โ† Cloud Security Service Integration

ISMS-P 2.10.2 ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ High Risk

ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์„ค์ •์ด ์ ์ ˆํžˆ ๊ด€๋ฆฌ๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 2.10.2๋Š” ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค ์ด์šฉ ์‹œ ์„ค์ • ์˜ค๋ฅ˜ ๋“ฑ์œผ๋กœ ์ค‘์š”์ •๋ณด๊ฐ€ ์œ ์ถœ๋˜์ง€ ์•Š๋„๋ก ๋ณดํ˜ธ๋Œ€์ฑ…์„ ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” Security Hub CSPM + S3 ํผ๋ธ”๋ฆญ ์ฐจ๋‹จ + CloudTrail ํ™œ์„ฑํ™”๋กœ ๊ตฌํ˜„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“‹

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 2.10.2 ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์š”๊ตฌ์‚ฌํ•ญ

2.10.2

ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค ์ด์šฉ ์‹œ ์„œ๋น„์Šค ์œ ํ˜•(SaaS, PaaS, IaaS ๋“ฑ)์— ๋”ฐ๋ฅธ ๋น„์ธ๊ฐ€ ์ ‘๊ทผ, ์„ค์ • ์˜ค๋ฅ˜ ๋“ฑ์— ๋”ฐ๋ผ ์ค‘์š”์ •๋ณด์™€ ๊ฐœ์ธ์ •๋ณด๊ฐ€ ์œ ยท๋…ธ์ถœ๋˜์ง€ ์•Š๋„๋ก ๊ด€๋ฆฌ์ž ์ ‘๊ทผ ๋ฐ ๋ณด์•ˆ ์„ค์ • ๋“ฑ์— ๋Œ€ํ•œ ๋ณดํ˜ธ๋Œ€์ฑ…์„ ์ˆ˜๋ฆฝยท์ดํ–‰ํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

๐Ÿ“Œ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • Security Hub๋กœ ๋ณด์•ˆ ํƒœ์„ธ(CSPM) ํ†ตํ•ฉ ๊ด€๋ฆฌ
  • CIS Benchmark, AWS FSBP ํ‘œ์ค€ ์ค€์ˆ˜
  • S3 ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ์ฐจ๋‹จ ๋ฐ ์•”ํ˜ธํ™” ํ•„์ˆ˜
  • Security Group ์ตœ์†Œ ๊ถŒํ•œ (0.0.0.0/0 ๊ธˆ์ง€)
  • CloudTrail/Config ์ „ ๋ฆฌ์ „ ํ™œ์„ฑํ™”

โš ๏ธ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: S3 ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ํ—ˆ์šฉ ์ƒํƒœ
  • ๊ฒฐํ•จ: Security Group 0.0.0.0/0 ํ—ˆ์šฉ
  • ๊ฒฐํ•จ: CloudTrail/Config ๋ฏธํ™œ์„ฑํ™”
  • ๊ฒฐํ•จ: ๋ณด์•ˆ์„ค์ • ๋ณ€๊ฒฝ ๊ถŒํ•œ ๊ณผ๋„ ๋ถ€์—ฌ
๐Ÿ“„ KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ โ†— ๐Ÿ“– ISMS-P 2.10.2 ์ƒ์„ธ ์•ˆ๋‚ด โ†—
๐Ÿ“ฐ

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

ํด๋ผ์šฐ๋“œ ์„ค์ • ์˜ค๋ฅ˜๋กœ ๋ฐœ์ƒํ•œ ๋Œ€๊ทœ๋ชจ ์œ ์ถœ ์‚ฌ๋ก€

2025.01

TalentHook 2,600๋งŒ๊ฑด ์ด๋ ฅ์„œ ์œ ์ถœ

๋ฏธ๊ตญ ์ธ์žฌ ์ฑ„์šฉ ํ”Œ๋žซํผ์—์„œ ํด๋ผ์šฐ๋“œ ์Šคํ† ๋ฆฌ์ง€ ์ ‘๊ทผ ๊ถŒํ•œ ์„ค์ • ์˜ค๋ฅ˜๋กœ 2,600๋งŒ ๊ฑด ์ด๋ ฅ์„œ ์ •๋ณด ์™ธ๋ถ€ ๋…ธ์ถœ. ์Šคํ† ๋ฆฌ์ง€์˜ ํผ๋ธ”๋ฆญ ์ ‘๊ทผ์ด ์ž˜๋ชป ์„ค์ •๋˜์–ด ๋ฏผ๊ฐํ•œ ๊ฐœ์ธ์ •๋ณด๊ฐ€ ์ธํ„ฐ๋„ท์— ๊ณต๊ฐœ๋จ.

๐Ÿ’ก ๊ตํ›ˆ: S3/์Šคํ† ๋ฆฌ์ง€ ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ์ฐจ๋‹จ ํ•„์ˆ˜, CSPM ๋„๊ตฌ๋กœ ์ง€์† ์ ๊ฒ€

์ถœ์ฒ˜: TechRadar โ†—
2024

๋„ค์ด๋ฒ„ ํด๋ผ์šฐ๋“œ-๋ผ์ธ์•ผํ›„ 40๋งŒ๊ฑด ์œ ์ถœ

ํ˜‘๋ ฅ์—…์ฒด PC ์•…์„ฑ์ฝ”๋“œ ๊ฐ์—ผ โ†’ ๋„ค์ด๋ฒ„ ํด๋ผ์šฐ๋“œ ์„œ๋ฒ„ โ†’ ์—ฐ๋™๋œ ์ผ๋ณธ ๋ผ์ธ์•ผํ›„ ์‹œ์Šคํ…œ ์นจํˆฌ โ†’ ๊ฐœ์ธ์ •๋ณด 40๋งŒ๊ฑด ์œ ์ถœ. ์•…์„ฑ์ฝ”๋“œ ๊ฐ์—ผ์„ ๋’ค๋Šฆ๊ฒŒ ๋ฐœ๊ฒฌํ•˜์—ฌ ์ œ๋•Œ ์ฐจ๋‹จ ์‹คํŒจ.

๐Ÿ’ก ๊ตํ›ˆ: ํด๋ผ์šฐ๋“œ ๊ฐ„ ์—ฐ๋™ ์‹œ ๋„คํŠธ์›Œํฌ ๋ถ„๋ฆฌ, ์‹ค์‹œ๊ฐ„ ๋ชจ๋‹ˆํ„ฐ๋ง ํ•„์ˆ˜

์ถœ์ฒ˜: ๋ฐ์ดํ„ฐ๋„ท โ†—
โšก

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

์„ค์ • ์˜ค๋ฅ˜๋กœ ์ธํ•œ ๋ณด์•ˆ ์ทจ์•ฝ์ 

๋ฏธ๊ด€๋ฆฌ (์œ„ํ—˜)

S3

๐Ÿชฃ

โ†’

Public

๐ŸŒ

โ†’

์œ ์ถœ

๐Ÿ’€

โ†‘ ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ํ—ˆ์šฉ

S3 ํผ๋ธ”๋ฆญ + SG 0.0.0.0/0 โ†’ ISMS-P 2.10.2 ๋ฏธ์ถฉ์กฑ

์ฒด๊ณ„์  ๊ด€๋ฆฌ (๊ถŒ์žฅ)

Security

๐Ÿ›ก๏ธ

โ†’

Hub

๐Ÿ“Š

โ†’

CSPM

โœ…

โ†‘ ๋ณด์•ˆ ํƒœ์„ธ ์ž๋™ ์ ๊ฒ€

Security Hub + ํผ๋ธ”๋ฆญ ์ฐจ๋‹จ โ†’ ์ธ์ฆ ๊ธฐ์ค€ ์ถฉ์กฑ

๐Ÿšจ

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: S3 ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ํ—ˆ์šฉ, Security Group 0.0.0.0/0

๋ฏผ๊ฐ ๋ฐ์ดํ„ฐ๊ฐ€ ์ €์žฅ๋œ S3 ๋ฒ„ํ‚ท์˜ ํผ๋ธ”๋ฆญ ์ ‘๊ทผ์ด ํ—ˆ์šฉ๋˜์–ด ์žˆ๊ณ , Security Group์—์„œ SSH(22), RDP(3389) ํฌํŠธ๊ฐ€ ์ „ ์„ธ๊ณ„์— ๊ฐœ๋ฐฉ.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
# S3 ๋ฒ„ํ‚ท - ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ํ—ˆ์šฉ (์œ„ํ—˜!)
resource "aws_s3_bucket_public_access_block" "data" {
  bucket = aws_s3_bucket.data.id
  # ๋ชจ๋‘ false - ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ๊ฐ€๋Šฅ!
  block_public_acls       = false
  block_public_policy     = false
}

# Security Group - 0.0.0.0/0 ์ธ๋ฐ”์šด๋“œ (์œ„ํ—˜!)
resource "aws_security_group" "web" {
  ingress {
    from_port   = 22
    cidr_blocks = ["0.0.0.0/0"]  # ์ „ ์„ธ๊ณ„ SSH!
  }
}

ISMS-P 2.10.2 ์œ„๋ฐ˜ ์‚ฌํ•ญ

โ—

S3 ๋ฒ„ํ‚ท ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ํ—ˆ์šฉ

โ—

Security Group 0.0.0.0/0 ํ—ˆ์šฉ

โ—

CloudTrail/Config ๋ฏธํ™œ์„ฑํ™”

โ—

Security Hub ๋ฏธํ™œ์„ฑํ™”

๐Ÿ”

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์„ค์ • ํƒ์ง€ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿชฃ S3 Public Access Block
์„ค์ • ์—†์Œ ๋˜๋Š” false Critical - ์ฐจ๋‹จ
4๊ฐœ ํ•ญ๋ชฉ ๋ชจ๋‘ true โœ“ ํ†ต๊ณผ
๐Ÿ”’ Security Group
0.0.0.0/0 ์ธ๋ฐ”์šด๋“œ (22, 3389) Critical - ์ฐจ๋‹จ
ํŠน์ • CIDR ๋˜๋Š” SG ์ฐธ์กฐ โœ“ ํ†ต๊ณผ
๐Ÿ“ CloudTrail
๋ฆฌ์†Œ์Šค ์—†์Œ High - ๊ฒฝ๊ณ 
multi_region_trail = true โœ“ ํ†ต๊ณผ
๐Ÿ””

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

Security Hub ๊ธฐ๋ฐ˜ ์‹ค์‹œ๊ฐ„ ๋ณด์•ˆ ํƒœ์„ธ ๋ชจ๋‹ˆํ„ฐ๋ง

ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ›ก๏ธ Security Hub
CIS ์œ„๋ฐ˜ Finding High - Slack ์•Œ๋ฆผ
Critical Finding Critical - ์ฆ‰์‹œ ์•Œ๋ฆผ
๐Ÿชฃ S3 Bucket
ACL public-read ํƒ์ง€ Critical - ์ž๋™ ์ฐจ๋‹จ
๐Ÿ”’ Security Group
0.0.0.0/0 ์ถ”๊ฐ€ ํƒ์ง€ Critical - ์ฆ‰์‹œ ์‚ญ์ œ ๊ถŒ๊ณ 

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

๋ฆฌ์†Œ์Šค ARN Security Hub Finding ID ์œ„๋ฐ˜ ํ‘œ์ค€ (CIS/FSBP) ๊ถŒ์žฅ ์กฐ์น˜
โœ“

์กฐ์น˜ ๊ฐ€์ด๋“œ

Security Hub ๋ฐ ๋ณด์•ˆ ์„ค์ • ๊ฐ•ํ™”

โŒ ๋ฌธ์ œ

S3 ํผ๋ธ”๋ฆญ ํ—ˆ์šฉ, SG 0.0.0.0/0, CloudTrail ๋ฏธํ™œ์„ฑํ™”

โœ“ ์ ์šฉ

Security Hub + Public Block + CloudTrail

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
cloud-security.tf
# Security Hub ํ™œ์„ฑํ™” - CSPM
resource "aws_securityhub_account" "main" {}

# CIS AWS Foundations Benchmark ํ™œ์„ฑํ™”
resource "aws_securityhub_standards_subscription" "cis" {
  standards_arn = "arn:aws:securityhub:::ruleset/cis-aws-foundations-benchmark/v/1.4.0"
}

# S3 ๋ฒ„ํ‚ท - ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ์™„์ „ ์ฐจ๋‹จ
resource "aws_s3_bucket_public_access_block" "data" {
  bucket = aws_s3_bucket.data.id

  block_public_acls       = true
  block_public_policy     = true
  ignore_public_acls      = true
  restrict_public_buckets = true
}

# Security Group - ์ตœ์†Œ ๊ถŒํ•œ (0.0.0.0/0 ์ ˆ๋Œ€ ๊ธˆ์ง€!)
resource "aws_security_group" "web" {
  ingress {
    from_port   = 443
    cidr_blocks = ["10.0.0.0/8"]  # ๋‚ด๋ถ€๋งŒ
  }
  # SSH๋Š” SSM Session Manager ์‚ฌ์šฉ ๊ถŒ์žฅ
}

# CloudTrail - ์ „ ๋ฆฌ์ „ ํ™œ์„ฑํ™”
resource "aws_cloudtrail" "main" {
  name                          = "organization-trail"
  is_multi_region_trail         = true
  include_global_service_events = true
  enable_log_file_validation    = true
}

๐Ÿ’ก ํ•ต์‹ฌ: AWS Security Hub๋ฅผ ํ™œ์„ฑํ™”ํ•˜์—ฌ CIS Benchmark, AWS FSBP ์ค€์ˆ˜ ์—ฌ๋ถ€๋ฅผ ์ž๋™ ์ ๊ฒ€ํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋“  S3 ๋ฒ„ํ‚ท์— Public Access Block์„ ์ ์šฉํ•˜๊ณ  4๊ฐœ ํ•ญ๋ชฉ์„ ๋ชจ๋‘ true๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. Security Group์—์„œ 0.0.0.0/0 ์ธ๋ฐ”์šด๋“œ๋ฅผ ์ ˆ๋Œ€ ํ—ˆ์šฉํ•˜์ง€ ์•Š๊ณ , SSH/RDP๋Š” SSM Session Manager๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

๐Ÿ›ก๏ธ AWS Security Hub CSPM โ†— ๐Ÿ“‹ CIS AWS Benchmark โ†— ๐Ÿชฃ AWS S3 ๋ณด์•ˆ ๋ชจ๋ฒ”์‚ฌ๋ก€ โ†—
๐Ÿ“Š

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ๋ณด์•ˆ ํƒœ์„ธ ๋ณด๊ณ 

๐Ÿ“‹ ์ง„๋‹จ ํ•ญ๋ชฉ

  • S3 ํผ๋ธ”๋ฆญ ์ ‘๊ทผ ์ฐจ๋‹จ ์„ค์ •
  • Security Group 0.0.0.0/0 ์—ฌ๋ถ€
  • CloudTrail ์ „ ๋ฆฌ์ „ ํ™œ์„ฑํ™”
  • Security Hub CIS ์ ์ˆ˜
  • Config ๊ทœ์ • ์ค€์ˆ˜ ํ˜„ํ™ฉ

๐Ÿ“… ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

Security Hub Critical Finding

์ฃผ๊ฐ„

CIS Benchmark ์ ์ˆ˜ ์ถ”์ด

์›”๊ฐ„

ISMS-P ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ ์ฆ์ 

๐Ÿ“ค ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack Security Hub

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)
โšก

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

๊ฐœ๋ณ„ ๋ฆฌ์†Œ์Šค ์„ค์ • ๊ฐ’ ๋‹จ์ˆœ ์ฒดํฌ

  • public_access == true ๋น„๊ต
  • ๊ฐœ๋ณ„ ๋ฆฌ์†Œ์Šค ๋‹จ์œ„ ์ ๊ฒ€
  • ์ •์  ๋ถ„์„ ๊ฒฐ๊ณผ๋งŒ ์ถœ๋ ฅ

ํ•œ๊ณ„: Security Hub ํ†ตํ•ฉ ์ ๊ฒ€ ๋ถˆ๊ฐ€, ์„ค์ • ๋ณ€๊ฒฝ ์ด๋ ฅ ์ถ”์  ๋ถˆ๊ฐ€

BSG ์ ‘๊ทผ ๋ฐฉ์‹

IaC + Security Hub + ์ž๋™ ์ˆ˜์ •

  • ๋ฐฐํฌ ์ „ S3 ํผ๋ธ”๋ฆญ, SG 0.0.0.0/0 ์ฐจ๋‹จ
  • Security Hub Finding ์‹ค์‹œ๊ฐ„ ์•Œ๋ฆผ
  • CIS Benchmark ํ†ตํ•ฉ ๋Œ€์‹œ๋ณด๋“œ

์ฐจ๋ณ„์ : CSPM ํ†ตํ•ฉ + ๊ทœ์ • ์ค€์ˆ˜ ๋ฆฌํฌํŠธ ์ž๋™ํ™” + ์ž๋™ ์ˆ˜์ •

<- Cloud Security & Access Control๋กœ ๋Œ์•„๊ฐ€๊ธฐ