โ† Cloud Security Service Integration

ISMS-P 2.6.1 ์ ‘๊ทผํ†ต์ œ High Risk

๋„คํŠธ์›Œํฌ ์ ‘๊ทผํ†ต์ œ๊ฐ€ ์ ์ ˆํžˆ ์ˆ˜ํ–‰๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 2.6.1์€ ๋„คํŠธ์›Œํฌ์— ๋Œ€ํ•œ ์ ‘๊ทผ์„ ์—…๋ฌด ๋ชฉ์ ์— ๋”ฐ๋ผ ์ตœ์†Œํ•œ์˜ ๋ฒ”์œ„๋กœ ์ œํ•œํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” ์„œ๋น„์Šค ๊ณ„์ •, ๋ณด์•ˆ ๊ทธ๋ฃน, ๋„คํŠธ์›Œํฌ ์ •์ฑ… ๋“ฑ์„ ํ†ตํ•ด ์ธ๊ฐ€๋œ ๋Œ€์ƒ๋งŒ ํ•„์š”ํ•œ ๋ฒ”์œ„ ๋‚ด์—์„œ ์ ‘๊ทผํ•˜๋„๋ก ํ†ต์ œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“‹

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 2.6.1 ์ ‘๊ทผํ†ต์ œ ์š”๊ตฌ์‚ฌํ•ญ

2.6.1

์ ‘๊ทผํ†ต์ œ

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์ •๋ณด์‹œ์Šคํ…œ๊ณผ ๊ฐœ์ธ์ •๋ณด ๋ฐ ์ค‘์š”์ •๋ณด์— ๋Œ€ํ•œ ์ ‘๊ทผ์€ ์ธ๊ฐ€๋œ ์‚ฌ์šฉ์ž, ํ”„๋กœ๊ทธ๋žจ, ํ”„๋กœ์„ธ์Šค๋งŒ์œผ๋กœ ์ œํ•œํ•˜๊ณ  ๋น„์ธ๊ฐ€๋œ ์ ‘๊ทผ ์‹œ๋„๋ฅผ ํƒ์ง€ํ•ด์•ผ ํ•œ๋‹ค."

๐Ÿ“Œ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • ์ปจํ…Œ์ด๋„ˆ/Pod ๋‹จ์œ„ ์ ‘๊ทผ๊ถŒํ•œ ๋ถ„๋ฆฌ
  • ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๊ธฐ๋ฐ˜ ๊ฒฉ๋ฆฌ ์ •์ฑ…
  • ์„œ๋น„์Šค ๊ณ„์ •๋ณ„ ์ตœ์†Œ๊ถŒํ•œ ๋ถ€์—ฌ
  • RBAC ์ •์ฑ…์˜ ์ ์ •์„ฑ ๊ฒ€ํ† 

โš ๏ธ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ๊ณผ๋„ํ•œ ๊ถŒํ•œ ๋ถ€์—ฌ๋กœ ์ตœ์†Œ๊ถŒํ•œ ์œ„๋ฐ˜
  • ๊ฒฐํ•จ: ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๊ฒฉ๋ฆฌ ์ •์ฑ… ๋ถ€์žฌ
  • ๊ถŒ๊ณ : ์ ‘๊ทผ๊ถŒํ•œ ์ •๊ธฐ ๊ฒ€ํ†  ์ ˆ์ฐจ ๋ฏธํก
๐Ÿ“„ KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ โ†— โ˜๏ธ AWS K-ISMS ๊ทœ์ • ์ค€์ˆ˜ โ†—
๐Ÿ“ฐ

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

์ ‘๊ทผ๊ถŒํ•œ ๊ด€๋ฆฌ ๋ฏธํก์œผ๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2024.01

Microsoft ์ž„์›์ง„ ์ด๋ฉ”์ผ ์นจํ•ด

MFA ๋ฏธ์ ์šฉ ๊ณ„์ • + ๊ณผ๊ถŒํ•œ OAuth ์•ฑ์„ ํ†ตํ•ด ๋Ÿฌ์‹œ์•„ APT(Midnight Blizzard)๊ฐ€ Microsoft ์ž„์›์ง„ ๋ฐ ๋ณด์•ˆํŒ€ ์ด๋ฉ”์ผ์— 1๊ฐœ์›” ์ด์ƒ ์ ‘๊ทผ.

๐Ÿ’ก ๊ตํ›ˆ: ํ…Œ์ŠคํŠธ ํ™˜๊ฒฝ์—๋„ ์ตœ์†Œ๊ถŒํ•œ ์›์น™ ์ ์šฉ, ๋ ˆ๊ฑฐ์‹œ OAuth ์•ฑ ์ •๊ธฐ ์ ๊ฒ€ ํ•„์š”

์ถœ์ฒ˜: Cloud Security Alliance โ†—
2024.05

Snowflake 165๊ฐœ ๊ธฐ์—… ์—ฐ์‡„ ์นจํ•ด

ํ•„์š” ์ด์ƒ์˜ ๊ถŒํ•œ์ด ๋ถ€์—ฌ๋œ ๊ณ„์ • ํƒˆ์ทจ๋กœ AT&T, Ticketmaster, Santander ๋“ฑ 165๊ฐœ ๊ธฐ์—… ์นจํ•ด. 3์ฒœ๋งŒ ๊ฐœ์ธ์ •๋ณด + 2,800๋งŒ ์‹ ์šฉ์นด๋“œ ์ •๋ณด ์œ ์ถœ.

๐Ÿ’ก ๊ตํ›ˆ: ์„œ๋น„์Šค ๊ณ„์ • ๊ถŒํ•œ ๋ฒ”์œ„ ์ตœ์†Œํ™”, ์ •๊ธฐ์ ์ธ ๊ถŒํ•œ ๊ฒ€ํ†  ํ•„์ˆ˜

์ถœ์ฒ˜: Cloud Security Alliance โ†—
โšก

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

Kubernetes์—์„œ ์ ‘๊ทผํ†ต์ œ๊ฐ€ ์œ„๋ฐ˜๋˜๋Š” ์ƒํ™ฉ

ClusterRoleBinding (์œ„ํ—˜)

frontend

โœ“

backend

โœ“

data

โœ“

โ†‘ ์ „์ฒด ๋„ค์ž„์ŠคํŽ˜์ด์Šค ์ ‘๊ทผ

ํด๋Ÿฌ์Šคํ„ฐ ์ „์ฒด ๋„ค์ž„์ŠคํŽ˜์ด์Šค์— ๊ถŒํ•œ ๋ถ€์—ฌ โ†’ ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๊ฒฉ๋ฆฌ ๋ฌดํšจํ™”

RoleBinding (๊ถŒ์žฅ)

frontend

โœ“

backend

โœ—

data

โœ—

โ†‘ ์ง€์ • ๋„ค์ž„์ŠคํŽ˜์ด์Šค๋งŒ ์ ‘๊ทผ

ํŠน์ • ๋„ค์ž„์ŠคํŽ˜์ด์Šค์—๋งŒ ๊ถŒํ•œ ๋ถ€์—ฌ โ†’ ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๊ฒฉ๋ฆฌ ์œ ์ง€

๐Ÿšจ

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: frontend-deployer ๊ณ„์ •์— ClusterRoleBinding ์‚ฌ์šฉ

edit Role ์ž์ฒด๋Š” ๊ณผ๊ถŒํ•œ์ด ์•„๋‹™๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ClusterRoleBinding์œผ๋กœ ๋ฐ”์ธ๋”ฉ๋˜์–ด frontend ์„œ๋น„์Šค ๊ณ„์ •์ด backend, data ๋“ฑ ๋ชจ๋“  ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๋ฆฌ์†Œ์Šค๋ฅผ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
kind: ClusterRoleBinding  # โš ๏ธ ํด๋Ÿฌ์Šคํ„ฐ ์ „์ฒด ๋ฒ”์œ„
metadata:
  name: frontend-deployer-binding
subjects:
  - kind: ServiceAccount
    name: frontend-deployer
    namespace: frontend
roleRef:
  kind: ClusterRole
  name: edit

ISMS-P 2.6.1 ์œ„๋ฐ˜ ์‚ฌํ•ญ

โ—

์„œ๋น„์Šค ๊ณ„์ •์ด ํ•„์š” ๋ฒ”์œ„ ์ดˆ๊ณผ ์ ‘๊ทผ ๊ฐ€๋Šฅ

โ—

์ตœ์†Œ๊ถŒํ•œ ์›์น™ ์œ„๋ฐ˜

โ—

๋„ค์ž„์ŠคํŽ˜์ด์Šค ๊ฒฉ๋ฆฌ ์ •์ฑ… ๋ฌดํšจํ™”

โ—

์นจํ•ด ์‹œ ์ „์ฒด ํด๋Ÿฌ์Šคํ„ฐ ํ”ผํ•ด ํ™•์‚ฐ ์œ„ํ—˜

๐Ÿ”

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

ClusterRoleBinding ํƒ์ง€ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ‘ค ๊ณ„์ • ์œ ํ˜•
kube-system kube-public โœ“ ํ†ต๊ณผ
์ผ๋ฐ˜ ์„œ๋น„์Šค ๊ณ„์ • (frontend, backend ๋“ฑ) โ†’ ๊ถŒํ•œ ๊ฒ€์‚ฌ
๐Ÿ”‘ ๊ถŒํ•œ ์ˆ˜์ค€
cluster-admin Critical - PR ์ฆ‰์‹œ ์ฐจ๋‹จ
edit admin High - ์ฐจ๋‹จ + Slack ์•Œ๋ฆผ
view Medium - ์•Œ๋ฆผ๋งŒ
๐Ÿ””

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ด์ƒํ–‰์œ„ ํƒ์ง€

ClusterRoleBinding ๋Ÿฐํƒ€์ž„ ์ด๋ฒคํŠธ ๋Œ€์‘ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ“ฆ IaC ๊ด€๋ฆฌ ์—ฌ๋ถ€
Terraform State์— ์กด์žฌ ์ •์ƒ IaC ๋ฐฐํฌ โœ“ ๋ณ€๊ฒฝ ์ด๋ ฅ๋งŒ ์ €์žฅ
Drift ๋ฐœ์ƒ ์ฝ˜์†”/kubectl ์ง์ ‘ ๋ณ€๊ฒฝ โ†’ ์ƒ์„ธ ๋ถ„์„
โฐ ๋ณ€๊ฒฝ ์ƒํ™ฉ

(Drift ๋ฐœ์ƒ ์‹œ)

์•ผ๊ฐ„ (22~06์‹œ) + ๋ฏธ๋“ฑ๋ก IAM Critical - PagerDuty ํ˜ธ์ถœ
10๋ถ„ ๋‚ด 3๊ฑด ์ด์ƒ ๋‹จ์‹œ๊ฐ„ ๋‹ค์ˆ˜ ๋ณ€๊ฒฝ High - Slack ์ฆ‰์‹œ ์•Œ๋ฆผ
๋“ฑ๋ก IAM + ์—…๋ฌด์‹œ๊ฐ„ ์ผ๋ฐ˜ Drift Medium - Slack ์•Œ๋ฆผ + ๋กœ๊น…

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

๋ณ€๊ฒฝ๋œ ๋ฐ”์ธ๋”ฉ ์ด๋ฆ„ ์˜ํ–ฅ๋ฐ›๋Š” ์„œ๋น„์Šค ๊ณ„์ • ๋ณ€๊ฒฝ ์ฃผ์ฒด (IAM) RoleBinding ์ „ํ™˜ ๊ฐ€์ด๋“œ
โœ“

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

โŒ ์‚ญ์ œ

frontend-deployer-binding ClusterRoleBinding

โœ“ ์ ์šฉ

frontend ๋„ค์ž„์ŠคํŽ˜์ด์Šค ํ•œ์ • RoleBinding

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
frontend-deployer-binding.yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding  # โœ“ Namespace ๋ฒ”์œ„๋กœ ๋ณ€๊ฒฝ
metadata:
  namespace: frontend  # โœ“ frontend NS๋กœ ์ œํ•œ
  name: frontend-deployer-binding
subjects:
  - kind: ServiceAccount
    name: frontend-deployer
roleRef:
  kind: ClusterRole  # ClusterRole ์ฐธ์กฐ๋Š” ๊ฐ€๋Šฅ
  name: edit  # RoleBinding์ด ๋ฒ”์œ„๋ฅผ ์ œํ•œ
  apiGroup: rbac.authorization.k8s.io

๐Ÿ’ก ํ•ต์‹ฌ: ClusterRole์„ ์ฐธ์กฐํ•˜๋”๋ผ๋„ RoleBinding์„ ์‚ฌ์šฉํ•˜๋ฉด ํ•ด๋‹น ๋„ค์ž„์ŠคํŽ˜์ด์Šค๋กœ ๊ถŒํ•œ์ด ์ œํ•œ๋ฉ๋‹ˆ๋‹ค. ๋ณ„๋„์˜ ์ปค์Šคํ…€ Role์„ ๋งŒ๋“ค ํ•„์š” ์—†์ด, ๊ธฐ์กด edit ClusterRole์„ ์žฌ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

โ˜๏ธ EKS Best Practices - IAM โ†— ๐Ÿ“˜ Kubernetes RBAC ๊ณต์‹ ๋ฌธ์„œ โ†— ๐Ÿ”’ AWS EKS Security Best Practices โ†—
๐Ÿ“Š

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

๐Ÿ“‹ ์ง„๋‹จ ํ•ญ๋ชฉ

  • ClusterRoleBinding ์ด ๊ฐœ์ˆ˜
  • ๋น„์‹œ์Šคํ…œ ๊ณ„์ • ๋ฐ”์ธ๋”ฉ ์ˆ˜
  • RoleBinding ๋Œ€์ฒด ๊ฐ€๋Šฅ ๊ฑด์ˆ˜
  • ์‹ ๊ทœ ์ƒ์„ฑ/๋ณ€๊ฒฝ ๊ฑด์ˆ˜ (๊ธฐ๊ฐ„๋ณ„)
  • ๋ฏธ์กฐ์น˜ ํ•ญ๋ชฉ ์ˆ˜

๐Ÿ“… ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

๋ณ€๊ฒฝ ์‚ฌํ•ญ ์•Œ๋ฆผ

์ฃผ๊ฐ„

์ทจ์•ฝ์  ํ˜„ํ™ฉ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ

๐Ÿ“ค ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)
โšก

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

Role ๊ถŒํ•œ ํŒจํ„ด๋งŒ ๊ฒ€์‚ฌ

  • cluster-admin Role ํƒ์ง€
  • Wildcard (*) ๊ถŒํ•œ ํƒ์ง€
  • secrets, nodes ๋“ฑ ๋ฏผ๊ฐ ๋ฆฌ์†Œ์Šค ์ ‘๊ทผ

ํ•œ๊ณ„: edit Role์ฒ˜๋Ÿผ ๊ถŒํ•œ์ด ๊ณผํ•˜์ง€ ์•Š์œผ๋ฉด, ClusterRoleBinding์ด์–ด๋„ ํƒ์ง€ ๋ชปํ•จ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • Binding ์ข…๋ฅ˜ ์ž์ฒด๋ฅผ ๊ฒ€์‚ฌ
  • ์‚ฌ์ „ ํƒ์ง€ + ์‚ฌํ›„ ๋ชจ๋‹ˆํ„ฐ๋ง ํ†ตํ•ฉ
  • ISMS-P ์ฆ์  ์ž๋™ ์ƒ์„ฑ

์ฐจ๋ณ„์ : ์ธ์ฆ ๊ธฐ์ค€ ๊ด€์ ์—์„œ ํƒ์ง€ โ†’ ์กฐ์น˜ โ†’ ์ฆ์  ์ „ ๊ณผ์ • ์ž๋™ํ™”

โ† Cloud Security๋กœ ๋Œ์•„๊ฐ€๊ธฐ