โ† Cloud Security Service Integration

ISMS-P 2.5.6 ์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ†  High Risk

์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ† ๊ฐ€ ์ •๊ธฐ์ ์œผ๋กœ ์ˆ˜ํ–‰๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 2.5.6์€ ์ ‘๊ทผ๊ถŒํ•œ์˜ ์ ์ •์„ฑ์„ ์ •๊ธฐ์ ์œผ๋กœ ๊ฒ€ํ† ํ•˜์—ฌ ๊ณผ๋„ํ•˜๊ฑฐ๋‚˜ ๋ถˆํ•„์š”ํ•œ ๊ถŒํ•œ์„ ์‹๋ณ„ํ•˜๊ณ  ์กฐ์ •ํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” IAM Access Analyzer + ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ์ž๋™ ํƒ์ง€ + ์ •๊ธฐ ๊ฒ€ํ†  ์ž๋™ํ™”๋กœ ๊ตฌํ˜„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“‹

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 2.5.6 ์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ†  ์š”๊ตฌ์‚ฌํ•ญ

2.5.6

์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ† 

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์ •๋ณด์‹œ์Šคํ…œ๊ณผ ๊ฐœ์ธ์ •๋ณด ๋ฐ ์ค‘์š”์ •๋ณด์— ๋Œ€ํ•œ ์ ‘๊ทผ๊ถŒํ•œ์˜ ์ ์ •์„ฑ์„ ์ •๊ธฐ์ ์œผ๋กœ ๊ฒ€ํ† ํ•˜์—ฌ ๊ณผ๋„ํ•˜๊ฑฐ๋‚˜ ๋ถˆํ•„์š”ํ•œ ๊ถŒํ•œ์„ ์‹๋ณ„ํ•˜๊ณ  ์กฐ์ •ํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

๐Ÿ“Œ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • IAM Access Analyzer๋กœ ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ์ž๋™ ๋ถ„์„
  • ์ตœ์†Œ ๋ฐ˜๊ธฐ 1ํšŒ ์ด์ƒ ์ ‘๊ทผ๊ถŒํ•œ ์ ์ •์„ฑ ๊ฒ€ํ† 
  • ๋ฏธ์‚ฌ์šฉ ์—ญํ• /Access Key ์ •๊ธฐ ์ ๊ฒ€ (90์ผ)
  • ์ง๋ฌด ๋ณ€๊ฒฝ ์‹œ ๊ธฐ์กด ๊ถŒํ•œ ๊ฒ€ํ†  ๋ฐ ์กฐ์ •
  • CloudTrail ๋กœ๊ทธ ๊ธฐ๋ฐ˜ ๊ถŒํ•œ ์‚ฌ์šฉ ๋ถ„์„

โš ๏ธ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ†  ๋ฏธ์ˆ˜ํ–‰ ๋˜๋Š” ํ˜•์‹์  ์ˆ˜ํ–‰
  • ๊ฒฐํ•จ: ํ‡ด์ง์ž/ํœด์ง์ž ๊ณ„์ • ๊ทธ๋Œ€๋กœ ์œ ์ง€
  • ๊ฒฐํ•จ: ์ง๋ฌด ๋ณ€๊ฒฝ ํ›„ ์ด์ „ ๊ถŒํ•œ ์œ ์ง€
  • ๊ฒฐํ•จ: ๊ฒ€ํ†  ๊ฒฐ๊ณผ ๋ฐ ์กฐ์น˜ ๋‚ด์—ญ ๋ฏธ๋ฌธ์„œํ™”
๐Ÿ“„ KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ โ†— ๐Ÿ“– ISMS-P 2.5.6 ์ƒ์„ธ ์•ˆ๋‚ด โ†—
๐Ÿ“ฐ

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ†  ๋ฏธํก์œผ๋กœ ๋ฐœ์ƒํ•œ ๋Œ€๊ทœ๋ชจ ์นจํ•ด ์‚ฌ๋ก€

2020-2024

SolarWinds ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ

SolarWinds Orion์ด IT ๋ชจ๋‹ˆํ„ฐ๋ง ์‹œ์Šคํ…œ์œผ๋กœ์„œ ๊ด‘๋ฒ”์œ„ํ•œ ํŠน๊ถŒ ์ ‘๊ทผ์„ ๋ณด์œ . ๊ณผ๋„ํ•œ ๊ถŒํ•œ์„ ๊ฐ€์ง„ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ์ •๊ธฐ์ ์œผ๋กœ ๊ฒ€ํ† ๋˜์ง€ ์•Š์•„ ์ „์‚ฌ ์‹œ์Šคํ…œ ์œ„ํ—˜ ๋…ธ์ถœ. 2024๋…„ 10์›”์—๋„ ์ƒˆ๋กœ์šด ์ทจ์•ฝ์ (CVE-2024-28987) ์•…์šฉ ์ง€์†.

๐Ÿ’ก ๊ตํ›ˆ: ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํฌํ•จ ๋ชจ๋“  ์ ‘๊ทผ๊ถŒํ•œ ์ •๊ธฐ ๊ฒ€ํ†  ํ•„์ˆ˜

์ถœ์ฒ˜: TechTarget โ†—
2024

๋ฏธ์‚ฌ์šฉ Admin ๊ถŒํ•œ ๋ฐฉ์น˜๋กœ ๋‚ด๋ถ€์ž ์œ„ํ˜‘

์ง๋ฌด ๋ณ€๊ฒฝ๋œ ์ง์›์ด ์ด์ „ ๋ถ€์„œ์˜ Admin ๊ถŒํ•œ์„ ๊ทธ๋Œ€๋กœ ๋ณด์œ , 90์ผ ์ด์ƒ ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ์ด ๊ฒ€ํ† ๋˜์ง€ ์•Š์•„ ํ‡ด์‚ฌ ์‹œ์ ์— ๋ฏผ๊ฐ ๋ฐ์ดํ„ฐ ์œ ์ถœ. Prowler์—์„œ Critical ์œ„ํ—˜์œผ๋กœ ๋ถ„๋ฅ˜.

๐Ÿ’ก ๊ตํ›ˆ: 90์ผ ์ฃผ๊ธฐ ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ์ž๋™ ํƒ์ง€ ๋ฐ ์ œ๊ฑฐ ํ•„์š”

์ถœ์ฒ˜: The Hacker News โ†—
โšก

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ† ๊ฐ€ ์ˆ˜ํ–‰๋˜์ง€ ์•Š๋Š” ์ƒํ™ฉ

๋ฏธ๊ฒ€ํ†  (์œ„ํ—˜)

IAM Role

๐Ÿ‘ค

โ†’

90์ผ+

๐Ÿ’ค

โ†’

๋ฐฉ์น˜

โš ๏ธ

โ†‘ ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ๊ฒ€ํ†  ์—†์Œ

๋ฏธ์‚ฌ์šฉ ์—ญํ• /Key ๋ฐฉ์น˜ + ๊ฒ€ํ†  ๋ฏธ์ˆ˜ํ–‰ โ†’ ISMS-P 2.5.6 ๋ฏธ์ถฉ์กฑ

์ •๊ธฐ ๊ฒ€ํ†  (๊ถŒ์žฅ)

Access

๐Ÿ”

โ†’

Analyzer

๐Ÿ“Š

โ†’

์ž๋™์กฐ์น˜

โœ…

โ†‘ 90์ผ ๋ฏธ์‚ฌ์šฉ ์ž๋™ ํƒ์ง€

Access Analyzer + ์ •๊ธฐ ๊ฒ€ํ†  ์ž๋™ํ™” โ†’ ์ธ์ฆ ๊ธฐ์ค€ ์ถฉ์กฑ

๐Ÿšจ

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: ๋ฏธ์‚ฌ์šฉ IAM ์—ญํ• /Access Key ๋ฐฉ์น˜, ์ •๊ธฐ ๊ฒ€ํ†  ๋ฏธ์ˆ˜ํ–‰

6๊ฐœ์›” ์ด์ƒ ๋ฏธ์‚ฌ์šฉ๋œ IAM Role์ด ๋ฐฉ์น˜๋˜์–ด ์žˆ๊ณ , ์ง๋ฌด ๋ณ€๊ฒฝ๋œ ์‚ฌ์šฉ์ž์˜ ์ด์ „ ๋ถ€์„œ ๊ถŒํ•œ์ด ๊ทธ๋Œ€๋กœ ์œ ์ง€.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
# 6๊ฐœ์›” ์ด์ƒ ๋ฏธ์‚ฌ์šฉ๋œ IAM ์—ญํ•  - ๊ฒ€ํ† ๋˜์ง€ ์•Š์Œ
resource "aws_iam_role" "legacy_admin" {
  name = "LegacyAdminRole"
  # 2023๋…„ ์ƒ์„ฑ ํ›„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์Œ
  # ์ •๊ธฐ ๊ฒ€ํ† ์—์„œ ๋ˆ„๋ฝ

  assume_role_policy = jsonencode({
    Statement = [{
      Principal = { AWS = "*" }  # ๊ณผ๋„ํ•œ Principal
    }]
  })
}

# ์ง๋ฌด ๋ณ€๊ฒฝ ํ›„์—๋„ ์œ ์ง€๋œ ์ด์ „ ๋ถ€์„œ ๊ถŒํ•œ
resource "aws_iam_user_policy_attachment" "old" {
  user       = aws_iam_user.moved_user.name
  policy_arn = "arn:aws:iam::aws:policy/AmazonRDSFullAccess"
  # ํ˜„์žฌ ์ง๋ฌด์™€ ๋ฌด๊ด€ํ•œ ๊ถŒํ•œ ์œ ์ง€
}

ISMS-P 2.5.6 ์œ„๋ฐ˜ ์‚ฌํ•ญ

โ—

์ ‘๊ทผ๊ถŒํ•œ ์ •๊ธฐ ๊ฒ€ํ†  ๋ฏธ์ˆ˜ํ–‰

โ—

๋ฏธ์‚ฌ์šฉ ์—ญํ• /Access Key ๋ฐฉ์น˜

โ—

์ง๋ฌด ๋ณ€๊ฒฝ ์‹œ ์ด์ „ ๊ถŒํ•œ ๋ฏธํšŒ์ˆ˜

โ—

๊ฒ€ํ†  ๊ฒฐ๊ณผ ๋ฐ ์กฐ์น˜ ๋‚ด์—ญ ๋ฏธ๋ฌธ์„œํ™”

๐Ÿ”

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ†  ํƒœ๊ทธ ํƒ์ง€ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ‘ค IAM Role
LastUsedDate ํƒœ๊ทธ ์—†์Œ Medium - ์ถ”์  ๋ถˆ๊ฐ€ ๊ฒฝ๊ณ 
ReviewDate 90์ผ ์ด์ƒ ๊ฒฝ๊ณผ High - ๊ฒ€ํ†  ํ•„์š” ์•Œ๋ฆผ
๐Ÿ“œ IAM Policy
Action: * ๋˜๋Š” Resource: * High - ๊ณผ๋„ํ•œ ๊ถŒํ•œ ๊ฒฝ๊ณ 
์ตœ์†Œ ๊ถŒํ•œ + ๊ฒ€ํ†  ํƒœ๊ทธ ์กด์žฌ โœ“ ํ†ต๊ณผ
๐Ÿท๏ธ IAM User ํƒœ๊ทธ
LastReviewedDate ์—†์Œ Medium - ๊ฒ€ํ†  ์ด๋ ฅ ๋ˆ„๋ฝ
LastReviewedDate + NextReviewDate ์กด์žฌ โœ“ ํ†ต๊ณผ
๐Ÿ””

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

IAM Access Analyzer ๊ธฐ๋ฐ˜ ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ์‹ค์‹œ๊ฐ„ ํƒ์ง€

๋ฏธ์‚ฌ์šฉ ์ ‘๊ทผ ๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ‘ค IAM Role
90์ผ ์ด์ƒ ๋ฏธ์‚ฌ์šฉ High - ์‚ญ์ œ ๊ถŒ๊ณ  ์•Œ๋ฆผ
90์ผ ๋ฏธ์‚ฌ์šฉ + Admin ๊ถŒํ•œ Critical - ์ฆ‰์‹œ ์กฐ์น˜ ํ•„์š”
๐Ÿ”‘ IAM Access Key
45์ผ ์ด์ƒ ๋ฏธ์‚ฌ์šฉ High - ๋น„ํ™œ์„ฑํ™” ๊ถŒ๊ณ 
90์ผ ์ด์ƒ ๋ฏธ์‚ฌ์šฉ Critical - ์ž๋™ ๋น„ํ™œ์„ฑํ™”
๐Ÿ“Š Access Analyzer
Unused permissions ํƒ์ง€ Medium - ๊ถŒํ•œ ์ถ•์†Œ ๊ถŒ๊ณ 

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

IAM Role/User ARN ๋งˆ์ง€๋ง‰ ์‚ฌ์šฉ ์ผ์‹œ ๋ฏธ์‚ฌ์šฉ ๊ธฐ๊ฐ„ ๋ถ€์—ฌ๋œ ๊ถŒํ•œ ์ˆ˜์ค€
โœ“

์กฐ์น˜ ๊ฐ€์ด๋“œ

IAM Access Analyzer ๋ฐ ์ •๊ธฐ ๊ฒ€ํ†  ์ž๋™ํ™”

โŒ ๋ฌธ์ œ

๋ฏธ์‚ฌ์šฉ ์—ญํ•  ๋ฐฉ์น˜, ๊ฒ€ํ†  ํƒœ๊ทธ ์—†์Œ, ์ž๋™ํ™” ๋ฏธ๊ตฌํ˜„

โœ“ ์ ์šฉ

Access Analyzer + ๊ฒ€ํ†  ํƒœ๊ทธ + ์ž๋™ ๋น„ํ™œ์„ฑํ™”

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
access-analyzer.tf
# IAM Access Analyzer - ๋ฏธ์‚ฌ์šฉ ์ ‘๊ทผ ๋ถ„์„ ํ™œ์„ฑํ™”
resource "aws_accessanalyzer_analyzer" "unused_access" {
  analyzer_name = "UnusedAccessAnalyzer"
  type          = "ORGANIZATION_UNUSED_ACCESS"

  configuration {
    unused_access {
      unused_access_age = 90  # 90์ผ ๋ฏธ์‚ฌ์šฉ ๊ธฐ์ค€
    }
  }

  tags = {
    Purpose     = "Unused-Access-Detection"
    ReviewCycle = "Quarterly"
    ISMS-P      = "2.5.6"
  }
}

# IAM ์—ญํ•  - ๊ฒ€ํ†  ์ถ”์  ํƒœ๊ทธ ํฌํ•จ
resource "aws_iam_role" "monitored_role" {
  name = "MonitoredServiceRole"

  tags = {
    CreatedDate      = "2024-01-15"
    LastReviewedDate = "2024-06-15"  # ์ •๊ธฐ ๊ฒ€ํ† ์ผ
    NextReviewDate   = "2024-12-15"  # ๋‹ค์Œ ๊ฒ€ํ†  ์˜ˆ์ •
    Owner            = "security-team@company.com"
    ISMS-P           = "2.5.6"
  }
}

# EventBridge - Access Analyzer ๋ฐœ๊ฒฌ ์‹œ ์ž๋™ ์•Œ๋ฆผ
resource "aws_cloudwatch_event_rule" "unused_alert" {
  name = "UnusedAccessFinding"

  event_pattern = jsonencode({
    source      = ["aws.access-analyzer"]
    detail-type = ["Access Analyzer Finding"]
    detail = {
      findingType = ["UnusedPermission", "UnusedIAMRole"]
    }
  })
}

# ์ฃผ๊ฐ„ ๊ฒ€ํ†  ์Šค์ผ€์ค„
resource "aws_cloudwatch_event_rule" "weekly_review" {
  name                = "WeeklyAccessReview"
  schedule_expression = "cron(0 9 ? * MON *)"  # ๋งค์ฃผ ์›”์š”์ผ
}

๐Ÿ’ก ํ•ต์‹ฌ: IAM Access Analyzer๋ฅผ ํ™œ์„ฑํ™”ํ•˜์—ฌ ๋ฏธ์‚ฌ์šฉ ์—ญํ• , Access Key, ๊ถŒํ•œ์„ ์ž๋™ ํƒ์ง€ํ•ฉ๋‹ˆ๋‹ค. 2024๋…„ ์‹ ๊ทœ ๊ธฐ๋Šฅ์œผ๋กœ unused_access_age ์„ค์ •์„ ํ†ตํ•ด 90์ผ ๋ฏธ์‚ฌ์šฉ ๊ธฐ์ค€์„ ๋ช…์‹œํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋“  IAM ๋ฆฌ์†Œ์Šค์— ๊ฒ€ํ†  ํƒœ๊ทธ๋ฅผ ๋ถ€์ฐฉํ•˜์—ฌ ์ •๊ธฐ ๊ฒ€ํ†  ์ฃผ๊ธฐ๋ฅผ ์ถ”์ ํ•˜๊ณ , EventBridge๋กœ ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ๋ฐœ๊ฒฌ ์‹œ ์ž๋™ ์•Œ๋ฆผ์„ ๋ฐ›์Šต๋‹ˆ๋‹ค.

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

๐Ÿ” AWS IAM Access Analyzer โ†— ๐Ÿ“Š Access Analyzer ๋ฏธ์‚ฌ์šฉ ์ ‘๊ทผ ๋ถ„์„ โ†— ๐Ÿ‘ค ๋ฏธ์‚ฌ์šฉ IAM ์—ญํ•  ์‹๋ณ„ โ†—
๐Ÿ“Š

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๊ฒ€ํ†  ๋ณด๊ณ 

๐Ÿ“‹ ์ง„๋‹จ ํ•ญ๋ชฉ

  • ๋ฏธ์‚ฌ์šฉ IAM Role (90์ผ+)
  • ๋ฏธ์‚ฌ์šฉ Access Key (45์ผ+, 90์ผ+)
  • ๋ฏธ์‚ฌ์šฉ IAM User Password
  • ๊ฒ€ํ†  ํƒœ๊ทธ ์กด์žฌ ์—ฌ๋ถ€
  • Access Analyzer Finding ํ˜„ํ™ฉ

๐Ÿ“… ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ฃผ๊ฐ„

๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ/๊ณ„์ • ํ˜„ํ™ฉ

์›”๊ฐ„

Access Analyzer ์ „์ฒด ๋ฆฌํฌํŠธ

๋ฐ˜๊ธฐ

ISMS-P ์ ‘๊ทผ๊ถŒํ•œ ๊ฒ€ํ†  ์ฆ์ 

๐Ÿ“ค ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack Security Hub

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)
โšก

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

๋ฏธ์‚ฌ์šฉ ์ผ์ˆ˜ ๊ธฐ์ค€ ๋‹จ์ˆœ ์ฒดํฌ

  • last_used > 90 days ๋น„๊ต
  • ์ •์  ๋ถ„์„ ๊ฒฐ๊ณผ๋งŒ ์ถœ๋ ฅ
  • ๊ฒ€ํ†  ์ˆ˜ํ–‰ ์—ฌ๋ถ€ ์ถ”์  ๋ถˆ๊ฐ€

ํ•œ๊ณ„: ์ •๊ธฐ ๊ฒ€ํ†  ์Šค์ผ€์ค„ ๊ด€๋ฆฌ ๋ฏธ์ง€์›, ๊ฒ€ํ†  ๊ฒฐ๊ณผ ๋ฌธ์„œํ™” ์ž๋™ํ™” ๋ถˆ๊ฐ€

BSG ์ ‘๊ทผ ๋ฐฉ์‹

IaC + Access Analyzer + ์ž๋™ํ™” ์›Œํฌํ”Œ๋กœ์šฐ

  • ๋ฐฐํฌ ์ „ ๊ฒ€ํ†  ํƒœ๊ทธ ๋ˆ„๋ฝ ๊ฒฝ๊ณ 
  • Access Analyzer ๊ธฐ๋ฐ˜ ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ์‹ค์‹œ๊ฐ„ ์•Œ๋ฆผ
  • ๊ฒ€ํ†  ์ฃผ๊ธฐ ์ž๋™ ๊ด€๋ฆฌ + ์ฆ์  ์ž๋™ ์ˆ˜์ง‘

์ฐจ๋ณ„์ : ์ •๊ธฐ ๊ฒ€ํ†  ์ผ์ • ์ž๋™ํ™” + ๋ฏธ์‚ฌ์šฉ ๊ถŒํ•œ ์ž๋™ ๋น„ํ™œ์„ฑํ™” + ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ์ž๋™ํ™”

<- Cloud Security & Access Control๋กœ ๋Œ์•„๊ฐ€๊ธฐ