상세 보기
사이버 침해사고 심각도 분석과 국가 차원의 대응 정책
- 정혜란;
- 정연수;
- 이태진
초록
Cyber incidents are no longer isolated concerns of individual organizations but have become directly linked to national-level crisis management challenges. However, Korea still lacks clearly defined assessment criteria and evaluation elements for measuring incident severity, revealing limitations in response prioritization and resource allocation. This study therefore focuses on the National Cyber Incident Scoring System (NCISS) operated by the United States, comparatively analyzes major overseas evaluation frameworks, and explores the feasibility of applying such a system in the Korean context. Applying the NCISS to the WannaCry ransomware attack, the Korea Hydro & Nuclear Power incident, and the SK Telecom breach confirms that quantitative assessment is achievable in a way that balances the distinct characteristics of each incident with their broader socioeconomic impacts. This analysis goes beyond simple case application, demonstrating that incidents of differing natures can be objectively compared and analyzed within a unified framework. By applying NCISS to both major cyber incidents and routine attack cases, this study empirically validates that escalating severity levels consistently correspond to higher-tier response transitions, providing analytical evidence for discussions on national-level cyber crisis management.
키워드
- 제목
- 사이버 침해사고 심각도 분석과 국가 차원의 대응 정책
- 제목 (타언어)
- Analysis of Cyber Incident Severity and National-Level Response Policies
- 저자
- 정혜란; 정연수; 이태진
- 발행일
- 2026-06
- 유형
- Y
- 저널명
- 정보보호학회논문지
- 권
- 36
- 호
- 3
- 페이지
- 1011 ~ 1023