정보보호 표준화

Similar documents
슬라이드 제목 없음


1.장인석-ITIL 소개.ppt

F1-1(수정).ppt

±â¼úµ¿Çâ5

ecorp-프로젝트제안서작성실무(양식3)

2

untitled

00내지1번2번

<4D F736F F F696E74202D FB5A5C0CCC5CDC5EBBDC5B0FA20B3D7C6AEBFF6C5A9205BC8A3C8AF20B8F0B5E55D>


학습영역의 Taxonomy에 기초한 CD-ROM Title의 효과분석


ISO17025.PDF

Service-Oriented Architecture Copyright Tmax Soft 2005

PowerPoint 프레젠테이션

<붙임2> IT분야 국제표준 채택현황 일련 제안규격명 규격번호 국제문자코드-한글음절문자표 (Hangul syllables) 단방향멀티케스트전송규격 (ECTP-1: Enhanced Communication Transport Protocol-S

<353020B9DAC3E1BDC42DC5ACB6F3BFECB5E520C4C4C7BBC6C3BFA1BCADC0C720BAB8BEC820B0EDB7C1BBE7C7D7BFA120B0FCC7D120BFACB1B82E687770>

SchoolNet튜토리얼.PDF

Security Overview

<BCBCC1BEB4EB BFE4B6F72E706466>

3. 클라우드 컴퓨팅 상호 운용성 기반의 서비스 평가 방법론 개발.hwp

슬라이드 제목 없음

97-newcomers-korean.pptx

KISO저널 원고 작성 양식

-

<30362E20C6EDC1FD2DB0EDBFB5B4EBB4D420BCF6C1A42E687770>

1ºÎ

- 2 -

강의지침서 작성 양식

세종대 요람

Microsoft PowerPoint - KNOM Tutorial 2005_IT서비스관리기술.ppt

°í¼®ÁÖ Ãâ·Â

歯튜토리얼-이헌중.PDF

04-다시_고속철도61~80p

CHAPTER 01

諛⑺넻?꾩뿰媛?遺€1?μ옱?몄쭛

DW 개요.PDF

untitled


레이아웃 1

thesis

歯3이화진

untitled

SW¹é¼Ł-³¯°³Æ÷ÇÔÇ¥Áö2013

<C3E2C0E5BAB8B0EDBCAD32372E687770>

정보보호능력은필수적인 기업의핵심경쟁력이다 국제정보보호표준 ISO/IEC 27001:2013 Information security management systems Requirements ( 정보보호경영시스템 ISO 27001:2013) - 1 -

Microsoft Word - 김정훈

Microsoft Word - 1-차우창.doc

±èÇö¿í Ãâ·Â


, N-. N- DLNA(Digital Living Network Alliance).,. DLNA DLNA. DLNA,, UPnP, IPv4, HTTP DLNA. DLNA, DLNA [1]. DLNA DLNA DLNA., [2]. DLNA UPnP. DLNA DLNA.


차 례... 박영목 **.,... * **.,., ,,,.,,

최종_백서 표지


그림 2. 5G 연구 단체 현황 앞으로 다가올 미래에는 고품질 멀 티미디어 서비스의 본격화, IoT 서 비스 확산 등의 변화로 인해 기하 급수적인 무선 데이터 트래픽 발생 및 스마트 기기가 폭발적으로 증대 할 것으로 예상된다 앞으로 다가올 미래에는 고품질 멀티미디어 서

표현의 자유

< FC1A4BAB8B9FDC7D D325FC3D6C1BEBABB2E687770>

< D28B9F8BFAA20BCF6C1A4BABB292E687770>

13 Who am I? R&D, Product Development Manager / Smart Worker Visualization SW SW KAIST Software Engineering Computer Engineering 3

ȲÁø°æ

untitled

untitled

20 여상수(763~772).hwp

슬라이드 1

<31B1E8C0B1C8F128C6ED2E687770>

본문

,,,,,,, ,, 2 3,,,,,,,,,,,,,,,, (2001) 2

10방송통신서비스_내지최종

歯I-3_무선통신기반차세대망-조동호.PDF

시안

03-ÀÌÁ¦Çö

Sensitive Compartmented Information Facility (SCIF) and Special Access Program Facility (SAPF) Criteria

인권1~2부73p

PowerPoint 프레젠테이션

15_3oracle


I

WHO 의새로운국제장애분류 (ICF) 에대한이해와기능적장애개념의필요성 ( 황수경 ) ꌙ 127 노동정책연구 제 4 권제 2 호 pp.127~148 c 한국노동연구원 WHO 의새로운국제장애분류 (ICF) 에대한이해와기능적장애개념의필요성황수경 *, (disabi

○ 제2조 정의에서 기간통신역무의 정의와 EU의 전자커뮤니케이션서비스 정의의 차이점은

DBPIA-NURIMEDIA

정보기술응용학회 발표

?흎튜

Journal of Educational Innovation Research 2016, Vol. 26, No. 1, pp.1-19 DOI: *,..,,,.,.,,,,.,,,,, ( )

MS-SQL SERVER 대비 기능

(JBE Vol. 23, No. 6, November 2018) (Special Paper) 23 6, (JBE Vol. 23, No. 6, November 2018) ISSN 2

미래 서비스를 위한 스마트 클라우드 모델 수동적으로 웹에 접속을 해야만 요구에 맞는 서비스를 받을 수 있었다. 수동적인 아닌 사용자의 상황에 필요한 정보를 지능적으로 파악 하여 그에 맞는 적합한 서비스 를 제공할 수 새로운 연구 개발이 요구 되고 있다. 이를 위하여,

슬라이드 1

PROCES-WP012A-KO-P, 현재의 안전 계측 시스템(SIS)이 최신 표준을 준수하고 있습니까?

10 이지훈KICS hwp


슬라이드 제목 없음

2013<C724><B9AC><ACBD><C601><C2E4><CC9C><C0AC><B840><C9D1>(<C6F9><C6A9>).pdf

0929 °úÇбâ¼úÁ¤Ã¥-¿©¸§

Journal of Educational Innovation Research 2018, Vol. 28, No. 4, pp DOI: A Study on Organizi

06_ÀÌÀçÈÆ¿Ü0926

요 약 문 1. 제목 : 개인정보 오남용 유출 2차 피해 최소화 방안 2. 연구의 배경 개인정보란 살아 있는 개인에 관한 정보로서 개인을 알아볼 수 있는 정보로 해당 정보만으로는 특정 개인을 알아볼 수 없더라도 다른 정보와 쉽게 결합하여 알아볼 수 있는 것을 포함한다.

지의 절반 정도를 데이터센터 냉각, 공조 등의 설비가 사용하며 나머지 절반을 IT 장비가 사용하고 있음을 고 있으므로, 본 고에서는 JTC1/SC39에서의 그린 데 이터센터 표준화 동향을 다루도록 한다. 알 수 있다[1]. 그러므로 데이터센터 에너지 효율의 향 상을 위


Transcription:

양수미 정보보호관련표준

차례 IETF 표준 ISO/IEC JTC1 표준 SC27 SC27 이외 ITU-T 표준

IETF 표준 IETF (Internet Engineering Task Force) 의 IESG (Internet Engineering Steering Grou p) 내의 Security Area 에서제정한표준들로여러 Working Group 에서연구 / 제정된다. It is established to support internet protocol engineering and development tool at 1986 under the ISOC( internet society).

IETF (Internet Engineering Task Force) 의주요한목표는인터넷의운영상, 기술상의문제점을해결하기위하여프로토콜및구조에대한표준을제안하고개발하는것

Internet standards and RFCs The Internet society IAB (Internet Architecture Board) : responsible for defining the overall architecture of the Internet, providing guidance and broad direction to the IETF IETF (Internet Engineering Task Force) : The protocol engineering and development arm of the Internet, 비영리단체인 IAB(Internet Archetecture Board) 의하위조직. TCP/IP 와인터넷에관한정책과표준안작성을담당 IESG (Internet Engineering Steering Group) : responsible for technical management of IETF activities and the Internet standards process Henric Johnson 5

IETF 표준화과정 Standard development stages Internet drafts : they are on working documents for RFC(request for comments), register on directory during 6M. Proposed standard : implement and test protocol( 6M-2Y) Draft standard : at least 2 independent and interoperated products, need more field test on different wide environments( 4M-2Y) Internet standard : successfully implemented operated protocol

IETF Working Groups(Active) APPLICATIONS INTERNET OPERATIONS and MANAGEMENT REAL-TIME APPLICATIONS and INFRASTR UCTURE ROUTING SECURITY TRANSPORT

Security area Working Groups abfab Application Bridging for Federated Access Beyond web dkim Domain Keys Identified Mail emu EAP Method Update hokey Handover Keying ipsecme IP Security Maintenance and Extensions isms Integrated Security Model for SNMP keyprov Provisioning of Symmetric Keys

Security area Working Groups kitten Common Authentication Technology Next Generation krb-wg Kerberos ltans Long-Term Archive and Notary Services msec Multicast Security nea Network Endpoint Assessment pkix Public-Key Infrastructure (X.509) tls Transport Layer Security

차례 IETF 표준 ISO/IEC JTC1 표준 SC27 SC27 이외 ITU-T 표준

ISO/IEC JTC1 표준 ISO( International Organizaton for Standardization)/ IEC(International Electronical Commission) JTC(Joint Technical Committee) 1 A combined organization ( ISO/TC97 : information processing system fields and IEC/TC 83 : information equipments) 정보처리시스템에대한국제표준화활동과정보기기에대한국제표준화활동을통합하여구성된정보기술분야의국제표준화활동을위한공동기술위원회 SC20( data cryptographic techniques) was expended into SC27( security techniques).

ISO/IEC JTC1 표준 Standard development stages Preliminary stage : preliminary work item (PWI) Proposal stage : new work item proposal ( NP) Preparatory stage : working drafts (WD) Committee stage : committee drafts (CD) Enquire stage : enquire drafts i.e. draft international standard (ISO) (DIS), committee draft for vote(iec) (CDV) Approval stage : final draft international standard (FDIS) Publication stage : international standard(iso,iec,iso/iec)

ISO/IEC JTC1 표준 SC27 : IT Security techniques IT 보안에관한일반적인방법과기술에대한표준을주로연구 / 제정한다. 응용에보안메커니즘을삽입하는것을제외한정보기술보안을위한일반적방법과기술에대한표준화 암호화알고리즘의표준화, 정보기술시스템보안서비스를위한일반적요구명세, 보안기술및메커니즘개발, 문서및표준을지원하는관리개발을포함 SC27 이외

SC27 이외

ISO/IEC 13335-1:2004 Information technology -- Security techniques -- Management of information and communications technology security -- Part 1: Concepts and models for information and communications technology security management ISO/IEC 13335-1:2004 presents the concepts and models fundamental to a basic understanding of ICT security, and addresses the general management issues that are essential to the successful planning, implementation and operation of ICT security. Part 2 of ISO/IEC 13335 (currently 2nd WD) provides operational guidance on ICT security. Together these parts can be used to help identify and manage all aspects of ICT security.

ISO/IEC 27002:2005(2007) BS 7799:1999으로부터발전 -> 17799 -> 27002 12 main sections Risk assessment Security policy - management direction Organization of information security - governance of information security Asset management - inventory and classification of information assets Human resources security - security aspects for employees joining, moving and leaving an organization Physical and environmental security - protection of the computer facilities Communications and operations management - management of technical security controls in systems and networks Access control - restriction of access rights to networks, systems, applications, functions and data Information systems acquisition, development and maintenance - building security into applications Information security incident management - anticipating and responding appropriately to information security breaches Business continuity management - protecting, maintaining and recovering business-critical processes and systems Compliance - ensuring conformance with information security policies, standards, laws and regulations

차례 IETF 표준 ISO/IEC JTC1 표준 SC27 SC27 이외 ITU-T 표준

ITU-T 표준 ITU-T (International Telecommunication Union-Tele communication Standardization Sector) 통신표준을정했던국제적인기관인 CCITT (Consultative Committee for International Telegraph and Telephone) 가개칭한단체. 디지털전송을위한표준과아날로그전송을위한인터페이스표준을정의

ITU-T 표준 SG 2, 3, 5, 9, 11, 12, 13, 15, 16, 17, TSAG(Telecommunication Standardization Advisory Group) SG 17 : Security [, languages and telecommunication software] 국내에서는한국정보통신기술협회 (TTA : Telecommunication Technology Association) : 민간단체성격의정보통신표준제정기관이담당 TC10 : security committee( IT security management, crypto technology, system security group)

ITU-T SG17 주요내용 NGN(Next Generation Network) Security Framework Multimedia Security Frameworks Guidelines Security Management Awareness Secure Communication Services

기타 ECMA(European computer manufacturers association) establish for data processing standard in Europe at 1961 TC 17( include communication), TC 36(IT security).tc 32( communication, network and interoperability, security) ETSI(European telecommunication standards institute) establish for communication/information/broadcasting standards in Europe at 1988 Standard process Inception : start development of standard Conception : define concept Drafting : propose standard Adoption ; adopt standard Promotion ; implement standard TC sec is security standard technical committee -> OGG(Operational Co-ordination Group)

기타 인터넷보안기술포럼 (ISTF : Information Security Technology Forum) : 인터넷보안기술분야의민간업체들이중심이되어구성된포럼으로시장수요를반영한사실 (de-facto) 표준을개발 Establish at 2000 for public internet security standard Network, PKI, mobile group.

NIST NIST (National Institute of Standards and Technology) To establish at 1901, named NBS(national bureau of standards) and then renamed NIST at 1988 under DoC(Department of Commerce). 10 research laboratories Building and fire research Chemical science and technology Electronics and electrical engineering Information technology Manufacturing engineering Materials science and engineering Nanoscale science and technology Neutron research Physics Technology services

NIST information technology lab. : 6 research areas Advanced Network Technologies Computer Security Information Access Mathematical & Computational Sciences Software & Systems Statistical Engineering

NIST 암호화기술 첨단인증기술 공개키기반구조 인터네트워킹보안 평가기준및제도 보안관리및지원 컴퓨터보안자원정보센터

ANSI ANSI(American national standards institute) To establish a non-profit organization at 1918. Have three characteristics : don t develop standards, ANS is used all industries, ANS is voluntary. Major fields : all technical fields ( accreditation 인정서, patent,etc) contribute ISO, IEC ANSI certifies other standard organizations of USA

KATS

KATS

정보보호평가기준 ITSEC(Information Technology Security Evaluation Criteria) : 유럽 TCSEC(Trusted Computer System Evaluation Criteria) : 미국 1) D(Minimal Protection : 최소한의보호 ) 2) C1(Discretionary Security Protection : 임의적접근보호 ) 3) C2(Controlled Access Protection : 통제된접근보호 ) 4) B1(Labeled Security Protection : 레이블된보호 ) 5) B2(Structured Protection : 구조적보호 ) 6) B3(Security Domain : 보안영역 ) 7) A1(Verified Design : 검증된설계 ) K Series : 한국 K1~ 7 국제공통평가기준 CC(Common Criteria) : EAL 1 ~ 7

42