DOI QR코드

DOI QR Code

The Effectiveness of Information Protection and Improvement Plan Based on SMEs Consulting Case

  • Kim, Jae-Nam (Dept. of Social Welfare, Kwangju Women's University)
  • Received : 2019.09.23
  • Accepted : 2019.10.06
  • Published : 2019.11.29

Abstract

In the phono-sapiens era of the intelligence information society, most business activities are increasingly dependent on networks and information systems. SMEs, which occupy the majority of Korean companies, are increasingly possessing the value and technology of their information assets, and their ability to protect core technologies that are the driving force of corporate growth will be the most important competitiveness of enterprises. Accordingly, the Ministry of Science and ICT and the Korea Internet & Security Agency(KISA) provides a foundation for minimizing the damage from cyber threats such as hacking and information leakage by evaluating the current information protection level of SMEs and enhancing information protection capability by supporting a high level of customized information protection consulting. In this study, we analyze the effectiveness of information protection based on the results of KISA SMEs consulting. In addition, by identifying problems and limitations derived from SMEs information protection consulting results, SMEs should propose measures to improve information security of SMEs that can manage information protection management system more efficiently and effectively.

지능정보사회의 포노 사피엔스 시대에 대부분 기업 활동은 네트워크 및 정보시스템에 대한 의존도가 더욱 높아지고 있다. 우리나라 기업의 대부분을 차지하고 있는 중소기업은 보유하고 있는 정보 자산의 가치와 기술력이 점차 증가하고 있고 기업 성장의 원동력이 되는 핵심기술에 대한 보호역량은 기업의 가장 중요한 경쟁력이 될 것이다. 이에 따라 과학기술정보통신부와 한국인터넷진흥원은 높은 수준의 기업 맞춤형 정보보호 컨설팅 지원을 통해 중소기업의 현재 정보보호 수준을 평가하고 정보보호 역량을 제고함으로써 해킹, 정보유출 등 각종 사이버 위협으로부터 받는 피해를 최소화할 수 있는 기반을 제공하고 있다. 본 연구에서는 한국인터넷진흥원에서 수행한 중소기업 정보보호 컨설팅 결과를 기반으로 정보보호 효과를 분석하고 중소기업 정보보호 컨설팅 결과에서 도출된 문제점과 한계점을 파악하여 중소기업이 정보보호 관리체계를 보다 효율적이고 효과적으로 관리할 수 있는 중소기업 정보보호의 개선방안을 제안하도록 한다.

Keywords

References

  1. YsPark, "An Application method of the Information Security Management System to Control Items : Focusing on Semiconductor Industry", Graduate School of Information Sciences Soongsil University, 2018.
  2. CoKim, "Balancing the Level of Information Protection through SMEs Information Protection Management System Standards", 2017.
  3. Ministry of SMEs and Startups, "Final Report of Actual Survey of Technology Protection Level of SMEs in 2018", 2019.
  4. CsRyu, "Knowledge Sharing Model of Government Supported SMEs Informatization Project", Korea Business Review, 1(2), pp. 85-97, 2008.
  5. YhKim & HbChang, "Propulsion Direction of Appropriate Level of SMEs Information Protection", Korea Institute of Information Security and Cryptology, 23(4), 41-46, 2013.
  6. Korea Internet & Security Agency(KISA), "SMEs Information Protection Consulting Result Report", 2018.
  7. Statistics Korea, "National Business Survey", 2017.
  8. http://stat.kbiz.or.kr/
  9. Ministry of SMEs and Startups, "Status of SMEs in Korea", SME Statistics & Statistics DB Search, 2019.
  10. HgShin, "Security Diagnosis and Improvement Examples of SMEs", Korea Industrial Technology Protection Association, 2012.
  11. BgLee, "Information Security Management System Suitable for SMEs", Graduate School of Information Sciences Soongsil University, 2017.
  12. CoKim, "Activation Plan of SMEs Information Protection Activity", Telecommunications Technology Association, 2017.
  13. Ministry of Science and ICT, "Criteria for Information Protection of Cloud Computing Services", 2017.