Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

美 NIST 보안성 자동평가프로토콜(SCAP)분석을 통한 공공기관의 정보보안관리실태 평가제도 개선방안 연구A Study on the Improvement of Information Security Management Condition Evaluation in Public Sector through the SCAP Analysis by NIST in U.S.

Other Titles
A Study on the Improvement of Information Security Management Condition Evaluation in Public Sector through the SCAP Analysis by NIST in U.S.
Authors
지윤석이용석윤덕중신용태
Issue Date
Aug-2019
Publisher
한국데이타베이스학회
Keywords
SCAP; NIST; Information Security Management Condition Evaluation(ISMCE); ISMS; .
Citation
Journal of Information Technology Applications & Management, v.26, no.4, pp.31 - 39
Journal Title
Journal of Information Technology Applications & Management
Volume
26
Number
4
Start Page
31
End Page
39
URI
http://scholarworks.bwise.kr/ssu/handle/2018.sw.ssu/35117
DOI
10.21219/jitam.2019.26.4.031
ISSN
1598-6284
Abstract
The 129 public institutions in Korea are subject to Information Security Management Condition Evaluation (ISMCE) as a part of the government management evaluation system by the Ministry of Economy and Finance. ISMCE is started in 2006 with the central government institutions, and applied to the all public institutions in 2009. This evaluation is annually conducted by the National Intelligence Service through the site visits, and the number of the evaluated institutions is increasing year by year. However, the process of ISMCE - identifying existing vulnerabilities in the information system - is conducted manually. To improve this inconvenience, this paper introduces the various evaluation system in the major countries, especially in the United States, and analyzes the Security Content Automation Protocol (SCAP) by NIST. SCAP is automation protocol for the system vulnerability management (in technical fields) and security policy compliance evaluation. Based on SCAP, this paper suggests an improvement plan for the ISMCE of Korea.
Files in This Item
There are no files associated with this item.
Appears in
Collections
College of Information Technology > School of Computer Science and Engineering > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Shin, Yong tae photo

Shin, Yong tae
College of Information Technology (School of Computer Science and Engineering)
Read more

Altmetrics

Total Views & Downloads

BROWSE