โ† IaC/Terraform Management

ISMS-P 2.9.4 ๋กœ๊ทธ ๋ฐ ์ ‘์†๊ธฐ๋ก ๊ด€๋ฆฌ High Risk

๋กœ๊ทธ ๋ฐ ์ ‘์†๊ธฐ๋ก์ด ์ ์ ˆํžˆ ๊ด€๋ฆฌ๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 2.9.4๋Š” ์„œ๋ฒ„, ์‘์šฉํ”„๋กœ๊ทธ๋žจ, ๋ณด์•ˆ์‹œ์Šคํ…œ, ๋„คํŠธ์›Œํฌ ์‹œ์Šคํ…œ์˜ ๋กœ๊ทธ๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ๋ณด๊ด€ํ•˜๊ณ  ์œ„ยท๋ณ€์กฐ๋˜์ง€ ์•Š๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” CloudTrail๊ณผ CloudWatch Logs๋กœ ์ค‘์•™ ์ˆ˜์ง‘ํ•˜๊ณ  ๋ฒ•์  ๋ณด์กด๊ธฐ๊ฐ„์„ ์ค€์ˆ˜ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“‹

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 2.9.4 ๋กœ๊ทธ ๋ฐ ์ ‘์†๊ธฐ๋ก ๊ด€๋ฆฌ ์š”๊ตฌ์‚ฌํ•ญ

2.9.4

๋กœ๊ทธ ๋ฐ ์ ‘์†๊ธฐ๋ก ๊ด€๋ฆฌ

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"์„œ๋ฒ„, ์‘์šฉํ”„๋กœ๊ทธ๋žจ, ๋ณด์•ˆ์‹œ์Šคํ…œ, ๋„คํŠธ์›Œํฌ์‹œ์Šคํ…œ ๋“ฑ ์ •๋ณด์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ์‚ฌ์šฉ์ž ์ ‘์†๊ธฐ๋ก, ์‹œ์Šคํ…œ๋กœ๊ทธ, ๊ถŒํ•œ๋ถ€์—ฌ ๋‚ด์—ญ ๋“ฑ์˜ ๋กœ๊ทธ์œ ํ˜•, ๋ณด์กด๊ธฐ๊ฐ„, ๋ณด์กด๋ฐฉ๋ฒ• ๋“ฑ์„ ์ •ํ•˜๊ณ  ์œ„ยท๋ณ€์กฐ, ๋„๋‚œ, ๋ถ„์‹ค ๋˜์ง€ ์•Š๋„๋ก ์•ˆ์ „ํ•˜๊ฒŒ ๋ณด์กดยท๊ด€๋ฆฌํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

๐Ÿ“Œ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • CloudTrail๋กœ API ํ˜ธ์ถœ ๋กœ๊ทธ ์ˆ˜์ง‘
  • CloudWatch Logs๋กœ ์‹œ์Šคํ…œ ๋กœ๊ทธ ์ค‘์•™ ์ง‘์ค‘
  • VPC Flow Logs๋กœ ๋„คํŠธ์›Œํฌ ์ ‘์† ๊ธฐ๋ก
  • S3 ๋ฒ„์ „ ๊ด€๋ฆฌ๋กœ ๋กœ๊ทธ ์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€

โš ๏ธ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ๋กœ๊ทธ ๊ด€๋ฆฌ ์ ˆ์ฐจ ๋ฏธ์ˆ˜๋ฆฝ
  • ๊ฒฐํ•จ: ์ ‘์†๊ธฐ๋ก ๋ณด์กด๊ธฐ๊ฐ„ ๋ฏธ์ค€์ˆ˜ (1๋…„/2๋…„)
  • ๊ฒฐํ•จ: ๋กœ๊ทธ ์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€ ์กฐ์น˜ ๋ฏธํก
๐Ÿ“„ KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ โ†— โ˜๏ธ AWS CloudTrail ๊ฐ€์ด๋“œ โ†—
๐Ÿ“ฐ

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

๋กœ๊ทธ ๊ด€๋ฆฌ ๋ฏธํก์œผ๋กœ ๋ฐœ์ƒํ•œ ์‹ค์ œ ์‚ฌ๊ณ 

2022.07

์•Œ๋ฆฌ๋ฐ”๋ฐ” ํด๋ผ์šฐ๋“œ 10์–ต ๋ช… ์ •๋ณด ๋…ธ์ถœ

ํด๋ผ์šฐ๋“œ ์„œ๋ฒ„ ์„ค์ • ์˜ค๋ฅ˜๋กœ 23TB ๋ฐ์ดํ„ฐ๊ฐ€ 1๋…„ ์ด์ƒ ๊ณต๊ฐœ. 10์–ต ๋ช…์˜ ์ค‘๊ตญ ์ผ๋ฐ˜์ธ๊ณผ ์ƒํ•˜์ด ๊ณต์•ˆ ์š”์› ์ •๋ณด ํฌํ•จ. ์ ‘๊ทผ ๋กœ๊ทธ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ถ€์žฌ๋กœ ์žฅ๊ธฐ๊ฐ„ ๋ฏธํƒ์ง€.

๐Ÿ’ก ๊ตํ›ˆ: ์ ‘๊ทผ ๋กœ๊ทธ ๋ชจ๋‹ˆํ„ฐ๋ง ํ•„์ˆ˜, ์ด์ƒ ์ ‘๊ทผ ์ž๋™ ํƒ์ง€ ์ฒด๊ณ„ ๊ตฌ์ถ•

์ถœ์ฒ˜: BleepingComputer โ†—
2016-2018

Uber 5,700๋งŒ ๋ช… ์œ ์ถœ ์‚ฌ๊ณ  ์€ํ

5,700๋งŒ ๋ช… ๊ฐœ์ธ์ •๋ณด ์œ ์ถœ ์‚ฌ๊ณ ๋ฅผ 1๋…„ ์ด์ƒ ์€ํ. ์ ‘์†๊ธฐ๋ก ๋ฏธ๋ณด์กด ๋ฐ ์€ํ๋กœ ์‚ฌ๊ณ  ์กฐ์‚ฌ ์ง€์—ฐ. ๋ฏธ๊ตญ 50๊ฐœ ์ฃผ์™€ 1์–ต 4800๋งŒ ๋‹ฌ๋Ÿฌ ํ•ฉ์˜.

๐Ÿ’ก ๊ตํ›ˆ: ์ ‘์†๊ธฐ๋ก ์˜๋ฌด ๋ณด์กด, ์‚ฌ๊ณ  ๋ฐœ์ƒ ์‹œ ์ฆ‰์‹œ ๋ณด๊ณ  ์ฒด๊ณ„ ๊ตฌ์ถ•

์ถœ์ฒ˜: FTC โ†—
โšก

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

AWS์—์„œ ๋กœ๊ทธ ๊ด€๋ฆฌ๊ฐ€ ์œ„๋ฐ˜๋˜๋Š” ์ƒํ™ฉ

๋กœ๊ทธ ๋ฏธ๊ด€๋ฆฌ ์ƒํƒœ (์œ„ํ—˜)

CloudTrail

90์ผ ์ œํ•œ

S3 ์ €์žฅ

๋ฏธ์„ค์ •

๋ฌด๊ฒฐ์„ฑ

๋ฏธ๊ฒ€์ฆ

โ†‘ ISMS-P ๋ณด์กด๊ธฐ๊ฐ„ ๋ฏธ์ค€์ˆ˜

๊ธฐ๋ณธ ์„ค์ •๋งŒ ์‚ฌ์šฉ ์‹œ 90์ผ ํ›„ API ๋กœ๊ทธ ์ž๋™ ์†Œ์‹ค โ†’ ๋ฒ•์  ๋ณด์กด๊ธฐ๊ฐ„ ์œ„๋ฐ˜

์ฒด๊ณ„์  ๋กœ๊ทธ ๊ด€๋ฆฌ (๊ถŒ์žฅ)

CloudTrail

S3 ์ €์žฅ

๋ณด์กด๊ธฐ๊ฐ„

730์ผ

๋ฌด๊ฒฐ์„ฑ

๊ฒ€์ฆ ํ™œ์„ฑ

โ†‘ ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ์ค€์ˆ˜

S3 ์žฅ๊ธฐ ๋ณด์กด + ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ + KMS ์•”ํ˜ธํ™”๋กœ ์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€

๐Ÿšจ

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: CloudTrail ๊ธฐ๋ณธ ์„ค์ •๋งŒ ์‚ฌ์šฉ

CloudTrail์ด ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์ง€๋งŒ S3 ์žฅ๊ธฐ ์ €์žฅ ๋ฏธ์„ค์ •. 90์ผ ์ดํ›„ ๋กœ๊ทธ๊ฐ€ ์†Œ์‹ค๋˜์–ด ๋ฒ•์  ๋ณด์กด๊ธฐ๊ฐ„(1๋…„/2๋…„) ๋ฏธ์ค€์ˆ˜. ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ๋ฏธํ™œ์„ฑํ™”๋กœ ๋กœ๊ทธ ์œ„ยท๋ณ€์กฐ ์—ฌ๋ถ€ ํ™•์ธ ๋ถˆ๊ฐ€.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
# CloudTrail ๊ธฐ๋ณธ ์„ค์ •๋งŒ ์‚ฌ์šฉ
# API ๋กœ๊ทธ 90์ผ ํ›„ ์ž๋™ ์†Œ์‹ค

# ๋ฌธ์ œ์ :
# - S3 ์žฅ๊ธฐ ๋ณด์กด ๋ฏธ์„ค์ •
# - ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ๋ฏธํ™œ์„ฑํ™”
# - CloudWatch Logs ๋ฏธ์—ฐ๋™
# - ๊ฐœ์ธ์ •๋ณด์ฒ˜๋ฆฌ์‹œ์Šคํ…œ ์ ‘์†๊ธฐ๋ก ๋ฏธ๊ธฐ๋ก

# ISMS-P ๊ฒฐํ•จ:
# - ๋ณด์กด๊ธฐ๊ฐ„ ๋ฏธ์ค€์ˆ˜ (1๋…„/2๋…„ ํ•„์ˆ˜)
# - ์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€ ์กฐ์น˜ ๋ฏธํก
# - ๋ฒ•์  ์ฆ์  ๋ถˆ๊ฐ€

ISMS-P 2.9.4 ์œ„๋ฐ˜ ์‚ฌํ•ญ

โ—

๋ณด์กด๊ธฐ๊ฐ„ ๋ฏธ์ค€์ˆ˜ - 1๋…„/2๋…„ ๋ฒ•์  ์š”๊ตฌ์‚ฌํ•ญ ๋ฏธ์ถฉ์กฑ

โ—

๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ๋ฏธํก - ๋กœ๊ทธ ์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€ ์กฐ์น˜ ์—†์Œ

โ—

ํ•„์ˆ˜ ํ•ญ๋ชฉ ๋ˆ„๋ฝ - ์ˆ˜ํ–‰์—…๋ฌด, ์ฒ˜๋ฆฌ ์ •๋ณด์ฃผ์ฒด ๋ฏธ๊ธฐ๋ก

โ—

์•”ํ˜ธํ™” ๋ฏธ์ ์šฉ - ๋กœ๊ทธ ๋ฐ์ดํ„ฐ ํ‰๋ฌธ ์ €์žฅ

๐Ÿ”

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

CloudTrail/CloudWatch ๋กœ๊ทธ ์„ค์ • ํƒ์ง€ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ“ฆ CloudTrail ์„ค์ •
Trail ๋ฆฌ์†Œ์Šค ๋ฏธ์ƒ์„ฑ Critical - ํ•„์ˆ˜ ์„ค์ • ํ•„์š”
is_multi_region_trail = true โœ“ ํ†ต๊ณผ
๐Ÿ”’ ๋ฌด๊ฒฐ์„ฑ/์•”ํ˜ธํ™”
enable_log_file_validation = false High - ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ๋ถˆ๊ฐ€
kms_key_id ๋ฏธ์„ค์ • Medium - ์•”ํ˜ธํ™” ๊ถŒ๊ณ 
S3 ๋ฒ„์ „ ๊ด€๋ฆฌ ๋ฏธํ™œ์„ฑํ™” High - ๋กœ๊ทธ ๋ณต๊ตฌ ๋ถˆ๊ฐ€
๐Ÿ“… ๋ณด์กด๊ธฐ๊ฐ„
retention_in_days ๋ฏธ์„ค์ • High - ๋ณด์กด๊ธฐ๊ฐ„ ๋ฏธ๊ด€๋ฆฌ
retention_in_days = 730 โœ“ 2๋…„ ๋ณด์กด ์ค€์ˆ˜
๐Ÿ””

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ด์ƒํ–‰์œ„ ํƒ์ง€

๋กœ๊ทธ ์ˆ˜์ง‘ ์ƒํƒœ ๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ“ก ๋กœ๊ทธ ์ „์†ก ์ƒํƒœ
๋กœ๊ทธ ์ด๋ฒคํŠธ ์ •์ƒ ์ˆ˜์‹  ์ง€์†์  ์ „์†ก โœ“ ์ •์ƒ
๋กœ๊ทธ ์ด๋ฒคํŠธ ๋ฏธ์ˆ˜์‹  ์ „์†ก ์ค‘๋‹จ Critical - SNS ์•Œ๋ฆผ ๋ฐœ์†ก
โš™๏ธ ์„ค์ • ๋ณ€๊ฒฝ ๊ฐ์ง€
CloudTrail ๋น„ํ™œ์„ฑํ™” Config Rule ์œ„๋ฐ˜ Critical - ์ฆ‰์‹œ ๋ณต๊ตฌ ์กฐ์น˜
CloudTrail ์„ค์ • ๋ณ€๊ฒฝ EventBridge ํƒ์ง€ High - ์Šน์ธ ์—ฌ๋ถ€ ํ™•์ธ
S3 ๋ฒ„ํ‚ท ์ ‘๊ทผ ์˜ค๋ฅ˜ ๊ถŒํ•œ/์ƒํƒœ ์ด์ƒ Critical - ๊ธด๊ธ‰ ์•Œ๋ฆผ + ๊ถŒํ•œ ์ ๊ฒ€

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

์˜ํ–ฅ๋ฐ›๋Š” Trail ์ด๋ฆ„ ๋ณ€๊ฒฝ ์ฃผ์ฒด (IAM) ๋ณ€๊ฒฝ ์‹œ๊ฐ ๋ณต๊ตฌ ๊ฐ€์ด๋“œ ๋งํฌ
โœ“

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

โŒ ํ˜„์žฌ ๋ฌธ์ œ

CloudTrail ๊ธฐ๋ณธ ์„ค์ •๋งŒ ์‚ฌ์šฉ, 90์ผ ํ›„ ๋กœ๊ทธ ์†Œ์‹ค

โœ“ ๊ถŒ์žฅ ์กฐ์น˜

S3 ์žฅ๊ธฐ ๋ณด์กด + ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ + 730์ผ ๋ณด์กด ์„ค์ •

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
cloudtrail.tf
# CloudTrail - ์ „์ฒด ๋ฆฌ์ „ API ๋กœ๊ทธ ์ˆ˜์ง‘
resource "aws_cloudtrail" "main" {
  name                          = "organization-trail"
  s3_bucket_name                = aws_s3_bucket.cloudtrail.id
  include_global_service_events = true
  is_multi_region_trail         = true
  enable_logging                = true

  # โœ“ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ํ™œ์„ฑํ™” (ISMS-P ํ•„์ˆ˜)
  enable_log_file_validation = true

  # โœ“ KMS ์•”ํ˜ธํ™” (์œ„ยท๋ณ€์กฐ ๋ฐฉ์ง€)
  kms_key_id = aws_kms_key.cloudtrail.arn

  # โœ“ CloudWatch Logs ์—ฐ๋™
  cloud_watch_logs_group_arn = "${aws_cloudwatch_log_group.cloudtrail.arn}:*"
  cloud_watch_logs_role_arn  = aws_iam_role.cloudtrail_cloudwatch.arn

  tags = {
    ISMS-P    = "2.9.4"
    Retention = "2-years"
  }
}

# CloudWatch Log Group - ๋ณด์กด๊ธฐ๊ฐ„ 2๋…„ ์„ค์ •
resource "aws_cloudwatch_log_group" "cloudtrail" {
  name              = "/aws/cloudtrail/organization"
  retention_in_days = 730  # 2๋…„ (5๋งŒ๋ช… ์ด์ƒ ์‚ฌ์—…์ž)
  kms_key_id        = aws_kms_key.cloudwatch.arn
}

# S3 ๋ฒ„ํ‚ท - ๋ฒ„์ „ ๊ด€๋ฆฌ ํ™œ์„ฑํ™”
resource "aws_s3_bucket_versioning" "cloudtrail" {
  bucket = aws_s3_bucket.cloudtrail.id
  versioning_configuration {
    status = "Enabled"  # ์‚ญ์ œ๋œ ๋กœ๊ทธ ๋ณต๊ตฌ ๊ฐ€๋Šฅ
  }
}

๐Ÿ’ก ํ•ต์‹ฌ: CloudTrail + CloudWatch Logs + S3 ๋ฒ„์ „ ๊ด€๋ฆฌ ์กฐํ•ฉ์œผ๋กœ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ, ์•”ํ˜ธํ™”, ๋ฒ•์  ๋ณด์กด๊ธฐ๊ฐ„์„ ๋ชจ๋‘ ์ถฉ์กฑํ•ฉ๋‹ˆ๋‹ค. ๊ฐœ์ธ์ •๋ณด์ฒ˜๋ฆฌ์‹œ์Šคํ…œ์€ 730์ผ(2๋…„) ๋ณด์กด์ด ํ•„์ˆ˜์ž…๋‹ˆ๋‹ค.

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

โ˜๏ธ AWS CloudTrail ๊ฐ€์ด๋“œ โ†— ๐Ÿ“˜ CloudWatch Logs ๊ฐ€์ด๋“œ โ†— ๐Ÿ”’ AWS K-ISMS ๊ทœ์ • ์ค€์ˆ˜ โ†—
๐Ÿ“Š

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

๐Ÿ“‹ ์ง„๋‹จ ํ•ญ๋ชฉ

  • CloudTrail ํ™œ์„ฑํ™” ํ˜„ํ™ฉ
  • S3 ์žฅ๊ธฐ ๋ณด์กด ์„ค์ • ์ƒํƒœ
  • ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ ํ™œ์„ฑํ™” ์—ฌ๋ถ€
  • CloudWatch ๋ณด์กด๊ธฐ๊ฐ„ ์„ค์ •
  • KMS ์•”ํ˜ธํ™” ์ ์šฉ ์ƒํƒœ

๐Ÿ“… ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

๋กœ๊ทธ ์ˆ˜์ง‘ ์ƒํƒœ ์•Œ๋ฆผ

์ฃผ๊ฐ„

์„ค์ • ๋ณ€๊ฒฝ ํ˜„ํ™ฉ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ

๐Ÿ“ค ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)
โšก

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

CloudTrail ํ™œ์„ฑํ™” ์—ฌ๋ถ€๋งŒ ํ™•์ธ

  • Trail ์กด์žฌ ์—ฌ๋ถ€ ์ฒดํฌ
  • ๋กœ๊ทธ ์กด์žฌ ์—ฌ๋ถ€ ๋‹จ์ˆœ ํ™•์ธ
  • ํ™œ์„ฑํ™”/๋น„ํ™œ์„ฑํ™” ์ƒํƒœ๋งŒ ํƒ์ง€

ํ•œ๊ณ„: ๋ณด์กด๊ธฐ๊ฐ„ ์ ์ •์„ฑ, ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ, ์•”ํ˜ธํ™” ์„ค์ • ๋“ฑ ISMS-P ์ƒ์„ธ ์š”๊ตฌ์‚ฌํ•ญ ๊ฒ€์ฆ ๋ถˆ๊ฐ€

BSG ์ ‘๊ทผ ๋ฐฉ์‹

ISMS-P ๊ด€์  ํ†ตํ•ฉ ์ ๊ฒ€

  • ๋ฒ•์  ๋ณด์กด๊ธฐ๊ฐ„ (1๋…„/2๋…„) ์ค€์ˆ˜ ์—ฌ๋ถ€ ์ž๋™ ๊ฒ€์ฆ
  • ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์ฆ, ์•”ํ˜ธํ™” ์„ค์ • ์ƒํƒœ ํ™•์ธ
  • ์‚ฌ์ „ ํƒ์ง€ + ์‚ฌํ›„ ๋ชจ๋‹ˆํ„ฐ๋ง ํ†ตํ•ฉ

์ฐจ๋ณ„์ : ISMS-P ์ ‘์†๊ธฐ๋ก ์š”๊ตฌ์‚ฌํ•ญ ๋งคํ•‘ + ์‹ฌ์‚ฌ ์ฆ์  ์ž๋™ํ™”

โ† ISMS-P ๋งคํ•‘ ๋ชฉ๋ก์œผ๋กœ ๋Œ์•„๊ฐ€๊ธฐ