<- ISMS-P Compliance Support

ISMS-P 1.4.2 ๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ High Risk

๊ด€๋ฆฌ์ฒด๊ณ„๊ฐ€ ์ •๊ธฐ์ ์œผ๋กœ ์ ๊ฒ€๋˜๊ณ  ๋ฐœ๊ฒฌ๋œ ๋ฌธ์ œ์ ์ด ๊ฐœ์„ ๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 1.4.2๋Š” ๊ด€๋ฆฌ์ฒด๊ณ„ ์ „๋ฐ˜์— ๋Œ€ํ•œ ์ •๊ธฐ ์ ๊ฒ€ ์ˆ˜ํ–‰๊ณผ ๋ฐœ๊ฒฌ๋œ ๋ฌธ์ œ์  ๊ฐœ์„ ์„ ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” Security Hub ์ง€์† ๋ชจ๋‹ˆํ„ฐ๋ง, Compliance Score ๋ถ„์„, ์ž๋™ ์ ๊ฒ€ ๋ฆฌํฌํŠธ ์ฒด๊ณ„๋ฅผ ํ†ตํ•ด ํšจ๊ณผ์ ์ธ ๊ด€๋ฆฌ์ฒด๊ณ„ ์šด์˜์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

📋

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 1.4.2 ๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€

1.4.2

๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"๊ด€๋ฆฌ์ฒด๊ณ„๊ฐ€ ์กฐ์ง์˜ ์ •๋ณด๋ณดํ˜ธ ๋ฐ ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ ๋ชฉํ‘œ์™€ ์ •์ฑ…์— ๋ถ€ํ•ฉํ•˜๋Š”์ง€, ํšจ๊ณผ์ ์œผ๋กœ ์šด์˜๋˜๊ณ  ์žˆ๋Š”์ง€๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ์ •๊ธฐ์ ์œผ๋กœ ๊ด€๋ฆฌ์ฒด๊ณ„ ์ „๋ฐ˜์— ๋Œ€ํ•œ ์ ๊ฒ€์„ ์ˆ˜ํ–‰ํ•˜๊ณ  ๋ฐœ๊ฒฌ๋œ ๋ฌธ์ œ์ ์„ ๊ฐœ์„ ํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

📌 ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • Security Hub ์ง€์† ๋ชจ๋‹ˆํ„ฐ๋ง ํ™œ์„ฑํ™”
  • Compliance Score ์‹ค์‹œ๊ฐ„ ๋ถ„์„
  • Findings ์ž๋™ ํƒ์ง€ ๋ฐ ๋ถ„๋ฅ˜
  • ์›”๊ฐ„ ์ ๊ฒ€ ๋ฆฌํฌํŠธ ์ž๋™ํ™”

⚠️ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ์ •๊ธฐ ์ ๊ฒ€ ์Šค์ผ€์ค„ ๋ฏธ์กด์žฌ
  • ๊ฒฐํ•จ: ๊ฐœ์„  ์ถ”์  ์ฒด๊ณ„ ๋ถ€์žฌ
  • ๊ถŒ๊ณ : ์ ๊ฒ€ ๋ฆฌํฌํŠธ ์ž๋™ํ™” ๋ฏธ๊ตฌ์„ฑ
📄 KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ ☁️ AWS Security Hub
📰

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ ๋ฏธํก์œผ๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2013-2014

Yahoo 30์–ต ๊ณ„์ • ์นจํ•ด

2013๋…„ ๋ฐœ์ƒํ•œ ์นจํ•ด ์‚ฌ๊ณ ๊ฐ€ 2๋…„ ์ด์ƒ ๋ฏธ๋ฐœ๊ฒฌ. ๊ด€๋ฆฌ์ฒด๊ณ„ ์ •๊ธฐ ์ ๊ฒ€ ๋ฏธํก์œผ๋กœ ์—ญ๋Œ€ ์ตœ๋Œ€ ๊ทœ๋ชจ ๋ฐ์ดํ„ฐ ์œ ์ถœ. Verizon ์ธ์ˆ˜๊ฐ€ 3.5์–ต ๋‹ฌ๋Ÿฌ ๊ฐ์†Œ.

💡 ๊ตํ›ˆ: ์ง€์†์  ๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ + ์‹ค์‹œ๊ฐ„ ์ด์ƒ ํƒ์ง€ ์ฒด๊ณ„ ํ•„์ˆ˜

์ถœ์ฒ˜: NPR ↗
2016

Uber ์นจํ•ด ์‚ฌ๊ณ  1๋…„๊ฐ„ ์€ํ

5,700๋งŒ ๊ณ ๊ฐ/๋“œ๋ผ์ด๋ฒ„ ๋ฐ์ดํ„ฐ ์œ ์ถœ ๋ฐœ๊ฒฌ ํ›„ 1๋…„๊ฐ„ ์€ํ. ๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ ๋ฐ ๋ณด๊ณ  ์ ˆ์ฐจ ๋ฏธ๋น„๋กœ ์กฐ์ง์  ์€ํ ๋ฐœ์ƒ. CSO ํ˜•์‚ฌ ๊ธฐ์†Œ.

💡 ๊ตํ›ˆ: ํˆฌ๋ช…ํ•œ ๋ณด๊ณ  ์ฒด๊ณ„ + ์ž๋™ํ™”๋œ ์ ๊ฒ€ ์ ˆ์ฐจ ํ•„์ˆ˜

์ถœ์ฒ˜: ๋ฏธ๊ตญ ๋ฒ•๋ฌด๋ถ€ (DOJ) ↗

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ ์ฒด๊ณ„๊ฐ€ ๋ฏธํกํ•œ ์ƒํ™ฉ

์ˆ˜๋™ ์ ๊ฒ€ (์œ„ํ—˜)

  • ์ •๊ธฐ ์ ๊ฒ€: ์—ฐ๊ฐ„ 1ํšŒ ์ˆ˜๋™ ๊ฐ์‚ฌ
  • ํšจ๊ณผ์„ฑ ๊ฒ€ํ† : ์ˆ˜๋™ ๋ถ„์„ (์ง€์—ฐ ๋ฐœ์ƒ)
  • ๋ฌธ์ œ ๋ฐœ๊ฒฌ: ์ˆ˜๋™ ์ ๊ฒ€ ์˜์กด
  • ๊ฐœ์„  ์ถ”์ : ๋ฌธ์„œ ๊ธฐ๋ฐ˜ ๊ด€๋ฆฌ

์ž๋™ํ™” ์ ๊ฒ€ (๊ถŒ์žฅ)

  • ์ •๊ธฐ ์ ๊ฒ€: Security Hub ์ง€์† ๋ชจ๋‹ˆํ„ฐ๋ง
  • ํšจ๊ณผ์„ฑ ๊ฒ€ํ† : Compliance Score ์‹ค์‹œ๊ฐ„ ๋ถ„์„
  • ๋ฌธ์ œ ๋ฐœ๊ฒฌ: Findings ์ž๋™ ํƒ์ง€
  • ๊ฐœ์„  ์ถ”์ : ํ‹ฐ์ผ“ ์‹œ์Šคํ…œ ์ž๋™ ์—ฐ๋™
🚨

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: ์ •๊ธฐ ์ ๊ฒ€ ์Šค์ผ€์ค„ ๋ฏธ์กด์žฌ + Compliance Score ๋ชจ๋‹ˆํ„ฐ๋ง ์—†์Œ

Security Hub๋Š” ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์œผ๋‚˜ ์›”๊ฐ„ ์ ๊ฒ€ ์Šค์ผ€์ค„์ด ๋ฏธ์„ค์ • ์ƒํƒœ์ž…๋‹ˆ๋‹ค. Compliance Score ํ•˜๋ฝ ์•Œ๋ฆผ์ด ์—†์–ด ๋ณด์•ˆ ์ƒํƒœ ์•…ํ™”๋ฅผ ์ธ์ง€ํ•˜์ง€ ๋ชปํ•  ์œ„ํ—˜์ด ์žˆ์Šต๋‹ˆ๋‹ค.

ISMS-P 1.4.2 ์œ„๋ฐ˜ ์‚ฌํ•ญ

์ •๊ธฐ ์ ๊ฒ€ ๋ฏธ์ˆ˜ํ–‰: ์ž๋™ํ™” ์Šค์ผ€์ค„ ์—†์Œ

ํšจ๊ณผ์„ฑ ๋ฏธ๊ฒ€ํ† : Compliance Score ๋ถ„์„ ์—†์Œ

๊ฐœ์„  ๋ฏธ์ถ”์ : ํ‹ฐ์ผ“ ์‹œ์Šคํ…œ ์—ฐ๋™ ์—†์Œ

๋ณด๊ณ ์„œ ๋ฏธ์ž‘์„ฑ: ์ž๋™ ๋ฆฌํฌํŠธ ์ฒด๊ณ„ ์—†์Œ

🔍

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ ์ฒด๊ณ„ ํƒ์ง€ ๋กœ์ง

ํƒ์ง€ ๋Œ€์ƒ ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
์ •๊ธฐ ์ ๊ฒ€ ์Šค์ผ€์ค„ aws_cloudwatch_event_rule ์›”๊ฐ„ audit ์Šค์ผ€์ค„ ๋ฏธ์กด์žฌ High
Compliance Dashboard aws_cloudwatch_dashboard Security ๊ด€๋ จ ๋Œ€์‹œ๋ณด๋“œ ๋ฏธ์กด์žฌ Medium
Score ์•Œ๋ฆผ ์„ค์ • aws_cloudwatch_metric_alarm ComplianceScore ์•Œ๋ฆผ ๋ฏธ์กด์žฌ Medium
๋ฆฌํฌํŠธ ์ž๋™ํ™” aws_lambda_function ์›”๊ฐ„ ๋ฆฌํฌํŠธ Lambda ๋ฏธ์กด์žฌ Medium
🔔

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ด์ƒํ–‰์œ„ ํƒ์ง€

๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ ์ƒํƒœ ๋Ÿฐํƒ€์ž„ ๋Œ€์‘ ๋กœ์ง

ํƒ์ง€ ์‹œ๋‚˜๋ฆฌ์˜ค ์กฐ๊ฑด ๊ฒฐ๊ณผ
์ ๊ฒ€ ๋ฏธ์ˆ˜ํ–‰ 30์ผ ์ด์ƒ ์ •๊ธฐ ์ ๊ฒ€ ๋ฏธ์ˆ˜ํ–‰ High - ์ฆ‰์‹œ ์ ๊ฒ€ ํ•„์š”
Compliance ๊ธ‰๋ฝ Security Hub Score 10% ์ด์ƒ ํ•˜๋ฝ High - ์›์ธ ๋ถ„์„ ํ•„์š”
๋ฏธ๊ฐœ์„  ๋ฌธ์ œ High/Critical Finding 60์ผ ์ด์ƒ ๋ฏธ์กฐ์น˜ High - ์—์Šค์ปฌ๋ ˆ์ด์…˜ ํ•„์š”
์ ๊ฒ€ ์ •์ƒ ์ˆ˜ํ–‰ ์›”๊ฐ„ ์ ๊ฒ€ + ๋ฆฌํฌํŠธ ์ƒ์„ฑ ์™„๋ฃŒ Info - ์ •์ƒ ์šด์˜

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

Compliance Score ์ถ”์ด High/Critical Findings ์ˆ˜ ๋ฏธ์กฐ์น˜ ๊ธฐ๊ฐ„ ๊ฐœ์„  ๊ถŒ๊ณ ์•ˆ

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

❌ ํ˜„์žฌ ์ƒํƒœ

์ •๊ธฐ ์ ๊ฒ€ ์Šค์ผ€์ค„ ์—†์Œ, Compliance Score ๋ชจ๋‹ˆํ„ฐ๋ง ์—†์Œ, ๊ฐœ์„  ์ถ”์  ์ฒด๊ณ„ ์—†์Œ

✓ ๊ถŒ์žฅ ์ƒํƒœ

์›”๊ฐ„ ์ž๋™ ์ ๊ฒ€, Score ํ•˜๋ฝ ์•Œ๋ฆผ, Finding ์—์Šค์ปฌ๋ ˆ์ด์…˜ ์ฒด๊ณ„ ์ ์šฉ

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
audit-schedule.tf
# 1. ์ •๊ธฐ ์ ๊ฒ€ ์Šค์ผ€์ค„ (์›”๊ฐ„)
resource "aws_cloudwatch_event_rule" "monthly_audit" {
  name                = "monthly-security-audit"
  schedule_expression = "cron(0 9 1 * ? *)"  # ๋งค์›” 1์ผ ์˜ค์ „ 9์‹œ
}

# 2. Compliance Dashboard
resource "aws_cloudwatch_dashboard" "security_posture" {
  dashboard_name = "security-management-system"
  dashboard_body = jsonencode({
    widgets = [{
      type       = "metric"
      properties = {
        title   = "Compliance Score Trend"
        metrics = [["AWS/SecurityHub", "ComplianceScore"]]
      }
    }]
  })
}

# 3. Compliance Score ํ•˜๋ฝ ์•Œ๋ฆผ
resource "aws_cloudwatch_metric_alarm" "compliance_drop" {
  alarm_name          = "security-compliance-score-drop"
  comparison_operator = "LessThanThreshold"
  threshold           = 80  # 80% ๋ฏธ๋งŒ ์‹œ ์•Œ๋ฆผ
  metric_name         = "ComplianceScore"
  namespace           = "AWS/SecurityHub"
  alarm_actions       = [aws_sns_topic.security_alerts.arn]
}

# 4. ๋ฏธ์กฐ์น˜ Finding ์—์Šค์ปฌ๋ ˆ์ด์…˜
resource "aws_cloudwatch_event_rule" "old_findings" {
  name                = "check-old-security-findings"
  schedule_expression = "rate(1 day)"
}

💡 ํ•ต์‹ฌ: ์›”๊ฐ„ ์ •๊ธฐ ์ ๊ฒ€ ์Šค์ผ€์ค„๋กœ ๊ด€๋ฆฌ์ฒด๊ณ„๋ฅผ ์ง€์†์ ์œผ๋กœ ์ ๊ฒ€ํ•˜๊ณ , Compliance Score ๋ชจ๋‹ˆํ„ฐ๋ง์œผ๋กœ ํšจ๊ณผ์„ฑ์„ ์‹ค์‹œ๊ฐ„ ๊ฒ€ํ† ํ•˜์—ฌ ISMS-P ์‹ฌ์‚ฌ ๋Œ€๋น„๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

📚 ์ฐธ๊ณ  ์ž๋ฃŒ

☁️ AWS Security Hub 📊 CloudWatch Dashboards 📅 CloudWatch Events
📊

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

📋 ์ง„๋‹จ ํ•ญ๋ชฉ

  • Compliance Score ์ถ”์ด
  • ์‹ ๊ทœ ๋ฐœ๊ฒฌ Findings ๋ชฉ๋ก
  • ์กฐ์น˜ ์™„๋ฃŒ/๋ฏธ์กฐ์น˜ ํ˜„ํ™ฉ
  • ์—์Šค์ปฌ๋ ˆ์ด์…˜ ๋Œ€์ƒ ํ•ญ๋ชฉ
  • ์ „์›” ๋Œ€๋น„ ๋ณ€ํ™” ๋ถ„์„

📅 ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

Score ํ•˜๋ฝ ๋ฐ ์‹ ๊ทœ Finding ์•Œ๋ฆผ

์ฃผ๊ฐ„

๊ฐœ์„  ํ˜„ํ™ฉ ์š”์•ฝ ๋ฆฌํฌํŠธ

์›”๊ฐ„

๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ ์ฆ์  ๋ฆฌํฌํŠธ

📤 ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

Security Hub ํ™œ์„ฑํ™”๋งŒ ๊ฒ€์‚ฌ

  • Security Hub ํ™œ์„ฑํ™” ์—ฌ๋ถ€๋งŒ ํ™•์ธ
  • ์ •๊ธฐ ์ ๊ฒ€ ์Šค์ผ€์ค„ ๋ฏธํ™•์ธ
  • Compliance Score ์ถ”์  ๋ฏธ๊ฒ€์‚ฌ

ํ•œ๊ณ„: ๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ ์ˆ˜ํ–‰ ์—ฌ๋ถ€ + ๊ฐœ์„  ์ถ”์  ์ฒด๊ณ„๋Š” ํƒ์ง€ ๋ชปํ•จ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • ์ ๊ฒ€: ์›”๊ฐ„ ์ •๊ธฐ ์ ๊ฒ€ ์Šค์ผ€์ค„ ๊ฒ€์ฆ
  • ๋ถ„์„: Compliance Score ์ถ”์„ธ + ํ•˜๋ฝ ์•Œ๋ฆผ
  • ๊ฐœ์„ : ๋ฏธ์กฐ์น˜ Finding ์—์Šค์ปฌ๋ ˆ์ด์…˜ ์ฒด๊ณ„
  • ์ฆ์ : ์›”๊ฐ„ ์ ๊ฒ€ ๋ณด๊ณ ์„œ ์ž๋™ ์ƒ์„ฑ

์ฐจ๋ณ„์ : ๊ด€๋ฆฌ์ฒด๊ณ„ ์ ๊ฒ€ -> ๋ถ„์„ -> ๊ฐœ์„  -> ์ฆ์  ์ „ ๊ณผ์ • ์ž๋™ํ™”

<- ISMS-P Compliance Support๋กœ ๋Œ์•„๊ฐ€๊ธฐ