The effects of the operation of an information security management system on the performance of information security
Sang-Soo Jang, Sang-Joon Lee, Bong-Nam Noh · Information Security and Cryptology · 2012
ABSTRACT Many domestic organizations are introducing and operating vario us information security management systems capable of coping with technical, administrative, and legal issues comprehensively and systematically, in order to prevent various infringement incidents such as personal information disclosure and hacking preemptively and actively. However, empirical analyses regarding the extent to which an information security management system contributes to information security performance have not been fully conducted, even though enterpri ses and organizations are actively introducing such systems in order to achieve their information security objectives as a par t of their organizational management activities in line with th eir respective business, by investing considerable effort and resou rces in developing and operating these systems. This approach can be used to apply, develop, and operate the information management system actively within an organization. this study focused on analyzing how each specific phase of the information security management system affects information security performance, compared with previous studies, which generally focus on the information security control item in analyzing information security performance. The information security management system was analyzed empirically to determine how the Security PCDA cycling model affects information security performance.Keywords: ISO27001, ISMS, PIMS, G-ISMS, RMF, Information Security Evalu ation, Information SecurityPerformance, PLS접수일(2012년 6월 11일), 수정일(2012년 9월 7일), 게재확정일(2012년 9월 27일)†주저자, [email protected]‡교신저자, [email protected]