중소기업 정보보호관리 모델의 개발: 실증 연구
Developing Information Security Management Model for SMEs: An Empirical Study
Asia Pacific Journal of Information Systems
약어 : APJIS
2005, vol.15, no.1, pp. 115-133 (19 pages)
발행기관 : 한국경영정보학회
연구분야 : 사회과학 > 경영학
1연세대학교
2연세대학교
3

초록
This study is to develop an information security management model (ISMM) for small and medium sized enterprises (SMEs). Based on extensive literature review, a five-pillar twelve-component reference ISMM is developed. The five pillars of SME's information security are: centralized decision making, ease of management, flexibility, agility and expandability. Twelve components are: scope & organization, security policy, resource assessment, risk assessment, implementation planning, control development, awareness training, monitoring, change management, auditing, maintenance and accident management. Subsequent survey designed and administered to expose experts' perception on the importance of these twelve components revealed that five out of tweleve components require relatively immediate attention than others, especially in SME's context. These five components are: scope and organization, resource assessment, auditing, change management, and incident management. Other seven components are policy, risk assessment, implementation planning, control development, awareness training, monitoring, and maintenance. It seems that resource limitation of SMEs directs their attention to ISMM activities that may not require a lot of resources. On the basis of these findings, a three-phase approach is developed and proposed here as an SME ISMM. Three phases are (1) foundation and promotion, (2) management and expansion, and (3) maturity. Implications of the model are discussed and suggestions are made for further research.
키워드
Small Businesses, Small and Medium Size Enterprises, Information Security, Information Security Management, Security Management Model
'WarrenPak 성과' 카테고리의 다른 글
[Proceeding]조직의 혁신분위기(Innovation Climate)가 조직 혁신능력(Innovation Capability)에 미치는 영향, 2010 (0) | 2010.10.20 |
---|---|
[KCI]IT서비스에 있어서 서비스 품질이 지식공유의도에 미치는 영향에 관한 연구 - 정보시스템 연구, 2010.09 (0) | 2010.05.31 |
[KCI]IT서비스품질과 관계품질이 지식공유 활동에 미치는 영향에 관한 연구 - 콘텐츠학회논문지.2010.8 (0) | 2010.05.14 |
[수상작] 관광 문화산업 활성화를 위한 디지털 한류 클러스터 사업 제안, 2008 (0) | 2008.06.04 |
[대상 수상]'중소기업 특성 기반의 정보보호 관리모델에 관한 연구, 2003 (0) | 2003.12.20 |