โ† CI/CD Security Operations

ISMS-P 2.11.2 ์ทจ์•ฝ์  ์ ๊ฒ€ ๋ฐ ์กฐ์น˜ High Risk

์ทจ์•ฝ์  ์ ๊ฒ€ ๋ฐ ์กฐ์น˜๊ฐ€ ์ˆ˜ํ–‰๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 2.11.2๋Š” ์ •๊ธฐ์ ์ธ ์ทจ์•ฝ์  ์ ๊ฒ€๊ณผ ์‹ ์†ํ•œ ์กฐ์น˜๋ฅผ ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” Amazon Inspector๋ฅผ ํ†ตํ•œ ์ง€์†์  ์ทจ์•ฝ์  ์Šค์บ”๊ณผ SLA ๊ธฐ๋ฐ˜ ์กฐ์น˜ ๊ด€๋ฆฌ ๋ฐ ์ž๋™ ํŒจ์น˜ ์ ์šฉ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“‹

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 2.11.2 ์ทจ์•ฝ์  ์ ๊ฒ€ ๋ฐ ์กฐ์น˜ ์š”๊ตฌ์‚ฌํ•ญ

2.11.2

์ทจ์•ฝ์  ์ ๊ฒ€ ๋ฐ ์กฐ์น˜

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์ •๋ณด์‹œ์Šคํ…œ์˜ ์ทจ์•ฝ์ ์ด ๋…ธ์ถœ๋˜์–ด ์žˆ๋Š”์ง€๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ์ •๊ธฐ์ ์œผ๋กœ ์ทจ์•ฝ์  ์ ๊ฒ€์„ ์ˆ˜ํ–‰ํ•˜๊ณ  ๋ฐœ๊ฒฌ๋œ ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด์„œ๋Š” ์‹ ์†ํ•˜๊ฒŒ ์กฐ์น˜ํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

๐Ÿ“Œ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • Amazon Inspector ์ง€์†์  ์ทจ์•ฝ์  ์Šค์บ”
  • Security Hub ํ†ตํ•ฉ ์ทจ์•ฝ์  ๊ด€๋ฆฌ
  • SSM Patch Manager ์ž๋™ ํŒจ์น˜
  • SLA ๊ธฐ๋ฐ˜ ์กฐ์น˜ ๊ธฐํ•œ ์ถ”์ 

โš ๏ธ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ์ •๊ธฐ ์ทจ์•ฝ์  ์ ๊ฒ€ ๋ฏธ์ˆ˜ํ–‰
  • ๊ฒฐํ•จ: ๋ฐœ๊ฒฌ ์ทจ์•ฝ์  ์กฐ์น˜ ์ง€์—ฐ/๋ฏธํก
  • ๊ถŒ๊ณ : ์ทจ์•ฝ์  ์กฐ์น˜ ์ด๋ ฅ ๊ด€๋ฆฌ ๋ฏธํก
๐Ÿ“„ KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ โ†— โ˜๏ธ Amazon Inspector ๊ฐ€์ด๋“œ โ†—
๐Ÿ“ฐ

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

์ทจ์•ฝ์  ๋ฏธ์กฐ์น˜๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2017.05-07

Equifax 1์–ต 4,700๋งŒ ๋ช… ์ •๋ณด ์œ ์ถœ

Apache Struts ์ทจ์•ฝ์ (CVE-2017-5638) ํŒจ์น˜ ๋ฏธ์ ์šฉ์œผ๋กœ 2๊ฐœ์›”๊ฐ„ ๋ฐฉ์น˜. ์ทจ์•ฝ์  ๋ฐœ๊ฒฌ ํ›„ ์‹ ์†ํ•œ ์กฐ์น˜ ๋ฏธ์ดํ–‰์œผ๋กœ ๋Œ€๊ทœ๋ชจ ๊ฐœ์ธ์ •๋ณด ์œ ์ถœ. 7์–ต ๋‹ฌ๋Ÿฌ ํ•ฉ์˜๊ธˆ ์ง€๋ถˆ.

๐Ÿ’ก ๊ตํ›ˆ: ์ทจ์•ฝ์  ๋ฐœ๊ฒฌ ์‹œ ์‹ ์†ํ•œ ํŒจ์น˜ ์ ์šฉ, SLA ๊ธฐ๋ฐ˜ ์กฐ์น˜ ๊ด€๋ฆฌ ํ•„์ˆ˜

์ถœ์ฒ˜: FTC โ†—
2021.12

Log4Shell ์ „ ์„ธ๊ณ„ ์ˆ˜๋ฐฑ๋งŒ ์‹œ์Šคํ…œ ์˜ํ–ฅ

Log4j ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ (CVE-2021-44228). SBOM ๋ถ€์žฌ๋กœ ์˜ํ–ฅ ๋ฒ”์œ„ ํŒŒ์•… ๋ถˆ๊ฐ€. ์ทจ์•ฝ ์ปดํฌ๋„ŒํŠธ ์œ„์น˜ ํŒŒ์•…์ด ์–ด๋ ค์›Œ ์กฐ์น˜ ์ง€์—ฐ ๋ฐœ์ƒ.

๐Ÿ’ก ๊ตํ›ˆ: SBOM ๊ด€๋ฆฌ, ์ทจ์•ฝ์  ์˜ํ–ฅ ๋ฒ”์œ„ ์ฆ‰์‹œ ํŒŒ์•… ์ฒด๊ณ„ ๊ตฌ์ถ• ํ•„์ˆ˜

์ถœ์ฒ˜: NVD โ†—
โšก

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

AWS์—์„œ ์ทจ์•ฝ์  ์ ๊ฒ€์ด ์œ„๋ฐ˜๋˜๋Š” ์ƒํ™ฉ

Inspector ๋ฏธํ™œ์„ฑํ™” (์œ„ํ—˜)

EC2

๋ฏธ์Šค์บ”

ECR

๋ฏธ์Šค์บ”

Lambda

๋ฏธ์Šค์บ”

โ†‘ ์ทจ์•ฝ์  ์ ๊ฒ€ ์ฒด๊ณ„ ๋ถ€์žฌ

Inspector ๋ฏธ์„ค์ • ์‹œ ์ทจ์•ฝ์  ์ž๋™ ํƒ์ง€ ๋ถˆ๊ฐ€ โ†’ ISMS-P ์ ๊ฒ€ ์š”๊ตฌ์‚ฌํ•ญ ๋ฏธ์ถฉ์กฑ

Inspector + Patch Manager (๊ถŒ์žฅ)

EC2

์ง€์† ์Šค์บ”

ECR

์ด๋ฏธ์ง€ ์Šค์บ”

Lambda

์ฝ”๋“œ ์Šค์บ”

โ†‘ ์ „์ฒด ๋ฆฌ์†Œ์Šค ์ทจ์•ฝ์  ์ ๊ฒ€

Inspector + SSM Patch Manager๋กœ ํƒ์ง€ โ†’ ์กฐ์น˜ ์ž๋™ํ™”

๐Ÿšจ

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: Inspector ๋ฏธํ™œ์„ฑํ™” + SSM ๋ฏธ์—ฐ๊ฒฐ

EC2 ์ธ์Šคํ„ด์Šค์— iam_instance_profile ๋ฏธ์„ค์ •. Inspector V2 ๋ฆฌ์†Œ์Šค ๋ฏธ์กด์žฌ๋กœ ์ทจ์•ฝ์  ์Šค์บ” ์ฒด๊ณ„ ๋ถ€์žฌ. ํŒจ์น˜ ๊ด€๋ฆฌ๊ฐ€ ์ˆ˜๋™์œผ๋กœ๋งŒ ์ด๋ฃจ์–ด์ ธ Critical ์ทจ์•ฝ์  ๋ฐฉ์น˜.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
# Inspector ๋น„ํ™œ์„ฑํ™” โ†’ ์ทจ์•ฝ์  ์ ๊ฒ€ ๋ฏธ์ˆ˜ํ–‰
# aws_inspector2_enabler ๋ฆฌ์†Œ์Šค ์—†์Œ

resource "aws_instance" "app" {
  ami           = "ami-12345678"
  instance_type = "t3.medium"
  # iam_instance_profile ๋ฏธ์„ค์ •
  # โ†’ SSM ์—ฐ๊ฒฐ ๋ถˆ๊ฐ€, ํŒจ์น˜ ๊ด€๋ฆฌ ๋ถˆ๊ฐ€
}

ISMS-P 2.11.2 ์œ„๋ฐ˜ ์‚ฌํ•ญ

โ—

์ •๊ธฐ ์ ๊ฒ€ ๋ฏธ์ˆ˜ํ–‰ - Inspector ๋ฏธํ™œ์„ฑํ™”

โ—

์‹ ์†ํ•œ ์กฐ์น˜ ๋ถˆ๊ฐ€ - SSM ๋ฏธ์—ฐ๊ฒฐ๋กœ ์ž๋™ ํŒจ์น˜ ๋ถˆ๊ฐ€

โ—

SLA ๋ฏธ๊ด€๋ฆฌ - ์ทจ์•ฝ์  ์กฐ์น˜ ๊ธฐํ•œ ์ถ”์  ์ฒด๊ณ„ ์—†์Œ

โ—

SBOM ๋ถ€์žฌ - ์ทจ์•ฝ์  ์˜ํ–ฅ ๋ฒ”์œ„ ํŒŒ์•… ๋ถˆ๊ฐ€

๐Ÿ”

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

Inspector/SSM ์ทจ์•ฝ์  ์ ๊ฒ€ ์ฒด๊ณ„ ํƒ์ง€ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ”Ž Inspector ์„ค์ •
aws_inspector2_enabler ๋ฆฌ์†Œ์Šค ๋ฏธ์กด์žฌ Critical - ํ•„์ˆ˜ ์„ค์ • ํ•„์š”
resource_types = ["EC2", "ECR", "LAMBDA"] โœ“ ํ†ต๊ณผ
๐Ÿ”— SSM ์—ฐ๊ฒฐ
EC2์— iam_instance_profile ๋ฏธ์„ค์ • High - ํŒจ์น˜ ๊ด€๋ฆฌ ๋ถˆ๊ฐ€
aws_ssm_patch_baseline ๋ฆฌ์†Œ์Šค ๋ฏธ์กด์žฌ Medium - ํŒจ์น˜ ์ •์ฑ… ๋ฏธ์„ค์ •
๐Ÿ“Š ํ†ตํ•ฉ ๊ด€๋ฆฌ
aws_securityhub_account Inspector ํ†ตํ•ฉ ๋ฏธํ™œ์„ฑํ™” Medium - ํ†ตํ•ฉ ๊ด€๋ฆฌ ๊ถŒ๊ณ 
aws_ssm_maintenance_window ์„ค์ • โœ“ ์ •๊ธฐ ํŒจ์น˜ ์ž๋™ํ™”
๐Ÿ””

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ด์ƒํ–‰์œ„ ํƒ์ง€

์ทจ์•ฝ์  ๋ฐœ๊ฒฌ ์‹œ ๋Ÿฐํƒ€์ž„ ๋Œ€์‘ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿšจ Finding ์‹ฌ๊ฐ๋„
severity = CRITICAL Critical - ์ฆ‰์‹œ ์•Œ๋ฆผ + 3์ผ SLA
severity = HIGH High - ์•Œ๋ฆผ + 7์ผ SLA
โฐ SLA ์ถ”์ 
firstObservedAt > 30days ๋ฏธ์กฐ์น˜ Critical - SLA ์œ„๋ฐ˜ ์—์Šค์ปฌ๋ ˆ์ด์…˜
ํŒจ์น˜ ๋ฏธ์ ์šฉ 30์ผ+ Non-Compliance High - ์œ ์ง€๋ณด์ˆ˜ ์œˆ๋„์šฐ ์˜ˆ์•ฝ
๐Ÿ”ง ์ž๋™ ํŒจ์น˜
Patch Manager ์‹คํ–‰ ์˜ค๋ฅ˜ High - ์ˆ˜๋™ ๊ฐœ์ž… ์š”์ฒญ + ์žฅ์•  ์•Œ๋ฆผ

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

์ทจ์•ฝ์  ID (CVE) ์˜ํ–ฅ๋ฐ›๋Š” ๋ฆฌ์†Œ์Šค ์กฐ์น˜ ๊ธฐํ•œ (SLA) ๊ถŒ์žฅ ์กฐ์น˜ ๋ฐฉ์•ˆ
โœ“

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

โŒ ํ˜„์žฌ ๋ฌธ์ œ

Inspector ๋ฏธํ™œ์„ฑํ™”, ์ทจ์•ฝ์  ์ ๊ฒ€ ์ฒด๊ณ„ ๋ถ€์žฌ

โœ“ ๊ถŒ์žฅ ์กฐ์น˜

Inspector V2 + SSM + Patch Manager ์ž๋™ํ™”

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
inspector.tf
# 1. Inspector V2 ํ™œ์„ฑํ™” (๋ชจ๋“  ๋ฆฌ์†Œ์Šค ํƒ€์ž…)
resource "aws_inspector2_enabler" "all" {
  account_ids    = [data.aws_caller_identity.current.account_id]
  resource_types = ["EC2", "ECR", "LAMBDA", "LAMBDA_CODE"]
}

# 2. EC2 - SSM ์—ฐ๊ฒฐ ์„ค์ •
resource "aws_iam_instance_profile" "ssm" {
  name = "ssm-instance-profile"
  role = aws_iam_role.ssm.name
}

resource "aws_iam_role_policy_attachment" "ssm" {
  role       = aws_iam_role.ssm.name
  policy_arn = "arn:aws:iam::aws:policy/AmazonSSMManagedInstanceCore"
}

# 3. Patch Baseline (Critical/Security ์ž๋™ ์Šน์ธ)
resource "aws_ssm_patch_baseline" "security" {
  name             = "security-patch-baseline"
  operating_system = "AMAZON_LINUX_2"

  approval_rule {
    approve_after_days = 7  # 7์ผ ํ›„ ์ž๋™ ์Šน์ธ
    compliance_level   = "CRITICAL"

    patch_filter {
      key    = "CLASSIFICATION"
      values = ["Security", "Bugfix"]
    }
  }
  tags = { ISMS-P = "2.11.2" }
}

# 4. Maintenance Window (์ •๊ธฐ ํŒจ์น˜ ์ ์šฉ)
resource "aws_ssm_maintenance_window" "patch" {
  name     = "weekly-patch-window"
  schedule = "cron(0 2 ? * SUN *)"  # ๋งค์ฃผ ์ผ์š”์ผ 02:00
  duration = 2
  cutoff   = 1
}

๐Ÿ’ก ํ•ต์‹ฌ: Inspector V2๋กœ EC2/ECR/Lambda ์ „์ฒด๋ฅผ ์ง€์† ์Šค์บ”ํ•˜๊ณ , SSM Patch Manager๋กœ Critical/Security ํŒจ์น˜๋ฅผ ์ž๋™ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค. SLA ๊ธฐ๋ฐ˜์œผ๋กœ Critical 3์ผ, High 7์ผ ๊ธฐํ•œ์„ ์ถ”์ ํ•˜์„ธ์š”.

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

โ˜๏ธ Inspector Findings ์ดํ•ด โ†— ๐Ÿ“˜ AWS Patch Manager ๊ฐ€์ด๋“œ โ†— ๐Ÿ”’ AWS K-ISMS ๊ทœ์ • ์ค€์ˆ˜ โ†—
๐Ÿ“Š

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

๐Ÿ“‹ ์ง„๋‹จ ํ•ญ๋ชฉ

  • Inspector ์Šค์บ” ์ปค๋ฒ„๋ฆฌ์ง€
  • ์ทจ์•ฝ์  ๋ฐœ๊ฒฌ ํ˜„ํ™ฉ (์‹ฌ๊ฐ๋„๋ณ„)
  • SLA ์ค€์ˆ˜์œจ (3์ผ/7์ผ/30์ผ)
  • ํŒจ์น˜ ์ปดํ”Œ๋ผ์ด์–ธ์Šค ํ˜„ํ™ฉ
  • SBOM ๊ด€๋ฆฌ ์ƒํƒœ

๐Ÿ“… ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์‹ค์‹œ๊ฐ„

Critical Finding ์ฆ‰์‹œ ์•Œ๋ฆผ

์ฃผ๊ฐ„

SLA ์ค€์ˆ˜์œจ ๋ฆฌํฌํŠธ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ

๐Ÿ“ค ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)
โšก

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

Inspector ํ™œ์„ฑํ™” ์—ฌ๋ถ€๋งŒ ๊ฒ€์‚ฌ

  • Inspector ๋ฆฌ์†Œ์Šค ์กด์žฌ ์—ฌ๋ถ€ ํ™•์ธ
  • ํ™œ์„ฑํ™”/๋น„ํ™œ์„ฑํ™” ์ƒํƒœ๋งŒ ํƒ์ง€
  • SSM ์—ฐ๊ฒฐ ์ƒํƒœ ๋ฏธ๊ฒ€์‚ฌ

ํ•œ๊ณ„: ๋ชจ๋“  ๋ฆฌ์†Œ์Šค ํƒ€์ž… ์ปค๋ฒ„๋ฆฌ์ง€, Patch Manager, SLA ์ค€์ˆ˜ ์ถ”์  ๋ถˆ๊ฐ€

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • Inspector + SSM + Security Hub ํ†ตํ•ฉ ๊ฒ€์ฆ
  • EC2/ECR/Lambda ์ „์ฒด ์ปค๋ฒ„๋ฆฌ์ง€ ํ™•์ธ
  • SLA ๊ธฐ๋ฐ˜ Finding ์กฐ์น˜์œจ ์ถ”์ 

์ฐจ๋ณ„์ : ์ ๊ฒ€ โ†’ ์กฐ์น˜ โ†’ ๊ฒ€์ฆ โ†’ ์ฆ์  ์ „ ๊ณผ์ • ์ž๋™ํ™”

โ† ISMS-P ๋งคํ•‘ ๋ชฉ๋ก์œผ๋กœ ๋Œ์•„๊ฐ€๊ธฐ