โ† Data Protection & Disaster Recovery

ISMS-P 3.4.1 ๊ฐœ์ธ์ •๋ณด์˜ ํŒŒ๊ธฐ Critical Risk

๊ฐœ์ธ์ •๋ณด ํŒŒ๊ธฐ๊ฐ€ ์ ์ ˆํžˆ ์ˆ˜ํ–‰๋˜๊ณ  ์žˆ๋Š”๊ฐ€?

ISMS-P 3.4.1์€ ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ๋˜๋Š” ์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ์‹œ ๊ฐœ์ธ์ •๋ณด๋ฅผ ๋ณต๊ตฌ ๋ถˆ๊ฐ€๋Šฅํ•œ ๋ฐฉ๋ฒ•์œผ๋กœ ์ง€์ฒด ์—†์ด ํŒŒ๊ธฐํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” S3 Lifecycle๊ณผ DynamoDB TTL์„ ํ†ตํ•ด ์ž๋™ํ™”๋œ ํŒŒ๊ธฐ ์ฒด๊ณ„๋ฅผ ๊ตฌ์ถ•ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“‹

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 3.4.1 ๊ฐœ์ธ์ •๋ณด์˜ ํŒŒ๊ธฐ ์š”๊ตฌ์‚ฌํ•ญ

3.4.1

๊ฐœ์ธ์ •๋ณด์˜ ํŒŒ๊ธฐ

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"๊ฐœ์ธ์ •๋ณด์˜ ๋ณด์œ ๊ธฐ๊ฐ„ ๋ฐ ํŒŒ๊ธฐ ๊ด€๋ จ ๋‚ด๋ถ€ ์ •์ฑ…์„ ์ˆ˜๋ฆฝํ•˜๊ณ  ๊ฐœ์ธ์ •๋ณด์˜ ๋ณด์œ ๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ, ์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ๋“ฑ ํŒŒ๊ธฐ ์‹œ์ ์ด ๋„๋‹ฌํ•œ ๋•Œ์—๋Š” ํŒŒ๊ธฐ์˜ ์•ˆ์ „์„ฑ ๋ฐ ์™„์ „์„ฑ์ด ๋ณด์žฅ๋  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์œผ๋กœ ์ง€์ฒด ์—†์ด ํŒŒ๊ธฐํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

๐Ÿ“Œ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • S3 Lifecycle Policy๋ฅผ ํ†ตํ•œ ์ž๋™ ํŒŒ๊ธฐ ๊ตฌํ˜„
  • DynamoDB TTL(Time To Live)๋กœ ์ž๋™ ๋งŒ๋ฃŒ ์ฒ˜๋ฆฌ
  • ๋ณต๊ตฌ ๋ถˆ๊ฐ€๋Šฅํ•œ ๋ฐฉ๋ฒ•์œผ๋กœ ํŒŒ๊ธฐ (๋ฎ์–ด์“ฐ๊ธฐ, ์ดˆ๊ธฐํ™”)
  • CloudTrail ๋ฐ Lifecycle ์ด๋ฒคํŠธ๋กœ ํŒŒ๊ธฐ ๊ธฐ๋ก ๊ด€๋ฆฌ
  • ์—ฐ๊ณ„ ์‹œ์Šคํ…œ(CRM, DW) ๋ณต์ œ๋ณธ ๋™์‹œ ํŒŒ๊ธฐ

โš ๏ธ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ํ›„ ๊ฐœ์ธ์ •๋ณด ํŒŒ๊ธฐ ๋ฏธ์ดํ–‰
  • ๊ฒฐํ•จ: ํŒŒ๊ธฐ ์ •์ฑ… ๋ฏธ์ˆ˜๋ฆฝ (๋Œ€์ƒ/์ฃผ๊ธฐ/๋ฐฉ๋ฒ• ๋“ฑ)
  • ๊ฒฐํ•จ: ์—ฐ๊ณ„ ์‹œ์Šคํ…œ ๋ณต์ œ๋ณธ ๋ฏธํŒŒ๊ธฐ
  • ๊ณผํƒœ๋ฃŒ: 3์ฒœ๋งŒ์› ์ดํ•˜ (๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ๋ฒ• ์ œ75์กฐ)
๐Ÿ“„ KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ โ†— ๐Ÿ“– IT์œ„ํ‚ค ISMS-P 3.4.1 โ†—
๐Ÿ“ฐ

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

๊ฐœ์ธ์ •๋ณด ํŒŒ๊ธฐ ๋ฏธ์ดํ–‰์œผ๋กœ ๋ฐœ์ƒํ•œ ํ–‰์ •์ฒ˜๋ถ„ ์‚ฌ๋ก€

2024.05

๊ณจํ”„์กด ๊ฐœ์ธ์ •๋ณด ๋ฏธํŒŒ๊ธฐ

๋ณด์œ ๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ๋˜๋Š” ์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ๋œ ์ตœ์†Œ 38๋งŒ์—ฌ๋ช…์˜ ๊ฐœ์ธ์ •๋ณด ๋ฏธํŒŒ๊ธฐ. ์ค€ํšŒ์› 383,365๋ช…, ํ‡ด์ง์ž 2,916๋ช…, ์ฑ„์šฉ ๊ด€๋ จ ์ •๋ณด 1,159๋ช…, VOC ์ •๋ณด ๋“ฑ ํฌํ•จ. ๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ๋ฒ• ์ œ21์กฐ ํŒŒ๊ธฐ์˜๋ฌด ์œ„๋ฐ˜์œผ๋กœ ๊ณผํƒœ๋ฃŒ 540๋งŒ์› ๋ถ€๊ณผ.

๐Ÿ’ก ๊ตํ›ˆ: ์ˆ˜๋™ ํŒŒ๊ธฐ ์˜์กด ์‹œ ๋ˆ„๋ฝ ๋ฐœ์ƒ, ์ž๋™ํ™”๋œ ํŒŒ๊ธฐ ์ฒด๊ณ„ ํ•„์ˆ˜

์ถœ์ฒ˜: ๋ณด์•ˆ๋‰ด์Šค โ†—
2025.04

ํด๋ž˜์Šค์œ  ์‹ ๋ถ„์ฆ ์‚ฌ๋ณธ ๋ฏธํŒŒ๊ธฐ

์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑํ•œ ์ด์šฉ์ž์˜ ์‹ ๋ถ„์ฆ ์‚ฌ๋ณธ์„ ํŒŒ๊ธฐํ•˜์ง€ ์•Š๊ณ  ๋ณด๊ด€. ์•ฝ 160๋งŒ๋ช… ๊ฐœ์ธ์ •๋ณด ์œ ์ถœ ์‚ฌ๊ณ  ๋ฐœ์ƒ. ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ์œ„์›ํšŒ๋กœ๋ถ€ํ„ฐ ๊ณผ์ง•๊ธˆ 5,360๋งŒ์›, ๊ณผํƒœ๋ฃŒ 720๋งŒ์› ๋ถ€๊ณผ.

๐Ÿ’ก ๊ตํ›ˆ: ๋ฏผ๊ฐ์ •๋ณด๋Š” ์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ์ฆ‰์‹œ ํŒŒ๊ธฐ, ์ž๋™ ํŒŒ๊ธฐ ์ •์ฑ… ํ•„์ˆ˜

์ถœ์ฒ˜: ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ์œ„์›ํšŒ โ†—
โšก

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

AWS์—์„œ ๊ฐœ์ธ์ •๋ณด ์ž๋™ ํŒŒ๊ธฐ๊ฐ€ ๋ฏธ๊ตฌํ˜„๋œ ์ƒํ™ฉ

์ˆ˜๋™ ํŒŒ๊ธฐ (์œ„ํ—˜)

๋ฐ์ดํ„ฐ

๐Ÿ“‚

โณ

๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ

โ“

โ†‘ ๋‹ด๋‹น์ž ์‹ค์ˆ˜๋กœ ํŒŒ๊ธฐ ๋ˆ„๋ฝ ๋นˆ๋ฒˆ

ํŒŒ๊ธฐ ๋ˆ„๋ฝ ์‹œ 3์ฒœ๋งŒ์› ์ดํ•˜ ๊ณผํƒœ๋ฃŒ โ†’ ISMS-P 3.4.1 ๋ฏธ์ถฉ์กฑ

์ž๋™ ํŒŒ๊ธฐ (๊ถŒ์žฅ)

S3 Lifecycle

โฑ๏ธ

โ†’

์ž๋™ ์‚ญ์ œ

๐Ÿ—‘๏ธ

โ†‘ ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ์‹œ ์ž๋™ ํŒŒ๊ธฐ

์ •์ฑ… ๊ธฐ๋ฐ˜ ์ž๋™ ์‚ญ์ œ + ์ด๋ฒคํŠธ ๋กœ๊ทธ โ†’ ์ธ์ฆ ๊ธฐ์ค€ ์ถฉ์กฑ

๐Ÿšจ

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: S3 ๋ฒ„ํ‚ท๊ณผ DynamoDB ํ…Œ์ด๋ธ”์— ์ž๋™ ํŒŒ๊ธฐ ์ •์ฑ… ๋ฏธ์„ค์ •

๊ฐœ์ธ์ •๋ณด๋ฅผ ์ €์žฅํ•˜๋Š” S3 ๋ฒ„ํ‚ท์— lifecycle_configuration์ด ๋ฏธ์„ค์ •๋˜์–ด ์žˆ๊ณ , DynamoDB ํ…Œ์ด๋ธ”์— ttl์ด ๋น„ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์–ด ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ๋ฐ์ดํ„ฐ๊ฐ€ ๋ฌด๊ธฐํ•œ ๋ณด๊ด€๋˜๋Š” ์ƒํ™ฉ.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
# S3 ๋ฒ„ํ‚ท - Lifecycle Policy ๋ฏธ์„ค์ •
resource "aws_s3_bucket" "user_data" {
  bucket = "company-user-data"

  # lifecycle_rule ๋ฏธ์„ค์ • - ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ๋ฐ์ดํ„ฐ ์ˆ˜๋™ ์‚ญ์ œ ์˜์กด
  tags = {
    Name = "user-data"
  }
}

# DynamoDB ํ…Œ์ด๋ธ” - TTL ๋ฏธ์„ค์ •
resource "aws_dynamodb_table" "user_sessions" {
  name         = "user-sessions"
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "session_id"

  # TTL ๋ฏธ์„ค์ • - ์„ธ์…˜ ๋ฐ์ดํ„ฐ ๋ฌด๊ธฐํ•œ ๋ณด๊ด€
}

ISMS-P 3.4.1 ์œ„๋ฐ˜ ์‚ฌํ•ญ

โ—

๊ฐœ์ธ์ •๋ณด ํŒŒ๊ธฐ ์ •์ฑ… ๋ฏธ์ˆ˜๋ฆฝ

โ—

๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ๋ฐ์ดํ„ฐ ์ž๋™ ํŒŒ๊ธฐ ๋ฏธ๊ตฌํ˜„

โ—

ํŒŒ๊ธฐ ๊ธฐ๋ก ์ž๋™ ์ƒ์„ฑ ์ฒด๊ณ„ ๋ถ€์žฌ

โ—

์—ฐ๊ณ„ ์‹œ์Šคํ…œ ๋ฐ์ดํ„ฐ ๋™์‹œ ํŒŒ๊ธฐ ๋ฏธ๊ณ ๋ ค

๐Ÿ”

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

๊ฐœ์ธ์ •๋ณด ์ž๋™ ํŒŒ๊ธฐ ์ •์ฑ… ํƒ์ง€ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ“ฆ S3 Lifecycle
๋ฏธ์„ค์ • Lifecycle ๊ตฌ์„ฑ ์—†์Œ Critical - ์ฐจ๋‹จ
์„ค์ •๋จ โ†’ Expiration ์•ก์…˜ ๊ฒ€์‚ฌ
๐Ÿ—‘๏ธ Expiration ์•ก์…˜
๋ฏธ์„ค์ • Transition๋งŒ ์กด์žฌ High - ๊ฒฝ๊ณ 
์„ค์ •๋จ ์ž๋™ ์‚ญ์ œ ํ™œ์„ฑํ™” โ†’ ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒ€์‚ฌ
โฑ๏ธ DynamoDB TTL
๋ฏธ์„ค์ • ttl ๋ธ”๋ก ์—†์Œ High - ๊ฒฝ๊ณ 
enabled = true โœ“ ํ†ต๊ณผ
๐Ÿ””

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ด์ƒํ–‰์œ„ ํƒ์ง€

ํŒŒ๊ธฐ ์ •์ฑ… ๋Ÿฐํƒ€์ž„ ์ด๋ฒคํŠธ ๋Œ€์‘ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ“ฆ ๋ณ€๊ฒฝ ์œ ํ˜•
IaC ๋ฐฐํฌ (Terraform) ์ •์ƒ ๋ณ€๊ฒฝ โœ“ ๋ณ€๊ฒฝ ์ด๋ ฅ๋งŒ ์ €์žฅ
Drift ๋ฐœ์ƒ ์ฝ˜์†” ์ง์ ‘ ๋ณ€๊ฒฝ โ†’ ์ƒ์„ธ ๋ถ„์„
โš ๏ธ ๋ณ€๊ฒฝ ๋‚ด์šฉ

(Drift ๋ฐœ์ƒ ์‹œ)

Lifecycle ๊ทœ์น™ ์‚ญ์ œ ์ž๋™ ํŒŒ๊ธฐ ๋น„ํ™œ์„ฑํ™” Critical - PagerDuty ํ˜ธ์ถœ
Expiration ๊ธฐ๊ฐ„ ์—ฐ์žฅ 365์ผ โ†’ 730์ผ High - Slack ์ฆ‰์‹œ ์•Œ๋ฆผ
TTL ๋น„ํ™œ์„ฑํ™” DynamoDB TTL ๋” High - Slack ์ฆ‰์‹œ ์•Œ๋ฆผ

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

S3 ๋ฒ„ํ‚ท/DynamoDB ํ…Œ์ด๋ธ” ARN ๋ณ€๊ฒฝ ์ „/ํ›„ ํŒŒ๊ธฐ ์ •์ฑ… ๋ณ€๊ฒฝ ์ฃผ์ฒด (IAM) Lifecycle/TTL ์„ค์ • ๊ฐ€์ด๋“œ
โœ“

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

โŒ ๋ฌธ์ œ

S3 Lifecycle ๋ฐ DynamoDB TTL ๋ฏธ์„ค์ • (์ˆ˜๋™ ํŒŒ๊ธฐ ์˜์กด)

โœ“ ์ ์šฉ

aws_s3_bucket_lifecycle_configuration + ttl ๋ธ”๋ก

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
data-lifecycle.tf
# S3 ๋ฒ„ํ‚ท - ๊ฐœ์ธ์ •๋ณด ์ €์žฅ์šฉ
resource "aws_s3_bucket" "user_data" {
  bucket = "company-user-data"

  tags = {
    Name        = "user-data"
    Environment = "production"
    ISMS-P      = "3.4.1"
  }
}

# S3 Lifecycle ๊ทœ์น™ - ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ํ›„ ์ž๋™ ์‚ญ์ œ
resource "aws_s3_bucket_lifecycle_configuration" "user_data" {
  bucket = aws_s3_bucket.user_data.id

  rule {
    id     = "expire-personal-data"
    status = "Enabled"

    filter {
      prefix = "personal-data/"
    }

    # ๋ณด์กด๊ธฐ๊ฐ„(์˜ˆ: 1๋…„) ๊ฒฝ๊ณผ ํ›„ ์ž๋™ ์‚ญ์ œ
    expiration {
      days = 365
    }
  }
}

# S3 Lifecycle ์ด๋ฒคํŠธ ์•Œ๋ฆผ (ํŒŒ๊ธฐ ์ฆ์ )
resource "aws_s3_bucket_notification" "user_data" {
  bucket = aws_s3_bucket.user_data.id

  lambda_function {
    lambda_function_arn = aws_lambda_function.log_deletion.arn
    events              = ["s3:LifecycleExpiration:*"]
  }
}

# DynamoDB ํ…Œ์ด๋ธ” - TTL ์„ค์ •
resource "aws_dynamodb_table" "user_sessions" {
  name         = "user-sessions"
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "session_id"

  attribute {
    name = "session_id"
    type = "S"
  }

  # TTL ํ™œ์„ฑํ™” - expire_at ํ•„๋“œ ๊ธฐ์ค€ ์ž๋™ ์‚ญ์ œ
  ttl {
    attribute_name = "expire_at"
    enabled        = true
  }

  tags = {
    Name   = "user-sessions"
    ISMS-P = "3.4.1"
  }
}

๐Ÿ’ก ํ•ต์‹ฌ: aws_s3_bucket_lifecycle_configuration์˜ expiration ๋ธ”๋ก์œผ๋กœ ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ๊ฐ์ฒด๋ฅผ ์ž๋™ ์‚ญ์ œํ•ฉ๋‹ˆ๋‹ค. DynamoDB๋Š” ttl ๋ธ”๋ก์„ ํ™œ์„ฑํ™”ํ•˜๊ณ  ๊ฐ ์•„์ดํ…œ์— Unix epoch ํ˜•์‹์˜ ๋งŒ๋ฃŒ ์‹œ๊ฐ„์„ ์ €์žฅํ•˜๋ฉด ์ž๋™์œผ๋กœ ์‚ญ์ œ๋ฉ๋‹ˆ๋‹ค. S3 Lifecycle ์ด๋ฒคํŠธ ์•Œ๋ฆผ์„ ํ†ตํ•ด ํŒŒ๊ธฐ ๊ธฐ๋ก์„ ์ž๋™์œผ๋กœ ์ˆ˜์ง‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

๐Ÿ“ฆ AWS S3 Lifecycle โ†— โฑ๏ธ AWS DynamoDB TTL โ†— ๐Ÿ“œ ๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ๋ฒ• ์ œ21์กฐ โ†—
๐Ÿ“Š

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

๐Ÿ“‹ ์ง„๋‹จ ํ•ญ๋ชฉ

  • Lifecycle ์ •์ฑ…์ด ์ ์šฉ๋œ S3 ๋ฒ„ํ‚ท ์ˆ˜
  • Expiration ์•ก์…˜ ๋ฏธ์„ค์ • ๋ฒ„ํ‚ท
  • TTL ํ™œ์„ฑํ™”๋œ DynamoDB ํ…Œ์ด๋ธ” ์ˆ˜
  • ํŒŒ๊ธฐ ๋Œ€์ƒ ๋ฐ์ดํ„ฐ ํ˜„ํ™ฉ (๋ณด์กด๊ธฐ๊ฐ„ ์ดˆ๊ณผ)
  • ํŒŒ๊ธฐ ์ด๋ฒคํŠธ ๋กœ๊ทธ ์ˆ˜์ง‘ ํ˜„ํ™ฉ

๐Ÿ“… ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

ํŒŒ๊ธฐ ์‹คํ–‰ ํ˜„ํ™ฉ (S3 Lifecycle ์ด๋ฒคํŠธ)

์ฃผ๊ฐ„

ํŒŒ๊ธฐ ์ •์ฑ… ์ค€์ˆ˜ ํ˜„ํ™ฉ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ (ํŒŒ๊ธฐ ๊ด€๋ฆฌ๋Œ€์žฅ)

๐Ÿ“ค ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)
โšก

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

๋‹จ์ˆœ Lifecycle ํ™œ์„ฑํ™” ๊ฒ€์‚ฌ

  • lifecycle_configuration.rules[].status == "Enabled" ๋‹จ์ˆœ ๋น„๊ต
  • Expiration ์•ก์…˜ ์œ ๋ฌด ๋ฏธ๊ฒ€์ฆ (Transition๋งŒ ์žˆ์–ด๋„ PASS)
  • ์ •์  ๋ถ„์„ ๊ฒฐ๊ณผ๋งŒ ์ถœ๋ ฅ

ํ•œ๊ณ„: DynamoDB TTL ๋ฏธ์ ๊ฒ€, ๋ณด์กด๊ธฐ๊ฐ„ ์ ์ •์„ฑ ๋ฏธ๊ฒ€์ฆ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

Lifecycle + Expiration + TTL ํ†ตํ•ฉ ์ ๊ฒ€

  • IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ Expiration ์•ก์…˜ ํ•„์ˆ˜ ๊ฒ€์ฆ
  • S3 + DynamoDB + RDS ๋ฐ์ดํ„ฐ ํŒŒ๊ธฐ ์ •์ฑ… ํ†ตํ•ฉ ๊ฒ€์ฆ
  • ๋Ÿฐํƒ€์ž„ ํŒŒ๊ธฐ ์ •์ฑ… ๋ณ€๊ฒฝ ๋ชจ๋‹ˆํ„ฐ๋ง + Drift ํƒ์ง€

์ฐจ๋ณ„์ : ISMS-P 3.4.2(์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ํ›„ ๋ณด์œ )์™€ ํ†ตํ•ฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ ์ƒ๋ช…์ฃผ๊ธฐ ์ „์ฒด ๊ฒ€์ฆ

โ† Data Protection & Disaster Recovery๋กœ ๋Œ์•„๊ฐ€๊ธฐ