¸ðµç È·ÁÇÑ °ÍÀº ¾îµÎ¿î ³»¸éÀ» °¡Áö°í ÀÖ´Ù:
Ŭ¶ó¿ìµå ÄÄÇ»ÆÃ, ¹ý±Ô ±×¸®°í µ¥ÀÌÅÍ º¸¾È À§Çè¿¡ °üÇÑ ÀÔ¹®
By Carl Cadregari, CISA, and Alfonzo Cutaia, Esq
ISACA Journal Volume 3, 2011
²÷ÀÓ¾øÀÌ º¯ÈÇÏ´Â °æÁ¦Àû ±×¸®°í ±Ô¹üÀû ºÐÀ§±â ¼Ó¿¡¼, ºñÁî´Ï½º ¿å±¸µµ ±×·¯ÇÑ ºÐÀ§±â¸¸ÅÀ̳ª ºü¸£°Ô º¯ÇÒ ¼ö ÀÖ´Ù. Á¶Á÷µéÀº ¼öÆò¼± À§ÀÇ Æødz¿ì¿¡µµ ÀûÀÀÇÒ ¼ö ÀÖÀ» ¸¸Å ¹ÎøÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. ¿¹»ê»ó Á¦¾à°ú ´Ã¾î³ª´Â ±ÔÁ¦ Áؼö À̴ϼÅƼºêµéÀº Á¶Á÷À¸·Î ÇÏ¿©±Ý ÀÏ»óÀû ¿ä±¸µé¿¡ ´ëÇÑ ´ë¾ÈÀ» ãµµ·Ï °¿äÇÏ°í ÀÖ´Ù.
ÇÑ°¡Áö ´ë¾È: Ŭ¶ó¿ìµå ÄÄÇ»ÆÃ
±×·¯³ª, Ŭ¶ó¿ìµå ÄÄÇ»Æà ÀÌ¿ëÀº ºñÁî´Ï½º¿¡ ¾î¶»°Ô ¿µÇâÀ» ¹ÌÄ¡´Â°¡? ±â¾÷Àº ¸Å¿ì ¹Î°¨ÇÑ ºñÁî´Ï½º ¹× °í°´ Á¤º¸ÀÇ ¼Õ½Ç ±×¸®°í ÀáÀçÀûÀ¸·Î À̾îÁö´Â ¹ú±Ý, Á¦Àç ±×¸®°í ¼Ò¼ÛÀ» ¾î¶»°Ô °ßµ®³¾ °ÍÀΰ¡?
¡°Å¬¶ó¿ìµå ÄÄÇ»Æá±Àº ÃÖ±Ù ¸¹ÀÌ Á¢ÇÏ°Ô µÇ¸é¼ È¥¶õÀ» ÃÊ·¡ÇÏ´Â ¿ë¾îÀÌ´Ù. ¡°Å¬¶ó¿ìµå cloud¡±´Â IT Á¶Á÷µéÀÌ 1990³â´ëÀÇ Åë½Å ¾÷°è¿¡¼ ºô·Á¿Â ¿ë¾îÀÌ´Ù. ±×°ÍÀº ¿ÀÈ÷·Á Á¤¹Ð °úÇÐ(¼öÇÐ ¶Ç´Â ¹°¸®ÇÐ °°Àº)º¸´Ù Æø³ÐÀº °³³äÀÌ´Ù. °¡Àå ºÐ¸íÇÑ(±¤¹üÀ§ÇÑ) Àǹ̷Π±×¸®°í ÀÌ·ÐÀûÀ¸·Î, Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀº ÄÄÇ»Æà ÀÚ¿øÀÇ °Å´ëÇÑ ÁýÁßÈÀÌ´Ù. ÀÌ·¯ÇÑ ÁýÁßÈ·Î, Á¤º¸, ÇÁ·Î¼¼½Ì ±×¸®°í ¼ÒÇÁÆ®¿þ¾î°¡ ÀϹÝÀûÀ¸·Î ¸Ö¸® ¶³¾îÁ® ÀÖÀ¸¸ç µ¶¸³ÀûÀ¸·Î ÅëÁ¦µÇ´Â Ŭ¶ó¿ìµå¿¡ Á¢¼ÓÇÔÀ¸·Î½á ´Ù¼öÀÇ È¸»ç, »ç¿ëÀÚ ±×¸®°í ¼ºñ½º¿¡ ÀÌ¿ëµÉ ¼ö ÀÖ´Ù. °¡»óȸ¦ Æ÷ÇÔÇÑ ½Å±â¼úÀÇ ÀÌ¿ëÀ¸·Î, »õ·Î¿î ÄÄÇ»ÅÍ ÀÚ¿øµéÀº Ãß°¡ ÀÚ¿øÀ» ÇÊ¿ä·Î ÇÏ´Â Á¶Á÷µé¿¡ ÀÇÇØ ºü¸£°Ô °ø±ÞµÉ ¼ö ÀÖ´Ù.
¾ÆÀÌ·¯´ÏÇÏ°Ôµµ, Áß¾ÓÁýÁß ÄÄÇ»Æ×ÇÁ·Î¼¼½Ì ÆÄ¿ö¸¦ Á¦°øÇÏ´Â Áß¾Ó¿¡ À§Ä¡ÇÑ ¸ÞÀÎÇÁ·¹ÀÓ ÄÄÇ»ÅÍ¿Í Àú±ÞÀÇ Ã³¸® ´É·ÂÀ» Áö´Ñ ¡°´õ¹Ì Å͹̳Î(dumb terminals)¡±ÀÌ ¿ø°Å¸®¿¡¼ ¸ÞÀÎÇÁ·¹ÀÓ¿¡ ¿¬°áµÇ¾î ÀÖ´Ù—Àº ÃÖÃÊÀÇ ÄÄÇ»Æà ¸ðµ¨À̾ú´Ù. ÄÄÇ»Æà ¸ðµ¨Àº ½Ã°£ÀÌ Áö³ª¸é¼ ÇÁ·Î¼¼½Ì ´É·ÂÀÌ »ó´ëÀûÀ¸·Î ½ÎÁ®¼, Ŭ¶óÀ̾ðÆ®-¼¹ö ¸ðµ¨·Î ¹Ù²î¾ú´Ù—¿©°ÍÀº ±âº»ÀûÀÎ ±â´É(¿¹¸¦ µé¸é, ÆÄÀÏ ÀúÀå, ÇÁ¸°Æ® Å¥ °ü¸®)À» ¼öÇàÇÏ´Â ¼·Î Á÷Á¢ ¿¬°áµÇ¾î ÀÖ´Â ÀÏ·ÃÀÇ ¼¹öµéÀÌ ÀÖ°í, ±×¸®°í ´ëºÎºÐÀÇ ÄÄÇ»Æà ÆÄ¿ö´Â ³×Æ®¿öÅ©ÀÇ °¡ÀåÀÚ¸®¿¡ Á¸ÀçÇÏ´Â ·¦Åé°ú µ¥½ºÅ©Å¾ ÄÄÇ»ÅÍ·Î À̵¿µÇ¾ú´Ù. ÀÌÁ¦ ÀÎÅͳÝÀÇ ÆíÀ缺, ±× Àü¿¡´Â µµ´ÞÇÒ ¼ö ¾ø¾ú´ø µ¥ÀÌÅÍ Àü¼Û ¼ÓµµÀÇ ÀÌ¿ë ±×¸®°í (Åë½Å) ´ë¿ªÆøÀÇ ¿©À¯ µîÀ¸·Î µ¥ÀÌÅÍ¿Í ÇÁ·Î¼¼½Ì À̵¿ÀÌ ºñ±³Àû Àú·ÅÇØÁ³À¸¸ç, ±×¸®°í Ŭ¶ó¿ìµå Á¦°øÀÚÀÇ °·ÂÇÑ ÄÄÇ»Å͵éÀº º¸´Ù Áß¾ÓÁýÁᫎ ÄÄÇ»Æà ¸ðµ¨·ÎÀÇ È¸±Í·Î À̲ö´Ù.
ÄÄÇ»Æà ¸ðµ¨·Î½á´Â Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀº À¯¾Æ±â¿¡ ¸Ó¹°·¯ ÀÖÀ¸³ª, ¸î¸î Ŭ¶ó¿ìµå °³³äµéÀº ³Î¸® »ç¿ëµÇ°í ÀÖ´Ù. µ¥ÀÌÅÍ ÇÁ·Î¼¼½Ì »ç¾÷Àº ¼ºñ½º·Î½á ¼ÒÇÁÆ®¿þ¾î(Software as a Service : SaaS)¿Í ¾ÖÇø®ÄÉÀÌ¼Ç ¼ºñ½º Á¦°øÀÚ(application service providers : ASP)¸¦ Æ÷ÇÔÇÑ ¾ÖÇø®ÄÉÀÌ¼Ç È£½ºÆÃ; Ŭ¶ó¿ìµå ½ºÅ丮Áö¿Í ¿Â¶óÀÎ ¹é¾÷À» Æ÷ÇÔÇÏ´Â ½ºÅ丮Áö °¡»óÈ; IT ¾Æ¿ô¼Ò½Ì(ITO); ±×¸®°í ÇïÇÁµ¥½ºÅ©, °¡»ó µ¥ÀÌÅÍ ¼¾ÅÍ ±×¸®°í È£½ºÆ¼µå (Ç÷§Æû) µ¥ÀÌÅÍ ¼¾Å͸¦ Æ÷ÇÔÇÏ´Â ºñÁî´Ï½º ÇÁ·Î¼¼½º ¾Æ¿ô¼Ò½Ì(BPO)¿Í °°Àº Ŭ¶ó¿ìµå ÄÄÇ»Æà ¿ë¾î ¹× °³³äµé¿¡ Á¡Á¡ Àͼ÷ÇØÁö°í ÀÖ´Ù. ±×·¸Áö¸¸, ÀÌ·¯ÇÑ Ä£±Ù°¨¿¡µµ ºÒ±¸ÇÏ°í, ÀÚ¿øÀÇ ÁýÁßÈ¿Í °øÀ¯·Î ÀÎÇÑ ÆóÇØÀÇ °¡´É¼ºÀÌ Å¬¶ó¿ìµå ÄÄÇ»Æÿ¡ ´ëÇÑ ºñÁî´Ï½ºÀû ÀÌÀÍÀ» ¼ø½Ä°£¿¡ Ãß¿ùÇÒ ¼ö ÀÖ´Â ¼öÁرîÁö Ä¿Áö°í ÀÖ´Ù. Ŭ¶ó¿ìµå ¼Ö·ç¼Ç È°¿ëÀ» ÁÖ½ÃÇÏ°í ÀÖ´Â ¸ðµç Á¶Á÷µéÀÌ ±×·¯ÇÑ ³ë·ÂÀ» ÅëÇØ ¼º°øÇÏ°í, ³ª¾Æ°¡¼´Â ¹øâÇϱâ À§Çؼ´Â ±×·¯ÇÑ À§ÇèÀ» ¹Ýµå½Ã ÀÌÇØÇÏ¿©¾ß¸¸ ÇÑ´Ù.
¸¸´ÉÀÇ Å¬¶ó¿ìµå—ÃøÁ¤ÇÒ ¼ö ÀÖ´Â º¸»ó
Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀ» ÀÌ¿ëÇÏ´Â ÀÕÁ¡Àº ¸Å¿ì ¸¹´Ù. 1 Ŭ¶ó¿ìµåÀÇ °øÀ¯ ¼ºÁú°ú Ŭ¶ó¿ìµå Á¦°øÀÚÀÇ °Å´ëÇÑ ±Ô¸ð´Â °í°´µé·Î ÇÏ¿©±Ý º¯ÈÇÏ´Â ¼ö¿ä¸¦ ÃæÁ·½ÃÅ°±â À§ÇÏ¿© ÀÚ±âµéÀÇ ½Ã½ºÅÛµéÀ» À绡¸® ±×¸®°í ¼Õ½±°Ô ´ÃÀ̰ųª ÁÙÀÏ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù. ÀÌ°ÍÀº ÇÇÅ© ŸÀÓ¿¡µµ ¼ö¿ë°¡´ÉÇÑ ¼º´ÉÀ» º¸ÀåÇϱâ À§ÇÏ¿© ¼³°èÀÚµéÀÌ À̵û±Ý °úµµÇÑ ¿ë·®À» ¼³°èÇϵµ·Ï ¸¸µå´Â ÀüÅëÀûÀΠŬ¶óÀ̾ðÆ®-¼¹ö ¹èÄ¡ÀÇ ºñÈ¿À²¼ºÀ» ÁÙÀδÙ. ¶ÇÇÑ, ¸¹Àº Ŭ¶ó¿ìµå ±â¹Ý ½Ã½ºÅÛµéÀº »ç¿ëÀÚµéÀÌ À¥ ºê¶ó¿ìÀú¿¡¼, ½ÉÁö¾î´Â ÃֽŠ½º¸¶Æ®ÆùÀ̳ª ÅÂºí¸´ Ç÷§Æû¿¡¼ Á¶Â÷ Á¤º¸¿¡ Á¢±ÙÇÒ ¼ö ÀÖµµ·Ï ÇÏ°í, ±×¸®°í »ç¿ëÀÚ °¢ÀÚ°¡ ÀÌ¿ëÇÏ´Â ÀÚ¿øÀÇ ¿ë·®ÀÌ ½Ã½ºÅÛÀÇ È¿À²¼ºÀ» ±Ø´ëÈÇϱâ À§ÇÏ¿© ¸ð´ÏÅ굃 ¼ö ÀÖ´Ù.
Ŭ¶ó¿ìµå ±â¹Ý ½Ã½ºÅÛµéÀ» ¹èÄ¡ÇÑ ±â¾÷Àº Çϵå¿þ¾î¿Í ÀÚ»êÀ¸·Î ÀâÈ÷´Â ¼ÒÇÁÆ®¿þ¾î(¿ªÀÚ ÁÖ: º¸Åë °³¹ßºñ(+alpha) ¸¸ÅÀ» ¹«ÇüÀÚ»êÀ¸·Î ÀνÄÇÏ¿©, °¨°¡»ó°¢ ó¸®ÇÔ)¿¡ ´ëÇÑ ÀÚº» ÁöÃâÀ» ÇÇÇÒ ¼ö ÀÖ´Ù. ¼Ò±Ô¸ð ±â¾÷ °í°´µéµµ ½Ã½ºÅÛ °ü¸®ÀÚ, ¹é¾÷ ÀÎÇÁ¶ó±¸Á¶ ±×¸®°í ³×Æ®¿öÅ© ÀÎÇÁ¶ó±¸Á¶¿Í °°Àº °ªºñ½Ñ ÀÚ¿øµé¿¡ ´ëÇÏ¿© º¹¼öÀÇ °í°´À¸·Î ÀÎÇØ Å¬¶ó¿ìµå Á¦°øÀÚÀÇ ±Ô¸ðÀÇ °æÁ¦·ÎºÎÅÍ ÀÌÀÍÀ» ¾òÀ» ¼ö ÀÖ´Ù. ¸ðµÎ ÀÎÇÁ¶ó±¸Á¶°¡ ÀüÇüÀûÀ¸·Î Á¦ 3ÀÚ¿¡ ÀÇÇØ Á¦°øµÇ°í ¶ÇÇÑ ÀÏȸ¼º ȤÀº ¾ÆÁÖ µå¹°°Ô ¹ß»ýÇÏ´Â Áý¾àÀûÀÎ ÄÄÇ»Æà ¾÷¹«¸¦ À§Çؼ ±¸¸ÅÇÒ ÇÊ¿ä°¡ ¾ø±â ¶§¹®¿¡ ÀÌ·¯ÇÑ ºÐ¾ß´Â ¿Ü°ü»óÀ¸·Î ÁøÀÔÀ庮ÀÌ ³·¾ÆÁú ¼ö ÀÖ´Ù.
Ŭ¶ó¿ìµåÀÇ ¾îµÎ¿î ¸é
Á¶Á÷ÀÇ Á¤º¸¿¡ ´ëÇØ ÅëÁ¦µÇÁö ¾Ê°Å³ª ¹Ì¸® ³»´Ùº¼ ¼ö ¾ø´Â À§Çè ¹× À§ÇùÀÌ °¡ÇØÁú ±Ø´ÜÀûÀÎ °¡´É¼ºÀ¸·Î ÀÎÇØ Å¬¶ó¿ìµåÀÇ ÀÕÁ¡Àº »ó¼âµÈ´Ù. ±â¾÷Àº µ¥ÀÌÅ͸¦ Ŭ¶ó¿ìµå·Î ¿Å±â±â Àü¿¡ ¹Ýµå½Ã ¸ðµç À§ÇèÀ» öÀúÈ÷ Æò°¡ÇÏ°í ÀÌÇØÇÏ°í ¿ÏȽÃÄѾ߸¸ ÇÑ´Ù.
»ç¾÷À» ¿µÀ§Çϴµ¥ ÇÊ¿äÇÑ Á¤º¸´Â ¶§·Î´Â À¯ÇüÀÇ, ¶§·Î´Â ¹«ÇüÀÇ °¡Ä¡°¡ ÀÖ´Â ÀÚ»êÀÌ´Ù. º¸À¯ÇÏ°í ÀÖ´Â µ¥ÀÌÅÍ ¹× Á¤º¸°¡ ±â¾÷¿¡ ¹«½¼ °¡Ä¡°¡ Àִ°¡? ±×°ÍÀº »çÀ̹ö ¹üÁËÀڵ鿡°Ô´Â ¾ó¸¶ ¸¶ÇÑ °¡Ä¡°¡ Àִ°¡? ÇØÄ¿´Â Á¤º¸¸¦ °¡Áö°í ¹«¾ùÀ» Çϴ°¡? ±â¾÷Àº ´Ù¸¥ ȸ»ç°¡ ¿ì¿¬È÷ ÀÚ½ÅÀÇ µ¥ÀÌÅÍ¿¡ Á¢±ÙÇÏ°í º¯°æÇÑ´Ù¸é ¾ó¸¶ ¸¸ÇÑ ¼ÕÇØÀΰ¡? ÀÒ¾î¹ö¸®°Å³ª Ŭ¶ó¿ìµå Á¦°øÀÚ°¡ ÀçÇظ¦ ´çÇØ ±â¾÷ ÀÚ½ÅÀÇ Á¤º¸¿¡ Á¢±ÙÀÌ ºÒ°¡´ÉÇÏ´Ù¸é ±â¾÷Àº ¾î¶»°Ô ÇÒ °ÍÀΰ¡? ´©±º°¡ ÀÚ½ÅÀÇ µ¥ÀÌÅ͸¦ º¯°æÇÑ´Ù¸é ±× »ç½ÇÀ» ¾î¶»°Ô ¾Ë ¼ö Àִ°¡? ÀÚ±âÀÇ µ¥ÀÌÅÍ°¡ ³ëÃâµÈ´Ù¸é ±â¾÷Àº ¹«¾ùÀ» ¹ýÀ¸·Î ó¸®ÇÒ °ÍÀΰ¡?
º¸¾È Ãë¾à¼º°ú µ¥ÀÌÅÍ ¼Õ½Ç »ç°í´Â Á¤±âÀûÀ¸·Î ÀϾÙ. 2010³â¿¡, µ¥ÀÌÅͺ긮ġ³Ý, ¹Ì¿¬¹æ¼ö»ç±¹(FBI), ÄÄÇ»Åͺ¸¾ÈÇùȸ(CSI) ±×¸®°í ÀÌ·± »ç°íµéÀ» ÃßÀûÇÏ´Â ±âŸ ´Ù¸¥ Á¶Á÷µé¿¡ µû¸£¸é, ¼öõ¾ï °³ÀÇ ·¹ÄÚµå À¯Ãâ »ç°í·Î ½Å¹®¿¡ º¸µµµÈ ÁÖ¿ä »ç°í¸¸µµ ¼ö¹é °ÇÀ̳ª µÈ´Ù. ÀÌÁ¦ »çÀ̹ö ¹üÁË´Â (ÀÏ»óÀûÀ¸·Î ÇàÇØÁö´Â) »î ÀÚü¶ó´Â »ç½ÇÀ» ±ú´ÝÁö ¾ÊÀ¸¸é ½Å¹®À» ÆîÄ¥ ¼öµµ ÀÎÅÍ³Ý ±â»ç¸¦ ÀÐÀ» ¼öµµ ¾ø´Â °ÍÀÌ Çö½ÇÀÌ´Ù—¿¹¸¦ µé¸é, ALDI, 5 T.J.Maxx, 6 ÇÏÆ®·£µå°áÁ¦½Ã½ºÅÛÁî, 7 ¹Ì±¹ ÀçÇⱺÀÎȸ, 8 Ben & Jerry¡¯s,9 and PETCO,10 µî¿¡ ±¦ÂúÀ¸´Ï È®ÀÎÇØ º¸½Ê½Ã¿À. °á·ÐÀº Ŭ¶ó¿ìµå Á¦°øÀÚ¸¦ ÀÌ¿ëÇÏ´Â °ÍÀº º¸¾È »ç°íÀÇ À§ÇèÀ» »ó´çÈ÷ ³ôÀÏ ¼ö ÀÖ°í µ¥ÀÌÅÍ À¯Ãâ¿¡ µû¸£´Â ¸ðµç ºñ¿ë, ¹ýÀû Á¦Àç ±×¸®°í ±âŸ ¼ÕÇØ µîÀÌ »ó´çÈ÷ Áõ°¡ÇÒ ¼ö ÀÖ´Ù. ±×·¸Áö¸¸, ³ô¾ÆÁø »ç°í ¹ß»ý À§Çè¿¡ ´õÇÏ¿©, »ç°í ¹ß»ýÀ» È®ÀÎÇÏ°í »ç°í ¼ö½ÀÀ» À§ÇÑ ºñ¿ëÀº Ŭ¶ó¿ìµå ÄÄÇ»Æà ÀÚüÀÇ Ãß»óÀû ¼ºÁú¿¡ ÀÇÇØ ´Ã¾î³¯ ¼ö ÀÖ´Ù.
µ¥ÀÌÅÍ, ±×¸®°í ±×¿¡ ´ëÇÑ Á¢±ÙÀº ±â¾÷ÀÇ Áö¼ÓÀûÀÎ ¿ÀÆÛ·¹ÀÌ¼Ç ±×¸®°í ƯÈ÷ ¼ºñ½º¸¦ Á¦°øÇÏ´Â °í°´¿¡°Ô´Â ½ÇÁúÀûÀÎ °¡Ä¡°¡ ÀÖ´Ù. À̵û±Ý, ÇØ´ç Á¤º¸¸¦ ÈÉÃļ Á¶ÀÛÇϰųª ½Å¿ëÀ» ¶³¾î¶ß¸®°í ½Í¾îÇÏ´Â ¾î¶°ÇÑ »ç¶÷, ±â¾÷, ½ÉÁö¾î ±¹°¡¸¦ À§Çؼ´Â ±×·¯ÇÑ µ¥ÀÌÅÍ°¡ ÃæºÐÈ÷ °¡Ä¡°¡ ÀÖ´Ù´Â Á¡Àº ºÐ¸íÇÑ »ç½ÇÀÌ´Ù. ±â¾÷¿¡ ´ëÇÑ Çù¹Ú¿ëÀ¸·Î ÀÌ¿ëÇÏ´Â »çÀ̹ö¹üÁËÀÚ¿¡°Ô ÇØ´ç µ¥ÀÌÅÍ´Â ¾ó¸¶³ª ¸¹Àº °¡Ä¡°¡ Àִ°¡? °ø°ÝÀÚµéÀº ÀڽŵéÀÇ À§ÇèÀ» ±× Á¤º¸¸¦ ¾ò´Â °Í¿¡ ´ëÇÑ º¸»óÀ¸·Î °£ÁÖÇÑ´Ù. Ŭ¶ó¿ìµå¸¦ ÀÌ¿ëÇÒ ¶§, ´ÙÀ½ÀÇ Áú¹®ÀÌ °¡´ÉÇÏ´Ù: ¼ö½Ê ȤÀº ¼ö¹é °³ÀÇ ¿©·¯ ±â¾÷µéÀÇ Áß¾ÓÁýÁß µ¥ÀÌÅÍ°¡ ¾î´À ÇÑ °³ ±â¾÷ÀÇ À§Çù »çÅ°¡ ¾î¶»°Ô ÀÛ¿ëÇϴ°¡? ´Ü¼øÇÑ »ç½ÇÀº Ŭ¶ó¿ìµå ¼Ó¿¡ µ¥ÀÌÅ͸¦ ³Ö¾îµÐ ºñÁî´Ï½º´Â ±×·¯ÇÑ µ¥ÀÌÅÍ°¡ ½ÇÁúÀûÀ¸·Î º¸°üµÇ¾î ÀÖ´Â Àå¼Ò¿¡ ´ëÇÏ¿© Àý´ëÀûÀ¸·Î ¾î¶°ÇÑ Á÷Á¢ÀûÀÎ ÅëÁ¦µµ °®°í ÀÖÁö ¾Ê´Ù´Â Á¡ÀÌ´Ù. ¿ª½Ã, Ç¥ÁØ ¼ºñ½º ¼öÁØ Çù¾à(standard SLAs)µµ Å©°Ô µµ¿òÀÌ µÇÁö ¾Ê´Â´Ù—¼³·É µµ¿òÀÌ µÉÁö¶óµµ, Ŭ¶ó¿ìµå Á¦°øÀÚµéÀº ÀÚ±âµé °í°´µéÀ» À§ÇÑ º¸¾È, °¡¿ë¼º ¶Ç´Â ÀÀ´ä½Ã°£À» º¸ÁõÇϱâ À§Çؼ Å©°Ô ÇÏ´Â ÀÏÀÌ °ÅÀÇ ¾øÀ» °ÍÀÌ´Ù. ´ëºÎºÐÀÇ SLAs´Â ºñÁî´Ï½º ¿À³ÊµéÀ» À§ÇÏ¿©, ƯÈ÷ ¹ýÀûÀΠåÀÓ¿¡ ´ëÇÏ¿©¼´Â, È®½ÇÇÑ º¸ÀåÀ» Á¦°øÇÏÁö ¾Ê±â À§ÇÑ Ä¿´Ù¶õ ½Ã°£Àû ¿©À¯¿Í ÃÖ¼±ÀÇ ³ë·Â ¿ïŸ¸®(¿ªÀÚÁÖ: ÃÖ¼±À» ´ÙÇÏ¸é ¸éÃ¥À» ¹ÞÀ» ¼ö ÀÖ´Ù´Â Á¶Ç×)¸¦ ³¢¿ö ³Ö´Â´Ù. ¾ðÁ¦ Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀ» ±âȹÇϵçÁö, µ¥ÀÌÅÍ´Â °ËÅäµÉ ÇÊ¿ä°¡ ÀÖÀ¸¸ç, ±×¸®°í Ŭ¶ó¿ìµå º¸¾È ¿¬ÇÕȸ¿¡¼ ¸¸µç ÃÖ¼ÒÇÑ ´ÙÀ½ 6°¡Áö Áú¹®¿¡ ´ëÇÏ¿©´Â ´äº¯ÀÌ µÇ°í Á¤ÀǵǾî¾ß ÇÒ ÇÊ¿ä°¡ ÀÖ´Ù:
1. ÀÚ»êÀÌ ³Î¸® °ø°³µÇ°í ³Î¸® ¹èÆ÷µÈ´Ù¸é, ±â¾÷Àº ¾ó¸¶³ª ¼ÕÇظ¦ º¼ °ÍÀΰ¡?
2. Ŭ¶ó¿ìµå Á¦°øÀÚÀÇ Á÷¿øÀÌ Àڻ꿡 Á¢±ÙÇÑ´Ù¸é, ±â¾÷Àº ¾ó¸¶³ª ¼ÕÇظ¦ º¼ °ÍÀΰ¡?
3. ÇØ´ç ÇÁ·Î¼¼½º ¶Ç´Â ±â´ÉÀÌ ¿ÜºÎÀο¡ ÀÇÇØ Á¶À۵ȴٸé, ±â¾÷Àº ¾ó¸¶³ª ¼ÕÇظ¦ º¼ °ÍÀΰ¡?
4. ÇØ´ç ÇÁ·Î¼¼½º ¶Ç´Â ±â´ÉÀÌ ±â´ë ¼öÁØ¿¡ ¹ÌÄ¡Áö ¸øÇϸé, ±â¾÷Àº ¾ó¸¶³ª ¼ÕÇظ¦ º¼ °ÍÀΰ¡?
5. Á¤º¸/µ¥ÀÌÅÍ°¡ °©Àڱ⠺¯°æµÈ´Ù¸é, ±â¾÷Àº ¾ó¸¶³ª ¼ÕÇظ¦ º¼ °ÍÀΰ¡?
6. ÀÚ»êÀÌ ÀÏÁ¤ ½Ã°£ µ¿¾È ÀÌ¿ëÇÒ ¼ö ¾ø°Ô µÇ¸é, ±â¾÷Àº ¾ó¸¶³ª ¼ÕÇظ¦ º¼ °ÍÀΰ¡?
Ŭ¶ó¿ìµå¿¡¼ÀÇ ¹ý±Ô Áؼö
¹Ì±¹ ¿¬¹æ Á¤º¸ º¸¾È °ü¸® ¹ý(FISMA Act); ¹Ì±¹ ¿¬¹æ °Ç° º¸Çè À̵¿ ¹× ÃÑ°ýÃ¥ÀÓ ¹ý(HIPAA Act); ¹Ì±¹ °æÁ¦Àû ¹× ÀÓ»óÀû °Ç°À» À§ÇÑ °Ç° Á¤º¸±â¼ú ¹ý(HITECH Act); ¹Ì±¹ ±×·¥ ¸®Ä¡ ºê¸±¸® ¹ý(GLBA; ±ÝÀ¶ ¼ºñ½º Çö´ëȸ¦ À§ÇÑ ¹ý·ü); PCI µ¥ÀÌÅÍ º¸¾È Ç¥ÁØ(PCI DSS); ¹Ì±¹ °¡Á· ±³À° ±Ç¸® ¹× ÇÁ¶óÀ̹ö½Ã ¹ý(FERPA); ¹Ì±¹ ¾Æµ¿ ÀÎÅÍ³Ý º¸È£¹ý(CIPA); ¹Ì±¹ »þº£ÀÎ-¿Á½½¸® ¹ý(SOX Act: ½Å·ÚÇÒ ¼ö ÀÖ´Â À繫º¸°í¸¦ À§ÇÑ ¹ý, ÀÏ¸í ³»ºÎ ÅëÁ¦ ü°è¸¦ ±¸ÃàÇϵµ·Ï ±ÔÁ¤ÇÏ°í ÀÖÀ½); ¹Ì±¹ ¸Þ»çÃß¼¼Ã÷ ¹ý·ü 17.00 ÀÇ 201Á¶·Ê(CMR); ¹Ì±¹ Ķ¸®Æ÷´Ï¾Æ »ó¿ø ¹ý·ü¾È 1386; ¹Ì±¹ ´º¿å Á¤º¸º¸¾È À¯Ãâ ÅëÁö ¹ý(NYISBNA); ¹Ì±¹ ¿¬¹æ ±ÔÁ¦ ŸÀÌƲ 21, ÆÄÆ® 11 Á¶·Ê(21CFR11); ±âŸ µ¥ÀÌÅÍ º¸¾È ¹ý±Ô¸¦ ÁؼöÇϱâ À§ÇÏ¿©, ±â¾÷Àº °¨»ç ¿ä°Ç°ú Á¶Ä¡¸¦ °®Ãç¾ß¸¸ ÇÑ´Ù. ±×·¡¼, ±â¾÷Àº ÀÌ¿ëÇϴ Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÌ ÀڽŵéÀÇ Ã¥ÀÓ°ú Áؼö È°µ¿¿¡ ¾î¶»°Ô ¿µÇâÀ» ÁÖ´ÂÁö¿¡ ´ëÇÑ Ã¶ÀúÇÑ ÀÌÇظ¦ ÇÊ¿ä·Î ÇÑ´Ù. ÀϹÝÀûÀ¸·Î, ´ëºÎºÐÀÇ ¹ý·ü°ú ±ÔÁ¦´Â ±â¾÷ ÀÚ½ÅÀÌ µ¥ÀÌÅÍ¿¡ ¿µÇâÀ» ÁÖ´Â ¹ý·ü°ú ±Ô¹ü¿¡ µû¶ó µ¥ÀÌÅ͸¦ º¸È£Çϱâ À§ÇÑ ±â¾÷ ³»ºÎÀÇ È£½ºÆ® ½Ã½ºÅÛ¿¡ ´ëÇؼ °®Ãç³õÀº °Í°ú ÃÖ¼ÒÇÑ µ¿µîÇϰųª ºñ½ÁÇÑ ÅëÁ¦¸¦ ÀÚ½ÅÀÇ Å¬¶ó¿ìµå Á¦°øÀÚ (ȤÀº ASP, SaaS Á¦°øÀÚ ¹×/¶Ç´Â ¾Æ¿ô¼Ò½Ì È£½ºÆ®)°¡ Áö´Ï°í ÀÖÀ½À» Áõ¸íÇϵµ·Ï ¿ä±¸ÇÏ°í ÀÖ´Ù. ±×·¯¹Ç·Î, ¾î¶² Á¶Á÷ÀÌ Á¤º¸ ¼öÁý Ã¥ÀÓÀ» °®°í¼ Á¶Á÷À¸·ÎºÎÅÍ °³ÀÎ ½Å»ó Á¤º¸¸¦ ¹Þ´Â Ŭ¶ó¿ìµå-±â¹Ý Á¦3ÀÚ ÁöºÒ ÇÁ·Î¼¼¼¸¦ ÀÇÁöÇÏ´Â °ø°ø ȸ»ç¶ó¸é, Ŭ¶ó¿ìµå Á¦°øÀÚ´Â ¹«¾ùÀ» Çؾ߸¸ Çϴ°¡? ±â¾÷Àº ¹«¾ùÀ» Çؾ߸¸ Çϴ°¡? ±×¸®°í µ¥ÀÌÅÍ°¡ ºÐ½Ç, ºÎÀûÀýÇÑ Á¢±Ù ȤÀº ´Ù¸¥ À§Å·οî ÀÏÀ» ´çÇßÀ» ¶§ ¾î¶»°Ô µÇ´Â°¡?
µ¥ÀÌÅÍ À¯ÃâÀÌ ÃÊ·¡ÇÏ´Â ºñ¿ë
¿äÁîÀ½ Àü¼¼°èÀûÀ¸·Î, ¾Ç¿ë µ¥ÀÌÅÍ, µµµÏ¸Â°Å³ª ºÐ½ÇµÈ ÀÚ»ê, ±×¸®°í °íÀÇÀû/ºñ°íÀÇÀû À¯ÃâÀÌ ±Ô¸ð ¹× ÇüÅ¿¡ »ó°ü¾øÀÌ ¸ðµç ȸ»ç¿¡¼ ³î¶ö ¸¸Å ¾î±è¾øÀÌ ¹ß»ýÇÑ´Ù. Æù¸ó Çùȸ(Ponemon Institute )¿¡ ÀÇÇØ ÀÌ·ç¾îÁø »çÀ̹ö ¹üÁËÀÇ ºñ¿ë ¹× ºóµµ¿¡ °üÇÑ ÃÖ±ÙÀÇ Á¶»ç¿¡¼´Â Á¶»ç ´ë»ó ȸ»ç¸¶´Ù ¸ÅÁÖ ÇѹøÀÇ »çÀ̹ö¹üÁ˸¦ °æÇèÇßÀ¸¸ç, ÀÌ·¯ÇÑ °ø°ÝÀ» °ü¸®Çϴµ¥ µå´Â ºñ¿ëÀÌ ¹ÌÈ 3¹é8½Ê¸¸ ´Þ·¯¸¦ ³Ñ¾ú´Ù°í ¹àÇôÁ³´Ù. 12 ±× Á¶»ç´Â ½ÇÁú ºñ¿ëµéÀ» ½±°Ô ¹è°¡½Ãų ¼ö ÀÖ´Â ¹ý±Ô ¹ÌÁؼö ¹ú±Ý, Á¦Àç ±×¸®°í º¯È£»çºñ µîÀ» Á¦¿ÜÇÏ°í »çÀ̹ö ¹üÁËÀÇ Àû¹ß, ȸÇÇ, »ç°í °ü¸® ¹× ÀÚ»ê ¼Õ½Ç ¸¸À» Æ÷ÇÔ½ÃÄÑ ¿µÇâÀ» ¹ÞÀº ´ëºÎºÐÀÇ ºñÁî´Ï½º ºÐ¾ß¿¡¼ÀÇ ºñ¿ëÀ» »ó¼úÇß´Ù. ÃÖ±Ù¿¡ ºÎ°úµÈ ¹ú±ÝÀÇ ÀϺΠ»ç·Ê´Â ´ÙÀ½À» Æ÷ÇÔÇÑ´Ù:
- Rite Aid¢ç—HIPAA À§¹ÝÀ¸·Î ¹ÌÈ ¹é¸¸ºÒ13
- The TJX Companies Inc. (T.J.Maxx°¡ ÀϺΠÁ¶Á÷ÀÓ)— ºÐ½ÇµÈ ½Å¿ë Ä«µå µ¥ÀÌÅÍ¿¡ ´ëÇؼ ¹ÌÈ 4õ9½Ê¸¸ ´Þ·¯14
- Health Net of NE—ºÐ½ÇµÈ ÇÏµå µå¶óÀ̺꿡 ´ëÇؼ ¹ÌÈ 25¸¸ ´Þ·¯ 15
- Six California (USA) hospitals—°³ÀÎÁ¤º¸ À¯Ãâ¿¡ ´ëÇؼ ¹Ì±¹ Ķ¸®Æ÷´Ï¾Æ °øÁßÀ§»ý±¹¿¡ ÀÇÇØ ¹ÌÈ 7½Ê9¸¸ ´Þ·¯ ÀÌ»ó 16
Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÌ ´Ã¾î°¡¸é¼, ±×°ÍÀÇ (À§Çù) ³ëÃâ°ú ¹üÁË È°µ¿¿¡¼ÀÇ ÀÌ¿ëµµ ´Ã¾î³¯ °ÍÀ̹ǷÎ, Ŭ¶ó¿ìµå ¹ýÀÇÇп¡ ´ëÇÑ ¿å±¸°¡ »ý°Ü³¯ °ÍÀÌ´Ù. ÀÌ°ÍÀº ÃÖ±ÙÀÇ µ¥ÀÌÅÍ À¯Ãâ ±â»ç ȤÀº µ¥ÀÌÅÍ À¯Ãâ À¥»çÀÌÆ® »ó¿¡¼ ¸í¹éÇÏ´Ù. ¿¹¸¦ µé¸é, °³¹ß Ç¥ÁØ Àç´Ü¿¡ ÀÇÇØ ¼³¸³µÈ Cloutage.org´Â 2010³â º¸µµµÈ 322°³ÀÇ »ç°í Áß¿¡¼, 54°³ÀÇ È®ÀÎµÈ µ¥ÀÌÅÍ ¼Õ½Ç »ç°í´Â Ŭ¶ó¿ìµå Á¦°øÀÚ°¡ ÇØÅ·´çÇ߰ųª Ŭ¶ó¿ìµå Ãë¾àÁ¡ÀÌ ¹ß°ßµÇ¾ú±â ¶§¹®À̶ó°í ÁÖÀåÇß´Ù. 17
Ŭ¶ó¿ìµå¸¦ º¸ÁõÇϱâ
Ŭ¶ó¿ìµå ÀÚ¿øÀÇ ÀÌ¿ëÀº ¸¹Àº ±â¾÷¿¡ ¸Å¿ì À¯ÀÍÇÒ ¼ö ÀÖ´Ù—±×·¯³ª ±â¾÷Àº Ç×»ó ±×¿¡ µû¸¥ À§Çèµµ ¾Ë¾Æ¾ß ÇÏ°í, Àû´çÇÑ ÀÚ¿ø°ú °¨»ç ¹× ¹ý·üÀû Ä¿¹Â´ÏƼ Ãâ½ÅÀÇ Àü¹®°¡¸¦ È°¿ëÇÏ¿©¾ß ÇÏ°í, ±×¸®°í ´ÙÀ½ÀÇ Áú¹®¿¡ ´äÇÒ Áغñ¸¦ ÇÏ¿©¾ß ÇÑ´Ù:
- º¸¾È
- º¸°ü ¹× À̵¿ ÁßÀÎ µ¥ÀÌÅ͸¦ ¾î¶»°Ô ¾ÏÈ£ÈÇϴ°¡?
- µ¥ÀÌÅÍ¿¡ ´ëÇÑ ºñ½ÂÀÎ Á¢±ÙÀ» ¾î¶»°Ô ¸·À» °ÍÀΰ¡?
- µ¥ÀÌÅ͸¦ ¾î¶»°Ô ¹èÄ¡Çϴ°¡?
- Ŭ¶ó¿ìµå Á¦°øÀÚ ³»ºÎ º¸¾ÈÀÌ ¾î¶»°Ô »ç¿ëµÇ°í ÀÖ´ÂÁö
– ÇàÁ¤°ü¸® ÅëÁ¦
– ¹°¸®Àû ÅëÁ¦
– ³í¸®Àû ÅëÁ¦
- ħÀÔ ´çÇßÀ» °æ¿ì, ±â¾÷Àº ¹«½¼ ±Ç¸®¿Í ´É·ÂÀ» °¡Á®¾ß ÇÏ´Â °ÍÀΰ¡? (¿¹¸¦ µé¸é, °¨»ç±Ç, ¹ýÀÇÇÐ Á¶»ç¸¦ ½Ç½ÃÇÒ ±Ç¸®)
- »ç¿ëÀÚ¿¡°Ô º¸¾È ħÅõ »ç½ÇÀ» ÅëÁöÇϱâ À§Çؼ, Ŭ¶ó¿ìµå Á¦°øÀÚ´Â ¹«½¼ º¸°í Àǹ«¸¦ °¡Á®¾ß Çϴ°¡?
- °ø°ÝÀ» ¿¹¹æÇϱâ À§Çؼ Ŭ¶ó¿ìµå Á¦°øÀÚ´Â ¾î¶² Á¶Ä¡¸¦ ÃëÇØ¾ß Çϴ°¡?
- ±â¾÷ÀÌ (Ŭ¶ó¿ìµå ÀÚ¿øÀ») Á¸ÀçÇϱâ À§Çؼ, Ŭ¶ó¿ìµå Á¦°øÀÚ´Â ¹«½¼ ¹æ¾î¸¦ ÇÊ¿ä·Î Çϴ°¡?
- Ŭ¶ó¿ìµå Á¦°øÀÚ´Â ÀÚ½ÅÀÇ º¸¾È ÀýÂ÷¸¦ ¹ÏÀ» ¼ö ÀÖµµ·Ï ¾î¶»°Ô °í°´¿¡°Ô º¸¿©ÁÖ°í ¼ÒÅëÇϴ°¡?
- Ŭ¶ó¿ìµå Á¦°øÀÚ´Â (°í°´À¸·Î ÇÏ¿©±Ý) °í°´ ÀÚ½ÅÀÇ º¸Áõ ÀýÂ÷¸¦, °¡·É º¸¾È ½ºÄ³´× ȤÀº °¨»ç, ÀÌÇàÇϱâ À§ÇØ °í°´¿¡°Ô ¾ó¸¶³ª ¸¹Àº ´É·ÂÀ» ºÎ¿©Çϴ°¡?
- Ŭ¶ó¿ìµå Á¦°øÀÚ´Â µ¥ÀÌÅÍ ÇÁ¶óÀ̹ö½Ã¿¡ °üÇÑ ÁßøµÇ°Å³ª ¸ð¼øµÈ (¹Ì±¹) ÁÖµéÀÇ ¹ý±ÔµéÀ» ¾î¶»°Ô Á¶Á¤Çϴ°¡
- Áؼö
- Ŭ¶ó¿ìµå Á¦°øÀÚ´Â ¹«½¼ ÄÄÇöóÀ̾𽺠ǥÁØÀ» µû¶ó¾ß Çϴ°¡?
- Ŭ¶ó¿ìµå·Î À̵¿Çϱâ ÀÌÀü, ÀÌÀüÇÏ´Â µ¿¾È ±×¸®°í ÀÌÀü ÀÌÈÄ¿¡ Áؼö°¡ ¾î¶»°Ô À¯ÁöµÇ´Â°¡?
- ÄÄÇöóÀ̾𽺸¦ º¸ÁõÇϴµ¥ ¾î¶°ÇÑ 3ÀÚ º¸Áõ(¿¹¸¦ µé¸é, SAS 70, WebTrust, SysTrust, ±âŸ.) ¹®¼°¡ ÀûÀýÇÑ°¡?
- ÄÄÇöóÀ̾𽺸¦ À§Çؼ ±â¾÷Àº ÀڽŠµ¥ÀÌÅÍÀÇ ¹°¸®Àû À§Ä¡¸¦ ¾î¶»°Ô ÃßÀûÇÒ ¼ö Àִ°¡? (¿¹¸¦ µé¸é, ¾î¶² ¹ý·üÀº µ¥ÀÌÅ͸¦ ƯÁ¤ ±¹°¡µé¿¡ ÀúÀåÇÏ´Â °ÍÀ» ±ÝÁöÇÑ´Ù.)
- µ¥ÀÌÅÍ º¸¾È ÀÌ¿Ü¿¡, ¹Ì±¹ »þº£ÀÎ-¿Á½½¸® ¹ý°ú °°Àº ¹ý·üÀÌ ÁöÁ¤ÇÏ´Â ÄÄÇöóÀ̾𽺠¿ä°ÇÀ» À¯ÁöÇϵµ·Ï Çϱâ À§Çؼ °í°´ ±â¾÷¿¡°Ô ¾î¶² ¹®¼°¡ Á¦°øµÉ °ÍÀΰ¡?
- ±â¾÷Àº ÀÚ½ÅÀÇ ¸ðµç µ¥ÀÌÅ͵鿡 ÀÇÇØ ¿ä±¸µÇ´Â ¼öÁØ¿¡ ÇÊ¿äÇÑ ³»ºÎ ÅëÁ¦ ¹× ÄÄÇöóÀ̾𽺸¦ À¯ÁöÇϱâ À§ÇÏ¿© ÁغñÇÏ¿´´Â°¡?
- ±â¾÷¿¡ ÀÇÇØ Á¦°øµÇ´Â ³»ºÎ ÅëÁ¦ ¹× ÀýÂ÷¿¡ ´ëÇÑ Á¤º¸°¡ ¾î´À ½ÃÁ¡¿¡ ºñÁî´Ï½º¸¦ À§ÅÂ·Ó°Ô ÇÒ¸¸Å ¸¹¾ÆÁö´Â°¡?
- °¡¿ë¼º
- ¾ó¸¶ÀÇ °¡µ¿½Ã°£À» º¸ÀåÇϴ°¡?
- º¸ÀåµÈ ¼ºñ½º ¼öÁØÀÌ Àִ°¡? ´©°¡ ±×°ÍÀ» ¸ð´ÏÅÍÇϴ°¡? º¸Àå ¼öÁØÀÌ ÁöÄÑÁöÁö ¾ÊÀ¸¸é, ¾î¶°ÇÑ ¹è»óÀÌ ÀÌ·ç¾îÁö´Â°¡?
- Áö±ÝÀº ¸ðµç ¼ºñ½º°¡ ÀÎÅÍ³Ý »ó¿¡¼ Á¢±ÙµÇ´Âµ¥, ±â¾÷Àº Àüü Á÷¿øµéÀ» À§ÇÑ ³×Æ®¿öÅ© ´ë¿ªÆøÀ» º¸À¯ÇÏ°í Àִ°¡, ±×¸®°í Ŭ¶ó¿ìµå Á¦°øÀÚ´Â ±â¾÷ÀÇ ¿å±¸¸¦ µé¾îÁÙ ¼ö ÀÖ´Â ÃæºÐÇÑ Àü·Â°ú ´ë¿ªÆøÀ» °¡Áö°í Àִ°¡?
- °ü·Ã¾ø´Â Ŭ¶ó¿ìµå ¼ÒºñÀÚ(¿¹¸¦ µé¸é, ÇÏµå µå¶óÀ̺ê subpoena(?))ÀÇ È°µ¿¿¡ ±âÃÊÇØ ¼ºñ½º°¡ Áß´ÜµÉ ¼ö Àִ°¡?
- Á¤º¸°¡ °í°´µé°£¿¡ ¾î¶»°Ô ºÐ¸®µÇ´Â°¡?
- ¾î¶»°Ô °¡¿ë¼º°ú °ü·ÃÇÑ º¸ÁõÀÌ Å¬¶ó¿ìµå Á¦°øÀÚ¿¡ ÀÇÇØ Á¦°øµÇ´Â°¡?
- Ŭ¶ó¿ìµå Á¦°øÀÚ´Â ¼ºñ½º Áß´Ü È¤Àº À̽´·Î ÀÎÇÑ ºñÁî´Ï½º ¼Õ½Ç¿¡ ´ëÇؼ, ÀçÁ¤ÀûÀ¸·Î, ¹ýÀûÀ¸·Î ¾Æ´Ï¸é ±× ¹ÛÀÇ ´Ù¸¥ Â÷¿ø¿¡¼ ¾î´À ¼öÁرîÁö Ã¥ÀÓÀÌ Àִ°¡?
- ±â¾÷ÀÌ ÀÏ´Ü Å¬¶ó¿ìµå ÀÎÇÁ¶ó¸¦ °®°Ô µÇ¸é, ÀçÇØ º¹±¸ ¹× »ç¾÷ ¿¬¼Ó¼º °èȹÀº ¹«¾ùÀΰ¡?
- ¿ÀÆÛ·¹À̼Ç
- ±â¾÷Àº ÀÌ¿ëÁßÀΠŬ¶ó¿ìµåÀÇ ºÎÇÏ¿Í ¼º´ÉÀ» ¾î¶»°Ô ¸ð´ÏÅÍÇϴ°¡?
- Ŭ¶ó¿ìµå Á¦°øÀÚ´Â »ç¿ë·®¿¡ ´ëÇÑ °ú±ÝÀÌ ÀûÁ¤ÇÏ´Ù´Â °ÍÀ» ±â¾÷¿¡°Ô ¾î¶»°Ô º¸ÁõÇÒ ¼ö Àִ°¡?
- Ŭ¶ó¿ìµå¿¡¼ º¸¾ÈÀ» ¸ð´ÏÅÍÇϱâ À§ÇÏ¿© ¾î¶°ÇÑ µµ±¸µéÀÌ ÀÌ¿ë°¡´ÉÇÏ°í Çã¿ëµÇ´Â°¡?
- Àüü ÇÁ·ÎÁ§Æ®
- ¾Õ¿¡¼ ¾ð±ÞÇÑ ¸ðµç ºÐ¾ß¿¡ ´ëÇÏ¿© µ¶¸³ÀûÀÎ °¨»ç´Â ´©°¡ Çϴ°¡?
- °¨»ç¸¦ ¾ó¸¶³ª ÀÚÁÖ ½Ç½ÃÇϴ°¡?
ÀÌ·¯ÇÑ Áú¹®µéÀÌ Å¬¶ó¿ìµå Á¦°øÀÚ¸¦ ÀÌ¿ëÇÏ·Á°í ¸¶À½¸Ô¾úÀ» ¶§, ´äº¯ÀÌ µÇ¾î¾ß ÇÏ´Â °¡Àå ±âº»ÀûÀÎ °ÍÀÌ´Ù; ±â¾÷Àº °¢ Áú¹®µé¿¡ °üÇÑ ±íÀÌ ÀÖ´Â ±â¼úÀû, ¹ýÀû ±×¸®°í »ç¾÷Àû ´ëȸ¦ Çϱâ À§Çؼ ÁغñÇÏ¿©¾ß ÇÑ´Ù. ¸ðµç °æ¿ì¿¡ ÀÖ¾î¼, ÇÑ°¡Áö ºó¾àÇÑ ÅëÁ¦¸¸À¸·Îµµ ±â¾÷ÀÇ ¸ðµç µ¥ÀÌÅ͸¦ »Ì¾Æ³»¼ ÀÌ¿ëÇϴµ¥ »ç¿ëµÉ ¼ö Àֱ⠶§¹®¿¡ Ŭ¶ó¿ìµå ÄÄÇ»Æà Á¦Á¶¾÷ü·ÎºÎÅÍÀÇ ºÒÈ®½ÇÇϰųª ºÎÁ¤ÀûÀÎ ´äº¯À» µè´Â´Ù¸é ÀÌ¿ë Áß´ÜÀ» °í·ÁÇÏ¿©¾ß ÇÑ´Ù.
°á·Ð
Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀ» °è¼ÓÇؼ Á¤º¸ ó¸®, µ¥ÀÌÅÍ ÀúÀå ±×¸®°í ±¹°¡°£ Ä¿¹Â´ÏÄÉÀ̼ÇÀÇ ÁÖ·ù·Î ¸ô¾Æ°¡°í Àֱ⠶§¹®¿¡, µ¥ÀÌÅÍ¿¡ ´ëÇÑ À§ÇèÀÌ ²ÙÁØÈ÷ °ËÅäµÇ°í, ÆÄ¾ÇµÈ À§ÇùÀÌ µ¥ÀÌÅÍÀÇ °¡Ä¡¿¡ »óÀÀÇÏ´Â ¼öÁØÀ¸·Î ¿ÏȽÃÅ°´Â °ÍÀÌ Áß¿äÇÏ´Ù. Ŭ¶ó¿ìµå ÄÄÇ»Æà ÀÎÇÁ¶óÀÇ °¡Ä¡´Â ÃøÁ¤ÀÌ °¡´ÉÇÏ´Ù: º¸»óÀº µ¥ÀÌÅÍ Á¢±Ù¼º, °í°´ °ü°è °ü¸®(CRM), ±×¸®°í Çϵå¿þ¾î ºñ¿ëÀÇ °¨¼Ò¿Í ÀÎÇÁ¶ó Áö¿ø¿¡¼ ãÀ» ¼ö ÀÖÁö¸¸, ÀáÁ¤ÀûÀ¸·Î µ¥ÀÌÅÍ À¯Ãâ ȤÀº ¼Õ½Ç¿¡ µû¸¥ ±ÔÁ¦ ±â°üÀÇ ¹ú±Ý, ¹Î»ç ¼Ò¼Û ȤÀº ÆòÆÇ ÈѼտ¡ ´ëÇÑ ºñ¿ëÀº ±× ¾î¶² º¸»óµµ ½±°Ô ÃÊ°úÇÒ ¼ö ÀÖ´Ù. µ¥ÀÌÅÍ ±â¹ÐÀ» ÁöÅ°°í, µ¥ÀÌÅÍ ¹«°á¼ºÀ» À¯ÁöÇÏ°í, µ¥ÀÌÅÍ °¡¿ë¼ºÀ» º¸ÁõÇÏ°í, ±ÔÁ¦ ȤÀº ¹ý·üÀû Àǹ«¸¦ ´ÙÇÏ°í, ±×¸®°í Ŭ¶ó¿ìµå ³»¿¡¼ À¯½ÇµÇÁö ¾Êµµ·Ï ÇÏ´Â °ÍÀº Ç×»ó ÇØ´ç ±â¾÷ÀÇ Ã¥ÀÓÀ̶ó´Â °ÍÀ» ¸í½ÉÇϽʽÿÀ.
Endnotes
1 See the case studies published by Microsoft (www.microsoft.com/en-us/cloud/tools-resources.aspx?CR_CC=200010704&WT.srch=1&WT.mc_id=A8A7CD18-DA39-4EEE-81FC-BA7440F28341&CR_SCC=200010704#casestudy) and the information provided from VMware (www.vmware.com/solutions/cloud-computing).
2 The Federal Bureau of Investigation, ¡°Internet Crime Trends—The Latest Report,¡± USA, www.fbi.gov/news/stories/2011/february/internet_022411/internet_022411.
3 Computer Security Institute, http://gocsi.com/sites/default/files/uploads/Surveyand%20webinar%20PR%202010.pdf
4 See www.bankinfosecurity.com, www.ftc.gov, www.first.org, www.cloudsecurityalliance.org and www.cloutage.org.
5 Aldi, ¡°ALDI Notifies Customers of Tampered Payment Card Terminals,¡± press release, 1 October 2010, www.aldifoods.com/us/media/company/company/Press_Release.pdf
6 Jewell, Mark; ¡°TJX, Visa Reach $40.9M Settlement for Data Breach,¡± USA Today, 30 November 2007, www.usatoday.com/money/industries/retail/2007-11-30-tjx-visa-breach-settlement_N.htm
7 McGlasson, Linda; ¡°Heartland Payment Systems, Forcht Bank Discover Data Breaches,¡± BankInfoSecurity.com, 21 January 2009, www.bankinfosecurity.com/articles.php?art_id=1168
8 Yen, Hope; ¡°VA Agrees to Pay $20 Million to Veterans in 2006 Data Breach,¡± Boston.com, 28 January 2009, www.boston.com/news/nation/washington/articles/2009/01/28/va_agrees_to_pay_20_million_to_veterans_in_2006_data_breach
9 See Open Security Foundation, http://datalossdb.org/incidents/3062-2-500-customers-names-and-addressesexposed-on-the-web.
10 See Open Security Foundation, http://datalossdb.org/incidents/30-up-to-500-000-credit-card-numbers-exposed.
11 Cloud Security Alliance, ¡°Security Guidance for Critical Areas of Focus in Cloud Computing V2.1,¡± USA, 2009, www.cloudsecurityalliance.org/guidance/csaguide.v2.1.pdf
12 Ponemon, Dr. Larry; ¡°Five Countries: Cost of Data Breach,¡± Ponemon Institute LLC, revised 19 April 2010, www.ponemon.org/local/upload/fckjail/generalcontent/18/file/2010%20Global%20CODB.pdf
13 Masters, Greg; ¡°Rite Aid to Pay $1 Million Fine for HIPAA Violation,¡± SC Magazine, 28 July 2010, www.scmagazineus.com/rite-aid-to-pay-1-million-fine-forhipaa-violation/article/175729
14 Op cit, Jewell, Mark
15 Santalesa, Richard L.; ¡°Health Net Agrees to $250,000 Fine and ¡®Corrective Action Plan¡¯ to Settle Loss of PHI,¡± Information Law Group, 21 July 2010, www.infolawgroup.com/2010/07/articles/hitech-1/health-net-agrees-to-250000-fine-and-corrective-actionplan-to-settle-loss-of-phi
16 Hennessy-Fiske, Molly; ¡°Six California Hospitals Fined for Medical Record Security Breaches,¡± Los Angeles Times, 19 November 2010, http://latimesblogs.latimes.com/lanow/2010/11/hospital-fines.html
17 See Open Security Foundation, http://cloutage.org/incidents?reported_year=2010.
Carl Cadregari, CISA
is principal and practice lead in the Enterprise Risk Management Division of the Bonadio Group and also serves as chief information security director at one of the largest insurance companies in upstate New York (USA). Cadregari has more than 28 years of experience in IT and IS security architecture, deployment, project management, security by design and governance.
Alfonzo Cutaia, Esq.
is an associate in the Information Technology & Internet Law Practice Group of Hodgson Russ LLP and focuses on patent practice. Before joining Hodgson Russ, Cutaia served as an intellectual property assistant for the Office of Science, Technology Transfer and Economic Outreach at the University at Buffalo (USA).