주요국 위험 기반 사이버보안 관리체계 분석 및 통합 프레임워크 도출 연구: 미국·영국·호주 사례를 중심으로

Vol. 35, No. 3, pp. 681-697, 6월. 2025
10.13089/JKIISC.2025.35.3.681, Full Text:
Keywords: risk management, Cybersecurity Framework, Security Governance
Abstract

As the scope and target categories of cybersecurity management continue to expand beyond the organizational level, the need for efficiency-driven management is growing. Furthermore, most incidents and accidents occurring within organizations now involve cyber elements, elevating cybersecurity to the same level of importance as high-risk areas like finance. In response, major countries have adopted risk-based cybersecurity management frameworks to enhance decision-making and management efficiency using timely and objective information. This paper analyzes the management guidelines, risk management frameworks, and systems of nations that have adopted a risk-based cybersecurity approach. By identifying essential concepts to be considered in their operational structures and latest approaches, we propose an integrated framework that reflects these elements comprehensively. The findings of this study are expected to aid in incorporating the concept of risk into South Korea's cybersecurity management system, enabling the implementation of consistent procedures while simultaneously enhancing management efficiency and effectiveness. Additionally, the proposed framework provides a foundation for flexible responses to emerging threats and management factors, contributing to the establishment of a sustainable cybersecurity management system.

Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[IEEE Style]
유영인, 김동희, 정세희, "Analysis of Risk-Based Cybersecurity management systems in US, UK and Australia and Derivation of an Integrated Cyber Risk Framework," Journal of The Korea Institute of Information Security and Cryptology, vol. 35, no. 3, pp. 681-697, 2025. DOI: 10.13089/JKIISC.2025.35.3.681.

[ACM Style]
유영인, 김동희, and 정세희. 2025. Analysis of Risk-Based Cybersecurity management systems in US, UK and Australia and Derivation of an Integrated Cyber Risk Framework. Journal of The Korea Institute of Information Security and Cryptology, 35, 3, (2025), 681-697. DOI: 10.13089/JKIISC.2025.35.3.681.