new part management, option management, and part change management. Errors which may occur in the design process can be reduced by reference to part information directly. In addition, the number of parts can be reduced by minimizing the frequency of new parts generation through the systematic management.

  • PDF

정보시스템통제 및 감사가 컴퓨터범죄의 인지된 위험에 미치는 영향: 금융기관을 중심으로 (The Impact of Information System Control and Audit on the Perceived Risk of the Computer Crime in Case of Financial Institutions)

  • 한인구;윤종호
    • Asia pacific journal of information systems
    • /
    • 제5권1호
    • /
    • pp.112-128
    • /
    • 1995
  • The information system control includes organizational structure, control mechanism, and management tools which contribute to accomplish the goals of information system: asset safeguarding, data integrity, effectiveness, and efficiency. Information system audit is the process to evaluate whether the information system accomplishs the goals. Information system auditor examine the reliability of information system control and suggest recommendations to improve the information system control. Both information system control and information system audit activities contribute to prevent and detect the computer crime for the organization. This paper proposes a causal model of information system control/audit and the perceived risk of computer crime, and tests the model using a survey on 38 financial institutions in Korea. Statistical results show that information system control and audit significantly reduce the computer crime risk perceived by the user group. The general control has a stronger impact than the application control. In addition, it turns out that the greater the deviation between the importance and the actual level of information system control is, the higher the perceived risk of computer crime is.

  • PDF

싸움소를 위한 RFID 기반 정보 관리시스템의 구현 (Implementation of RFID-based Information Management System for Bullfights)

  • 조용현
    • 한국지능시스템학회논문지
    • /
    • 제18권6호
    • /
    • pp.768-774
    • /
    • 2008
  • 본 논문에서는 무선주파수 신호를 이용하여 자동으로 식별하는 전자태그를 포함하는 RFID 기술 기반 싸움소 정보 관리시스템을 구현하였다. 제안된 시스템은 싸움소의 효율적인 관리를 위한 이력정보 시스템과 훈련정보 시스템, 그리고 소 소유자나 관리자를 위한 인터넷 기반 실시간 정보제공을 위한 시스템으로 구성하였다. 구현을 위해서 먼저 RFID에 기반을 둔싸움소의 사육과 전적의 이력 및 훈련 정보들을 분석 검토하고, 이를 바탕으로 필드의 싸움소에 대한 정보를 효율적으로 관리할 수 있는 RFID 미들웨어 시스템, 관련정보를 통합 관리 및 제공할 수 있는 웹기반 관리시스템을 설계 구현하였다. 이력 관리시스템에서는 하나의 전자태그씩 순차적으로 인식되도록 하였으며, 훈련정보 관리시스템에서는 다수개의 전자태그들을 동시에 인식되도록 하였다.

A Beacon-Based Trust Management System for Enhancing User Centric Location Privacy in VANETs

  • Chen, Yi-Ming;Wei, Yu-Chih
    • Journal of Communications and Networks
    • /
    • 제15권2호
    • /
    • pp.153-163
    • /
    • 2013
  • In recent years, more and more researches have been focusing on trust management of vehicle ad-hoc networks (VANETs) for improving the safety of vehicles. However, in these researches, little attention has been paid to the location privacy due to the natural conflict between trust and anonymity, which is the basic protection of privacy. Although traffic safety remains the most crucial issue in VANETs, location privacy can be just as important for drivers, and neither can be ignored. In this paper, we propose a beacon-based trust management system, called BTM, that aims to thwart internal attackers from sending false messages in privacy-enhanced VANETs. To evaluate the reliability and performance of the proposed system, we conducted a set of simulations under alteration attacks, bogus message attacks, and message suppression attacks. The simulation results show that the proposed system is highly resilient to adversarial attacks, whether it is under a fixed silent period or random silent period location privacy-enhancement scheme.

Design and Implementation of Road Construction Risk Management System based on LPWA and Bluetooth Beacon

  • Lee, Seung-Soo;Kim, Yun-cheol;Jee, Sung-Hyun
    • 한국컴퓨터정보학회논문지
    • /
    • 제23권12호
    • /
    • pp.145-151
    • /
    • 2018
  • While commercialization of IoT technologies in the safety management sector is being promoted in terms of industrial safety of large indoor businesses, implementing a system for risk management of small outdoor work sites with frequent site movements is not actively implemented. In this paper, we propose an efficient dynamic workload balancing strategy which combined low-power, wide-bandwidth (LPWA) communication and low-power Bluetooth (BLE) communication technologies to support customized risk management alarm systems for each individual (driver/operator/manager). This study was designed to enable long-term low-power collection and transmission of traffic information in outdoor environment, as well as to implement an integrated real-time safety management system that notifies a whole field worker who does not carry a separate smart device in advance. Performance assessments of the system, including risk alerts to drivers and workers via Bluetooth communication, the speed at which critical text messages are received, and the operation of warning/lighting lamps are all well suited to field application.

선행연구자료 데이터베이스 구축을 통한 한의학 고혈압 정보 시스템 개발 (Implement Traditional Korean Medical Information System of Hypertension through Building Database of Advanced Research Articles)

  • 예상준;김창석;김철;김영은;장현철;김상균;김보영;송미영
    • 한국한의학연구원논문집
    • /
    • 제18권1호
    • /
    • pp.35-43
    • /
    • 2012
  • Objectives: Hypertension is the highest ratio among chronic disease in Korea, and the western medical information about hypertension is provided by many web sites. Advanced researches about hypertension have been conducted in Traditional Korean Medicine(TKM) for decades, but the research results are not arranged. So the results have not been utilized in following research nor contributed to the expansion of public knowledge. Methods : We did this study to improve this situation. In this study, we built database about advanced research articles related hypertension in TKM and implemented TKM information system of hypertension. Results : First, we benchmarked hypertension information systems and designed the TKM information system based on the benchmarking results and comments from TKM doctors. And it was composed of introduce, treatment, and etc. Second, we built prescription, herb, acumoxa, qigong, prevention/management, and pill database which is about 600 data extracted from papers and books. Third, we implemented JAVA/JSP based web information system which provides the database. And we created links for the each papers and books to use more easily. Conclusions : If we provide the research results about TKM hypertension diagnosis and combinational medication of western and oriental medicine, this information system will be more useful. And if we add internal and external project report about hypertension, it will be more worthy.