

의료기관 종별 웹 사이트 정보보안 관리 실태 연구


Study on Information Security Management of Hospital Web Sites

김종민, 류황건

In this paper, we evaluated web security vulnerability and privacy information management of hospital web sites which are registered at the Korea Hospital Association. Vulnerability Scanner (WVS) based on the OWASP Top 10 was used to evaluate the web security vulnerability of the web sites. And to evaluate the privacy information management, we used ten rules which were based on guidelines for protecting privacy information on web sites. From the results of the evaluation, we discovered tertiary hospitals had relatively excellent web security compared to other type of hospitals. But all the hospital types had not only high level vulnerabilities but also the other level of vulnerabilities. Additionally, 97% of the hospital web sites had a certain level of vulnerability, so a security inspection is needed to secure the web sites. We discovered a few SQL Injection and XSS vulnerabilities in the web sites of tertiary hospitals. However, these are very critical vulnerabilities, so all hospital types have to be inspected to protect their web sites against attacks from hacker. On the other hand, the inspection results of the tertiary hospitals for privacy information management had a better compliance rate than that of the other hospital types.


 Ⅰ. 서론
 Ⅱ. 연구방법
  1. 평가 대상 및 기간
  2. 평가 방법
 Ⅲ. 연구결과
  1. 보안취약성 분석 결과
  2. 개인정보 관리실태 분석 결과
 Ⅳ. 고찰 및 결론


  • 김종민 Jong-Min Kim. 고신대학교 인터넷비즈니스학과
  • 류황건 Hwang-Gun Ryu. 고신대학교 의료경영학과


