With the activation of information search, ubiquitous computing, e-commerce, internet banking, etc., entities such as the government, corporations and individuals are becoming increasingly dependent on information and information systems. Taking advan...
With the activation of information search, ubiquitous computing, e-commerce, internet banking, etc., entities such as the government, corporations and individuals are becoming increasingly dependent on information and information systems. Taking advantage of this trend, various types of threats including worms/viruses and hacking are increasing through the vulnerability of information and information systems.
In order to protect information and information systems from various types of threats, research is being made in the governmental dimension on product evaluation and certification for security systems, information security policies, the improvement of systems, etc. Current methodologies for raising the information security level are under development in consideration of the evaluation of various aspects.
As an effort to enhance the corporate information security level, the present study examined information security level self-assessment methodologies, and designed and implemented a self-assessment tool. Weighting factor was calculated according to the characteristics of corporate business and the importance of security policy factors such as confidentiality, integrity and availability in the area of information security level control.
Through this study on information security level assessment methodologies, we can reduce errors from evaluators' subjective opinions and provide useful materials for corporations' establishment of information security measures. In addition, the implementation of a self-assessment tool will enable evaluation with fewer personnel, and save cost and time.