โ† Data Protection & Disaster Recovery

ISMS-P 3.4.2 ์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ํ›„ ๋ณด์œ  ์‹œ ์กฐ์น˜ High Risk

์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ํ›„ ๋ณด์œ  ์กฐ์น˜๊ฐ€ ์ ์ ˆํ•œ๊ฐ€?

ISMS-P 3.4.2๋Š” ๋ฒ•๋ น์— ๋”ฐ๋ผ ๊ฐœ์ธ์ •๋ณด๋ฅผ ๋ณด์กดํ•ด์•ผ ํ•  ๊ฒฝ์šฐ, ์ตœ์†Œํ•œ์˜ ํ•ญ๋ชฉ์œผ๋กœ ์ œํ•œํ•˜๊ณ  ๋‹ค๋ฅธ ๊ฐœ์ธ์ •๋ณด์™€ ๋ถ„๋ฆฌํ•˜์—ฌ ์ €์žฅยท๊ด€๋ฆฌํ•˜๋„๋ก ์š”๊ตฌํ•ฉ๋‹ˆ๋‹ค. ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ๋Š” ๋ณ„๋„ ๋ฒ„ํ‚ท + Object Lock + ์ ‘๊ทผ๊ถŒํ•œ ์ตœ์†Œํ™”๋กœ ๊ตฌํ˜„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ“‹

ISMS-P ์ธ์ฆ ๊ธฐ์ค€

ISMS-P 3.4.2 ์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ํ›„ ๋ณด์œ  ์‹œ ์กฐ์น˜ ์š”๊ตฌ์‚ฌํ•ญ

3.4.2

์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ํ›„ ๋ณด์œ  ์‹œ ์กฐ์น˜

์ธ์ฆ ๊ธฐ์ค€ ์ •์˜

"๊ฐœ์ธ์ •๋ณด์˜ ๋ณด์œ ๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ๋˜๋Š” ์ฒ˜๋ฆฌ๋ชฉ์  ๋‹ฌ์„ฑ ํ›„์—๋„ ๊ด€๋ จ ๋ฒ•๋ น ๋“ฑ์— ๋”ฐ๋ผ ํŒŒ๊ธฐํ•˜์ง€ ์•„๋‹ˆํ•˜๊ณ  ๋ณด์กดํ•˜๋Š” ๊ฒฝ์šฐ์—๋Š” ํ•ด๋‹น ๋ชฉ์ ์— ํ•„์š”ํ•œ ์ตœ์†Œํ•œ์˜ ํ•ญ๋ชฉ์œผ๋กœ ์ œํ•œํ•˜๊ณ  ๋‹ค๋ฅธ ๊ฐœ์ธ์ •๋ณด์™€ ๋ถ„๋ฆฌํ•˜์—ฌ ์ €์žฅยท๊ด€๋ฆฌํ•˜์—ฌ์•ผ ํ•œ๋‹ค."

๐Ÿ“Œ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ ์ ์šฉ ํฌ์ธํŠธ

  • S3 ๋ณ„๋„ ๋ฒ„ํ‚ท์œผ๋กœ ๋ฌผ๋ฆฌ์ /๋…ผ๋ฆฌ์  ๋ถ„๋ฆฌ ์ €์žฅ
  • S3 Object Lock (Compliance Mode)์œผ๋กœ ๋ฌด๊ฒฐ์„ฑ ๋ณด์žฅ
  • IAM ์ •์ฑ…์œผ๋กœ ์ ‘๊ทผ๊ถŒํ•œ ์ตœ์†Œ ์ธ์› ์ œํ•œ
  • S3 Glacier๋กœ ์žฅ๊ธฐ ๋ณด๊ด€ ๋น„์šฉ ์ตœ์ ํ™”
  • ๋ฒ•์ • ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ํ›„ ์ž๋™ ํŒŒ๊ธฐ ์—ฐ๊ณ„ (3.4.1)

โš ๏ธ ๋ฏธ์ค€์ˆ˜ ์‹œ ์‹ฌ์‚ฌ ์˜ํ–ฅ

  • ๊ฒฐํ•จ: ๋ฒ•์ • ๋ณด์กด ๊ฐœ์ธ์ •๋ณด ๋ฏธ๋ถ„๋ฆฌ ์ €์žฅ
  • ๊ฒฐํ•จ: ๋ถ„๋ฆฌ ์ €์žฅ ํ›„ ์ ‘๊ทผ๊ถŒํ•œ ๋ฏธ๋ถ„๋ฆฌ
  • ๊ฒฐํ•จ: ๋ฒ•์ • ๋ณด์กด๊ธฐ๊ฐ„ ์ดˆ๊ณผ ์žฅ๊ธฐ ๋ณด๊ด€
  • ๊ณผํƒœ๋ฃŒ: 1์ฒœ๋งŒ์› ์ดํ•˜ (๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ๋ฒ• ์ œ75์กฐ)
๐Ÿ“„ KISA ISMS-P ์ธ์ฆ๊ธฐ์ค€ ์•ˆ๋‚ด์„œ โ†— ๐Ÿ“– ISMS-P 3.4.2 ์ƒ์„ธ ์•ˆ๋‚ด โ†—
๐Ÿ“ฐ

์‹ค์ œ ๋ณด์•ˆ ์‚ฌ๊ณ  ์‚ฌ๋ก€

๋ถ„๋ฆฌ ๋ณด๊ด€ ๋ฏธ์ดํ–‰์œผ๋กœ ๋ฐœ์ƒํ•œ ๊ฐœ์ธ์ •๋ณด ์œ ์ถœ ์‚ฌ๋ก€

2025.12

์ฟ ํŒก ํƒˆํ‡ดํšŒ์› ์ •๋ณด ๋ถ„๋ฆฌ๋ณด๊ด€ ๋ฏธ์ดํ–‰

ํƒˆํ‡ด 2๋…„ ๊ฒฝ๊ณผํ•œ ํšŒ์›์˜ ๊ฐœ์ธ์ •๋ณด๊นŒ์ง€ ์œ ์ถœ. ์ „์ž์ƒ๊ฑฐ๋ž˜๋ฒ•์ƒ 5๋…„ ๋ณด์กด ์˜๋ฌด ๋ฐ์ดํ„ฐ๋Š” ํ™œ์„ฑ ํšŒ์› ์ •๋ณด์™€ ๋ถ„๋ฆฌ ์ €์žฅํ•ด์•ผ ํ•˜๋‚˜, ๋ถ„๋ฆฌ ๋ณด๊ด€ ๋ฏธ์ดํ–‰ ์˜ํ˜น. ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ์œ„์›ํšŒ ์กฐ์‚ฌ ์ง„ํ–‰ ์ค‘.

๐Ÿ’ก ๊ตํ›ˆ: ๋ฒ•์ • ๋ณด์กด ๋ฐ์ดํ„ฐ๋Š” ๋ณ„๋„ ๋ฒ„ํ‚ท/ํ…Œ์ด๋ธ”๋กœ ๋ถ„๋ฆฌ, ์ ‘๊ทผ ๊ถŒํ•œ ์ตœ์†Œํ™” ํ•„์ˆ˜

์ถœ์ฒ˜: SBS ๋‰ด์Šค โ†—
2023

์˜จ๋ผ์ธ ์‡ผํ•‘๋ชฐ ๋ฒ•์ • ๋ณด์กด์ •๋ณด ์œ ์ถœ

์ „์ž์ƒ๊ฑฐ๋ž˜๋ฒ•์ƒ 5๋…„ ๋ณด์กด ์ฃผ๋ฌธ์ •๋ณด ํ…Œ์ด๋ธ”์—์„œ ๊ฐœ์ธ์ •๋ณด ์œ ์ถœ. ํšŒ์›์ •๋ณด์™€ ๋ถ„๋ฆฌ๋˜์ง€ ์•Š์€ ์ฃผ๋ฌธ์ •๋ณด ํ…Œ์ด๋ธ”์ด ํ•ดํ‚น ๋Œ€์ƒ์ด ๋จ. ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ์œ„์›ํšŒ๋กœ๋ถ€ํ„ฐ ๊ณผํƒœ๋ฃŒ 600๋งŒ์› ๋ถ€๊ณผ.

๐Ÿ’ก ๊ตํ›ˆ: ๋ฒ•์ • ๋ณด์กด ๋ฐ์ดํ„ฐ๋„ ๋ณ„๋„ ์ €์žฅ์†Œ๋กœ ๋ถ„๋ฆฌํ•˜๊ณ  ์ ‘๊ทผ ํ†ต์ œ ๊ฐ•ํ™” ํ•„์š”

์ถœ์ฒ˜: ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ์œ„์›ํšŒ ์˜๊ฒฐ โ†—
โšก

ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์˜ ์œ„ํ—˜

AWS์—์„œ ๋ฒ•์ • ๋ณด์กด ๋ฐ์ดํ„ฐ ๋ถ„๋ฆฌ ์ €์žฅ์ด ๋ฏธ๊ตฌํ˜„๋œ ์ƒํ™ฉ

๋ฏธ๋ถ„๋ฆฌ ์ €์žฅ (์œ„ํ—˜)

ํ™œ์„ฑ ํšŒ์›

๐Ÿ‘ค

+

ํƒˆํ‡ด ํšŒ์›

๐Ÿ‘ค

โ†‘ ๋™์ผ ๋ฒ„ํ‚ท์— ํ˜ผ์žฌ ์ €์žฅ

์ „์ฒด ๋ฐ์ดํ„ฐ ์œ ์ถœ ์œ„ํ—˜ + 1์ฒœ๋งŒ์› ์ดํ•˜ ๊ณผํƒœ๋ฃŒ โ†’ ISMS-P 3.4.2 ๋ฏธ์ถฉ์กฑ

๋ถ„๋ฆฌ ์ €์žฅ (๊ถŒ์žฅ)

์šด์˜ ๋ฒ„ํ‚ท

๐Ÿ‘ค

|

๋ฒ•์ • ๋ณด์กด

๐Ÿ”’

โ†‘ ๋ณ„๋„ ๋ฒ„ํ‚ท + Object Lock

๋ฌผ๋ฆฌ์  ๋ถ„๋ฆฌ + ์ ‘๊ทผ ๊ถŒํ•œ ์ตœ์†Œํ™” โ†’ ์ธ์ฆ ๊ธฐ์ค€ ์ถฉ์กฑ

๐Ÿšจ

๋ฐœ๊ฒฌ ์‚ฌ๋ก€: ํƒˆํ‡ดํšŒ์› ์ •๋ณด๊ฐ€ ํ™œ์„ฑํšŒ์›๊ณผ ๋™์ผ ๋ฒ„ํ‚ท์— ์ €์žฅ, ์ ‘๊ทผ ๊ถŒํ•œ ๋ฏธ๋ถ„๋ฆฌ

๋ฒ•์ • ๋ณด์กด์ด ํ•„์š”ํ•œ ํƒˆํ‡ดํšŒ์› ๋ฐ์ดํ„ฐ๊ฐ€ ๋™์ผ S3 ๋ฒ„ํ‚ท์— Flag๊ฐ’๋งŒ ๋ณ€๊ฒฝํ•˜์—ฌ ์ €์žฅ๋˜์–ด ์žˆ๊ณ , Object Lock์ด ๋ฏธ์„ค์ •๋˜์–ด ์‚ญ์ œ/์ˆ˜์ •์ด ๊ฐ€๋Šฅํ•œ ์ƒํ™ฉ.

ํ˜„์žฌ ์ƒํƒœ - ๋ฌธ์ œ๊ฐ€ ๋˜๋Š” ์„ค์ •
# ๋™์ผ ๋ฒ„ํ‚ท์— ํ™œ์„ฑ ํšŒ์›๊ณผ ํƒˆํ‡ด ํšŒ์› ํ˜ผ์žฌ
resource "aws_s3_bucket" "user_data" {
  bucket = "company-user-data"

  # ํƒˆํ‡ดํšŒ์› ์ •๋ณด๋„ ๋™์ผ ๋ฒ„ํ‚ท์— ์ €์žฅ
  # ๋ณ„๋„ ๋ถ„๋ฆฌ ๋ฒ„ํ‚ท ์—†์Œ
  # Object Lock ๋ฏธ์„ค์ •
}

# IAM ์ •์ฑ… - ๋ชจ๋“  ์šด์˜์ž๊ฐ€ ์ „์ฒด ๋ฒ„ํ‚ท ์ ‘๊ทผ
resource "aws_iam_policy" "s3_access" {
  name = "s3-full-access"
  policy = jsonencode({
    Statement = [{
      Effect   = "Allow"
      Action   = ["s3:*"]
      Resource = ["arn:aws:s3:::company-user-data/*"]
    }]
  })
}

ISMS-P 3.4.2 ์œ„๋ฐ˜ ์‚ฌํ•ญ

โ—

๋ฒ•์ • ๋ณด์กด ๊ฐœ์ธ์ •๋ณด ๋ฏธ๋ถ„๋ฆฌ ์ €์žฅ

โ—

๋ถ„๋ฆฌ ์ €์žฅ ํ›„ ์ ‘๊ทผ๊ถŒํ•œ ๋ฏธ๋ถ„๋ฆฌ

โ—

๋ฐ์ดํ„ฐ ๋ฌด๊ฒฐ์„ฑ ๋ณดํ˜ธ ์กฐ์น˜ ๋ถ€์žฌ

โ—

๋ฒ•์ • ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ํ›„ ์ž๋™ ํŒŒ๊ธฐ ๋ฏธ์—ฐ๊ณ„

๐Ÿ”

์‚ฌ์ „ ํƒ์ง€ ๋ฐฉ์•ˆ

IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ์ „ ์ ๊ฒ€

๋ฒ•์ • ๋ณด์กด ๋ฐ์ดํ„ฐ ๋ถ„๋ฆฌ ์ €์žฅ ํƒ์ง€ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ“ฆ ๋ฒ•์ • ๋ณด์กด์šฉ ๋ณ„๋„ ๋ฒ„ํ‚ท
๋ฏธ์กด์žฌ ๋ถ„๋ฆฌ ์ €์žฅ ์•ˆ๋จ Critical - ์ฐจ๋‹จ
์กด์žฌ โ†’ Object Lock ๊ฒ€์‚ฌ
๐Ÿ”’ Object Lock ์„ค์ •
๋ฏธ์„ค์ • ์‚ญ์ œ/์ˆ˜์ • ๊ฐ€๋Šฅ High - ๊ฒฝ๊ณ 
Governance Mode ์šฐํšŒ ๊ฐ€๋Šฅ Medium - Compliance ๊ถŒ์žฅ
Compliance Mode โ†’ ์ ‘๊ทผ ๊ถŒํ•œ ๊ฒ€์‚ฌ
๐Ÿ‘ฅ Bucket Policy
์ ‘๊ทผ ์ œํ•œ ์—†์Œ ์ „์ฒด ์ ‘๊ทผ ํ—ˆ์šฉ High - ๊ฒฝ๊ณ 
์ตœ์†Œ ๊ถŒํ•œ ์ ์šฉ โœ“ ํ†ต๊ณผ
๐Ÿ””

์‚ฌํ›„ ๋Œ€์‘ ๋ฐฉ์•ˆ

๋Ÿฐํƒ€์ž„ ๋ชจ๋‹ˆํ„ฐ๋ง ๋ฐ ์ด์ƒํ–‰์œ„ ํƒ์ง€

๋ถ„๋ฆฌ ์ €์žฅ ์„ค์ • ๋Ÿฐํƒ€์ž„ ์ด๋ฒคํŠธ ๋Œ€์‘ ๋กœ์ง

ํŒ๋‹จ ์กฐ๊ฑด ์กฐ๊ฑด ๊ฐ’ ๊ฒฐ๊ณผ
๐Ÿ“ฆ ๋ณ€๊ฒฝ ์œ ํ˜•
IaC ๋ฐฐํฌ (Terraform) ์ •์ƒ ๋ณ€๊ฒฝ โœ“ ๋ณ€๊ฒฝ ์ด๋ ฅ๋งŒ ์ €์žฅ
Drift ๋ฐœ์ƒ ์ฝ˜์†” ์ง์ ‘ ๋ณ€๊ฒฝ โ†’ ์ƒ์„ธ ๋ถ„์„
โš ๏ธ ๋ณ€๊ฒฝ ๋‚ด์šฉ

(Drift ๋ฐœ์ƒ ์‹œ)

Object Lock ๋น„ํ™œ์„ฑํ™” ๋ฌด๊ฒฐ์„ฑ ์†์ƒ Critical - PagerDuty ํ˜ธ์ถœ
Bucket Policy ์™„ํ™” ์ ‘๊ทผ ๊ถŒํ•œ ํ™•๋Œ€ High - Slack ์ฆ‰์‹œ ์•Œ๋ฆผ
๋ฒ•์ • ๋ณด์กด ๋ฒ„ํ‚ท ์‚ญ์ œ ์‹œ๋„ Critical - ์ฐจ๋‹จ + PagerDuty

๋ชจ๋“  ์•Œ๋ฆผ์— ํฌํ•จ๋˜๋Š” ์ •๋ณด

๋ฒ•์ • ๋ณด์กด ๋ฒ„ํ‚ท ARN ๋ณ€๊ฒฝ ์ „/ํ›„ Object Lock ์„ค์ • ๋ณ€๊ฒฝ ์ฃผ์ฒด (IAM) ๋ถ„๋ฆฌ ์ €์žฅ ๊ฐ€์ด๋“œ
โœ“

์กฐ์น˜ ๊ฐ€์ด๋“œ

์ฆ‰์‹œ ์ ์šฉ ๊ฐ€๋Šฅํ•œ ๊ถŒ์žฅ ์„ค์ •

โŒ ๋ฌธ์ œ

ํ™œ์„ฑ/ํƒˆํ‡ด ํšŒ์› ๋™์ผ ๋ฒ„ํ‚ท, Object Lock ๋ฏธ์„ค์ •, ์ ‘๊ทผ ๊ถŒํ•œ ๋ฏธ๋ถ„๋ฆฌ

โœ“ ์ ์šฉ

๋ณ„๋„ ๋ฒ„ํ‚ท + Object Lock (Compliance) + IAM ์ตœ์†Œ ๊ถŒํ•œ

๊ถŒ์žฅ ์„ค์ • (๋ณต์‚ฌํ•˜์—ฌ ์ ์šฉ)
legal-retention.tf
# ๋ฒ•์ • ๋ณด์กด์šฉ ๋ณ„๋„ ๋ฒ„ํ‚ท (๋ถ„๋ฆฌ ์ €์žฅ)
resource "aws_s3_bucket" "legal_retention" {
  bucket              = "company-legal-retention"
  object_lock_enabled = true  # Object Lock ํ•„์ˆ˜

  tags = {
    Name    = "legal-retention"
    ISMS-P  = "3.4.2"
    Purpose = "๋ฒ•์ • ๋ณด์กด ๊ฐœ์ธ์ •๋ณด ๋ถ„๋ฆฌ ์ €์žฅ"
  }
}

# Object Lock ์„ค์ • (Compliance Mode - ๋ˆ„๊ตฌ๋„ ์‚ญ์ œ ๋ถˆ๊ฐ€)
resource "aws_s3_bucket_object_lock_configuration" "legal_retention" {
  bucket = aws_s3_bucket.legal_retention.id

  rule {
    default_retention {
      mode  = "COMPLIANCE"  # ๋ˆ„๊ตฌ๋„ ์‚ญ์ œ/์ˆ˜์ • ๋ถˆ๊ฐ€
      years = 5             # ์ „์ž์ƒ๊ฑฐ๋ž˜๋ฒ•: ๊ฑฐ๋ž˜๊ธฐ๋ก 5๋…„
    }
  }
}

# Bucket Policy - ์ ‘๊ทผ๊ถŒํ•œ ์ตœ์†Œํ™”
resource "aws_s3_bucket_policy" "legal_retention" {
  bucket = aws_s3_bucket.legal_retention.id

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [{
      Sid       = "DenyAllExceptLegalAdmin"
      Effect    = "Deny"
      Principal = "*"
      Action    = ["s3:DeleteObject", "s3:PutObject"]
      Resource  = "${aws_s3_bucket.legal_retention.arn}/*"
      Condition = {
        StringNotEquals = {
          "aws:PrincipalArn" = ["arn:aws:iam::ACCOUNT:role/LegalRetentionAdmin"]
        }
      }
    }]
  })
}

# ๋ฒ•์ • ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ํ›„ ์ž๋™ ํŒŒ๊ธฐ (3.4.1 ์—ฐ๊ณ„)
resource "aws_s3_bucket_lifecycle_configuration" "legal_retention" {
  bucket = aws_s3_bucket.legal_retention.id

  rule {
    id     = "archive-and-expire"
    status = "Enabled"

    transition {
      days          = 90
      storage_class = "GLACIER"
    }

    expiration {
      days = 1825  # 5๋…„ ํ›„ ์ž๋™ ์‚ญ์ œ
    }
  }
}

๐Ÿ’ก ํ•ต์‹ฌ: object_lock_enabled = true๋กœ ๋ฒ„ํ‚ท ์ƒ์„ฑ ์‹œ Object Lock์„ ํ™œ์„ฑํ™”ํ•˜๊ณ , mode = "COMPLIANCE"๋ฅผ ์„ค์ •ํ•˜๋ฉด ๋ฒ•์ • ๋ณด์กด๊ธฐ๊ฐ„ ๋™์•ˆ ๋ˆ„๊ตฌ๋„ ๋ฐ์ดํ„ฐ๋ฅผ ์‚ญ์ œํ•˜๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. aws_s3_bucket_policy๋กœ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ตœ์†Œ ์ธ์›(๋ฒ•์ • ๋ณด์กด ๊ด€๋ฆฌ์ž)์œผ๋กœ ์ œํ•œํ•ฉ๋‹ˆ๋‹ค. ๋ฒ•์ • ๋ณด์กด๊ธฐ๊ฐ„ ๊ฒฝ๊ณผ ํ›„์—๋Š” Lifecycle Expiration์œผ๋กœ ์ž๋™ ํŒŒ๊ธฐ๋˜์–ด 3.4.1๊ณผ ์—ฐ๊ณ„๋ฉ๋‹ˆ๋‹ค.

๐Ÿ“š ์ฐธ๊ณ  ์ž๋ฃŒ

๐Ÿ”’ AWS S3 Object Lock โ†— ๐Ÿ—„๏ธ AWS S3 Glacier โ†— ๐Ÿ“œ ์ „์ž์ƒ๊ฑฐ๋ž˜๋ฒ• ์‹œํ–‰๋ น โ†—
๐Ÿ“Š

๋ฆฌํฌํŠธ ๋ฐฉ์•ˆ

ISMS-P ์‹ฌ์‚ฌ ์ฆ์  ๋ฐ ์ •๊ธฐ ๋ณด๊ณ 

๐Ÿ“‹ ์ง„๋‹จ ํ•ญ๋ชฉ

  • ๋ฒ•์ • ๋ณด์กด์šฉ ๋ถ„๋ฆฌ ๋ฒ„ํ‚ท ์กด์žฌ ์—ฌ๋ถ€
  • Object Lock Compliance Mode ์„ค์ •
  • Bucket Policy ์ ‘๊ทผ ๊ถŒํ•œ ํ˜„ํ™ฉ
  • ๋ฒ•์ • ๋ณด์กด ๋ฐ์ดํ„ฐ ๋ณด๊ด€ ๊ธฐ๊ฐ„
  • ์ž๋™ ํŒŒ๊ธฐ ์—ฐ๊ณ„ (Lifecycle) ์„ค์ •

๐Ÿ“… ๋ฆฌํฌํŠธ ์ฃผ๊ธฐ

์ผ๊ฐ„

Object Lock/Policy ๋ณ€๊ฒฝ ์ด๋ฒคํŠธ

์ฃผ๊ฐ„

๋ถ„๋ฆฌ ์ €์žฅ ์ค€์ˆ˜ ํ˜„ํ™ฉ ์š”์•ฝ

์›”๊ฐ„

ISMS-P ์ฆ์  ๋ฆฌํฌํŠธ (๋ถ„๋ฆฌ๋ณด๊ด€ ๋Œ€์žฅ)

๐Ÿ“ค ๋ฐœ์†ก ๋ฐ ์ €์žฅ

๋ฐœ์†ก ์ฑ„๋„

Email Slack

์ €์žฅ์†Œ

S3 (5๋…„ ๋ณด๊ด€)
โšก

BSG ์ฐจ๋ณ„์ 

๊ธฐ์กด ๋„๊ตฌ๊ฐ€ ๋†“์น˜๋Š” ์ ๊ฒ€ ์˜์—ญ

๊ธฐ์กด ๋„๊ตฌ ๋ฐฉ์‹

๋‹จ์ˆœ Object Lock ํ™œ์„ฑํ™” ๊ฒ€์‚ฌ

  • bucket.object_lock == True ๋‹จ์ˆœ ๋น„๊ต
  • Compliance/Governance ๋ชจ๋“œ ๊ตฌ๋ถ„ ์—†์Œ
  • ์ •์  ๋ถ„์„ ๊ฒฐ๊ณผ๋งŒ ์ถœ๋ ฅ

ํ•œ๊ณ„: ๋ถ„๋ฆฌ ์ €์žฅ ์—ฌ๋ถ€ ๋ฏธ์ ๊ฒ€, ์ ‘๊ทผ ๊ถŒํ•œ ๋ถ„๋ฆฌ ๋ฏธ์ ๊ฒ€, ๋ณด์กด๊ธฐ๊ฐ„ ์ ์ •์„ฑ ๋ฏธ๊ฒ€์ฆ

BSG ์ ‘๊ทผ ๋ฐฉ์‹

๋ถ„๋ฆฌ ์ €์žฅ + Object Lock + ์ ‘๊ทผ ๊ถŒํ•œ ํ†ตํ•ฉ ์ ๊ฒ€

  • IaC ์ฝ”๋“œ ๋ถ„์„ ๊ธฐ๋ฐ˜ ๋ฒ•์ • ๋ณด์กด ์•„ํ‚คํ…์ฒ˜ ๊ฒ€์ฆ
  • Object Lock Compliance Mode ํ•„์ˆ˜ ๊ฒ€์ฆ
  • ๋Ÿฐํƒ€์ž„ ์„ค์ • ๋ณ€๊ฒฝ ๋ชจ๋‹ˆํ„ฐ๋ง + Drift ํƒ์ง€

์ฐจ๋ณ„์ : ISMS-P 3.4.1(๊ฐœ์ธ์ •๋ณด ํŒŒ๊ธฐ)๊ณผ ํ†ตํ•ฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ ์ƒ๋ช…์ฃผ๊ธฐ ์ „์ฒด ๊ฒ€์ฆ

โ† Data Protection & Disaster Recovery๋กœ ๋Œ์•„๊ฐ€๊ธฐ