Ŭ¶ó¿ìµð µ¥ÀÌÁî (Cloudy Daze)
*¿ªÀÚÁÖ: ¿äÁò ¸¹Àº ³í¶õ(?)À» ºÒ·¯ÀÏÀ¸Å°°í Àִ Ŭ¶ó¿ìµå ÄÄÇ»ÆÃ(cloud computing)¿¡ ´ëÇÑ À¯È¤À» °£Á¢ÀûÀ¸·Î Ç¥ÇöÇÑ °ÍÀ¸·Î »ý°¢µÊ
By Steven J. Ross, CISM, CISSP. MBCP
ISACA Journal Volume 1, 2010
Á¤¸» (Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÇ) Á¦Ã¢ÀÚ°¡ ÁÖÀåÇÏ´Â °Íó·³ Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀº ÄÄÇ»Æà ´É·Â¿¡ ÀÖ¾î¼ È¹±âÀûÀÎ È®ÀåÀ» °¡Á®´Ù Áִ°¡? ¾Æ´Ï¸é, Áö³ ¼ö½Ê ³â°£ ¹ßÀüÇØ¿Â ¾Æ¿ô¼Ò½Ì Æ®·£µå¿¡ ´ëÇÑ ÀÚ¿¬ÀûÀ¸·Î º¯ÈÇÑ ¸ð½ÀÀΰ¡? Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀº º¸´Ù ¾ÈÀüÇÑ°¡, ¾Æ´Ï¸é º¸´Ù ¾ÈÀüÇÏÁö ¸øÇÑ °ÍÀΰ¡?
±×·¸½À´Ï´Ù.(Yes.)
Plus ca reste la même chose¡¦©÷
³»°¡ µè°í Åä·ÐÇß´ø Ŭ¶ó¿ìµå ÄÄÇ»Æÿ¡ ´ëÇÑ ´ëºÎºÐÀÇ °ü½É»ç´Â ÇÑ°¡Áö »ç½Ç¿¡ ÁýÁߵȴÙ: ÀÌÁ¦ ´õ ÀÌ»ó Á¶Á÷ÀÇ µ¥ÀÌÅÍ ¹× ¼ÒÇÁÆ®¿þ¾î°¡ ±× Á¶Á÷ÀÇ µ¥ÀÌÅÍ ¼¾ÅÍ ¾È¿¡ Á¸ÀçÇÏÁö ¾Ê´Â´Ù. ¸¹Àº Á¶Á÷µéÀº ¼ÒÀ¯°¡ °ð ÅëÁ¦ÀÌ¸ç º¸¾ÈÀ̶ó´Â »ý°¢À» ³»ÀçÀûÀ¸·Î ºÐ¸íÈ÷ °¡Áö°í ÀÖ¾úÀ» °ÍÀÌÁö¸¸, ÀÌ µî½ÄÀÌ Àǹ̰¡ Àְڴ°¡? Ŭ¶ó¿ìµå ÄÄÇ»Æÿ¡¼ÀÇ Ä¿´Ù¶õ º¯È´Â µ¥ÀÌÅÍ ¼¾Å͸¦ µÑ·¯½Î°í ÀÖ´Â º®µéÀÌ »ç¶óÁø °ÍÀ̸ç, ÀÌ°Í ¸»°í´Â ¾î¶°ÇÑ º¯Èµµ ¾ø´Ù.
ÄÄÇ»ÅÍ°¡ ÀÖ´Â °÷ÀÌ¸é °ÅÀÇ ´ëºÎºÐ Á¤º¸ ó¸®¿Í Á¤º¸¸¦ ó¸®ÇÏ´Â ÀåºñÀÇ ¼ÒÀ¯°¡ ºÐ¸®µÇ¾î ÀÖ´Â ¼ºñ½ºµéÀÌ Á¸ÀçÇÑ´Ù. 1950³â´ë¿¡, IBMÀº °í°´µéÀ» À§Çؼ ÇÁ·Î±×·¥À» ÀÚ½ÅÀÇ ÄÄÇ»ÅÍ¿¡¼ ½ÇÇà½ÃÄÑÁÖ´Â Àü¹® ¼ºñ½º ȸ»ç(BSC)¸¦ ¼³¸³Çß´Ù. ¾Æ¿ô¼Ò½ÌÀ̶ó´Â ¿ë¾î°¡ À¯ÇàÇϱâ ÈξÀ ÀÌÀüÀ̾úÀ¸³ª, 1962³â ÃÊ¿¡ À̸£·¯ ·Î½º Æä·ÔÀÇ EDS(Electronic Data Systems)´Â ¾Æ¿ô¼Ò½ÌÀ» ½ÃÀÛÇÑ´Ù. ÀΰǺñÀÇ Â÷ÀÌ·Î ÀÎÇØ ÀçÁ¤°Å·¡°¡ °¡´ÉÇØÁø °æÁ¦´Â ¼¾çÀÇ ¸¹Àº ȸ»çµé·Î ÇÏ¿©±Ý Á¤º¸±â¼ú ±â´ÉÀ» ¾Æ½Ã¾Æ¿¡ ÀÖ´Â Á¶Á÷µé¿¡°Ô ¾Æ¿ô¼Ò½ÌÇϵµ·Ï ¸¸µé¾ú´Ù. ¾Æ¸¶µµ ¿¹ÀüÀÇ ¾Æ¿ô¼Ò½ÌÀÌ ³»Æ÷ÇÏ°í ÀÖ´Â ¹®Á¦Á¡¿¡ ´ëÇÑ ÀνÄÀÌ Å¬¶ó¿ìµå ÄÄÇ»Æà Á¦°øÀÚ¿¡°Ô ¾Æ¿ô¼Ò½ÌÇÏ´Â °Í¿¡ ´ëÇÑ µÎ·Á¿òÀº Áõ°¡½ÃÅ°Áö¸¸, ±×°ÍÀº »õ·Î¿î °ü½É»ç°¡ ¾Æ´Ï´Ù.
±âº»ÀûÀ¸·Î, Ŭ¶ó¿ìµå ÄÄÇ»Æÿ¡ ´ëÇÑ °æ¿µÁøÀÇ ¿ì·Á´Â ´ÙÀ½ 2°¡Áö·Î Ãà¾àÇÒ ¼ö ÀÖ´Ù:
l ³» Á¤º¸°¡ ¾îµò°¡¿¡¼ 󸮵ǰí ÀÖÀ¸³ª, ³ª´Â ¾îµðÀÎÁö ¸ð¸¥´Ù.
l ³» Á¤º¸¸¦ ´©±º°¡°¡ º¸È£ÇÏ°í ÀÖÀ¸³ª, ³ª´Â ±×°¡ ´©±¸ÀÎÁö ¸ð¸¥´Ù.
´Ù¼Ò °ÆÁ¤Àº µÇ°ÚÁö¸¸, Ã¥»ó ¼¶øÀÇ Á¾ÀÌ ÆÄÀÏÀÌ ´Ù¸¥ µ¥ÀÌÅÍ ¼¾ÅÍ ¾È¿¡ º¼ ¼ö ¾ø´Â ºñÆ®(bits)·Î º¯È¯µÇ¾úÀ» ½Ã´ë¿¡ °æÇèÇß´ø µÎ·Á¿ò°ú º°¹Ý ´Ù¸£Áö ¾Ê´Ù. ¾ðÁ¦³ª Á¤º¸ÀÇ ¼ÒÀ¯ÁÖ¿Í Ã³¸®±â »çÀÌ¿¡´Â °Å¸®°¡ ¶³¾îÁ® ÀÖ°Ô µÇ´Âµ¥, ±×¿Í °°Àº ±³ÈÆÀ» ´Ù½Ã ÇнÀÇÏ¿©¾ß¸¸ ÇÑ´Ù: º¸È£ÀÚÀÇ À̵¿Àº ¿À³Ê½ÊÀÇ À̵¿°ú ´Ù¸£´Ù. ÄÄÇ»Æà ¼ºñ½º¸¦ À§ÇÑ º¸È£ ¹× ÅëÁ¦ÀÇ ±Ùº»Àº °áÄÚ º¯ÇÏÁö ¾Ê´Â´Ù.
l Á¤º¸ ¹× Á¤º¸ º¸È£¿¡ ´ëÇÑ ¿À³Ê½ÊÀº ¿©ÀüÈ÷ °í°´ÀÇ ¸òÀÌ´Ù.
l º¸È£¸¦ ÀÌÇàÇϴ åÀÓÀº ¿À³Ê¿Í ¼ºñ½º Á¦°øÀÚ°¡ ¼·Î °øÀ¯ÇÑ´Ù.
l Á¤º¸ÀÇ ¼ÒÀ¯ÀÚ´Â ¼ºñ½º Á¦°øÀÚ°¡ ±× Á¤º¸¿¡ ´ëÇÑ º¸È£¸¦ ÀÌÇàÇÏ°í °Á¦Çϵµ·Ï º¸ÀåÇÒ Ã¥ÀÓÀ» Áö´Ñ´Ù.
Á¶Á÷ÀÌ Á÷Á¢ µ¥ÀÌÅÍ ¼¾Å͸¦ ¼ÒÀ¯Çϰųª, ¿ÀÆÛ·¹ÀÌÅÍ¿¡°Ô ±Þ¿©¸¦ ÁöºÒÇÏÁö ¾Ê´Â´Ù´Â ÀÌÀ¯¸¸À¸·Î Á¤º¸¿Í ¼ÒÇÁÆ®¿þ¾î¿¡ ´ëÇÑ ÅëÁ¦¸¦ »ó½ÇÇÏ´Â °ÍÀ» ÀǹÌÇÏÁö ¾Ê´Â´Ù. Á¤º¸ ½Çü¿¡ ´ëÇÑ ¹°¸®Àû ÅëÁ¦¿¡ °üÇÑ ½Å·Ú¸¦ °ú´ëÆò°¡ÇÏ¿´´Ù. ÀÚüÀûÀÎ °úÁ¦¸¦ ¾È°í ÀÖ´Â ¹é¾÷ Å×ÀÌÇÁ¸¦ Á¦¿ÜÇϸé, µ¥ÀÌÅÍ´Â ¸¸Áú ¼öµµ À̵¿ÇÒ ¼öµµ ¾ø´Ù. Ư±ÇÀ» °¡Áø »ç¿ëÀڷμÀÇ ¿ÀÆÛ·¹ÀÌÅÍ°¡ ½ÇÁúÀûÀ¸·Î °ü½ÉÀÇ ´ë»óÀÌÁö¸¸, ¿À´Ã³¯ÀÇ – ±×¸®°í ¹Ì·¡ÀÇ – ±â¼úÀº ±×·± ¿ÀÆÛ·¹ÀÌÅÍµé ¸¶Àú µ¥ÀÌÅ͸¦ ´Ù·ç±â À§Çؼ ¹°¸®Àû Á¢±ÙÀ» ÇÊ¿ä·Î ÇÏÁö ¾Ê´Â´Ù.
¡¦Plus Ca Change4
±×¸®°í ¾ÆÁ÷±îÁö´Â, ÀÌÀüÀÇ ¾Æ¿ô¼Ò½Ì ÇüÅÂ¿Í Å¬¶ó¿ìµå ÄÄÇ»Æà »çÀÌ¿¡´Â ½ÇÁúÀûÀÎ Â÷ÀÌ°¡ ÀÖ´Ù. °¡Àå ºÐ¸íÇÑ °ÍÀº Á¤º¸°¡ ±â¹Ð¼º ¹× ¹«°á¼º¿¡ ´ëÇÏ¿© ÇÔÃàÇÏ°í ÀÖ´Â ¸ðµç Ư¡À» Áö´Ï¸é¼ ÀÎÅͳÝÀ» ÅëÇؼ Á¢±ÙµÈ´Ù´Â °ÍÀÌ´Ù. Á¤º¸ ±â¼úÀÌ °¡»óÈ¿¡ ÀÇÇØ °¡´ÉÇØÁø ´ÙÀ̳»¹ÍÇÏ°Ô ÃøÁ¤ÇÒ ¼ö ÀÖ´Â ¼ºñ½º·Î º¯ÇØ °¡´Â °ÍÀº º¸´Ù ¹Î°¨Çϸé¼, ±Ã±ØÀûÀ¸·Î´Â º¸´Ù ¸¹Àº º¸¾ÈÀ» ÇÊ¿ä·Î ÇÑ´Ù. Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÇ °¡´É¼ºÀÌ ½ÇÇöµÈ´Ù¸é, Á¶Á÷Àº ÀÚ½ÅÀÌ »ç¿ëÇÏ´Â ¼ÒÇÁÆ®¿þ¾î, ÀÎÇÁ¶ó, ³×Æ®¿öÅ© ±×¸®°í ÀúÀåÀåÄ¡¸¦ ½Å¼ÓÇÏ°Ô È®ÀåÇÏ¿© °è¾àÇÒ ¼ö ÀÖ´Ù. ¾î´À ÇϳªÀÇ ÄÄÇ»Æà ÀÚ¿ø¿¡, ƯÈ÷ ¾ÖÇø®ÄÉÀÌ¼Ç µ¥ÀÌÅÍ, ÀûÇÕÇÑ º¸¾ÈÀº ´Ù¸¥ °Í¿¡´Â ÀûÇÕÇÏÁö ¾ÊÀ» ¼ö ÀÖ´Ù. ±Þ¼ÓÈ÷ º¯¸ðÇØ°¡´Â »óȲ¿¡¼, ´ÙÀ̳»¹ÍÇÏ°Ô º¸¾È°ú À§Çè°ú °ßÁÖ´Â °ÍÀº ¾î·Á¿î ÀÏÀÌ´Ù.
Ŭ¶ó¿ìµå ÄÄÇ»Æà º¸¾È¿¡ °üÇؼ ÀÌ·¯ÇÑ »óȲÀû º¯È¸¦ ´Ù·çÁö ¾ÊÀº ä·Î ¼ö¾øÀÌ ¸¹ÀÌ ¾²¿©Áö°í ÀÖ´Ù. ±×°Íº¸´Ù ¾Æ¿ô¼Ò½Ì¿¡ ¼ö¹ÝµÇ´Â º¸¾È À§Çù¿¡ ÃÊÁ¡À» ¸ÂÃß°í ÀÖ´Ù: Ư±ÇÀû Á¢±Ù¿¡ °üÇÑ ÅëÁ¦, ¹ý±Ô ÁؼöÀÇ ¾î·Á¿ò, ¾Ë ¼ö ¾ø´Â µ¥ÀÌÅÍ ¼ÒÀçÁö, °í°´µé°£ÀÇ µ¥ÀÌÅÍ ºÐ¸®, Á¶»ç Áö¿ø ±×¸®°í º¥´õ »ýÁ¸·Â. ¾Æ¿ô¼Ò½ÌÀ» ÃÊ¿ùÇؼ Ŭ¶ó¿ìµå ÄÄÇ»Æÿ¡¸¸ ÇØ´çÇÏ´Â ¼ö¸¹Àº º¸¾È °í·Á»çÇ×ÀÌ ÀÖ´Ù.
l À§Çè °ü¸®°¡ IT ¼ºñ½ºµéÀÇ ´ÙÀ̳»¹ÍÇÔÀ¸·Î º¹ÀâÇØÁö°í ÀÖ´Ù. ¸ðµç À§Çè °ü¸® Á¢±Ù¹æ¹ý¿¡ À־Â, (ÀÚ¿øÀÇ) °¡Ä¡¸¦ ºÒ¹®ÇÏ°í, °ü¸®ÇÒ ÀÚ¿øÀÇ ¾ÈÁ¤Àº ±Ù¿øÀûÀÌ´Ù. ¿¹¸¦ µé¸é, °ÅÀÇ 1³â ³»³» ±¤°í¸¦ ÇÏ°í ¼º¼ö±â¿¡´Â ¸ÅÃâÀÌ ´Ã¾î³ª´Â ¿Â¶óÀÎ ¼Ò¸Å»ó¿¡ ÀÇÇؼ Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÌ ÀÌ¿ëµÈ´Ù¸é, º»ÁúÀû À§ÇèÀº 1³â »çÀÌ¿¡µµ ¿©·¯ Â÷·Ê ´Þ¶óÁø´Ù. È«º¸¿¡¼ ¿µ¾÷À¸·ÎÀÇ ÀüȯÀÌ Áï½Ã ÀÌ·ç¾îÁø´Ù¸é ±×·¯ÇÑ À§ÇèµéÀº ¾î´À Á¤µµ ÆÄ¾ÇµÉ ¼ö ÀÖÁö¸¸, ±×·¯ÇÑ ÀüȯÀÌ ½Ã°£ÀÌ Áö³ª¸é¼ ºÒ±ÔÄ¢ÀûÀ¸·Î ³ªÅ¸³´Ù¸é À§ÇèÀ» °áÁ¤ÇϱⰡ ÈξÀ ¾î·Æ°Ô µÈ´Ù.
l ¾ÖÇø®ÄÉÀ̼ǰú Á¤º¸°¡ ÀÎÅͳÝÀ» ÅëÇØ Á¢±ÙµÇ±â ¶§¹®¿¡, (À¥) ºê¶ó¿ìÀú°¡ ´ëºÎºÐÀÇ »ó¾÷Àû ºê¶ó¿ìÀúµéÀÇ ´É·ÂÀ» ´É°¡ÇÏ¿© Á¢±Ù ÅëÁ¦ ¸ÞÄ¿´ÏÁòÀÌ µÇ°í ÀÖ´Ù. ¸¹Àº ºê¶ó¿ìÀúµéÀÌ ¸ñÀûÁö¿Í È°µ¿À» Á¦ÇÑÇÏ´Â °ÍÀÌ °¡´ÉÇÏÁö¸¸, ±× Áß ¼Ò¼ö´Â »ç¿ëÀÚµéÀ» ºÐ¸íÇÏ°Ô ½Äº°Çϰųª (ÀÚ¿øÀ») ÃæºÐÈ÷ ¼¼ºÐÈÇÏ¿© Á¢±ÙÀ» Á¦ÇѽÃÅ°´Â ´É·ÂÀ» °®°í ÀÖ´Ù. ½Å¿ø ¹× Á¢±Ù °ü¸® ½Ã½ºÅÛÀ» °¡Áø ºê¶ó¿ìÀúµéÀÇ ÅëÇÕÀº »ó¾÷Àû ¸ñÀûÀ¸·Î Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÇ ÀÌ¿ëÀ» È®»ê½ÃÅ°±â À§ÇÑ ºÒ°¡°áÇÑ ¼±Çà Á¶Ä¡ÀÌ´Ù.
l À§ÇèÀ» Á¤·®ÈÇؼ º¸ÇèÀ¸·Î Ã¥ÀÓÀ» Àü°¡ÇÏ´Â °ÍÀº ¾î·Á¿î ÀÏÀÌ´Ù. Ŭ¶ó¿ìµå ÄÄÇ»Æà Á¦°øÀÚµéÀº º¸Çè¿¡´Â °¡ÀÔÇÏÁö¸¸, °í°´¿¡ ´ëÇÑ Áß´ëÇÑ ¼ÕÇØ¿¡ ´ëÇؼ´Â ºÐ¸í ¾Æ´Ï´Ù. Á¤º¸ ¼ÒÀ¯Àڴ åÀÓÀ» ÀڽŵéÀÇ ¼ºñ½º Á¦°øÀÚ¿¡°Ô Àü°¡ÇÒ ¼ö ¾ø´Ù. ¸¶Âù°¡Áö·Î, ¾Ë ¼ö ¾ø°í ºÒ±ÔÄ¢ÀûÀ¸·Î º¯ÇÏ´Â Á¤º¸ ÀÚ¿øÀ» À§Çؼ º¸Çè ȸ»çµµ ÃÊ°úº¸Çè ȤÀº ÀϺκ¸ÇèÀ» ¿ä±¸ÇϵçÁö ºÎº¸¸¦ Á¦°øÇÒ ¼ö ¾ø´Ù. ±×·¯ÇÑ 2°¡Áö ´ë¾ÈÀÌ ÀÖ´Ù¸é, ¸¹Àº °æ¿ì¿¡ ÀÖ¾î¼ °æ¿µÁøÀº °¡Àå Àú·ÅÇÑ º¸Çè»óÇ°À» ¼±ÅÃÇÏ°í ÀÜ¿© À§ÇèÀº ¹Þ¾ÆµéÀδÙ.
l PKI ¹æ½ÄÀÇ °·ÂÇÑ ¾ÏÈ£È ±â¹ýÀÌ ÀÎÅÍ³Ý ±â¹Ý ¼ºñ½º¿¡ ÀÖ¾î¼ ±â¹Ð¼º°ú ¹«°á¼ºÀ» ´Þ¼ºÇϴµ¥ ÇʼöÀûÀÌ´Ù. ¸Ö¸® ¶³¾îÁ® ÀÖ´Â ¾î´À ¼ºñ½º Á¦°øÀÚÀÇ °¡»ó ¹× ½ÇÁúÀûÀÎ ½Ã½ºÅ۵鿡 È¥ÀçµÈ µ¥ÀÌÅÍ¿¡ ´ëÇÏ¿© ¾Ïȣȴ Áß¿äÇÑ µ¥ÀÌÅÍ¿¡ ´ëÇؼ ¸¸ÀÌ ¾Æ´Ï¶ó Ŭ¶ó¿ìµå ¾È¿¡ ÀÖ´Â ¸ðµç µ¥ÀÌÅÍ¿¡ ´ëÇÏ¿© äÅÃÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. (ºÒÇàÇÏ°Ôµµ, ÀÌ°ÍÀº µ¥ÀÌÅÍ ¹× ¼ºñ½º °¡¿ë¼ºÀ» »ó½ÇÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡¿¡ ³ëÃâµÈ´Ù.) ¿À´Ã³¯ »ç¿ëÀÌ °¡´ÉÇÑ °·ÂÇÑ ¾ÏÈ£È ¾Ë°í¸®µë°ú Å° °ü¸® ±â¹ýÀÌ ÀÖÁö¸¸, Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀº ¼¼°èÀûÀ¸·Î ü°èÈµÈ °øÁßÅ° °ü¸® ½Ã½ºÅÛÀ» ÇÊ¿ä·Î ÇÑ´Ù. ¿äÁîÀ½, ¾ÏÈ£È ¹× PKI µÑ ´Ù °æÇè(=»ç¿ë)ÇÏ´Â °ÍÀº ÀϹÝÀûÀÌÁö ¾Ê´Ù. ±×·¯ÇÑ °æÇèÀ» ¾ò°íÀÚ ÇÏ´Â °úÁ¤¿¡¼´Â ¹Ýµå½Ã ½É°¢ÇÑ ¿À·ù°¡ ¹ß»ýÇÑ´Ù.
Ç×»ó ±×·¨µíÀÌ, Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀ» À§ÇÑ Á¤º¸ º¸È£µµ ºñ¿ëÀÌ ¹ß»ýÇÑ´Ù. ¶ÇÇÑ À§Çè °ü¸®¿¡¼ ½ÃÀÛµÈ ¾î·Á¿òµéÀÌ °áÁ¤Çϱâ Èûµç º¸¾È ÅëÁ¦ÀÇ ºñ¿ë-È¿°ú¸¦ °áÁ¤Áþ´Â´Ù. ¿ì¸®´Â ¾ÆÁ÷ Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÇ ÃÊâ±â¿¡ ÀÖÀ¸¸ç, ±×¸®°í ±Ô¸ðÀÇ °æÁ¦´Â Ä¿´Ù¶õ ±â¾÷µé¿¡ ÀÇÇØ ³Î¸® ÀÌ¿ëµÇ°í ÀÖ´Â ÀÌ·¯ÇÑ »õ·Î¿î ±â¼ú¿¡ ¿ªÇàÇÏ°í ÀÖ´Ù. ¶Ç ´Ù¸¥ »õ·Î¿î ±â¼ú¿¡ ´ëÇÑ °æÇè¿¡ ±Ù°ÅÇØ, ³ª´Â Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀº º¸¾ÈÀÌ °è¼ÓÇؼ ºÒÃæºÐÇÒ °ÍÀ¸·Î ¿¹»óÇϸç, °á±¹¿¡´Â º¸¾ÈÀ» ¿À¹öÇìµå·Î ÀνÄÇÏ´Â °ÍÀ» ÁÙ¾îµé°í, º¸´Ù ¸¹ÀÌ ÃËÁøÀÚ(enabler)·Î °£ÁÖÇÏ°Ô µÉ °ÍÀÌ´Ù.
³» »ý°¢¿¡, Ŭ¶ó¿ìµå ÄÄÇ»Æÿ¡ ÀÖ¾î¼ °¡Àå Ä¿´Ù¶õ À§ÇèÀº ȸ»ç°¡ °Ç¸ÁÁõ¿¡ ºüÁú °¡´É¼º°ú º¹±¸ÇÒ °¡´É¼ºÀÌ ¾ø´Â Á¤º¸ÀÇ ¼Õ½ÇÀÌ´Ù. ÀÌ°ÍÀº Ŭ¶ó¿ìµå ¾È¿¡¼ º¹±¸´É·Â -¹Ì·¡ÀÇ Ä÷³¿¡¼ ´Ù·ç¾îÁú ÁÖÁ¦- ¿¡ ´ëÇÏ¿© ÃÑüÀûÀÎ À̽´¸¦ ¾ß±âÇÒ °ÍÀÌ´Ù.
¿ªÀÚÁÖ: cloud ´Â ÀÎÅͳÝÀ» ÀǹÌÇϴµ¥, ÀÌ°ÍÀº ³×Æ®¿öÅ© ±¸¼ºµµ¿¡¼ ±¸¸§ ¸ð¾çÀÇ Çü»óÀ¸·Î ÀÎÅͳÝÀ» Ç¥½ÃÇÑ µ¥¼ ¿¬À¯ÇÑ´Ù.
Endnotes
1 An entire article could be written on definitions of cloud computing. (In fact, there are already quite a few. For example: Kennedy, Niall, ¡°The Anatomy of Cloud Computing,¡± 14 March 2009, http://www.niallkennedy.com/blog/2009/03/cloud-computing-stack.html. Bulkely, William; ¡°How Well Do You Know¡¦The Cloud,¡± The Wall Street Journal, 12 October 2009.) For purposes of level setting, I shall define it as dynamically scalable, virtualized computing services offered internally and as a commercial service, using Internet technology for access.
2 Jean-Baptiste Alphonso Karr (1808-1890), ¡°plus ca change, plus ca reste la même chose,¡± ¡°the more things change, the more things stay the same.¡±
3 Ross, Steven J.; ¡°Falling Off the Truck,¡± Information Systems Control Journal, vol. 3, 2006
4 Op cit, Jean-Baptiste Alphonso Karr
5 Readers might find value in a podcast I made, ¡°Cloud computing data security creates challenges for compliance officers,¡± http://itknowledgeexchange.techtarget.com/it-compliance/cloud-computing-data-security-createschallenges-for-compliance-officers/, 29 July 2009
6 There are many sources for these views. See Heiser, Jay; Mark Nicolett; ¡°Assessing the Security Risks of Cloud Computing,¡± Gartner Inc., June 2008. I am not giving short shrift to this Gartner publication. Rather, it is representative of much that is currently published.
7 As of the time of writing, customers of T-Mobile and Microsoft¡¯s Sidekick are experiencing a significant data loss. See ¡°Some Users May Lose Data on a T-Mobile Smartphone,¡± New York Times, 11 October 2009.
Steven J. Ross, CISA, MBCP, CISSP
a retired director from Deloitte, is the founder of Risk Masters Inc. He can be reached at stross@riskmastersinc.com.
--------------------------------------------------------------------------------
ISACA Journal, formerly Information Systems Control Journal, is published by ISACA, a nonprofit organization created for the public in 1969. Membership in the association, a voluntary organization serving IT governance professionals, entitles one to receive an annual subscript-xion to the ISACA Journal.
Opinions expressed in the ISACA Journal represent the views of the authors and advertisers. They may differ from policies and official statements of ISACA and/or the IT Governance Institute and their committees, and from opinions endorsed by authors, employers or the editors of this Journal. ISACA Journal does not attest to the originality of authors¡¯ content.
Instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. For other copying, reprint or republication, permission must be obtained in writing from the association. Where necessary, permission is granted by the copyright owners for those registered with the Copyright Clearance Center (CCC), 27 Congress St., Salem, Mass. 01970, to photocopy articles owned by ISACA, for a flat fee of US $2.50 per article plus 25¢ per page. Send payment to the CCC stating the ISSN (1526-7407), date, volume, and first and last page number of each article. Copying for other than personal use or internal reference, or of articles or columns not owned by the association without express permission of the association or the copyright owner is expressly prohibited.
Subscript-xion Rates:
US: one year (6 issues) $75.00
All international orders: one year (6 issues) $90.00
Remittance must be made in US funds.