โ† ISMS-P Compliance Support

ISMS-P 1.2.3 ์œ„ํ—˜ ํ‰๊ฐ€ High Risk

์œ„ํ—˜ ํ‰๊ฐ€๊ฐ€ ์ฒด๊ณ„์ ์œผ๋กœ ์ˆ˜ํ–‰๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 1.2.3์€ ์กฐ์ง์˜ ๋Œ€๋‚ด์™ธ ํ™˜๊ฒฝ๋ถ„์„์„ ํ†ตํ•ด ์œ„ํ—˜์„ ์‹๋ณ„ํ•˜๊ณ  ์œ„ํ—˜ ์ˆ˜์ค€์„ ๊ฒฐ์ •ํ•˜์—ฌ ์ฒ˜๋ฆฌ ์ „๋žต์„ ์ˆ˜๋ฆฝํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” Security Hub + Inspector ๊ธฐ๋ฐ˜์œผ๋กœ ์œ„ํ—˜ ์ž๋™ ํƒ์ง€ ๋ฐ ์‹ฌ๊ฐ๋„ ๊ธฐ๋ฐ˜ ๋ถ„๋ฅ˜๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

📋

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 1.2.3 ์œ„ํ—˜ ํ‰๊ฐ€ ์š”๊ตฌ์‚ฌํ•ญ

1.2.3

์œ„ํ—˜ ํ‰๊ฐ€

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์กฐ์ง์˜ ๋Œ€๋‚ด์™ธ ํ™˜๊ฒฝ๋ถ„์„์„ ํ†ตํ•ด ์œ ์ถœ, ๋ณ€์กฐ, ํ›ผ์†์˜ ์œ„ํ—˜์„ ์‹๋ณ„ํ•˜๊ณ , ์œ„ํ—˜์˜ ๋ฐœ์ƒ ๊ฐ€๋Šฅ์„ฑ, ์˜ํ–ฅ๋„๋ฅผ ๋ถ„์„ํ•˜์—ฌ ์œ„ํ—˜ ์ˆ˜์ค€์„ ๊ฒฐ์ •ํ•˜๊ณ  ์ฒ˜๋ฆฌ์ „๋žต์„ ์ˆ˜๋ฆฝํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

📌 ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • Security Hub ์ž๋™ ์œ„ํ—˜ ํƒ์ง€
  • Inspector ์ทจ์•ฝ์  ์Šค์บ”
  • Severity Score ๊ธฐ๋ฐ˜ ์œ„ํ—˜ ๋ถ„๋ฅ˜
  • ์ž๋™ Remediation ์ฒ˜๋ฆฌ ์ „๋žต

⚠️ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ์œ„ํ—˜ ์‹๋ณ„ ์ฒด๊ณ„ ๋ฏธ๊ตฌ์ถ•
  • ๊ฒฐํ•จ: ์œ„ํ—˜ ์ˆ˜์ค€ ๊ฒฐ์ • ๊ธฐ์ค€ ๋ถ€์žฌ
  • ๊ถŒ๊ณ : ์ฒ˜๋ฆฌ ์ „๋žต ์ˆ˜๋ฆฝ ๋ฏธํก
📄 KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ ☁️ AWS Security Hub
📰

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

์œ„ํ—˜ ํ‰๊ฐ€ ๋ฏธํก์œผ๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2020.12

SolarWinds ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ

์ œ3์ž ์†Œํ”„ํŠธ์›จ์–ด ์œ„ํ—˜ ํ‰๊ฐ€ ๋ฏธํก์œผ๋กœ ๋Œ€๊ทœ๋ชจ ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ ๋ฐœ์ƒ. ๋Ÿฌ์‹œ์•„ ๊ตญ๊ฐ€์ง€์› ํ•ด์ปค(SVR)๊ฐ€ Orion ์†Œํ”„ํŠธ์›จ์–ด ์—…๋ฐ์ดํŠธ์— ์•…์„ฑ์ฝ”๋“œ๋ฅผ ์‚ฝ์ž…ํ•˜์—ฌ ๋ฏธ ์ •๋ถ€ ๊ธฐ๊ด€ ๋ฐ ๋ฏผ๊ฐ„ ๊ธฐ์—… 18,000์—ฌ ๊ณณ์— ์นจํˆฌ.

💡 ๊ตํ›ˆ: ๊ณต๊ธ‰๋ง ์†Œํ”„ํŠธ์›จ์–ด ํฌํ•จ ์ „๋ฐฉ์œ„ ์œ„ํ—˜ ํ‰๊ฐ€ + ์ง€์†์  ๋ชจ๋‹ˆํ„ฐ๋ง ํ•„์ˆ˜

์ถœ์ฒ˜: CISA Advisory AA20-352A ↗
2021.12

Log4j ์›๊ฒฉ์ฝ”๋“œ์‹คํ–‰ ์ทจ์•ฝ์ 

์˜คํ”ˆ์†Œ์Šค ์˜์กด์„ฑ ์œ„ํ—˜ ํ‰๊ฐ€ ๋ฏธํก์œผ๋กœ CVE-2021-44228 (Log4Shell) ์ทจ์•ฝ์  ์‚ฌ์ „ ํƒ์ง€ ์‹คํŒจ. CVSS 10.0 Critical ๋“ฑ๊ธ‰, ์ „ ์„ธ๊ณ„ ์ˆ˜์–ต ๊ฐœ ์‹œ์Šคํ…œ์— ์˜ํ–ฅ. ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰์„ ํ†ตํ•œ ์‹œ์Šคํ…œ ์™„์ „ ์žฅ์•… ๊ฐ€๋Šฅ.

💡 ๊ตํ›ˆ: ์˜์กด์„ฑ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ํฌํ•จ ์ทจ์•ฝ์  ์ž๋™ ์Šค์บ” + ์ฆ‰์‹œ ํŒจ์น˜ ์ฒด๊ณ„ ํ•„์ˆ˜

์ถœ์ฒ˜: NIST NVD CVE-2021-44228 ↗

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

์œ„ํ—˜ ํ‰๊ฐ€ ์ฒด๊ณ„๊ฐ€ ๋ฏธ๊ตฌ์ถ•๋œ ์ƒํ™ฉ

❌ ์œ„ํ—˜ ์ƒํƒœ

  • ์œ„ํ—˜ ์‹๋ณ„: ๋ฏธ์ˆ˜ํ–‰
  • ๋ฐœ์ƒ ๊ฐ€๋Šฅ์„ฑ: ๋ฏธ๋ถ„์„
  • ์˜ํ–ฅ๋„: ๋ฏธ์‚ฐ์ •
  • ์œ„ํ—˜ ์ˆ˜์ค€: ๋ฏธ๊ฒฐ์ •
  • ์ฒ˜๋ฆฌ ์ „๋žต: ๋ฏธ์ˆ˜๋ฆฝ

✅ ๊ถŒ์žฅ ์ƒํƒœ

  • ์œ„ํ—˜ ์‹๋ณ„: Security Hub + Inspector
  • ๋ฐœ์ƒ ๊ฐ€๋Šฅ์„ฑ: Finding ๋นˆ๋„ ๋ถ„์„
  • ์˜ํ–ฅ๋„: Severity Score ํ™œ์šฉ
  • ์œ„ํ—˜ ์ˆ˜์ค€: Critical/High/Medium ๋ถ„๋ฅ˜
  • ์ฒ˜๋ฆฌ ์ „๋žต: ์ž๋™ Remediation ์„ค์ •
🚨

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: ์œ„ํ—˜ ํ‰๊ฐ€ ์ฒด๊ณ„ ๋ฏธ๊ตฌ์ถ•

Security Hub, Inspector๊ฐ€ ๋ฏธํ™œ์„ฑํ™”๋˜์–ด ์žˆ์–ด ์œ„ํ—˜ ์ž๋™ ํƒ์ง€๊ฐ€ ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์ทจ์•ฝ์  ๋ฐœ์ƒ ์‹œ ์ˆ˜๋™ ๋ถ„์„์— ์˜์กดํ•˜์—ฌ ํƒ์ง€ ์ง€์—ฐ ๋ฐ ๋Œ€์‘ ๋ˆ„๋ฝ ์œ„ํ—˜์ด ๋†’์Šต๋‹ˆ๋‹ค.

ํ˜„์žฌ ์ƒํƒœ - ์œ„ํ—˜ ํ‰๊ฐ€ ์ฒด๊ณ„ ๋ถ€์žฌ
# Terraform (๋ฌธ์ œ)
# ์œ„ํ—˜ ํ‰๊ฐ€ ์ฒด๊ณ„ ๋ฏธ๊ตฌ์ถ•

# Security Hub ๋ฏธํ™œ์„ฑํ™”
# resource "aws_securityhub_account" ๋ฏธ์กด์žฌ

# Inspector ๋ฏธํ™œ์„ฑํ™”
# resource "aws_inspector2_enabler" ๋ฏธ์กด์žฌ

# Security Standards ๋ฏธ์ ์šฉ
# resource "aws_securityhub_standards_subscription" ๋ฏธ์กด์žฌ

# ์œ„ํ—˜ ์•Œ๋ฆผ ๋ฏธ์„ค์ •
# resource "aws_cloudwatch_event_rule" ๋ฏธ์กด์žฌ

ISMS-P 1.2.3 ์œ„๋ฐ˜ ์‚ฌํ•ญ

์œ„ํ—˜ ๋ฏธ์‹๋ณ„: Security Hub ๋ฏธํ™œ์„ฑํ™”

์ทจ์•ฝ์  ๋ฏธ์Šค์บ”: Inspector ๋ฏธ์„ค์ •

์œ„ํ—˜ ์ˆ˜์ค€ ๋ฏธ๊ฒฐ์ •: ๋ถ„๋ฅ˜ ์ฒด๊ณ„ ์—†์Œ

์ฒ˜๋ฆฌ ์ „๋žต ๋ฏธ์ˆ˜๋ฆฝ: Remediation ์—†์Œ

🔍

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

์œ„ํ—˜ ํ‰๊ฐ€ ์ฒด๊ณ„ ํƒ์ง€ ๋กœ์ง

ํƒ์ง€ ๋Œ€์ƒ ์กฐ๊ฑด ๊ฒฐ๊ณผ
Security Hub aws_securityhub_account ๋ฏธ์กด์žฌ Critical - ์œ„ํ—˜ ํƒ์ง€ ๋ถˆ๊ฐ€
Inspector aws_inspector2_enabler ๋ฏธ์กด์žฌ High - ์ทจ์•ฝ์  ์Šค์บ” ๋ถˆ๊ฐ€
Security Standards aws_securityhub_standards_subscription ๋ฏธ์กด์žฌ High - ๊ธฐ์ค€ ๋ฏธ์ ์šฉ
Auto Remediation EventBridge + Lambda ๋ฏธ์„ค์ • Medium - ์ฒ˜๋ฆฌ ์ „๋žต ๋ถ€์žฌ
🔔

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์œ„ํ—˜ ํƒ์ง€ ๋Œ€์‘

Security Hub Finding ๋Œ€์‘ ๋กœ์ง

ํƒ์ง€ ์‹œ๋‚˜๋ฆฌ์˜ค ์กฐ๊ฑด ๊ฒฐ๊ณผ
Critical Finding Severity = CRITICAL Critical - PagerDuty ์ฆ‰์‹œ ํ˜ธ์ถœ
High Finding Severity = HIGH High - Slack ์•Œ๋ฆผ + ์ž๋™ ์กฐ์น˜
์‹ ๊ทœ CVE ํƒ์ง€ Inspector ์ƒˆ ์ทจ์•ฝ์  ๋ฐœ๊ฒฌ High - ํŒจ์น˜ ์šฐ์„ ์ˆœ์œ„ ๋ถ€์—ฌ
๋ฏธ์ฒ˜๋ฆฌ ์œ„ํ—˜ 30์ผ+ ๋ฏธ์กฐ์น˜ Finding High - ์—์Šค์ปฌ๋ ˆ์ด์…˜

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

Finding ID ์˜ํ–ฅ๋ฐ›๋Š” ๋ฆฌ์†Œ์Šค Severity Score ๊ถŒ์žฅ ์กฐ์น˜ ๊ฐ€์ด๋“œ

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

๊ถŒ์žฅ ์„ค์ • (Terraform)
risk-assessment.tf
# 1. Security Hub ํ™œ์„ฑํ™” (์œ„ํ—˜ ํ†ตํ•ฉ ๊ด€๋ฆฌ)
resource "aws_securityhub_account" "main" {}

resource "aws_securityhub_standards_subscription" "aws_foundational" {
  standards_arn = "arn:aws:securityhub:::ruleset/aws-foundational-security-best-practices/v/1.0.0"
}

resource "aws_securityhub_standards_subscription" "cis" {
  standards_arn = "arn:aws:securityhub:::ruleset/cis-aws-foundations-benchmark/v/1.4.0"
}

# 2. Inspector ํ™œ์„ฑํ™” (์ทจ์•ฝ์  ์Šค์บ”)
resource "aws_inspector2_enabler" "main" {
  account_ids    = [data.aws_caller_identity.current.account_id]
  resource_types = ["EC2", "ECR", "LAMBDA"]
}

# 3. ์œ„ํ—˜ ์ˆ˜์ค€๋ณ„ ์•Œ๋ฆผ ์„ค์ •
resource "aws_cloudwatch_event_rule" "critical_findings" {
  name = "critical-security-findings"

  event_pattern = jsonencode({
    source      = ["aws.securityhub"]
    detail-type = ["Security Hub Findings - Imported"]
    detail = {
      findings = {
        Severity = { Label = ["CRITICAL", "HIGH"] }
      }
    }
  })
}

# 4. ์ž๋™ Remediation (์œ„ํ—˜ ์ฒ˜๋ฆฌ ์ „๋žต)
resource "aws_lambda_function" "auto_remediate" {
  function_name = "security-auto-remediation"
  handler       = "index.handler"
  runtime       = "python3.11"
  role          = aws_iam_role.remediation.arn
}
🛡

Security Hub

์œ„ํ—˜ ํ†ตํ•ฉ ๊ด€๋ฆฌ

🔍

Inspector

์ทจ์•ฝ์  ์ž๋™ ์Šค์บ”

📈

Severity

์œ„ํ—˜ ์ˆ˜์ค€ ์ž๋™ ๋ถ„๋ฅ˜

Auto Remediation

์œ„ํ—˜ ์ฒ˜๋ฆฌ ์ž๋™ํ™”

📊

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

📋 ์ง„๋‹จ ํ•ญ๋ชฉ

  • Security Hub ํ™œ์„ฑํ™” ์—ฌ๋ถ€
  • Inspector ์ปค๋ฒ„๋ฆฌ์ง€ ํ˜„ํ™ฉ
  • Critical/High Finding ๊ฐœ์ˆ˜
  • ํ‰๊ท  ์กฐ์น˜ ์†Œ์š” ์‹œ๊ฐ„
  • ๋ฏธ์กฐ์น˜ Finding ์ˆ˜

📅 ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

Critical Finding ์•Œ๋ฆผ

์ฃผ๊ฐ„

์œ„ํ—˜ ํ˜„ํ™ฉ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ

📤 ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

๊ฐœ๋ณ„ ์„œ๋น„์Šค ์ ๊ฒ€๋งŒ ์ˆ˜ํ–‰

  • Security Hub ํ™œ์„ฑํ™” ์—ฌ๋ถ€๋งŒ ํ™•์ธ
  • Security Standards ์ ์šฉ ๋ฏธํ™•์ธ
  • Inspector ์—ฐ๋™ ๋ฏธ๊ฒ€์‚ฌ
  • ์ž๋™ Remediation ๋ฏธํ™•์ธ

ํ•œ๊ณ„: ISMS-P ๊ด€์ ์˜ ์œ„ํ—˜ ํ‰๊ฐ€ ์ฒด๊ณ„ ์ „์ฒด๋ฅผ ์ ๊ฒ€ํ•˜์ง€ ์•Š์Œ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • ์‹๋ณ„: Security Hub + Inspector ํ†ตํ•ฉ
  • ํ‰๊ฐ€: Severity Score ๊ธฐ๋ฐ˜ ์ž๋™ ๋ถ„๋ฅ˜
  • ์ฒ˜๋ฆฌ: Auto Remediation ๊ฒ€์ฆ
  • ์ฆ์ : ์œ„ํ—˜ ํ‰๊ฐ€ ๋ฆฌํฌํŠธ ์ž๋™ํ™”

์ฐจ๋ณ„์ : ์ธ์ฆ ๊ธฐ์ค€ ๊ด€์ ์—์„œ ํƒ์ง€ → ์กฐ์น˜ → ์ฆ์  ์ „ ๊ณผ์ • ์ž๋™ํ™”

โ† ISMS-P Compliance Support๋กœ ๋Œ์•„๊ฐ€๊ธฐ