Personal Information Impact Assessment refers to the analysis of the risk factors and evaluation for improvement if the information subject is concerned about the infringement of personal information by the operation of the personal information file corresponding to Article 35 of the Act.

 

The evaluation organization shall be reviewed and designated by the Designated Judging Committee composed of up to 15 members appointed by the Minister of Public Administration and Security. There is.

 

[Evaluation procedure]

Designated application announcement → Designated application reception → Review of submitted documents → Designated examination committee composition → Document screening → On-site audit → Comprehensive audit → Verification of audit result → Identification of personnel performing impact assessment → Assignment of evaluation agency

 

 

The qualifications of personnel who can perform personal information impact assessment can be classified into general performance personnel and advanced performance personnel, The notices on personal information impact assessment describe the eligibility requirements as follows.

 

 1. General performance personnel qualification

  A. Any person who has experience in assessing impacts for more than 5 years after being qualified as the general performance worker in Item 1

  B. A person who has worked in the field of personal information impact assessment for more than one year after obtaining the personal information manager qualification implemented by Korea CPO Forum.

 

 2. Advanced Performance Personnel Qualifications

 A. Any person who has experience in assessing impacts for more than 5 years after being qualified as the general performance worker in Item 1

 B. Applicants must have at least three years of experience in assessing impacts after obtaining a Ph.D.

 C. Information management engineer, computer system application technician,  Persons with at least three years of experience in assessing impacts after acquiring the qualification for ICT

'Security' 카테고리의 다른 글

What is IAM??  (0) 2018.12.19
SCTP(Stream Control Transmission Protocol) Note 1  (0) 2018.12.09
Firmware encrypt note  (0) 2018.12.05
IoT law note  (0) 2018.10.03
Differences between ACESS TOKEN and REFRESH TOKEN Note 1  (0) 2018.09.29

Security

What is IAM??

2018. 12. 19. 08:51


1. Definition of IAM (Identity Access Management) 
: Establish security policies that your organization needs and manage user accounts and permissions automatically according to policies.
 Solutions (SSO + Authority Management + Resource Management + Security Policy establishment + Provisioning)
 
 
2. Components of the IAM 
Component
Explanation
Clients

 Delivered on the Internet (Extranet) to various users including internal employees, business partners and customers
EAM
 - Authentication, Authorization
Provisioning

 - RBAC-based authorization management
 - Automated account management
 - Process definition for account management
Workflow

 - Process automation of account management
 - Define work procedures for creating, modifying, approving, or rejecting accounts

Security Policy
& Audit

 - Integrated management of user information of all system accounts, DB, and applications
 - Integrated Audit for Account Management Information

Self-Service
& Delegation

 - Direct management of user-visible information
 - Delegate administrative authority
Legacy System
 - Various period system and application such as groupware, ERP, KMS
Monitoring 
 - Usage status of each system, real-time monitoring of illegal users 

3. Introduction effect of IAM 
- Security Efficiency: Affects business processes that need to provide a consistent and improved security access control foundation.
- Security Effectiveness: Provision of safety based on access control and transparency
- Business agility and productivity: Flexible when business changes are needed
- Reduced costs: Automated security management to keep the computer input optimal
- Streamlining IT operations: Automation and transparency of IT resource access requests and approval processing procedures
- Strengthen IT risk management: Apply security policies and effective security controls
- Regulatory Compliance: Compliance with Sarbanes-Oxley, GLBA, etc.

[Note: Comparison of SSO, EAM, IAM]
 
Division
SSO
EAM
IAM
Purpose
Single login, integrated authentication
SSO + Integrated Rights Management
EAM + Integrated account management
Function
Single account
Access control according to security policy

Automatic account management through provisioning
Tech
PKI, LDAP
ACL, RBAC
Workflow
Pros
User convenience
Security Enhancement
Strengthen management efficiency
Cons
Other than authentication, security vulnerability
User management difficulty
Complex system construction 


1. Overview
A. Definition
- Developed to support transmission of Voice over IP (VoIP) signal relay and multimedia applications that are not supported with existing TCP.

B. Backscape
- Development of VoIP transmission standards for IP networks is a major goal and RFC 2960 was established in October 2000.
- Multi-streaming function is required and is being developed by Transport Area WG.

C. Features
- combines UDP datagram orientation with TCP sequencing and reliability features
- Multi-stream and message-oriented transfer characteristics in multi-homeing environments


2. SCTP Structure and Packet Structure
A. Rescue


B. Packet structure


3. Status of SCTP development

A. Relevant IETF standard documents

- The SCTP base specification document is RFC 2960 and is a supplement to RFC 3257, 3286 documents

- Transport layer security documents related to SCTP are established as RFC 3436.



4. Conclusion and Future Prospect

- SCTP is the next-generation transport layer protocol after TCP and is expected to continue to expand and distribute standards.

- Used inside LTE and can be used on the internet in the future


'Security' 카테고리의 다른 글

What is a personal information impact assessment (PIA)?  (0) 2018.12.21
What is IAM??  (0) 2018.12.19
Firmware encrypt note  (0) 2018.12.05
IoT law note  (0) 2018.10.03
Differences between ACESS TOKEN and REFRESH TOKEN Note 1  (0) 2018.09.29
조회수 확인