• 제목/요약/키워드: risk process

검색결과 2,909건 처리시간 0.204초

효과적인 위협관리를 위한 보안 위험도 평가기법 (Security Risk Evaluation Scheme for Effective Threat Management)

  • 강필용
    • 한국정보과학회논문지:시스템및이론
    • /
    • 제36권5호
    • /
    • pp.380-386
    • /
    • 2009
  • 중요 IT 자산에 대한 보안성 강화를 위해서는 관련 위협(또는 취약점)의 식별 및 이에 대한 보안 대비책의 적정성 분석이 선행되어야 한다. 이를 위해 본 논문에서는 자산 및 위협에 기반한 보안 위험도 평가기법을 제안한다. 제안한 기법은 식별된 자산 및 위협 관련 공격시도 탐지와 취약점 점검 등의 대응 범위 및 수준의 사전 점검과 정량적인 위험도 평가를 제공함으로써 기존 연구에 비해 효과적으로 위협관리 업무에 활용될 것으로 기대된다.

정보시스템통제 및 감사가 컴퓨터범죄의 인지된 위험에 미치는 영향: 금융기관을 중심으로 (The Impact of Information System Control and Audit on the Perceived Risk of the Computer Crime in Case of Financial Institutions)

  • 한인구;윤종호
    • Asia pacific journal of information systems
    • /
    • 제5권1호
    • /
    • pp.112-128
    • /
    • 1995
  • The information system control includes organizational structure, control mechanism, and management tools which contribute to accomplish the goals of information system: asset safeguarding, data integrity, effectiveness, and efficiency. Information system audit is the process to evaluate whether the information system accomplishs the goals. Information system auditor examine the reliability of information system control and suggest recommendations to improve the information system control. Both information system control and information system audit activities contribute to prevent and detect the computer crime for the organization. This paper proposes a causal model of information system control/audit and the perceived risk of computer crime, and tests the model using a survey on 38 financial institutions in Korea. Statistical results show that information system control and audit significantly reduce the computer crime risk perceived by the user group. The general control has a stronger impact than the application control. In addition, it turns out that the greater the deviation between the importance and the actual level of information system control is, the higher the perceived risk of computer crime is.

  • PDF

Enhancement of VECTOR Method by Adapting OCTAVE for Risk Analysis in Legacy System Migration

  • Hakemi, Aida;Jeong, Seung Ryul;Ghani, Imran;Sanaei, Mojtaba Ghanaatpisheh
    • KSII Transactions on Internet and Information Systems (TIIS)
    • /
    • 제8권6호
    • /
    • pp.2118-2138
    • /
    • 2014
  • Risks are involved in all phases of the software life cycle, and due to these risks, software can face various problems that can cause different negative outcomes and sometimes, in extreme cases, the failure of the software. Most of these risks lie in the legacy software migration process. These risks can create many problems, and in the worst case they can lead to the failure of the migration project. This paper explores different types of risk analysis methods such as CRAMM, CORAS, OCTAVE and VECTOR. After comparing these methods, the two suitable methods were chosen, namely, OCTAVE and VECTOR. Based on the use of these two methods, the project suggests an enhanced EOV method for risk analysis in the migration of legacy software.

Development of a Cost-benefit Model for the Management of Structural Risk on Oil Facilities in Mexico

  • Leon, David-De;Alfredo H-S. Ang
    • Computational Structural Engineering : An International Journal
    • /
    • 제2권1호
    • /
    • pp.19-23
    • /
    • 2002
  • A reliability-based cost-benefit model for the risk management of oil platforms in the formulation of optimal decisions based on life-cycle consideration is proposed. The model is based on structural risk assessments and the integration of social issues and economics into the management decision process. Structural risks result from the platform's exposure to the random environmental loading associated with the offshore site where it is located. Several alternative designs of a typical platform are proposed and assessed from the cost-effectiveness viewpoint. This assessment is performed through the generation of cost/benefit relationships that are used, later on, to select the optimal design.

  • PDF

Risk Priority and Allocation of Private Investment in Port Development

  • Seong, Yu-Chang;Youn, Myung-Ou;Keum, Jong-Soo;Kinzo, Inoue
    • 한국항해항만학회지
    • /
    • 제30권7호
    • /
    • pp.599-605
    • /
    • 2006
  • The Port Development has been achieved by the Government because it needs large scale of funds. However, since 1994, the Govenment has been implemeting private investments for constructing and operating the ports and so on. Although the Government had high expectation that it could expedite the expansion of the port facilities, there were many problems in view of construction, management, financial and social environment. This study figure out that most of the important reasons are the uncertainty of risk allocation between private investors and the Government, using with Analytic Hierarchy Process. It is expected that the results of this study will encourage more private investors to participate in port private investments in the future.

리스크관리에 의한 건설안전관리의 분석 및 발전방안 (Improvement Plan and Analysis of Construction Safety Management for Risk Management)

  • 정병화;김성득
    • 한국건축시공학회지
    • /
    • 제6권4호
    • /
    • pp.53-60
    • /
    • 2006
  • Quality control and safety represent increasingly important concerns for project managers. In the worst case, failures may cause personal injuries or fatalities. Accidents during the construction process can similarly result in personal injuries and large costs. We present the results of a study designed to identify the tools that are most widely used and those that are associated with successful project management in general, and with effective project risk management in particular. The study is based on a questionnaire administered to a sample of project managers from construction enterprises. The response data was analyzed in order to find which tools are more likely to be used in the those organizations that report better project management performance and in those that value the contribution of risk management processes.

An optimal continuous type investment policy for the surplus in a risk model

  • Choi, Seung Kyoung;Lee, Eui Yong
    • Communications for Statistical Applications and Methods
    • /
    • 제25권1호
    • /
    • pp.91-97
    • /
    • 2018
  • In this paper, we show that there exists an optimal investment policy for the surplus in a risk model, in which the surplus is continuously invested to other business at a constant rate a > 0, whenever the level of the surplus exceeds a given threshold V > 0. We assign, to the risk model, two costs, the penalty per unit time while the level of the surplus being under V > 0 and the opportunity cost per unit time by keeping a unit amount of the surplus. After calculating the long-run average cost per unit time, we show that there exists an optimal investment rate $a^*$>0 which minimizes the long-run average cost per unit time, when the claim amount follows an exponential distribution.

Risk-based optimum repair planning of corroded reinforced concrete structures

  • Nepal, Jaya;Chen, Hua-Peng
    • Structural Monitoring and Maintenance
    • /
    • 제2권2호
    • /
    • pp.133-143
    • /
    • 2015
  • Civil engineering infrastructure is aging and requires cost-effective maintenance strategies to enable infrastructure systems operate reliably and sustainably. This paper presents an approach for determining risk-cost balanced repair strategy of corrosion damaged reinforced concrete structures with consideration of uncertainty in structural resistance deterioration. On the basis of analytical models of cover concrete cracking evolution and bond strength degradation due to reinforcement corrosion, the effect of reinforcement corrosion on residual load carrying capacity of corroded reinforced concrete structures is investigated. A stochastic deterioration model based on gamma process is adopted to evaluate the probability of failure of structural bearing capacity over the lifetime. Optimal repair planning and maintenance strategies during the service life are determined by balancing the cost for maintenance and the risk of structural failure. The method proposed in this study is then demonstrated by numerical investigations for a concrete structure subjected to reinforcement corrosion. The obtained results show that the proposed method can provide a risk cost optimised repair schedule during the service life of corroded concrete structures.

설계안전성 검토 시행에 따른 국내 건설업 주체의 안전개선 연구 (A Study on safety improvement of Domestic Construction Industry subject to Design for Safety review)

  • 지경환;최병정
    • 대한안전경영과학회지
    • /
    • 제19권4호
    • /
    • pp.63-76
    • /
    • 2017
  • This thesis provides background information on DFS carried out by the government in an effort to reduce the accident rate, cases of DFS in other advanced countries to study their risk detection, risk assessment, risk control measures, and cases in which application of DFS during the designing phase succesfully led to reduction of the accident rate. Till now, the focus has been on incident responses after the occurance of accidents, it describes the importance of considering safety during the desining process through safety results and cases.

에어프라이어의 화재사례와 재현실험을 통한 화재위험성 분석 (Fire Risk Analysis through Airfryer's Fire Cases and Reproduction Experiments)

  • 이정일;조명식
    • 대한안전경영과학회지
    • /
    • 제22권2호
    • /
    • pp.39-46
    • /
    • 2020
  • This paper recognizes the risk of ignition of air fryer (machine that can cook fried dishes with hot air without oil) that is far exceeding the sales rate of microwave ovens, which is necessary to modern household kitchen, and identifies fire risk through the operation principle of the process of heat transfer, and the main structure of the machine. The fire test that we conducted is to observe the risk of ignition of the machine due to the damage to the safety system and the possibility of igniting oil paper along with food, to experiment with the possibility of ignition due to blockage of the exhaust due to obstacles, and accumulation of oil stains on the hot wire, and to present the method of fire control and devise countermeasures.