โ† ISMS-P Compliance Support

ISMS-P 1.2.1 ์ •๋ณด์ž์‚ฐ ์‹๋ณ„ High Risk

์ •๋ณด์ž์‚ฐ ์‹๋ณ„์ด ์ ์ ˆํžˆ ์ˆ˜ํ–‰๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 1.2.1์€ ์กฐ์ง์˜ ๋ชจ๋“  ์ •๋ณด์ž์‚ฐ์„ ์‹๋ณ„ยท๋ถ„๋ฅ˜ํ•˜๊ณ  ์ค‘์š”๋„๋ฅผ ์‚ฐ์ •ํ•˜์—ฌ ๋ชฉ๋ก์„ ์ตœ์‹ ์œผ๋กœ ๊ด€๋ฆฌํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” AWS Config๋ฅผ ํ†ตํ•ด ๋ชจ๋“  ์ž์‚ฐ์„ ์ž๋™ ํƒ์ง€ํ•˜๊ณ  ํƒœ๊ทธ ๊ธฐ๋ฐ˜์œผ๋กœ ๋ถ„๋ฅ˜ํ•˜์—ฌ ๊ด€๋ฆฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“‹

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 1.2.1 ์ •๋ณด์ž์‚ฐ ์‹๋ณ„ ์š”๊ตฌ์‚ฌํ•ญ

1.2.1

์ •๋ณด์ž์‚ฐ ์‹๋ณ„

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์กฐ์ง์˜ ์—…๋ฌดํŠน์„ฑ์— ๋”ฐ๋ผ ์ •๋ณด์ž์‚ฐ ๋ถ„๋ฅ˜๊ธฐ์ค€์„ ์ˆ˜๋ฆฝํ•˜์—ฌ ๊ด€๋ฆฌ์ฒด๊ณ„ ๋ฒ”์œ„ ๋‚ด ๋ชจ๋“  ์ •๋ณด์ž์‚ฐ์„ ์‹๋ณ„ยท๋ถ„๋ฅ˜ํ•˜๊ณ , ์ค‘์š”๋„๋ฅผ ์‚ฐ์ •ํ•œ ํ›„ ๊ทธ ๋ชฉ๋ก์„ ์ตœ์‹ ์œผ๋กœ ๊ด€๋ฆฌํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

๐Ÿ“Œ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • AWS Config ๊ธฐ๋ฐ˜ ์ž์‚ฐ ์ž๋™ ํƒ์ง€
  • Tag Policy๋กœ ์ž์‚ฐ ๋ถ„๋ฅ˜ ์ฒด๊ณ„ ๊ฐ•์ œ
  • Resource Groups๋กœ ์ž์‚ฐ ๊ทธ๋ฃนํ™”
  • Config Aggregator๋กœ ๋ฉ€ํ‹ฐ ๊ณ„์ • ํ†ตํ•ฉ

โš ๏ธ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ์ •๋ณด์ž์‚ฐ ๋ชฉ๋ก ๋ฏธ๋ณด์œ 
  • ๊ฒฐํ•จ: ์ž์‚ฐ ๋ถ„๋ฅ˜ ๊ธฐ์ค€ ๋ฏธ์ˆ˜๋ฆฝ
  • ๊ถŒ๊ณ : ์ž์‚ฐ ๋ชฉ๋ก ์ตœ์‹ ํ™” ๋ฏธํก
๐Ÿ“„ KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ โ†— โ˜๏ธ AWS K-ISMS ๊ทœ์ • ์ค€์ˆ˜ โ†—
๐Ÿ“ฐ

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

์ž์‚ฐ ๊ด€๋ฆฌ ๋ฏธํก์œผ๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2024.08

๋ฒ•๋ฌด๋ฒ•์ธ ๋กœ๊ณ ์Šค ์ž์‚ฐ๊ด€๋ฆฌ ๋ฏธํก ์นจํ•ด

๋‚ด๋ถ€ ์ „์‚ฐ์‹œ์Šคํ…œ ์ž์‚ฐ ๊ด€๋ฆฌ ๋ฏธํก์œผ๋กœ ์†Œ์†ก์ž๋ฃŒ 18๋งŒ ๊ฑด ํ•ดํ‚น. ์ž์‚ฐ์— ๋Œ€ํ•œ ์ ‘๊ทผํ†ต์ œ ํ˜„ํ™ฉ ํŒŒ์•… ๋ถ€์žฌ๋กœ ์™ธ๋ถ€ ์นจ์ž… ๊ฐ์ง€ ์‹คํŒจ.

๐Ÿ’ก ๊ตํ›ˆ: ๋ชจ๋“  ์ž์‚ฐ์˜ ์ž๋™ ํƒ์ง€ + ์ ‘๊ทผํ†ต์ œ ํ˜„ํ™ฉ ๊ฐ€์‹œํ™” ํ•„์ˆ˜

์ถœ์ฒ˜: M์ด์ฝ”๋…ธ๋ฏธ๋‰ด์Šค โ†—
2023.05

Toyota ํด๋ผ์šฐ๋“œ ์ž์‚ฐ 10๋…„ ๋ฐฉ์น˜

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์„ค์ • ์˜ค๋ฅ˜๊ฐ€ 10๋…„๊ฐ„ ๋ฐฉ์น˜. ์ž์‚ฐ ํ˜„ํ™ฉ ์ ๊ฒ€ ์ฒด๊ณ„ ๋ถ€์žฌ๋กœ 26๋งŒ ๋ช… ๊ณ ๊ฐ ๋ฐ์ดํ„ฐ ์œ ์ถœ.

๐Ÿ’ก ๊ตํ›ˆ: ์ž์‚ฐ ์ž๋™ ํƒ์ง€ + ์ •๊ธฐ ๋ณด์•ˆ ์ ๊ฒ€ ์ฒด๊ณ„ ํ•„์ˆ˜

์ถœ์ฒ˜: TechCrunch โ†—
โšก

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

AWS์—์„œ ์ž์‚ฐ ์‹๋ณ„์ด ์œ„๋ฐ˜๋˜๋Š” ์ƒํ™ฉ

Config ๋ฏธํ™œ์„ฑํ™” (์œ„ํ—˜)

EC2

?

RDS

?

S3

?

โ†‘ ์ž์‚ฐ ํ˜„ํ™ฉ ํŒŒ์•… ๋ถˆ๊ฐ€

Config ๋ฏธํ™œ์„ฑํ™” โ†’ ์–ด๋–ค ์ž์‚ฐ์ด ์žˆ๋Š”์ง€ ํŒŒ์•… ๋ถˆ๊ฐ€

Config ํ™œ์„ฑํ™” (๊ถŒ์žฅ)

EC2

15

RDS

3

S3

8

โ†‘ ์ „์ฒด ์ž์‚ฐ ์‹ค์‹œ๊ฐ„ ์ถ”์ 

Config ํ™œ์„ฑํ™” โ†’ ๋ชจ๋“  ์ž์‚ฐ ์ž๋™ ํƒ์ง€ ๋ฐ ์ถ”์ 

๐Ÿšจ

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: AWS Config ๋ฏธํ™œ์„ฑํ™” ๋ฐ ํƒœ๊ทธ ์ •์ฑ… ๋ฏธ์ˆ˜๋ฆฝ

aws_config_configuration_recorder๊ฐ€ ์—†์–ด ์ž์‚ฐ ํƒ์ง€๊ฐ€ ๋ถˆ๊ฐ€ํ•˜๋ฉฐ, ํƒœ๊ทธ ์ •์ฑ…์ด ์—†์–ด ์ž์‚ฐ ๋ถ„๋ฅ˜ยท์ค‘์š”๋„ ์‚ฐ์ •์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
# ์ž์‚ฐ ์‹๋ณ„ ์ฒด๊ณ„ ๋ฏธ๊ตฌ์ถ•

# aws_config_configuration_recorder ์—†์Œ - ์ž์‚ฐ ํƒ์ง€ ๋ถˆ๊ฐ€
# aws_config_configuration_aggregator ์—†์Œ - ํ†ตํ•ฉ ๊ด€๋ฆฌ ๋ถˆ๊ฐ€
# aws_organizations_policy (TAG_POLICY) ์—†์Œ - ๋ถ„๋ฅ˜ ์ฒด๊ณ„ ์—†์Œ

resource "aws_instance" "app" {
  ami           = "ami-12345678"
  instance_type = "t3.medium"
  # tags ๋ฏธ์„ค์ • - ์ž์‚ฐ ๋ถ„๋ฅ˜ ๋ถˆ๊ฐ€
}

ISMS-P 1.2.1 ์œ„๋ฐ˜ ์‚ฌํ•ญ

โ—

์ž์‚ฐ ๋ฏธ์‹๋ณ„: Config ๋ฏธํ™œ์„ฑํ™”

โ—

๋ถ„๋ฅ˜ ๋ฏธ์ˆ˜ํ–‰: ํƒœ๊ทธ ์ •์ฑ… ์—†์Œ

โ—

์ค‘์š”๋„ ๋ฏธ์‚ฐ์ •: ๋“ฑ๊ธ‰ ํƒœ๊ทธ ์—†์Œ

โ—

๋ชฉ๋ก ๋ฏธ๊ด€๋ฆฌ: ์ž์‚ฐ ์ธ๋ฒคํ† ๋ฆฌ ์—†์Œ

๐Ÿ”

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

์ž์‚ฐ ์‹๋ณ„ ์ฒด๊ณ„ ํƒ์ง€ ๋กœ์ง

ํƒ์ง€ ๋Œ€์ƒ ํŒ๋‹จ ์กฐ๊ฑด ๊ฒฐ๊ณผ
๐Ÿ“ฆ Config Recorder
aws_config_configuration_recorder ๋ฏธ์กด์žฌ Critical - ์ž์‚ฐ ํƒ์ง€ ๋ถˆ๊ฐ€
๐Ÿ”— Config Aggregator
aws_config_configuration_aggregator ๋ฏธ์กด์žฌ High - ํ†ตํ•ฉ ๊ด€๋ฆฌ ๋ถˆ๊ฐ€
๐Ÿท๏ธ Tag Policy
TAG_POLICY ๋ฏธ์กด์žฌ High - ๋ถ„๋ฅ˜ ์ฒด๊ณ„ ์—†์Œ
๐Ÿ“‹ Resource Groups
aws_resourcegroups_group ๋ฏธ์กด์žฌ Medium - ๊ทธ๋ฃนํ™” ๋ถˆ๊ฐ€
๐Ÿ”– ํ•„์ˆ˜ ํƒœ๊ทธ
default_tags ๋˜๋Š” resource tags ๋ฏธ์„ค์ • High - ์ž์‚ฐ ์‹๋ณ„ ์–ด๋ ค์›€
๐Ÿ””

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ด์ƒํ–‰์œ„ ํƒ์ง€

์ž์‚ฐ ๋ณ€๊ฒฝ ๋Ÿฐํƒ€์ž„ ์ด๋ฒคํŠธ ๋Œ€์‘ ๋กœ์ง

ํƒ์ง€ ์‹œ๋‚˜๋ฆฌ์˜ค ์กฐ๊ฑด ๊ฒฐ๊ณผ
๐Ÿท๏ธ ๋ฏธํƒœ๊น… ์ž์‚ฐ ์ƒ์„ฑ
ํ•„์ˆ˜ ํƒœ๊ทธ ์—†๋Š” ๋ฆฌ์†Œ์Šค ์ƒ์„ฑ High - ํƒœ๊ทธ ์ถ”๊ฐ€ ํ•„์š”
โž• ์‹ ๊ทœ ์ž์‚ฐ ์ƒ์„ฑ
์ƒˆ ๋ฆฌ์†Œ์Šค ์ƒ์„ฑ (ํƒœ๊ทธ ์™„๋น„) โœ“ ์ž์‚ฐ ๋ชฉ๋ก ์ž๋™ ๊ฐฑ์‹ 
๐Ÿ’ค ๋ฏธ์‚ฌ์šฉ ์ž์‚ฐ ํƒ์ง€
90์ผ+ ๋ฏธ์ ‘๊ทผ ๋ฆฌ์†Œ์Šค Medium - ํ๊ธฐ ๊ฒ€ํ†  ํ•„์š”
๐Ÿ—‘๏ธ ์ž์‚ฐ ์‚ญ์ œ
๋ฆฌ์†Œ์Šค ์ข…๋ฃŒ โœ“ ๋ชฉ๋ก ์ž๋™ ๋ฐ˜์˜

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

๋ฆฌ์†Œ์Šค ์œ ํ˜•/ID ๋ˆ„๋ฝ๋œ ํƒœ๊ทธ ๋ชฉ๋ก ์ƒ์„ฑ ์ฃผ์ฒด (IAM) ํƒœ๊ทธ ์ถ”๊ฐ€ ๊ฐ€์ด๋“œ
โœ“

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

โŒ ๋ฌธ์ œ

Config ๋ฏธํ™œ์„ฑํ™”, ํƒœ๊ทธ ์ •์ฑ… ์—†์Œ, ์ž์‚ฐ ๋ถ„๋ฅ˜ ๋ถˆ๊ฐ€

โœ“ ์ ์šฉ

Config + Aggregator + Tag Policy + Resource Groups

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
asset-identification.tf
# 1. AWS Config ํ™œ์„ฑํ™” (์ž์‚ฐ ์ž๋™ ํƒ์ง€)
resource "aws_config_configuration_recorder" "main" {
  name     = "asset-recorder"
  role_arn = aws_iam_role.config.arn
  recording_group {
    all_supported                 = true
    include_global_resource_types = true
  }
}

# 2. Config Aggregator (๋ฉ€ํ‹ฐ ๊ณ„์ • ํ†ตํ•ฉ)
resource "aws_config_configuration_aggregator" "org" {
  name = "org-asset-aggregator"
  organization_aggregation_source {
    all_regions = true
    role_arn    = aws_iam_role.aggregator.arn
  }
}

# 3. ํ•„์ˆ˜ ํƒœ๊ทธ ๊ฒ€์‚ฌ Rule
resource "aws_config_config_rule" "required_tags" {
  name = "required-asset-tags"
  source {
    owner             = "AWS"
    source_identifier = "REQUIRED_TAGS"
  }
  input_parameters = jsonencode({
    tag1Key = "AssetType"
    tag2Key = "DataClassification"
    tag3Key = "Owner"
    tag4Key = "Environment"
  })
}

# 4. Provider ๊ธฐ๋ณธ ํƒœ๊ทธ
provider "aws" {
  default_tags {
    tags = {
      ManagedBy   = "Terraform"
      Project     = "isms-compliance"
    }
  }
}

๐Ÿ’ก ํ•ต์‹ฌ: Config Recorder๋กœ ๋ชจ๋“  ์ž์‚ฐ์„ ์ž๋™ ํƒ์ง€ํ•˜๊ณ , REQUIRED_TAGS Rule๋กœ ๋ฏธํƒœ๊น… ์ž์‚ฐ์„ ์ž๋™ ํƒ์ง€ํ•ฉ๋‹ˆ๋‹ค. Aggregator๋ฅผ ํ†ตํ•ด ๋ฉ€ํ‹ฐ ๊ณ„์ • ํ™˜๊ฒฝ์—์„œ๋„ ํ†ตํ•ฉ ์ž์‚ฐ ๋ชฉ๋ก์„ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

โ˜๏ธ AWS Config ์ž‘๋™ ๋ฐฉ์‹ โ†— ๐Ÿ“˜ Resource Groups ๊ฐ€์ด๋“œ โ†— ๐Ÿท๏ธ Tag Policies โ†—
๐Ÿ“Š

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

๐Ÿ“‹ ์ง„๋‹จ ํ•ญ๋ชฉ

  • ์ „์ฒด ์ž์‚ฐ ์ˆ˜ (๋ฆฌ์†Œ์Šค ์œ ํ˜•๋ณ„)
  • ๋ฏธํƒœ๊น… ์ž์‚ฐ ์ˆ˜
  • ์ค‘์š”๋„๋ณ„ ์ž์‚ฐ ๋ถ„ํฌ
  • ์‹ ๊ทœ ์ƒ์„ฑ ์ž์‚ฐ (๊ธฐ๊ฐ„๋ณ„)
  • ๋ฏธ์‚ฌ์šฉ ์ž์‚ฐ (90์ผ+)

๐Ÿ“… ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

์‹ ๊ทœ/์‚ญ์ œ ์ž์‚ฐ ์•Œ๋ฆผ

์ฃผ๊ฐ„

์ž์‚ฐ ์ธ๋ฒคํ† ๋ฆฌ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ

๐Ÿ“ค ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)
โšก

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

Config ํ™œ์„ฑํ™” ์—ฌ๋ถ€๋งŒ ๊ฒ€์‚ฌ

  • Config Recorder ์กด์žฌ ์—ฌ๋ถ€ ํ™•์ธ
  • Recording ์ƒํƒœ ํ™•์ธ

ํ•œ๊ณ„: ํƒœ๊ทธ ์ •์ฑ…, Resource Groups, ์ž์‚ฐ ๋ถ„๋ฅ˜ ์ฒด๊ณ„๋Š” ๊ฒ€์‚ฌ ์•ˆํ•จ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • ์‹๋ณ„: Config + Aggregator ๊ฒ€์ฆ
  • ๋ถ„๋ฅ˜: Tag Policy ์ ์šฉ ํ™•์ธ
  • ์ค‘์š”๋„: DataClassification ํƒœ๊ทธ ๊ฒ€์ฆ
  • ๋ชฉ๋ก: ์ž์‚ฐ ์ธ๋ฒคํ† ๋ฆฌ ์ž๋™ํ™” ํ™•์ธ

์ฐจ๋ณ„์ : ์ธ์ฆ ๊ธฐ์ค€ ๊ด€์ ์—์„œ ํƒ์ง€ โ†’ ๋ถ„๋ฅ˜ โ†’ ์ฆ์  ์ „ ๊ณผ์ • ์ž๋™ํ™”

โ† ISMS-P Compliance๋กœ ๋Œ์•„๊ฐ€๊ธฐ