โ† IaC-based ISMS-P Cloud Security Consulting

IaC Management with Terraform Cloud

์ธํ”„๋ผ ๋ณ€๊ฒฝ์ด Git ๊ธฐ๋ฐ˜์œผ๋กœ ๊ด€๋ฆฌ๋˜๊ณ  ์žˆ๋Š”์ง€, Policy as Code๋กœ ๋ณด์•ˆ ์ •์ฑ…์ด ์ž๋™ ๊ฒ€์ฆ๋˜๋Š”์ง€ ์ ๊ฒ€ํ•ฉ๋‹ˆ๋‹ค. ์ฝ”๋“œ์™€ ์‹ค์ œ ์ธํ”„๋ผ ๊ฐ„ ๋“œ๋ฆฌํ”„ํŠธ ํƒ์ง€ ์ฒด๊ณ„๊ฐ€ ๊ตฌ์ถ•๋˜์–ด ์žˆ๋Š”์ง€ ์ง„๋‹จํ•˜๊ณ , ISMS-P ์š”๊ตฌ์‚ฌํ•ญ์— ๋ถ€ํ•ฉํ•˜๋Š” ๊ฐœ์„ ๋ฐฉ์•ˆ์„ ์ œ์‹œํ•ฉ๋‹ˆ๋‹ค.

์†Œ์Šค ๊ด€๋ฆฌ
ISMS-P 2.8.5 ์†Œ์Šค ํ”„๋กœ๊ทธ๋žจ ๊ด€๋ฆฌ / 2.8.6 ์šด์˜ํ™˜๊ฒฝ ์ด๊ด€

IaC ์†Œ์Šค ๊ด€๋ฆฌ ๋ฐ ํ™˜๊ฒฝ ์ด๊ด€

์ธํ”„๋ผ ์ฝ”๋“œ๊ฐ€ ๋ฒ„์ „ ๊ด€๋ฆฌ๋˜๊ณ  ํ™˜๊ฒฝ๋ณ„ ์ด๊ด€ ์ ˆ์ฐจ๊ฐ€ ์ˆ˜๋ฆฝ๋˜์–ด ์žˆ๋Š”์ง€ ์ ๊ฒ€ํ•ฉ๋‹ˆ๋‹ค.

์ ๊ฒ€๊ฒฐ๊ณผ: "์†Œ์Šค ๋ฐ ํ™˜๊ฒฝ ๊ด€๋ฆฌ ๋ฏธํก"

์›์ธ: ๋ฒ„์ „ ๊ด€๋ฆฌ ์—†์Œ, ํ™˜๊ฒฝ ๋ถ„๋ฆฌ ๋ฏธํก

๊ถŒ๊ณ : Git ๊ธฐ๋ฐ˜ ๋ฒ„์ „ ๊ด€๋ฆฌ ๋ฐ Workspace ๋ถ„๋ฆฌ

๋ณ€๊ฒฝ ๊ด€๋ฆฌ
ISMS-P 2.9.1 ๋ณ€๊ฒฝ๊ด€๋ฆฌ / 2.9.2 ์„ฑ๋Šฅ ๋ฐ ์žฅ์• ๊ด€๋ฆฌ

๋ณ€๊ฒฝ ๋ฐ ์žฅ์•  ๊ด€๋ฆฌ

์ธํ”„๋ผ ๋ณ€๊ฒฝ์ด ํ†ต์ œ๋˜๊ณ  ์žฅ์•  ๋ฐœ์ƒ ์‹œ ๋กค๋ฐฑ ์ฒด๊ณ„๊ฐ€ ๊ตฌ์ถ•๋˜์–ด ์žˆ๋Š”์ง€ ์ ๊ฒ€ํ•ฉ๋‹ˆ๋‹ค.

์ ๊ฒ€๊ฒฐ๊ณผ: "๋ณ€๊ฒฝ ๋ฐ ์žฅ์•  ๊ด€๋ฆฌ ๋ฏธํก"

์›์ธ: ์Šน์ธ ์—†์ด ๋ณ€๊ฒฝ, ๋กค๋ฐฑ ์ฒด๊ณ„ ๋ฏธ๋น„

๊ถŒ๊ณ : PR ์›Œํฌํ”Œ๋กœ์šฐ ๋ฐ State ๋กค๋ฐฑ ์ฒด๊ณ„ ๊ตฌ์ถ•

๋กœ๊ทธ ๊ด€๋ฆฌ
ISMS-P 2.9.4 ๋กœ๊ทธ ๋ฐ ์ ‘์†๊ธฐ๋ก ๊ด€๋ฆฌ / 2.9.6 ์‹œ๊ฐ„ ๋™๊ธฐํ™”

๊ฐ์‚ฌ ๋กœ๊ทธ ๋ฐ ์‹œ๊ฐ„ ๋™๊ธฐํ™”

์ธํ”„๋ผ ๋ณ€๊ฒฝ ์ด๋ ฅ์ด ๊ธฐ๋ก๋˜๊ณ  ๋กœ๊ทธ ์‹œ๊ฐ„์ด ๋™๊ธฐํ™”๋˜์–ด ์žˆ๋Š”์ง€ ์ ๊ฒ€ํ•ฉ๋‹ˆ๋‹ค.

์ ๊ฒ€๊ฒฐ๊ณผ: "๋กœ๊ทธ ๊ด€๋ฆฌ ์ฒด๊ณ„ ๋ฏธํก"

์›์ธ: ๋กœ๊ทธ ๋ณด์กด ๋ถ€์žฌ, ์‹œ๊ฐ„ ๋ถˆ์ผ์น˜

๊ถŒ๊ณ : Terraform Cloud Audit Log ๋ฐ NTP ์„ค์ •

โ† Back to Overview