<- ISMS-P Compliance Support

ISMS-P 1.4.1 ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ์ค€์ˆ˜ ๊ฒ€ํ†  High Risk

๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ์ด ๊ทœ์ •์— ๋ฐ˜์˜๋˜๊ณ  ์ค€์ˆ˜ ์—ฌ๋ถ€๊ฐ€ ์ง€์†์ ์œผ๋กœ ๊ฒ€ํ† ๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 1.4.1์€ ์ •๋ณด๋ณดํ˜ธ ๋ฐ ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ ๊ด€๋ จ ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ์„ ์ฃผ๊ธฐ์ ์œผ๋กœ ํŒŒ์•…ํ•˜์—ฌ ๊ทœ์ •์— ๋ฐ˜์˜ํ•˜๊ณ  ์ค€์ˆ˜ ์—ฌ๋ถ€๋ฅผ ๊ฒ€ํ† ํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” Security Standards ๊ตฌ๋…, Audit Manager ์ฆ์  ์ˆ˜์ง‘, Compliance ์ž๋™ ๊ฒ€์ฆ ์ฒด๊ณ„๋ฅผ ํ†ตํ•ด ์ง€์†์ ์ธ ์ค€์ˆ˜ ๋ชจ๋‹ˆํ„ฐ๋ง์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

📋

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 1.4.1 ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ์ค€์ˆ˜ ๊ฒ€ํ† 

1.4.1

๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ์ค€์ˆ˜ ๊ฒ€ํ† 

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์กฐ์ง์ด ์ค€์ˆ˜ํ•˜์—ฌ์•ผ ํ•  ์ •๋ณด๋ณดํ˜ธ ๋ฐ ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ ๊ด€๋ จ ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ์„ ์ฃผ๊ธฐ์ ์œผ๋กœ ํŒŒ์•…ํ•˜์—ฌ ๊ทœ์ •์— ๋ฐ˜์˜ํ•˜๊ณ , ์ค€์ˆ˜ ์—ฌ๋ถ€๋ฅผ ์ง€์†์ ์œผ๋กœ ๊ฒ€ํ† ํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

📌 ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • Security Standards ๊ตฌ๋… ๋ฐ ์ž๋™ ์—…๋ฐ์ดํŠธ
  • Conformance Pack ๊ธฐ๋ฐ˜ ๋ฒ•๊ทœ ์ž๋™ ์ ์šฉ
  • Security Hub ์‹ค์‹œ๊ฐ„ Compliance ๊ฒ€์ฆ
  • Audit Manager ์ฆ์  ์ž๋™ ์ˆ˜์ง‘

⚠️ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: Security Standards ๋ฏธ๊ตฌ๋…
  • ๊ฒฐํ•จ: Compliance ๊ฒ€์ฆ ์ฒด๊ณ„ ๋ถ€์žฌ
  • ๊ถŒ๊ณ : ์ฆ์  ์ž๋™ ์ˆ˜์ง‘ ๋ฏธ๊ตฌ์„ฑ
📄 KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ ☁️ AWS Security Hub Standards
📰

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ๋ฏธ์ค€์ˆ˜๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2018.09

British Airways GDPR ์œ„๋ฐ˜

์‚ฌ์ด๋ฒ„ ๊ณต๊ฒฉ์œผ๋กœ ์•ฝ 50๋งŒ ๋ช… ๊ณ ๊ฐ์˜ ๊ฐœ์ธ์ •๋ณด ์œ ์ถœ. GDPR ์š”๊ตฌ์‚ฌํ•ญ ๋ฏธ๋ฐ˜์˜์œผ๋กœ ์ ์ ˆํ•œ ๊ธฐ์ˆ ์ /์กฐ์ง์  ๋ณด์•ˆ ์กฐ์น˜ ๋ฏธ์ดํ–‰ ํŒ์ •. 2,000๋งŒ ํŒŒ์šด๋“œ ๋ฒŒ๊ธˆ.

💡 ๊ตํ›ˆ: ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ์ค€์ˆ˜ ๊ฒ€ํ†  ์ฒด๊ณ„ + ์ •๊ธฐ ๋ณด์•ˆ ์ ๊ฒ€ ํ•„์ˆ˜

์ถœ์ฒ˜: EDPB/ICO ๊ณต์‹ ๋ฐœํ‘œ ↗
2019.07

Facebook 50์–ต ๋‹ฌ๋Ÿฌ ๋ฒŒ๊ธˆ

Cambridge Analytica ์‚ฌ๊ฑด. 8,700๋งŒ ๋ช… ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ๋ฅผ ๋™์˜ ์—†์ด ์ œ3์ž์—๊ฒŒ ์ œ๊ณต. 2012๋…„ FTC ํ•ฉ์˜ ์กฐํ•ญ ์œ„๋ฐ˜์œผ๋กœ ์—ญ๋Œ€ ์ตœ๋Œ€ ๊ฐœ์ธ์ •๋ณด ๋ฒŒ๊ธˆ.

💡 ๊ตํ›ˆ: ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ์ง€์† ๋ชจ๋‹ˆํ„ฐ๋ง + ์ปดํ”Œ๋ผ์ด์–ธ์Šค ์ž๋™ํ™” ํ•„์ˆ˜

์ถœ์ฒ˜: FTC Press Release ↗

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ์ค€์ˆ˜ ์ฒด๊ณ„๊ฐ€ ๋ฏธํกํ•œ ์ƒํ™ฉ

์ˆ˜๋™ ๊ด€๋ฆฌ (์œ„ํ—˜)

  • ์š”๊ตฌ์‚ฌํ•ญ ํŒŒ์•…: ์ˆ˜๋™ ๋ชจ๋‹ˆํ„ฐ๋ง (๋ˆ„๋ฝ ์œ„ํ—˜)
  • ๊ทœ์ • ๋ฐ˜์˜: ์ˆ˜๋™ ์ •์ฑ… ์ ์šฉ (์ง€์—ฐ ๋ฐœ์ƒ)
  • ์ค€์ˆ˜ ๊ฒ€ํ† : ์ •๊ธฐ ์ˆ˜๋™ ์ ๊ฒ€ (์‹ค์‹œ๊ฐ„ ๋ถˆ๊ฐ€)
  • ์ฆ์  ๊ด€๋ฆฌ: ๋ฌธ์„œ ๊ธฐ๋ฐ˜ ๊ด€๋ฆฌ (๋ˆ„๋ฝ ์œ„ํ—˜)

์ž๋™ํ™” ๊ด€๋ฆฌ (๊ถŒ์žฅ)

  • ์š”๊ตฌ์‚ฌํ•ญ ํŒŒ์•…: Security Standards ๊ตฌ๋…
  • ๊ทœ์ • ๋ฐ˜์˜: Conformance Pack ์ž๋™ ์ ์šฉ
  • ์ค€์ˆ˜ ๊ฒ€ํ† : Security Hub ์‹ค์‹œ๊ฐ„ Compliance
  • ์ฆ์  ๊ด€๋ฆฌ: Audit Manager ์ž๋™ ์ˆ˜์ง‘
🚨

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: Security Standards ๋ฏธ๊ตฌ๋… + Audit Manager ๋ฏธ์‚ฌ์šฉ

Security Hub๋Š” ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์œผ๋‚˜ CIS, PCI-DSS ๋“ฑ ๋ฒ•๊ทœ ๊ธฐ๋ฐ˜ Standards๊ฐ€ ๋ฏธ๊ตฌ๋… ์ƒํƒœ์ž…๋‹ˆ๋‹ค. ๋˜ํ•œ Audit Manager๊ฐ€ ๋ฏธ์„ค์ •๋˜์–ด ์ฆ์  ์ž๋™ ์ˆ˜์ง‘์ด ๋ถˆ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

ISMS-P 1.4.1 ์œ„๋ฐ˜ ์‚ฌํ•ญ

์š”๊ตฌ์‚ฌํ•ญ ๋ฏธํŒŒ์•…: Security Standards ๋ฏธ๊ตฌ๋…

๊ทœ์ • ๋ฏธ๋ฐ˜์˜: Conformance Pack ๋ฏธ์ ์šฉ

์ค€์ˆ˜ ๋ฏธ๊ฒ€ํ† : Compliance ์ž๋™ ๊ฒ€์ฆ ์—†์Œ

์ฆ์  ๋ฏธ๊ด€๋ฆฌ: Audit Manager ๋ฏธ์‚ฌ์šฉ

🔍

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ์ค€์ˆ˜ ์ฒด๊ณ„ ํƒ์ง€ ๋กœ์ง

ํƒ์ง€ ๋Œ€์ƒ ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
Security Standards aws_securityhub_standards_subscription CIS/PCI-DSS ๋ฏธ๊ตฌ๋… Critical
Audit Manager aws_auditmanager_account_registration ๋ฏธ์กด์žฌ High
Conformance Pack aws_config_conformance_pack ๋ฒ•๊ทœ ๊ด€๋ จ Pack ๋ฏธ์กด์žฌ High
์ฆ์  ๋ณด๊ด€ ์ •์ฑ… aws_s3_bucket_lifecycle_configuration expiration < 5๋…„ Medium
🔔

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ด์ƒํ–‰์œ„ ํƒ์ง€

Compliance ์ƒํƒœ ๋ณ€๊ฒฝ ๋Ÿฐํƒ€์ž„ ๋Œ€์‘ ๋กœ์ง

ํƒ์ง€ ์‹œ๋‚˜๋ฆฌ์˜ค ์กฐ๊ฑด ๊ฒฐ๊ณผ
์‹ ๊ทœ ๋ฒ•๊ทœ/ํ‘œ์ค€ ์ƒˆ๋กœ์šด Security Standard ๋ฐœํ‘œ Info - ๊ตฌ๋… ๊ฒ€ํ†  ๊ถŒ๊ณ 
Non-Compliant ๋ฆฌ์†Œ์Šค Security Hub Compliance ์ƒํƒœ ์œ„๋ฐ˜ High - ์ฆ‰์‹œ ์กฐ์น˜ ํ•„์š”
์ฆ์  ์ˆ˜์ง‘ ์‹คํŒจ Audit Manager Evidence ๋ฏธ์ˆ˜์ง‘ Medium - ์ˆ˜์ง‘ ์˜ค๋ฅ˜ ํ™•์ธ
๋ฆฌํฌํŠธ ์ง€์—ฐ ์›”๊ฐ„ Compliance ๋ฆฌํฌํŠธ ๋ฏธ์ƒ์„ฑ Medium - ๋ฆฌํฌํŠธ ์ƒ์„ฑ ํ•„์š”

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

์œ„๋ฐ˜ Standard ๋ช… Non-Compliant ๋ฆฌ์†Œ์Šค ์กฐ์น˜ ๊ถŒ๊ณ ์•ˆ Conformance Pack ์ ์šฉ ๊ฐ€์ด๋“œ

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

❌ ํ˜„์žฌ ์ƒํƒœ

Security Standards ๋ฏธ๊ตฌ๋…, Audit Manager ๋ฏธ์‚ฌ์šฉ, ์ฆ์  ์ž๋™ ์ˆ˜์ง‘ ๋ถˆ๊ฐ€

✓ ๊ถŒ์žฅ ์ƒํƒœ

CIS/PCI-DSS ๊ตฌ๋…, Audit Manager ํ™œ์„ฑํ™”, 5๋…„ ์ฆ์  ๋ณด๊ด€ ์ •์ฑ… ์ ์šฉ

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
compliance.tf
# 1. Security Hub ํ™œ์„ฑํ™”
resource "aws_securityhub_account" "main" {}

# 2. Security Standards ๊ตฌ๋… (๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ๊ธฐ์ค€)
resource "aws_securityhub_standards_subscription" "cis" {
  standards_arn = "arn:aws:securityhub:::ruleset/cis-aws-foundations-benchmark/v/1.4.0"
  depends_on    = [aws_securityhub_account.main]
}

resource "aws_securityhub_standards_subscription" "pci_dss" {
  standards_arn = "arn:aws:securityhub:::ruleset/pci-dss/v/3.2.1"
  depends_on    = [aws_securityhub_account.main]
}

# 3. Audit Manager ํ™œ์„ฑํ™”
resource "aws_auditmanager_account_registration" "main" {
  kms_key = aws_kms_key.audit.arn
}

# 4. ์ฆ์  ๋ณด๊ด€ ๋ฒ„ํ‚ท (5๋…„ ๋ณด๊ด€)
resource "aws_s3_bucket_lifecycle_configuration" "evidence" {
  bucket = aws_s3_bucket.audit_evidence.id

  rule {
    id     = "retain-evidence"
    status = "Enabled"
    expiration { days = 1825 }  # 5๋…„ ๋ณด๊ด€
  }
}

💡 ํ•ต์‹ฌ: Security Standards ๊ตฌ๋…์œผ๋กœ ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ์„ ์ž๋™์œผ๋กœ ํŒŒ์•…ํ•˜๊ณ , Audit Manager๋กœ ์ฆ์ ์„ ์ž๋™ ์ˆ˜์ง‘ํ•˜์—ฌ ISMS-P ์‹ฌ์‚ฌ ๋Œ€๋น„๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

📚 ์ฐธ๊ณ  ์ž๋ฃŒ

☁️ Security Hub Standards 📊 AWS Audit Manager 📦 Config Conformance Packs
📊

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

📋 ์ง„๋‹จ ํ•ญ๋ชฉ

  • Security Standards ๊ตฌ๋… ํ˜„ํ™ฉ
  • Non-Compliant ๋ฆฌ์†Œ์Šค ๋ชฉ๋ก
  • Audit Manager ์ฆ์  ์ˆ˜์ง‘ ์ƒํƒœ
  • Conformance Pack ์ ์šฉ ํ˜„ํ™ฉ
  • ์‹œ๊ฐ„๋ณ„ ์ค€์ˆ˜์œจ ์ถ”์ด

📅 ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

Compliance ์ƒํƒœ ๋ณ€๊ฒฝ ์•Œ๋ฆผ

์ฃผ๊ฐ„

์ค€์ˆ˜์œจ ํ˜„ํ™ฉ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ

📤 ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

Security Hub ํ™œ์„ฑํ™”๋งŒ ๊ฒ€์‚ฌ

  • Security Hub ํ™œ์„ฑํ™” ์—ฌ๋ถ€๋งŒ ํ™•์ธ
  • Security Standards ๊ตฌ๋… ์—ฌ๋ถ€ ๋ฏธํ™•์ธ
  • Audit Manager ๋ฏธ๊ฒ€์‚ฌ

ํ•œ๊ณ„: ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ๋ฐ˜์˜ + ์ฆ์  ์ˆ˜์ง‘ ์ฒด๊ณ„๋Š” ํƒ์ง€ ๋ชปํ•จ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • ํŒŒ์•…: Security Standards ๊ตฌ๋… ๊ฒ€์‚ฌ
  • ๋ฐ˜์˜: Conformance Pack ์ ์šฉ ๊ฒ€์‚ฌ
  • ๊ฒ€ํ† : Compliance ์ž๋™ ๊ฒ€์ฆ ํ™•์ธ
  • ์ฆ์ : Audit Manager 5๋…„ ๋ณด๊ด€ ๊ฒ€์ฆ

์ฐจ๋ณ„์ : ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ํŒŒ์•… -> ๋ฐ˜์˜ -> ๊ฒ€ํ†  -> ์ฆ์  ์ „ ๊ณผ์ • ์ž๋™ํ™”

<- ISMS-P Compliance Support๋กœ ๋Œ์•„๊ฐ€๊ธฐ