Àú³Î ¿Â¶óÀÎ: ¼ÒÇÁÆ® IT °Å¹ö³Í½º
By Kazuhiro Uehara, CGEIT, CISA, CIA, PMP, and Sayaka Akino, CISA
ISACA Journal Online Volume 1, 2010
±Û·Î¹ú IT °Å¹ö³Í½º¿¡ ´ëÇÑ µµÀü°úÁ¦µé
¸¹Àº ±Û·Î¹ú ±â¾÷, ƯÈ÷ ±× ±â¾÷µéÀÇ º»»ç´Â ÀڽŵéÀÇ ±Û·Î¹ú IT ¿ÀÆÛ·¹ÀÌ¼Ç °ü¸®°¡ ¾î·Æ´Ù´Â Á¡À» ¾Ë°í ÀÖ´Ù. (³Ñ¾î¾ß ÇÒ) À庮À¸·Î´Â ¾ð¾î, °Å¸®, ÇöÁöÀÇ °í°´ ¹× ±ÔÁ¦µéÀÌ Æ÷ÇԵǴµ¥, À̵éÀº ¿©ÀüÈ÷ ¾î·Á¿î Àå¾Ö¹°·Î ³²¾Æ ÀÖ´Ù.
Áß±¹¿¡¼´Â, ÀÏ»óÀûÀÎ ´ëȸ¦ Ç¥ÁØ ¸¸´Ù¸°¾î(Áß±¹ÀÇ º¸ÅëÈPutonghua/´ë¸¸ÀÇ ±¹¾îGuoyu/ ½Ì°¡ÆúÀÇ È¾îHuayu)·Î ÇÒ ¼öµµ ÀÖ°í, ±×·¸Áö ¾Ê°í ´Ù¸¥ ¾ð¾î·Î ÇÒ ¼öµµ ÀÖÀ¸¸ç, ÀÏ¹Ý Á÷¿øµé¿¡°Ô´Â ¾ÆÁ÷ ±â¹Ð µ¥ÀÌÅÍÀÇ °ø°³¸¦ ¿¹¹æÇϱâ À§ÇÑ º¸¾È ÀÇ½Ä ÈÆ·ÃÀÌ ÇÊ¿äÇÒ °ÍÀÌ´Ù. À¯·´¿¡¼´Â, ±×¸®½º Ãâ½Å µ¿·á°¡ ¿µ¾î¸¦ ÀÌÇØÇÏÁö ¸øÇÒ ¼öµµ ÀÖ°í, ³²¾Æ½Ã¾Æ¿¡¼´Â, ÀÎÅͳݿ¡ ´ëÇÑ ÁÖ¿ä Á¢±Ù °æ·Î¸¦ ¼Óµµ°¡ »ó´çÈ÷ ¶³¾îÁö´Â ´ÙÀ̾ó ÀüÈ¿¡ ÀÇÁ¸ÇÒ ¼öµµ ÀÖ´Ù. ½ÃÂ÷ ¹®Á¦´Â º»»ç¿¡¼ È»ó ȸÀÇ—ÀÌ°ÍÀº ÀÇ»ç¼ÒÅ븸À» ¸ñÀûÀ¸·Î ÇÏ´Â °ÍÀº ¾Æ´Ï¸ç, ¾ÆÁ÷±îÁö´Â ´ë¸é ȸÀǺ¸´Ù´Â ´ú È¿°úÀûÀÌ´Ù—¸¦ °³ÃÖÇÏ´Â °ÍÀ» ¹æÇØÇÑ´Ù.
ÀÌ·± ÇüÅÂÀÇ °øÅëÀûÀÎ Àå¾Ö¿¡ ´õÇÏ¿©, ±Û·Î¹ú ºñÁî´Ï½º´Â ±Û·Î¹ú ÇÕº´(M&A), ±Ô¹ü Áؼö¸¦ À§ÇÑ À繫 º¸°í¿¡ °üÇÑ ³»ºÎ ÅëÁ¦, ±×¸®°í »ç¾÷ °áÇÕ ¹× ¿¬°á À繫Á¦Ç¥¸¦ À§ÇÑ È¸°è»óÀÇ ±¹Á¦ À繫 º¸°í ±âÁØ(IFRS: International Financial Reporting Standards) µî°ú °°Àº »õ·Î¿î µµÀü¿¡ Á÷¸éÇÏ°í ÀÖ´Ù.
Áö±Ý±îÁö´Â, IT °ü¸®¿¡ ÀÖ¾î¼ È¿°úÀûÀÎ °ÍÀ¸·Î, ¡°Â¡¹ú ¹× ½ÂÀΡ±ÀÌ IT Á÷¿ø/»ç¿ëÀÚ¸¦ °ü¸®ÇÏ°í ±×µéÀÇ È°µ¿À» ÅëÁ¦Çϱâ À§ÇÑ ÀüÅëÀûÀÎ °Å¹ö³Í½º ÇüÅÂÀ̾ú´Ù. ºñÁî´Ï½º ±×·ìÀÌ ÁÖ·Î ÀÚ±¹ ±â¾÷µé·Î ±¸¼ºµÇ¾î ÀÖÀ» °æ¿ì¿¡ IT¸¦ °ü¸®ÇÏ´Â °ÍÀÌ ÈξÀ ¿ëÀÌÇÏ°í ¶ÇÇÑ IT ÀÚ¿øÀ» °¡±î¿î °÷À¸·Î¸¸ º¸³¾ ¼ö°¡ ÀÖ´Ù.
±×·¸Áö¸¸, ¹é ³â¿¡ Çѹø ã¾Æ¿Ã±î ÇÏ´Â ±ÝÀ¶ À§±â ¼Ó¿¡¼1, ¸¹Àº ±Û·Î¹ú ±â¾÷Àº ÀÚ±âµéÀÇ »ç¾÷ü¸¦ Àü¼¼°èÀûÀ¸·Î È®»ê½ÃÅ°±â À§Çؼ IT °ü¸®¿¡, ÀÚüÀÌµç ¿ÜºÎÁ¶´Þ(¾Æ¿ô¼Ò½Ì)À̵ç, ÃæºÐÇÑ ÀÚ¿øÀ» ÇÒ´çÇÒ ¼ö ÀÖ´Â ¿©À¯°¡ ¾ø´Ù.
¼¼°èÀûÀÎ °æÁ¦ ºÒȲ°ú ÇÔ²² ÇÏ´Â ¿À´Ã³¯ÀÇ ±Û·Î¹ú IT °Å¹ö³Í½º ½Ã´ë¿¡, ¡°è¿Í ½ÂÀÎÀ¸·Î »ó¡µÇ´Â Çϵå IT °Å¹ö³Í½º´Â ±â¾÷ÀÇ IT¸¦ È¿°úÀûÀ̸ç È¿À²ÀûÀ¸·Î °ü¸®Çϴµ¥ ºÎÀûÇÕÇÏ´Ù.
±Û·Î¹ú IT °Å¹ö³Í½º¸¦ º¸¿ÏÇÏ°í Çâ»ó½ÃÅ°±â À§ÇÏ¿©, ¼ÒÇÁÆ® ÆÄ¿ö ÀÌ·ÐÀ» ÀÀ¿ëÇÔÀ¸·Î½á ¼ÒÇÁÆ® IT °Å¹ö³Í½º¶ó´Â ½Å°³³äÀ» Àû¿ëÇÒ ¼ö ÀÖ´Ù.
¼ÒÇÁÆ® ÆÄ¿ö ÀÌ·Ð
¡®¼ÒÇÁÆ® ÆÄ¿ö: ¼¼°è Á¤Ä¡¿¡¼ ¼º°øÇϱâ À§ÇÑ ¼ö´Ü¡¯ÀÇ ÀúÀÚÀÌÀÚ ¼ÒÇÁÆ® ÆÄ¿ö ÀÌ·ÐÀÇ ÁÖâÀÚÀÎ, Á¶ÁöÇÁ ³ªÀÌ(Joseph Nye ) 2´Â ÆÄ¿ö(power)ÀÇ ±âº» °³³äÀ» ´ÙÀ½°ú °°ÀÌ Á¤ÀÇÇÑ´Ù:
´Ù¸¥ »ç¶÷µé·Î ÇÏ¿©±Ý ´ç½ÅÀÌ ¿øÇÏ´Â °ÍÀ» Çϵµ·Ï ±×µé¿¡°Ô ¿µÇâÀ» ¹ÌÄ¡´Â ´É·Â. ±×°ÍÀ» Çϱâ À§ÇÑ °ÍÀ¸·Î 3°¡Áö ¹æ¹ýÀÌ ÀÖ´Ù: Çϳª´Â ±×µéÀ» ¸ùµÕÀÌ·Î À§ÇùÇÏ´Â °Í; µÑ°´Â ±×µé¿¡°Ô ´ç±Ù(º¸»ó)À» ÁÖ´Â °Í; ¼¼¹ø°´Â ±×µéÀÇ °ü½ÉÀ» ºÒ·¯ÀÏÀ¸Å°°Å³ª ÇÔ²² µ¿Âü½ÃÅ°´Â °Í, ±×·¡¼ ±×µéÀÌ ´ç½ÅÀÌ ¹Ù¶ó´Â °ÍÀ» Çϵµ·Ï ÇÑ´Ù. ´ç½ÅÀÌ ±×µé·Î ÇÏ¿©±Ý ´ç½ÅÀÌ ¿øÇÏ´Â °ÍÀ» ¿øÇϵµ·Ï ±×,µéÀÇ °ü½ÉÀ» ²ø ¼ö ÀÖ´Ù¸é, ÀÌ ¹æ¹ýÀº ´ç±ÙÀ̳ª À§ÇùÀûÀÎ ¹æ¹ýº¸´Ù ÈξÀ ºñ¿ëÀÌ Àû°Ô µç´Ù.
±×·¡¼, ±×´Â ´ÙÀ½À» ¹¦»çÇϱâ À§ÇØ ¼ÒÇÁÆ® ÆÄ¿ö¶ó´Â ¿ë¾î¸¦ °í¾ÈÇØ ³»¾ú´Ù:
À¯ÀÎÇÏ°í ¼³µæ½ÃÅ°´Â ±¹°¡ÀÇ ´É·ÂÀ». ¹Ý¸é¿¡ Çϵå ÆÄ¿ö´Â—¾ï¾ÐÇÏ´Â ´É·Â—³ª¶óÀÇ ±º´ë³ª °æÁ¦Àû Èû¿¡¼ »ý°Ü³ª´Â ¹Ý¸é¿¡ ¼ÒÇÁÆ® ÆÄ¿ö´Â ±× ³ª¶óÀÇ ¹®È, Á¤Ä¡Àû ÀÌ»ó ±×¸®°í Á¤Ã¥ÀÇ ¸Å·ÂÀ¸·ÎºÎÅÍ »ý°Ü³´Ù.
±×¸² 1Àº ÇÏµå ¹× ¼ÒÇÁÆ® ÆÄ¿ö¿¡ ÇØ´çÇÏ´Â Çൿ ¹× ÀÚ¿øÀ» º¸¿©ÁØ´Ù.
±×¸² 1—Çϵå vs. ¼ÒÇÁÆ® ÆÄ¿ö ¸ÅÆ®¸¯½º |
|
Çϵå ÆÄ¿ö |
¼ÒÇÁÆ® ÆÄ¿ö |
Çൿ ½ºÆåÆ®·³ |
¸í·É, °Á¦·Â ±×¸®°í À¯ÀÎ |
Çൿ Áöħ ¼ö¸³, À¯È¤ ±×¸®°í µ¿Âü |
°¡Àå ¾Ë¸Â´Â ÀÚ¿ø |
°Á¦, ½ÂÀÎ ±×¸®°í ¡°è |
Á¦µµ, °¡Ä¡°ü, ¹®È ±×¸®°í Á¤Ã¥ |
¼ÒÇÁÆ® ÆÄ¿ö ÀÌ·ÐÀÌ ±¹Á¦ Á¤Ä¡¿¡¼ À¯¿ëÇÏ´Ù¸é, ±×°ÍÀ» IT °Å¹ö³Í½º¿¡ Àû¿ëÇÏÁö ¸øÇÒ ÀÌÀ¯°¡ Àִ°¡? ¼ÒÇÁÆ® IT °Å¹ö³Í½º´Â ºñÁî´Ï½º¸¦ Áö¿øÇϱâ À§ÇÑ À¯¿ëÇÑ IT °ü¸® µµ±¸°¡ µÉ °ÍÀÌ´Ù. COBITÀÇ 34 °³ ÇÁ·Î¼¼½º¿¡ °üÇؼ, ºñÁî´Ï½º/IT °ü¸®¿¡ È¿°úÀûÀÎ ´ÙÀ½°ú °°Àº Çϵå/¼ÒÇÁÆ® IT °Å¹ö³Í½º »ç·Ê¸¦ ã¾Æº¼ ¼ö ÀÖ´Ù.
COBIT ÇÁ·Î¼¼½º¿¡ ÀÖ´Â Çϵå/¼ÒÇÁÆ® IT °Å¹ö³Í½º
COBIT 4.1Àº IT °Å¹ö³Í½º¸¦ ¡°°íÀ§ ÀÓ¿ø°ú ÀÌ»çȸÀÇ Ã¥ÀÓÀ̸ç, ¶ÇÇÑ ±â¾÷ÀÇ IT°¡ Á¶Á÷ÀÇ Àü·« ¹× ¸ñÇ¥¸¦ À¯ÁöÇÏ°í È®Àå½ÃÅ°µµ·Ï º¸ÁõÇÏ´Â ¸®´õ½Ê, Á¶Á÷ ±¸Á¶ ±×¸®°í ÇÁ·Î¼¼½ºµé·Î ±¸¼ºµÈ´Ù¡±¶ó°í Á¤ÀÇÇÑ´Ù. 3 ÀÌ°ÍÀº ±âº»ÀûÀ¸·Î IT °Å¹ö³Í½º°¡ IT "¿¡ ÀÇÇÑ" °Å¹ö³Í½º°¡ ¾Æ´Ï¶ó, ºñÁî´Ï½º Àü·« ¹× ¸ñÇ¥¸¦ Áö¿øÇÏ´Â IT "¿¡ ´ëÇÑ" °Å¹ö³Í½º¶ó´Â »ç½ÇÀ» ÀǹÌÇÏ´Â °ÍÀÌ´Ù. ±×·¡¼, IT °ü¸®¸¦ Æò°¡ÇÒ °æ¿ì¿¡, ¾ðÁ¦³ª ºñÁî´Ï½º ¸Å´ÏÁö¸ÕÆ®¿¡ ´ëÇÑ È¿°ú¿Í ¿¬°èµÇ¾î¾ß ÇÑ´Ù(¿¹¸¦ µé¸é, ½Å·Ú »ç½½ reliance chain).
IT °Å¹ö³Í½ºÀÇ 2°¡Áö ÇüÅ¿¡ ´ëÇÑ Á¤ÀÇ´Â ´ÙÀ½°ú °°´Ù:
- Çϵå IT °Å¹ö³Í½º—°æ¿µÀÚ°¡ ¸®´õ½Ê, Á¶Á÷ ±¸Á¶ ±×¸®°í ÇÁ·Î¼¼½º¸¦ Á÷Á¢ÀûÀ¸·Î °³¼±½ÃÅ°°í Çâ»ó½ÃÅ°±â À§ÇÏ¿© Çϵå-ÆÄ¿ö ¼ö´Ü, ¿¹¸¦ µé¾î, °¿ä, ½ÂÀÎ, ¡°è °°Àº °ÍÀ» ÀÌ¿ëÇÏ¿© IT Á÷¿ø/»ç¿ëÀÚ¿¡°Ô ¸í·ÉÇÏ°í ±ÇÀ¯ÇÏ´Â °ÍÀÌ´Ù.
- ¼ÒÇÁÆ® IT °Å¹ö³Í½º—°æ¿µÀÚ°¡ ¸®´õ½Ê, Á¶Á÷ ±¸Á¶ ±×¸®°í ÇÁ·Î¼¼½º¿¡ ´ëÇÑ º¸´Ù ÁÁÀº ȯ°æÀ» °£Á¢ÀûÀ¸·Î Á¶¼ºÇϱâ À§ÇÏ¿© ¼ÒÇÁÆ®-ÆÄ¿ö, ¿¹¸¦ µé¾î, Á¦µµ, °¡Ä¡°ü, ¹®È, Á¤Ã¥ °°Àº °ÍÀ» ÀÌ¿ëÇÏ¿©, ÀÇÁ¦¸¦ ¼³Á¤ÇÏ°í ±×¸®°í IT Á÷¿ø/»ç¿ëÀÚ¸¦ À¯µµÇÏ¿© µ¿Âü½ÃÅ°´Â °ÍÀÌ´Ù.
½º¸¶Æ® IT °Å¹ö³Í½º
¡°´Ü´ÜÇÑ ¸ð·ç¿¡°Ô´Â, ±êÅÐÀÌ ÇظÓÀÌ´Ù,¡±¡±ÁøÈë º®ÀÌ Ä³³í º¼À» ¸·´Â´Ù¡± ±×¸®°í ¡°À¯¿¬ÇÔÀÌ ´Ü´ÜÇÔ º¸´Ù ´õ °ÇÏ´Ù,¡± µîÀÇ ¿¾³¯ ¼Ó´ãÀ̳ª ¹«¼úÀ» º¸¸é, »ç¶÷Àº ¼ÒÇÁÆ® ÆÄ¿öÀÇ °³³äÀ̳ª °¡Ä¡°üÀ» ¿À·¡ ±â¾ïÇÑ´Ù.
´õ´õ¿í, ¡°ÇÏµå ¹× ¼ÒÇÁÆ® ÆÄ¿ö¸¦ ÇϳªÀÇ ¼º°ø Àü·«À¸·Î °áÇÕÇÏ´Â ´É·Â¡±Àº Áß¿äÇÏ´Ù; ±×·± ´É·ÂÀ» ¡°½º¸¶Æ® ÆÄ¿ö¡±¶ó ºÎ¸¥´Ù. 4, 5
IT °Å¹ö³Í½º¿¡ ÀÖ¾î¼, IT Àü·«¿¡ ±âÃÊÇÑ (±×¸² 2¿¡¼ º¸´Â) ÇÏµå ¹× ¼ÒÇÁÆ® IT °Å¹ö³Í½º·ÎºÎÅÍ ¿Ã¹Ù¸¥ µµ±¸¸¦ ã¾Æ¼ ¼±ÅÃÇϱâ À§ÇÏ¿© ÀÌ·± ½º¸¶Æ® ÆÄ¿ö¸¦ ÀÌ¿ëÇÏ´Â °Íµµ µµ¿òÀÌ µÈ´Ù.
±×¸² 2—Çϵå/¼ÒÇÁÆ® IT °Å¹ö³Í½º ¸ÅÆ®¸¯½º |
COBIT µµ¸ÞÀÎ |
Çϵå IT °Å¹ö³Í½º ¿¹½Ã |
¼ÒÇÁÆ® IT °Å¹ö³Í½º ¿¹½Ã |
±âȹ ¹× Á¶Á÷ |
[PO1] IT Àü·« °èȹ ¼ö¸³
1.ºñÁî´Ï½º Àü·«°ú ¿¬°èµÇÁö ¾ÊÀ¸¸é, IT Àü·«°èȹÀÌ ½ÂÀ뵃 ¼ö ¾ø´Ù. [½ÂÀÎ]
[PO4] IT ÇÁ·Î¼¼½º, Á¶Á÷ ¹× °ü°èÀÇ Á¤ÀÇ
1.ÇÙ½É IT ÇÁ·Î¼¼½º(¿¹¸¦ µé¸é, IT Àü·« ¼ö¸³ ¶Ç´Â ÇÙ½É ºñÁî´Ï½º¸¦ À§ÇÑ ¼³°è)°¡ Á¤Àǵǰí, ±×°ÍÀº ¿ÜÁÖ¸¦ ÁÖÁö ¾Ê´Â´Ù(ÀÚü ÇÙ½É IT ÀÚ¿øÀ¸·Î À¯ÁöÇÑ´Ù). [°Á¦, ¡°è]
[PO7] IT ÀÎÀû ÀÚ¿ø °ü¸®
1.Àû¼Ò ¹èÄ¡¸¦ À§ÇÏ¿© ½Ç¹« ÈÆ·Ã ´ë»óÀÚµéÀº IT °ü¸® °æ·ÂÀÇ ±Ëµµ ¾È¿¡¼ Á÷¿øµéÀÇ °æ·Â Ãʱ⿡ ¹Ì¸® ¼±Á¤µÈ´Ù. [°Á¦]
[PO9] IT À§Çè Áø´Ü ¹× °ü¸®
1.À§Çè Æò°¡¿Í À§Çè ¿ÏÈ ÅëÁ¦¿¡ ´ëÇÑ °í·Á¾øÀÌ IT ÅõÀÚ ¹× ÇÁ·ÎÁ§Æ®´Â ½ÂÀεÇÁö ¾Ê´Â´Ù. [½ÂÀÎ]
[PO10] ÇÁ·ÎÁ§Æ® °ü¸®
1.PMO(project management office)°¡ Àη ¹× ¿¹»ê¿¡ ´ëÇؼ ÇÁ·ÎÁ§Æ®¸¦ °ü¸®ÇÒ ±ÇÇÑÀ» °®´Â´Ù. [°Á¦, ¡°è] |
[PO1] IT Àü·« °èȹ ¼ö¸³
1.ȸ»çÀÇ ¸î¸î IT Àü·« ¼³°è¿¡ ºñÁî´Ï½º ¹× Áö¿ª ÀÌÇØ°ü°èÀÚ°¡ Ãʱ⿡ Âü¿©ÇÑ´Ù. [°¡Ä¡°ü, ¹®È, Á¤Ã¥]
[PO3] ±â¼ú¹æÇâÀÇ °áÁ¤
1.±â¼ú ÂüÁ¶ ¸ðµ¨ÀÌ IT Á¤Ã¥ ¹× Àü·«°ú Àß ¿¬°èµÇ°í ¸ÅÇεȴÙ. [°¡Ä¡°ü, Á¤Ã¥]
[PO4] IT ÇÁ·Î¼¼½º, Á¶Á÷ ¹× °ü°èÀÇ Á¤ÀÇ
1.ÇÕº´ ÈÄÀÇ ÅëÇÕ ¸Å´º¾óÀÌ ÇÕº´ ¹× ÇÇÇÕº´ IT Á¶Á÷µé¿¡ Á¦°øµÈ´Ù. [Á¦µµ, Á¤Ã¥]
2.Á¶Á÷ÀÇ ÀÚü IT ºÎ¼»Ó¸¸ ¾Æ´Ï¶ó 3ÀÚ, ¿î¼Û ±×¸®°í ÄÁ¼³Æà ȸ»çÀÇ ¼ºñ½º¸¦ ÅëÇÕ½Ãų ¼ö ÀÖ´Â È®ÀåµÈ(°¡»óÀÇ) IT Á¶Á÷°ú ¼ºñ½º°¡ Á¤ÀǵǾî ÀÖ´Ù.[Á¦µµ, °¡Ä¡°ü]
[PO5] IT ÅõÀÚ °ü¸®
1. IT ÅõÀÚ °áÁ¤À» Çϴµ¥ Á¤¼ºÀûÀÎ (Æò°¡) ¿ä¼Òµéµµ(µ¿±â, ÀûÀýÇÑ ¼ÒÅë) Æ÷ÇԵǾî ÀÖ´Ù. [°¡Ä¡°ü]
[PO6] °æ¿µ ¸ñÇ¥ ¹× ¹æħ ÀüÆÄ
1.ºñµð¿À ÄÁÆÛ·±½º ½Ã½ºÅÛ °°Àº ¼ÒÅë µµ±¸¸¦ ÀÌ¿ëÇϱâ Àü¿¡ ½Å·Ú °ü°è¸¦ ½×±â À§ÇÏ¿© Á÷Á¢ ´ë¸é ȸÀǸ¦ ¸ÕÀú °³ÃÖÇÑ´Ù. [°¡Ä¡°ü]
[PO7] IT ÀÎÀû ÀÚ¿ø °ü¸®
1.(ÇØ¿Ü/Áö¹æ) Áö¿ª¿¡ ±Ù¹«ÇÏ´Â Á÷¿øµéÀÌ ±â¾÷ º»»ç¿¡¼ ÀÏÇÒ ±âȸ¸¦ °®´Âµ¥, ÀÌ°ÍÀÌ »ç±â¸¦ ÁøÀÛ½ÃŲ´Ù. [Á¦µµ, ¹®È]
2.¿¹¸¦ µé¾î, ¿µ±¹ÀÇ Á¤º¸ ¼¼´ë¸¦ À§ÇÑ ½ºÅ³ ÇÁ·¹ÀÓ¿öÅ©[SFIA], ÀϺ»ÀÇ »ç¿ëÀÚ Á¤º¸ ½ºÅ³ Ç¥ÁØ[UISS]°ú IT ½ºÅ³ Ç¥ÁØ[ITSS] µîÀÇ ½ºÅ³(skill) ÇÁ·¹ÀÓ¿öÅ©¿¡ ±â¹ÝÇÑ IT Á÷¿ø¿ë Ä¿¸®¾î ·Îµå¸ÊÀÌ ¸¸µé¾îÁ® ÀÖ´Ù. (Á¦µµ, Á¤Ã¥)
[PO8] Ç°Áú °ü¸®
1.ÀϺ»ÀÇ Ç°ÁúÅëÁ¦È°µ¿ÀÎ QC ¼Å¬ ȤÀº Six Sigma °°Àº ÀüÅëÀûÀÎ ¸Þ¼Òµå¸¦ ÀÌ¿ëÇÏ¿© Áö¼ÓÀûÀ¸·Î ÀÚ°¡ Áø´Ü È°µ¿À» ÇÑ´Ù. [Á¦µµ, °¡Ä¡°ü]
[PO9] IT À§Çè Áø´Ü ¹× °ü¸®
1.Á÷¿øµéÀÇ ºÎÁÖÀÇÇÑ ½Ç¼ö·Î ÀÎÇÑ °Í Á¶Â÷µµ, °æ¿µÀÚ´Â IT Á÷¿øÀ¸·ÎºÎÅÍÀÇ ¾î¶°ÇÑ À§Çè º¸°í¼µµ ÁøÁöÇÏ°Ô ¹Þ¾ÆµéÀδÙ. [°¡Ä¡°ü]
[PO10] ÇÁ·ÎÁ§Æ® °ü¸®
1.PMBOK(Project Management Body of Knowledge)¿Í °°Àº ³Î¸® º¸±ÞµÈ ÁöħÀÌ ÇÁ·ÎÁ§Æ®¸¦ °ü¸®Çϱâ À§ÇÏ¿© ±×·ì ¹× ±Û·Î¹ú °øÅë ¾ð¾î·Î ½±»ç¸® ¼ö¿ëµÈ´Ù. [°¡Ä¡°ü, Á¤Ã¥] |
ȹµæ ¹× ±¸Çö |
[AI1] ÀÚµ¿ ¼Ö·ç¼Ç µµÃâ
1.¿ä±¸»çÇ× ¹× Ÿ´ç¼º Á¶»ç°¡ ¹®¼ÈµÇ°í ½ÂÀεǾúÀ» °æ¿ì¿¡¸¸, ÇÁ·ÎÁ§Æ®°¡ ´ÙÀ½ °øÁ¤À¸·Î À̾îÁú ¼ö ÀÖ´Ù. [½ÂÀÎ]
[AI3] ±â¼ú ÀÎÇÁ¶ó µµÀÔ ¹× À¯Áöº¸¼ö
1.IT ÀÎÇÁ¶ó´Â ¹Ì¸® Á¤ÀÇµÈ IT ¾ÆÅ°ÅØó ¹× ±â¼ú Ç¥ÁØ¿¡ ÀÏÄ¡ÇÏ¿©¾ß¸¸ ÇÑ´Ù. [½ÂÀÎ]
[AI4] ¿î¿µ ¹× ÀÌ¿ë È®º¸
1.¾î¶°ÇÑ ¾ÖÇø®ÄÉÀ̼ǵµ ÀûÀýÇÑ »ç¿ëÀÚ ¹× ¿î¿µÀÚ ¸Å´º¾óÀ» Á¦°øÇÏÁö ¾ÊÀ¸¸é ¿î¿µ ȯ°æÀ¸·Î ÀÌ°üµÉ ¼ö ¾ø´Ù. [½ÂÀÎ]
[AI6] º¯°æ °ü¸®
1.±ä±ÞÀÌµç ¾Æ´Ïµç ¸ðµç º¯°æ ¿äûÀº ±× º¯°æ »çÇ×ÀÌ ÇÁ·Î´ö¼Ç ȯ°æ¿¡ ±¸ÇöµÇ±â Àü¿¡ ¹®¼ÈµÇ°í ½ÂÀεȴ٠(Áï, ºñ½ÂÀÎ º¯°æÀº ÀüÇô ¾ø´Ù). [½ÂÀÎ]
|
[AI1] ÀÚµ¿ ¼Ö·ç¼Ç µµÃâ
1.¿¹¸¦ µé¾î, BABOK(Business Analysis Body of Knowledge) °°Àº Àß È®¸³µÈ ¹æ¹ý·ÐÀÌ IT ¼Ö·ç¼ÇÀÇ È®Àΰú Æò°¡¿¡ ÀÌ¿ëµÈ´Ù. ±×·¯ÇÑ ¹æ¹ý·ÐÀº ¿î¿µ°è·ÎÀÇ ÀÌ°ü ¹× À¯Áöº¸¼ö¸¦ È¿À²ÀûÀ¸·Î Çϵµ·Ï ÇÏ´Â ¹Ì¸® Á¤ÇØÁø ±¸Á¶ÀÇ ¹®¼¸¦ »ý»êÇÑ´Ù. [Á¤Ã¥]
[AI2] ÀÀ¿ë ¼ÒÇÁÆ®¿þ¾î ȹµæ ¹× À¯Áö
1.ºñ±â´É¼º ¿ä±¸»çÇ×(¿¹¸¦ µé¸é, ¼º´É, ½Å·Ú¼º, È®À强, º¸¾È)ÀÌ ÃæºÐÈ÷ °í·ÁµÇ¾î ¼³°è ¸í¼¼¿¡ ¹Ý¿µµÈ´Ù. [Á¦µµ, °¡Ä¡°ü]
[AI3] ±â¼ú ÀÎÇÁ¶ó µµÀÔ ¹× À¯Áöº¸¼ö
1.º¸´Ù ÀÛÀº ¼ºñ½º ¸ñÇ¥¿Í ±×ÀÇ ÀÎÇÁ¶ó ¼öÁØ(¿¹¸¦ µé¾î, ±¤¿ªº¸´Ù´Â °³º° µµ½Ã)ÀÌ (¼¼¹ÐÇÏ°Ô) Á¶Á¤µÈ IT ¼ºñ½ºµéÀ» Á¦°øÇÑ´Ù). [Á¦µµ]
[AI4] ¿î¿µ ¹× ÀÌ¿ë È®º¸
1.¿ÀÆÛ·¹ÀÌÅÍ ¹× »ç¿ëÀÚ°¡ ¸Å´º¾óÀ» ÀÛ¼ºÇÏ°í °ËÅäÇÏ´Â °ÍÀ» µµ¿ï ¼ö ÀÖ´Â ÃæºÐÇÑ ½Ã°£À» °®´Â´Ù. [Á¦µµ, ¹®È]
[AI6] º¯°æ °ü¸®
1.º¯°æ ¿äûÀÌ °ÅºÎµÇ°Å³ª Áö¿¬µÇÁö ¾Êµµ·Ï Çϱâ À§ÇÏ¿©, ¿äû»çÇ×µéÀº Á¤±âÀûÀ¸·Î °ËÅäµÇ°í ¼öÁ¤µÈ´Ù. [°¡Ä¡°ü, ¹®È]
2.º¯°æ ¿äûÀÌ ºó¹øÇÏÁö ¾Ê°Ô ÀϾ°í, ÀûÀýÇÑ º¯°æ °ü¸® (ÀýÂ÷)¸¦ ¹Þ¾ÆµéÀδÙ. [°¡Ä¡°ü]
[AI7] ¼Ö·ç¼Ç ¹× º¯°æÀÇ ¼³Ä¡ ¹× Àΰ¡
1.³ôÀº Ç°ÁúÀ» Áõ¸íÇϱâ À§ÇÏ¿© (»ç¿ë¿¡ ¾Õ¼) Àΰ¡°¡ ÇàÇØÁö°í, (ÀÌ·¯ÇÑ ÇàÀ§°¡) ¾ÖÇø®ÄÉÀ̼ǿ¡ °üÇÑ Ç¥ÁØ (ÀýÂ÷)ÀÌ´Ù. [°¡Ä¡°ü, ¹®È] |
Á¦°ø ¹× Áö¿ø |
[DS1] ¼ºñ½º ¼öÁØ Á¤ÀÇ ¹× °ü¸®
1.Á¤ÀÇµÈ ¼ºñ½º ¼öÁØÀ» ´Þ¼ºÇϰųª ¹Ì´ÞÇßÀ» ¶§ º¸»ó ¶Ç´Â ¹úÄ¢ÀÌ ³»·ÁÁø´Ù.[½ÂÀÎ, ¡°è]
[DS2] ¿ÜÁÖ ¼ºñ½º °ü¸®
1.È¿À²Àû °ü¸®¸¦ À§Çؼ Çã°¡ÇØÁØ ¿ÜÁÖ ¾÷üÀÇ ¼ö¸¦ ÁÙÀδÙ.[°Á¦]
[DS3] ¼º´É ¹× ¿ë·® °ü¸®
1.Á¦ÇÑµÈ ¿ë·®À¸·Î ³×Æ®¿öÅ© ´ë¿ªÆø °°Àº IT ¼ºñ½º ¼öÁØÀÌ ¾î´À Á¤µµ·Î Á¦ÇѵȴÙ. [°Á¦]
[DS9] Çü»ó °ü¸®
1.¸ðµç Ŭ¶óÀ̾ðÆ® PC¿¡ ÇØ´ç ÄÄÇ»ÅÍÀÇ ¼ÒÇÁÆ®¿þ¾î/Çϵå¿þ¾î ±¸¼ºÀ» ¸ð´ÏÅÍÇÏ´Â ¿¡ÀÌÀüÆ® (ÇÁ·Î±×·¥)°¡(ÀÌ) ¼³Ä¡µÇ¾î¾ß¸¸ ÇÑ´Ù. [°Á¦]
[DS12] ¹°¸®Àû ȯ°æ °ü¸®
1.±¸³», °Ç¹° ±×¸®°í Áö¿ª¿¡ ´ëÇÑ Á¢±ÙÀº »ýüÃøÁ¤ ¹æ½ÄÀ¸·Î Çã°¡µÇ¾î¾ß¸¸ ÇÑ´Ù. [°Á¦, ½ÂÀÎ] |
[DS1] ¼ºñ½º ¼öÁØ Á¤ÀÇ ¹× °ü¸®
1.IT ¼ºñ½º ¹× ±×ÀÇ ¼öÁØ¿¡ °üÇÏ¿©, IT°ü¸®ÀÚ ¹× ºñÁî´Ï½º °í°´ »çÀÌ¿¡ È¿°úÀûÀÎ ¼ÒÅë ¹æ¹ý(¿¹¸¦ µé¸é, ¼ºñ½º Ä«´Þ·Î±×)ÀÌ Àß ¸¶·ÃµÇ¾î ÀÖ´Ù.. [°¡Ä¡°ü, ¹®È]
[DS2] ¿ÜÁÖ ¼ºñ½º °ü¸®
1.¸±·¹ÀÌ¼Ç½Ê Ç°ÁúÀÌ ½Å·Ú¿Í Åõ¸í¼º¿¡ ±âÃÊÇÏ´Â °ÍÀ» º¸ÁõÇϱâ À§ÇÏ¿© ¸±·¹ÀÌ¼Ç½Ê ¿À³Ê°¡ °í°´ ¹× °ø±ÞÀÚ¿Í ¿¬¶ôÇÏ¿©¾ß ÇÑ´Ù. [°¡Ä¡°ü, ¹®È]
2.ÀáÀçÀûÀÎ º¥´õ¿ÍÀÇ ¼ÒÅë ä³ÎÀ» ´ÃÀδÙ.[°¡Ä¡°ü]
[DS4] ¼ºñ½º Áö¼Ó¼º È®º¸
1.ÀáÀçÀûÀÎ µÅÁö/Á¶·ù ÀÎÇ÷翣ÀÚ¿¡ ÀÇÇÑ ¼¼°èÀûÀÎ À¯Çà °°Àº »õ·Î¿î À§ÇùÀ» ¸ð´ÏÅÍÇÏ°í À§Çè ¿µÇâÀ» ºÐ¼®ÇÑ´Ù. [°¡Ä¡°ü, ¹®È]
[DS5] ½Ã½ºÅÛ º¸¾È È®º¸
1.º¸¾È ¼öÁØÀÌ ³Ê¹« ¾ö°ÝÇÏÁöµµ ±×¸®°í ´À½¼ÇÏÁöµµ ¾Êµµ·ÏIT °ü¸®ÀÚ¿Í ºñÁî´Ï½º °í°´°£¿¡ ÃæºÐÈ÷ Åä·ÐµÇ°í ÇÕÀǵȴÙ. [°¡Ä¡°ü, Á¤Ã¥]
[DS9] Çü»ó °ü¸®
1.IT Á÷¿øÀÌ Á¤±âÀûÀ¸·Î IT Àڻ꿡 ´ëÇÑ ¹°¸®Àû Àç°í¸¦ Á¶»çÇÏ°í üũÇϸç, À̸¦ À§ÇØ »ç¿ëÀÚ¿Í ¸¸³ª À̾߱âÇÔÀ¸·Î½á ÀÚ»êÀÌ ÀÌ¿ëµÇ´Â ȯ°æÀ» ÀÌÇØÇÒ ¼ö ÀÖ´Ù. ¿¹¸¦ µé¾î, ¿, ½Àµµ, ÀüÀڱ⠰°Àº ȯ°æ Á¤º¸´Â ÀÚ»ê ¸ð´ÏÅÍ Åø·Î´Â ¾òÀ» ¼ö ¾ø´Â °ÍÀÌ´Ù. [°¡Ä¡°ü, ¹®È]
[DS11] µ¥ÀÌÅÍ °ü¸®
1.º¸°ü Á¤Ã¥¿¡ ±Ù°ÅÇØ, ºÒÇÊ¿äÇÑ µ¥ÀÌÅ͸¦ Á¦°ÅÇÏ°í ¼ø¼´ë·Î ³Ö±â À§Çؼ »ç¿ëÀÚµéÀÌ ÀڽŵéÀÇ µ¥ÀÌÅ͸¦ Á¤±âÀûÀ¸·Î Á¡°ËÇÑ´Ù. [°¡Ä¡°ü, ¹®È]
[DS12] ¹°¸®Àû ȯ°æ °ü¸®
1.Ã¥»ó, ÀÇÀÚ, ´Ü¸»±â, ¸¶¿ì½º, Å°º¸µå °°Àº IT Á÷¿øÀ» À§ÇÑ ÀÛ¾÷ ȯ°æÀÌ ÀÎü°øÇÐÀûÀ¸·Î ¼³°èµÇ¾î ÀÖ´Ù. [°¡Ä¡°ü, ¹®È] |
¸ð´ÏÅÍ ¹× Æò°¡ |
[ME3] ¿ÜºÎ ¿ä°Ç Áؼö º¸Áõ
1.ÇØ¿Ü ¼ÒÀçÁöÀÇ ¹ý±Ô¸¦ ÁؼöÇϱâ À§ÇÏ¿© ¼³Ä¡µÈ °í°¡ÀÇ IT ÀåÄ¡¿¡ °üÇÑ Á¤º¸°¡ ¼öÁýµÈ´Ù.[°Á¦, ¡°è]
[ME4] IT °Å¹ö³Í½º Áغñ
1. CGEIT ¶Ç´Â CISA °°Àº °ü·Ã ÀÚ°ÝÀ» ¼ÒÁöÇÑ °æÇèÀÖ´Â IT Àü¹®°¡¿¡ ÀÇÇØ IT °Å¹ö³Í½º¿¡ ´ëÇÑ º¸ÁõÀÌ ¿ä±¸µÇ°í ȹµæµÈ´Ù. [°Á¦] |
[ME2] ³»ºÎ ÅëÁ¦ ¸ð´ÏÅÍ ¹× Æò°¡
1.Àß ¾Ë·ÁÁø ¹æ¹ý·Ð¿¡ ±â¹ÝÇÑ ÀÚ°¡Áø´Ü(¿¹¸¦ µé¸é, ÅëÁ¦ ÀÚ°¡Áø´Ü(CSA: Control Self-Assessment)) ¹× °£»çÀÇ Áö¿øÀ» ¹Þ´Â CSA ¿öÅ©¼¥ °°Àº ¼ÒÇÁÆ® ÅëÁ¦¿¡ ³ôÀº °¡Ä¡¸¦ ºÎ¿©ÇÑ´Ù. [Á¦µµ, °¡Ä¡°ü]
[ME4] IT °Å¹ö³Í½º Áغñ
1.¿ÜºÎ ¿ä°Ç ¹× ±ÔÁ¦ »çÇ×À» ÀÌÇØÇϱâ À§ÇÏ¿© IT Ã¥ÀÓÀÚµéÀÌ IT °ü·Ã Çùȸ¿¡ Âü¿©ÇÑ´Ù . [°¡Ä¡°ü, ¹®È] |
¿Ã¹Ù¸¥ µµ±¸¸¦ ¼±ÅÃÇϱâ À§ÇÑ °áÁ¤ ±â¹ýÀÎ ½º¸¶Æ® IT °Å¹ö³Í½º´Â ºñÁî´Ï½º À¯Çü/¹üÁÖ ±×¸®°í Áß¾ÓÁý±ÇÇü/ºÐ»êÇü ÆÄ¿ö ±ÕÇü¿¡ ÀÇÇÑ ¿µÇâÀ» °¨¾ÈÇØ¾ß ÇÑ´Ù(¿¹¸¦ µé¸é, ±ÝÀ¶ ¼ºñ½º¿¡ ´ëÇؼ´Â Áß¾ÓÁý±ÇÇü °Å¹ö³Í½º ±×¸®°í Á¦Á¶¾÷À» À§Çؼ´Â ºÐ»êÇü/ÀÚÄ¡Çü °Å¹ö³Í½º). ÀÇ»ç°áÁ¤ ÇÁ·Î¼¼½º¿¡¼, °Å¹ö³Í½º Á¤·Ä ¸ÅÆ®¸¯½º6°¡ Âü°í·Î ÀÌ¿ëµÉ ¼ö ÀÖ´Ù. Çϵå/¼ÒÇÁÆ® IT °Å¹ö³Í½º´Â °¢°¢ÀÇ ÀÇ»ç°áÁ¤ ÇÁ·Î¼¼½º(¿¹¸¦ µé¸é, IT ¿øÄ¢, IT ¾ÆÅ°ÅØó, ºñÁî´Ï½º ÀÀ¿ë ¿ä±¸, IT ÅõÀÚ)¸¶´Ù °Å¹ö³Í½º ±âº»¸ðÇü(¿¹¸¦ µé¸é, ºñÁî´Ï½º/IT ±ºÁÖÁ¦, ¿¬¹æ, ¾ç°Ã¼Á¦)¿¡¼ ¾à°£ Á¶Á¤µÉ ¼ö ÀÖ´Ù.
COBITÀÇ ¼öÇàÃ¥ÀÓ, ÃÑ°ýÃ¥ÀÓ, ÄÁ¼³Æà ±×¸®°í Á¤º¸Á¦°ø(RACI) Â÷Æ®´Â °Å¹ö³Í½º Á¤·Ä ¸ÅÆ®¸¯½º¿Í °°Àº µ¿ÀÏÇÑ ÀÇ»ç°áÁ¤ ±â¹ýÀ» Á¦°øÇÑ´Ù. °³°³ÀÇ IT ÅëÁ¦ È°µ¿º°·Î ¾î´À ´ã´ç(°³ÀÎ)ÀÌ ¼öÇàÃ¥ÀÓ, ÃÑ°ýÃ¥ÀÓ, ÀÚ¹® ȤÀº Á¤º¸Á¦°øÀ» Çϴ°¡¸¦ ³ªÅ¸³»´Â RACI Â÷Æ®´Â ÀÇ»ç°áÁ¤ ±â¹ý»Ó¸¸ ¾Æ´Ï¶ó ÀÌ»óÀûÀÎ IT °ü¸® Á¶Á÷(±â´É ¸ðµ¨)À» ¸¸µå´Âµ¥ ÀÌ¿ëµÉ ¼ö ÀÖ´Ù.
±×¸² 3ÀÇ °Å¹ö³Í½º Á¤·Ä ¸ÅÆ®¸¯½º¿Í ±×¸² 4ÀÇ COBIT RACI Â÷Æ®¿¡¼¿Í °°ÀÌ, °³°³ÀÇ °Å¹ö³Í½ºÀüÇü/´ã´ç±â´ÉÀº °¢°¢ÀÇ ÀÇ»ç°áÁ¤/È°µ¿¿¡ °üÇÑ °·ÂÇÑ (ÃÑ°ýÃ¥ÀÓ/¼öÇàÃ¥ÀÓ) ÆÄ¿ö¸¦ °®´Â´Ù. ±×·¡¼, ´©±º°¡ °·ÂÇÑ ÈûÀ» °®°í ÀÇ»ç°áÁ¤À» ÇÒ ¶§, Çϵå»Ó¸¸ ¾Æ´Ï¶ó ¼ÒÇÁÆ® IT °Å¹ö³Í½º¿¡µµ »óÀÀÇÏ´Â °í·Á°¡ ÀÖ¾î¾ß ÇÑ´Ù.
±×¸² 3—°Å¹ö³Í½º Á¤·Ä ¸ÅÆ®¸¯½º ¹ßÃé |
°áÁ¤»çÇ×(decision)
°Å¹ö³Í½º ÀüÇü(archetypes) |
IT ¿øÄ¢ |
IT ¾ÆÅ°ÅØó |
ºñÁî´Ï½º ÀÀ¿ë ¿ä±¸ |
IT ÅõÀÚ |
ºñÁî´Ï½º µ¶´Ü |
|
|
|
°·Â |
IT µ¶´Ü |
|
°·Â |
|
|
¿¬ÇÕ |
|
|
°·Â |
|
¾ç°Ã¼Á¦(ºñÁî´Ï½º ¹× IT) |
°·Â |
|
|
|
ºñÁî´Ï½º µ¶´Ü¿¡¼´Â ºñÁî´Ï½º °íÀ§ »óÀÓÀÓ¿ø; IT µ¶´Ü¿¡¼´Â IT ÁýÇàÀÓ¿ø; ¿¬ÇÕ ÀüÇü¿¡¼´Â IT ÀÇ»ç°áÁ¤ÀÌ Áß¾Ó ¹× »ç¾÷Àå °£¿¡ Á¶Á¤µÈ´Ù; ±×¸®°í ¾ç°±¸µµ¿¡¼´Â IT ÁýÇàÀÓ¿ø°ú ¶Ç ´Ù¸¥ ±×·ì(¿¹¸¦ µé¸é, °íÀ§ ÁýÇàÀÓ¿ø ȤÀº »ç¾÷ Á¶Á÷)ÀÌ´Ù. |
¿øõ: Weill and Ross, IT Governance, 2004 |
±×¸² 4—COBIT RACI Â÷Æ® ¹ßÃé |
È°µ¿(activities)
´ã´ç(function) |
IT Á¤Ã¥ °³¹ß ¹× À¯Áö |
ȸ»ç/±â¾÷ Á¤º¸ ¸ðµ¨ ÀÛ¼º ¹× À¯Áö |
ºñÁî´Ï½º ±â´É ¹× ±â¼ú ¿ä±¸»çÇ×À» Á¤ÀÇ |
(IT ÅõÀÚ) ÇÁ·ÎÁ§Æ® Æ÷Æ®Æú¸®¿À¸¦ À¯Áö |
ºñÁî´Ï½º ÁýÇàÀÓ¿ø |
I |
I |
C |
A/R |
Á¤º¸´ã´çÀÓ¿ø |
A/R |
A |
C |
A/R |
ºñÁî´Ï½º ÇÁ·Î¼¼½º ¿À³Ê |
- |
C |
R |
C |
¼ö¼® ¼³°èÀÚ |
C |
R |
R |
C |
°³¹ß ºÎ¼Àå |
C |
C |
R |
C |
IT ÇàÁ¤ ºÎ¼Àå |
R |
C |
- |
- |
PMO |
- |
- |
A/R |
C |
±âÈ£: R: ¼öÇàÃ¥ÀÓ, A: ÃÑ°ýÃ¥ÀÓ, C: Á¶¾ð, I: Á¤º¸ |
¿øõ: IT °Å¹ö³Í½º Çùȸ, COBIT 4.1, 2007 |
¸¶Âù°¡Áö·Î, IT °ü¸® ¼º¼÷µµ ¼öÁصµ °í·ÁµÇ¾î¾ß ÇÑ´Ù. ¼öÁØÀÌ ³·´Ù¸é, IT¸¦ °ü¸®Çϱâ À§ÇØ ÇÏµå ¹× ¼ÒÇÁÆ® ÆÄ¿ö ¸ðµÎ¸¦ »ç¿ëÇÒ ÇÊ¿ä°¡ ÀÖÀ» °ÍÀ̸ç, ¹Ý¸é¿¡ º¸´Ù ³ôÀº ¼º¼÷µµ ¼öÁØÀ̶ó¸é ¼ÒÇÁÆ® ÆÄ¿ö¸¸À» »ç¿ëÇÒ ¼ö ÀÖ´Ù. ÀÌ¿¡ °üÇؼ, ºñÁ¸Àç(0)ºÎÅÍ ÃÖÀûÈ(5)±îÁö ¼º¼÷µµ¸¦ ¸Å±â´ÂCOBITÀÇ ¼º¼÷µµ ¸ðµ¨Àº IT °ü¸® ¼öÁصéÀ» Â÷º°ÈÇϱâ À§ÇÏ¿© ¿Ã¹Ù¸¥ ÆÄ¿ö µµ±¸µéÀ» ½Äº°Çϱâ À§ÇÑ À¯¿ëÇÑ ÁöħÀ» Á¦°øÇÑ´Ù.
°á·Ð
¡°°Å¹ö³Í½º¡±ÀÇ ¾î¿øÀº (¶óƾ¾î gubernare, ±×¸®½º¾î kybernan ¿¡¼ ¿Â) ¡°ÀÏÁ¤¹æÇâÀ¸·Î ³ª¾Æ°¡°Ô ÇÏ´Â °Í to steer¡± ÀÌ´Ù. ±×°ÍÀº À繫 ¹× Àλ翡 ´ëÇÏ¿©¼ ȸ»ç ±×·ìÀ» Çϵå ÆÄ¿ö¸¸À¸·Î ÅëÄ¡ÇÏ´Â °ÍÀ» ÀǹÌÇÏÁö ¾Ê´Â´Ù.
Çϵå ÆÄ¿ö¿¡ ´õÇÏ¿©, ±â¾÷ ÃÑ°ý º»ºÎ´Â ¼¼°è °÷°÷ÀÇ ±×·ì³» ¸ðµç ȸ»çµéÀ» ¸ÅȤ½ÃÅ°°í µ¿Âü½Ãų ¼ö ÀÖ´Â ¼ÒÇÁÆ® ÆÄ¿ö¸¦ °¡Á®¾ß¸¸ ÇÑ´Ù. ÀÌ·¸°Ô Á¶ÇÕµÈ ÆÄ¿ö´Â ÁøÁ¤ÇÑ °Å¹ö³Í½º¸¦ Á¦°øÇÏ°í ±×¸®°í IT °ü¸®¿¡µµ Àû¿ëÇÒ ¼ö ÀÖ´Ù.
IT Àü·«, °Å¹ö³Í½º ÀüÇü ±×¸®°í ¼º¼÷µµ¿¡ ±âÃÊÇؼ, COBIT 34°³ ÇÁ·Î¼¼½º¿¡¼ ÃßÃâÇÑ ÇÏµå ¹× ¼ÒÇÁÆ® IT °Å¹ö³Í½º »ç·ÊµéÀº º¸´Ù È¿°úÀûÀÌ°í È¿À²ÀûÀÎ ±Û·Î¹ú IT °Å¹ö³Í½º¸¦ ½ÇÇöÇϱâ À§ÇÏ¿© ¼·Î °áÇÕµÉ ¼ö ÀÖ´Ù.
References
- Nikkei BP, ¡°Global Information Technology Management,¡± 2009
- International Accounting Standards Board (IASB), International Financial Reporting Standards (IFRS)
- Committee of Sponsoring Organizations of the Treadway Commission (COSO), Internal Control—Integrated Framework
- The Institute of Internal Auditors, ¡°GAIT Methodology, Guide to the Assessment of IT Risk,¡± August 2007
- Office of Government Commerce (OGC), Information Technology Infrastructure Library (ITIL) Version 3, 2008
- Project Management Institute (PMI), Project Management Body of Knowledge (PMBOK), 3rd Edition, 2004
- International Institute of Business Analysis (IIBA), Business Analysis Body of Knowledge (BABOK), Version 2, 2008
- Hitachi Ltd., ¡°JP1/Automatic Job Management System,¡± 2009
- Hitachi Ltd., ¡°Open Middleware Report Web: Vol.47— Supporting Hitachi Group IT Governance,¡± 2009
- Hubbard, Larry; Control Self-Assessment, The Institute of Internal Auditors, 2000
- Nitobe, Inazo; Bushido: The Soul of Japan, 1969
- Powell, Colin L.; Joseph E. Persico; My American Journey, 2003
- Shultz, George P.; William J. Perry; Henry A. Kissinger; Sam Nunn; ¡°A World Free of Nuclear Weapons,¡± The Wall Street Journal, January 2007
- Carr, Nicholas G.; Does It Matter? Information Technology and the Corrosion of Competitive Advantage, 2004
- Masaki, Akira; What Is Mandala?, NHK books, 2007
- De Haes, Steven; Wim Van Grembergen, ¡°Moving From IT Governance to Enterprise Governance of IT,¡± ISACA Journal, vol. 3, 2009
- IT Governance Institute, Val IT, 2006-2008, www.isaca.org/valit
- The Institute of Internal Auditors, GTAG (Global Technology Audit Guide) Change and Patch Management Controls: Critical for Organizational Success, 2005
Endnotes
1 Committee of Government Oversight and Reform, ¡°Testimony of Dr. Alan Greenspan,¡± 23 October 2008
2 Nye, Joseph S. Jr.; Soft Power: The Means to Success in World Politics, 2004
3 IT Governance Institute, COBIT 4.1, USA, 2007, www.isaca.org/cobit
4 Ibid., Nye 2004
5 Nye, Joseph S. Jr.; The Powers to Lead, 2008
6 Weill, Peter; Jeanne W. Ross; IT Governance, 2004
Kazuhiro Uehara, CGEIT, CISA, CIA, PMP
is a consulting manager specialized in IT management and IT governance at the Hitachi Consulting Co. Ltd. Uehara is vice chairman of the ISACA Tokyo Chapter¡¯s Research Board, a coleader of the chapter¡¯s ISACA Journal reading session, and contributes to translation reviews for the ISACA Tokyo chapter and ITGI Japan. He can be reached at kuehara@hitachiconsulting.co.jp.
Sayaka Akino, CISA
is a member of the Tokyo Chapter¡¯s ISACA Journal reading session and contributes to translation reviews for the ISACA Tokyo Chapter. At Hitachi Ltd., she has been working for the Hitachi¡¯s global IT management group. She can be reached at sayaka.akino.kt@hitachi.com.