<- ISMS-P Compliance Support

ISMS-P 2.1.3 ์ •๋ณด์ž์‚ฐ ๊ด€๋ฆฌ High Risk

์ •๋ณด์ž์‚ฐ ๊ด€๋ฆฌ๊ฐ€ ์ ์ ˆํžˆ ์ˆ˜ํ–‰๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 2.1.3์€ ์ •๋ณด์ž์‚ฐ์— ๋Œ€ํ•œ ๊ด€๋ฆฌ์ฑ…์ž„๊ณผ ๋ณดํ˜ธ๋Œ€์ฑ…์„ ์ •ํ•˜์—ฌ ๊ด€๋ฆฌํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” Owner ํƒœ๊ทธ ๊ธฐ๋ฐ˜ ์ฑ…์ž„ ์ง€์ •, Config Rules ๊ธฐ๋ฐ˜ ๋ณดํ˜ธ๋Œ€์ฑ… ๊ฒ€์ฆ, ๋ณ€๊ฒฝ ์ถ”์  ๋ฐ ์•Œ๋ฆผ ์ฒด๊ณ„๋ฅผ ํ†ตํ•ด ์ฒด๊ณ„์ ์ธ ์ž์‚ฐ ๊ด€๋ฆฌ๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

📋

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 2.1.3 ์ •๋ณด์ž์‚ฐ ๊ด€๋ฆฌ ์š”๊ตฌ์‚ฌํ•ญ

2.1.3

์ •๋ณด์ž์‚ฐ ๊ด€๋ฆฌ

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์‹๋ณ„๋œ ์ •๋ณด์ž์‚ฐ์— ๋Œ€ํ•˜์—ฌ ๊ด€๋ฆฌ์ฑ…์ž„ ๋ฐ ๋ณดํ˜ธ๋Œ€์ฑ…์„ ์ •ํ•˜์—ฌ ๊ด€๋ฆฌํ•˜์—ฌ์•ผ ํ•˜๋ฉฐ, ์ •๋ณด์ž์‚ฐ์˜ ์ด์šฉ ๋“ฑ ๋ณ€๊ฒฝ์ด ๋ฐœ์ƒํ•œ ๊ฒฝ์šฐ ์ ์‹œ์— ๋ฐ˜์˜ํ•˜๊ณ  ์ •๋ณด์ž์‚ฐ ๋ชฉ๋ก์˜ ์ •ํ™•์„ฑ, ์ตœ์‹ ์„ฑ์„ ์ฃผ๊ธฐ์ ์œผ๋กœ ๊ฒ€ํ† ํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

📌 ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • Owner ํƒœ๊ทธ๋กœ ๊ด€๋ฆฌ์ฑ…์ž„์ž ๋ช…์‹œ
  • Config Rules๋กœ ๋ณดํ˜ธ๋Œ€์ฑ… ์ž๋™ ๊ฒ€์ฆ
  • Conformance Pack์œผ๋กœ ํ†ตํ•ฉ ์ •์ฑ… ์ ์šฉ
  • Config Timeline์œผ๋กœ ๋ณ€๊ฒฝ ์ถ”์ 

⚠️ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ์ž์‚ฐ๋ณ„ ๊ด€๋ฆฌ์ฑ…์ž„์ž ๋ฏธ์ง€์ •
  • ๊ฒฐํ•จ: ๋ณดํ˜ธ๋Œ€์ฑ… ์ˆ˜๋ฆฝ ๋ฐ ์ ์šฉ ๋ฏธํก
  • ๊ถŒ๊ณ : ์ž์‚ฐ ๋ณ€๊ฒฝ ์‹œ ๋ชฉ๋ก ๋ฐ˜์˜ ์ง€์—ฐ
📄 KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ ☁️ AWS Config Managed Rules
📰

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

์ž์‚ฐ ๊ด€๋ฆฌ ๋ฏธํก์œผ๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2016.10

Uber AWS ํ‚ค ๊ด€๋ฆฌ ๋ฏธํก ์นจํ•ด

๊ฐœ๋ฐœ์ž๊ฐ€ GitHub์— AWS ํ‚ค๋ฅผ ์—…๋กœ๋“œํ•˜์˜€์œผ๋‚˜ ๊ด€๋ฆฌ์ฑ…์ž„์ž ๋ฏธ์ง€์ •์œผ๋กœ 1๋…„๊ฐ„ ๋ฐฉ์น˜. ์™ธ๋ถ€ ํ•ด์ปค๊ฐ€ ๋ฐœ๊ฒฌํ•˜์—ฌ 5,700๋งŒ ๋ช… ๊ฐœ์ธ์ •๋ณด ํƒˆ์ทจ.

💡 ๊ตํ›ˆ: ๋ชจ๋“  ์ž์‚ฐ์— Owner ํƒœ๊ทธ ํ•„์ˆ˜, ํ‚ค ๊ด€๋ฆฌ ์ฑ…์ž„์ž ๋ช…์‹œ ํ•„์š”

์ถœ์ฒ˜: TechCrunch ↗
2019.07

Honda ์ž์‚ฐ ๊ด€๋ฆฌ ๊ณต๋ฐฑ ๋…ธ์ถœ

Elasticsearch ํด๋Ÿฌ์Šคํ„ฐ๊ฐ€ Public ๋…ธ์ถœ. ๋‹ด๋‹น์ž ํ‡ด์‚ฌ ํ›„ ์ธ์ˆ˜์ธ๊ณ„ ๋ฏธํก์œผ๋กœ ์ž์‚ฐ ๊ด€๋ฆฌ ๊ณต๋ฐฑ ๋ฐœ์ƒ. ๋‚ด๋ถ€ ์‹œ์Šคํ…œ ์ •๋ณด 1.34์–ต ๊ฑด ๋…ธ์ถœ.

💡 ๊ตํ›ˆ: Owner ํƒœ๊ทธ ๋ณ€๊ฒฝ ์‹œ ์•Œ๋ฆผ ์ฒด๊ณ„, ์ธ์ˆ˜์ธ๊ณ„ ํ”„๋กœ์„ธ์Šค ํ•„์ˆ˜

์ถœ์ฒ˜: BleepingComputer ↗

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

์ •๋ณด์ž์‚ฐ ๊ด€๋ฆฌ๊ฐ€ ๋ฏธํกํ•œ ์ƒํ™ฉ

์ž์‚ฐ ๊ด€๋ฆฌ ๋ฏธํก (์œ„ํ—˜)

  • ❌ ๊ด€๋ฆฌ์ฑ…์ž„: ๋‹ด๋‹น์ž ๋ฏธ์ง€์ •, Owner ํƒœ๊ทธ ์—†์Œ
  • ❌ ๋ณดํ˜ธ๋Œ€์ฑ…: Config Rules ๋ฏธ์„ค์ •
  • ❌ ๋ณ€๊ฒฝ๊ด€๋ฆฌ: ์ด๋ ฅ ์ถ”์  ์—†์Œ, ์•Œ๋ฆผ ์—†์Œ
  • ❌ ์ •ํ™•์„ฑ๊ฒ€ํ† : Compliance ์ ๊ฒ€ ๋ฏธ์ˆ˜ํ–‰

์ฒด๊ณ„์  ๊ด€๋ฆฌ (๊ถŒ์žฅ)

  • ✅ ๊ด€๋ฆฌ์ฑ…์ž„: Owner ํƒœ๊ทธ ํ•„์ˆ˜ ์ ์šฉ
  • ✅ ๋ณดํ˜ธ๋Œ€์ฑ…: Config Rules + Conformance Pack
  • ✅ ๋ณ€๊ฒฝ๊ด€๋ฆฌ: Config Timeline + SNS ์•Œ๋ฆผ
  • ✅ ์ •ํ™•์„ฑ๊ฒ€ํ† : ์ฃผ๊ฐ„ Compliance ๋ฆฌํฌํŠธ
🚨

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: ์ž์‚ฐ ๊ด€๋ฆฌ ์ฒด๊ณ„ ๋ฏธ๊ตฌ์ถ•

EC2 ์ธ์Šคํ„ด์Šค์— Owner ํƒœ๊ทธ๊ฐ€ ์—†์–ด ๊ด€๋ฆฌ์ฑ…์ž„์ž ๋ถˆ๋ช…ํ™•. Config Rules ๋ฏธ์„ค์ •์œผ๋กœ ๋ณดํ˜ธ๋Œ€์ฑ… ๊ฒ€์ฆ ๋ถˆ๊ฐ€. ๋ณ€๊ฒฝ ๋ฐœ์ƒ ์‹œ ์•Œ๋ฆผ ์—†์–ด ์ ์‹œ ๋Œ€์‘ ๋ถˆ๊ฐ€.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
# Terraform (๋ฌธ์ œ) - ์ž์‚ฐ ๊ด€๋ฆฌ ์ฒด๊ณ„ ๋ฏธ๊ตฌ์ถ•

resource "aws_instance" "app" {
  ami           = "ami-12345678"
  instance_type = "t3.medium"
  # Owner ํƒœ๊ทธ ์—†์Œ - ๊ด€๋ฆฌ์ฑ…์ž„์ž ๋ถˆ๋ช…ํ™•
  # ๋ณ€๊ฒฝ ์ถ”์  ์—†์Œ
}

# Config Rules ๋ฏธ์„ค์ •
# ๋ณดํ˜ธ๋Œ€์ฑ… ์ž๋™ ๊ฒ€์ฆ ์—†์Œ

# SNS ์•Œ๋ฆผ ๋ฏธ์„ค์ •
# ๋ณ€๊ฒฝ ๋ฐœ์ƒ ์‹œ ํ†ต๋ณด ์—†์Œ

ISMS-P 2.1.3 ์œ„๋ฐ˜ ์‚ฌํ•ญ

๊ด€๋ฆฌ์ฑ…์ž„ ๋ฏธ์ง€์ •: Owner ํƒœ๊ทธ ์—†์Œ

๋ณดํ˜ธ๋Œ€์ฑ… ๋ฏธ์ˆ˜๋ฆฝ: Config Rules ์—†์Œ

๋ณ€๊ฒฝ ๋ฏธ์ถ”์ : ์ด๋ ฅ ๊ธฐ๋ก/์•Œ๋ฆผ ์—†์Œ

์ •ํ™•์„ฑ ๋ฏธ๊ฒ€ํ† : Compliance ๋ฆฌํฌํŠธ ์—†์Œ

🔍

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

์ •๋ณด์ž์‚ฐ ๊ด€๋ฆฌ ์ฒด๊ณ„ ํƒ์ง€ ๋กœ์ง

ํƒ์ง€ ๋Œ€์ƒ ์กฐ๊ฑด ๊ฒฐ๊ณผ
Owner ํƒœ๊ทธ ํƒœ๊ทธ ๋ฏธ์กด์žฌ High - ๊ด€๋ฆฌ์ฑ…์ž„ ๋ถˆ๋ช…ํ™•
Config Rules ๋ฆฌ์†Œ์Šค ์—†์Œ High - ๋ณดํ˜ธ๋Œ€์ฑ… ๋ฏธ๊ฒ€์ฆ
SNS Topic ๋ณ€๊ฒฝ ์•Œ๋ฆผ ํ† ํ”ฝ ๋ฏธ์„ค์ • Medium - ๋ณ€๊ฒฝ ์•Œ๋ฆผ ๋ถˆ๊ฐ€
Conformance Pack ๋ฆฌ์†Œ์Šค ์—†์Œ Medium - ํ†ตํ•ฉ ์ •์ฑ… ์—†์Œ
🔔

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ๋ณ€๊ฒฝ ํƒ์ง€

์ž์‚ฐ ๊ด€๋ฆฌ ์ด๋ฒคํŠธ ๋Œ€์‘ ๋กœ์ง

ํƒ์ง€ ์‹œ๋‚˜๋ฆฌ์˜ค ์กฐ๊ฑด ๊ฒฐ๊ณผ
Owner ํƒœ๊ทธ ๋ณ€๊ฒฝ Owner ํƒœ๊ทธ ๊ฐ’ ๋ณ€๊ฒฝ ๊ฐ์ง€ Info - ์ธ์ˆ˜์ธ๊ณ„ ์ถ”์ 
๋ณด์•ˆ ์„ค์ • ๋ณ€๊ฒฝ Security Group / IAM ๋ณ€๊ฒฝ High - Slack ์ฆ‰์‹œ ์•Œ๋ฆผ
Config Rule ์œ„๋ฐ˜ NON_COMPLIANT ์ƒํƒœ High - ๋ณดํ˜ธ๋Œ€์ฑ… ์œ„๋ฐ˜
๋ฏธ์‚ฌ์šฉ ์ž์‚ฐ 90์ผ+ ๋ฏธ์ ‘๊ทผ ๋ฆฌ์†Œ์Šค Medium - ํ๊ธฐ ๊ฒ€ํ†  ํ•„์š”

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

๋ณ€๊ฒฝ๋œ ๋ฆฌ์†Œ์Šค ARN Owner ์ •๋ณด ๋ณ€๊ฒฝ ์ฃผ์ฒด (IAM) ๊ถŒ์žฅ ์กฐ์น˜ ๊ฐ€์ด๋“œ

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
asset-management.tf
# 1. ํ•„์ˆ˜ ํƒœ๊ทธ (๊ด€๋ฆฌ์ฑ…์ž„ + ๋ณดํ˜ธ๋“ฑ๊ธ‰)
resource "aws_instance" "app" {
  ami           = "ami-12345678"
  instance_type = "t3.medium"

  tags = {
    Name               = "production-app-server"
    Owner              = "devops-team@company.com"  # ๊ด€๋ฆฌ์ฑ…์ž„์ž
    DataClassification = "Confidential"
    Environment        = "Production"
  }

  lifecycle {
    prevent_destroy = true  # ์‹ค์ˆ˜ ์‚ญ์ œ ๋ฐฉ์ง€
  }
}

# 2. Config Rules (๋ณดํ˜ธ๋Œ€์ฑ… ์ž๋™ ๊ฒ€์ฆ)
resource "aws_config_config_rule" "required_tags" {
  name = "required-asset-tags"

  source {
    owner             = "AWS"
    source_identifier = "REQUIRED_TAGS"
  }

  input_parameters = jsonencode({
    tag1Key = "Owner"
    tag2Key = "DataClassification"
    tag3Key = "Environment"
  })
}

# 3. ๋ณ€๊ฒฝ ์•Œ๋ฆผ ์ฒด๊ณ„
resource "aws_cloudwatch_event_rule" "owner_change" {
  name = "detect-owner-tag-change"

  event_pattern = jsonencode({
    source      = ["aws.tag"]
    detail-type = ["Tag Change on Resource"]
    detail = {
      "changed-tag-keys" = ["Owner"]
    }
  })
}

resource "aws_cloudwatch_event_target" "notify" {
  rule      = aws_cloudwatch_event_rule.owner_change.name
  target_id = "notify-sns"
  arn       = aws_sns_topic.asset_changes.arn
}

💡 ํ•ต์‹ฌ: Owner ํƒœ๊ทธ๋กœ ๊ด€๋ฆฌ์ฑ…์ž„์ž๋ฅผ ๋ช…์‹œํ•˜๊ณ , Config Rules๋กœ ๋ณดํ˜ธ๋Œ€์ฑ…์„ ์ž๋™ ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค. EventBridge๋กœ Owner ํƒœ๊ทธ ๋ณ€๊ฒฝ ์‹œ ์•Œ๋ฆผ์„ ๋ฐ›์•„ ์ธ์ˆ˜์ธ๊ณ„๋ฅผ ์ถ”์ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

📚 ์ฐธ๊ณ  ์ž๋ฃŒ

☁️ AWS Config Managed Rules 📦 AWS Conformance Packs 🏷️ AWS Resource Tagging
📊

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

📋 ์ง„๋‹จ ํ•ญ๋ชฉ

  • Owner ํƒœ๊ทธ ๋ฏธ๋ถ€์—ฌ ์ž์‚ฐ ์ˆ˜
  • Config Rules ์ ์šฉ ํ˜„ํ™ฉ
  • NON_COMPLIANT ๋ฆฌ์†Œ์Šค ์ˆ˜
  • Owner ๋ณ€๊ฒฝ ์ด๋ ฅ (๊ธฐ๊ฐ„๋ณ„)
  • ๋ฏธ์‚ฌ์šฉ ์ž์‚ฐ ๋ชฉ๋ก

📅 ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

Owner/๋ณด์•ˆ ์„ค์ • ๋ณ€๊ฒฝ ์•Œ๋ฆผ

์ฃผ๊ฐ„

Compliance ํ˜„ํ™ฉ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ

📤 ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

๊ฐœ๋ณ„ Config Rule ์กด์žฌ ์—ฌ๋ถ€๋งŒ ํ™•์ธ

  • Config Recorder ํ™œ์„ฑํ™” ์—ฌ๋ถ€
  • ๊ฐœ๋ณ„ Rule ์กด์žฌ ์—ฌ๋ถ€
  • ๊ธฐ๋ณธ ํƒœ๊ทธ ์กด์žฌ ์—ฌ๋ถ€๋งŒ ํ™•์ธ

ํ•œ๊ณ„: Owner ํƒœ๊ทธ ๊ฒ€์ฆ ์—†์Œ, ๋ณ€๊ฒฝ ์•Œ๋ฆผ ์ฒด๊ณ„ ๋ฏธํ™•์ธ, ํ๊ธฐ ์›Œํฌํ”Œ๋กœ์šฐ ๋ฏธ๊ฒ€์ฆ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • ์ฑ…์ž„: Owner ํƒœ๊ทธ ๊ฐ•์ œ + ๋ณ€๊ฒฝ ์•Œ๋ฆผ
  • ๋ณดํ˜ธ: Config Rules + Conformance Pack ๊ฒ€์ฆ
  • ์ถ”์ : ๋ณ€๊ฒฝ ์ด๋ ฅ + ์ธ์ˆ˜์ธ๊ณ„ ๋ชจ๋‹ˆํ„ฐ๋ง

์ฐจ๋ณ„์ : ์ธ์ฆ ๊ธฐ์ค€ ๊ด€์ ์—์„œ ํƒ์ง€ -> ์กฐ์น˜ -> ์ฆ์  ์ „ ๊ณผ์ • ์ž๋™ํ™”

<- ISMS-P Compliance Support๋กœ ๋Œ์•„๊ฐ€๊ธฐ