IT °Å¹ö³Í½º, ÅëÁ¦, º¸¾È ±×¸®°í º¸Áõ ¾÷°èÀÇ ±Û·Î¹ú ¸®´õ
 
 
HOME > Ä¿¹Â´ÏƼ > ¼­Æò & ¹ø¿ª¹°
  ÅëÁ¦¸¦ Áø´ÜÇϱâ Àü¿¡ ´øÁ®¾ß ÇÒ 5°¡Áö Áú¹® By Brian Barnier, CGEIT
  ±Û¾´ÀÌ : ½ÅÀÎö     ³¯Â¥ : 11-06-13 01:20     Á¶È¸ : 2787     Ãßõ : 9     Æ®·¢¹é ÁÖ¼Ò

Ask Five Questions Before Assessing Your Controls

ÅëÁ¦¸¦ Áø´ÜÇϱâ Àü¿¡ 5°¡Áö Áú¹®À» Ç϶ó.

 

By Brian Barnier, CGEIT

@ISACA Relevant Timely News Volume 12: 8 June 2011

À§Çè ¹× ÅëÁ¦ Áø´ÜÀº ±âº»ÀûÀÎ ¼ö´ÜµéÀÌ´Ù. ¸ðµç »ç¶÷ÀÌ ±×°ÍµéÀ» ÀÌ¿ëÇÏ°í, ´ëºÎºÐ »ç¶÷µéÀÌ ±×°Íµé°ú ½Î¿î´Ù. ¾î¶² ÄÁÆÛ·±½º¿¡ °¡¼­ ´Ù¼¸ »ç¶÷¿¡°Ô ¹°¾îº¸¸é ±× ¸íĪ Á¶Â÷ Á¦ °¢°¢À̶ó´Â »ç½ÇÀ» ¹ß°ßÇÒ °ÍÀÌ´ÙÀ§Çè ¹× ÅëÁ¦ ÀÚ°¡ Áø´Ü, À§Çè ÅëÁ¦ ÀÚ°¡ Áø´Ü, ÅëÁ¦ ÀÚ°¡ Áø´Ü µî. ÀÌ·¯ÇÑ Áø´ÜµéÀº ÁÖ¿ä ¼±Çà Á¶°ÇµéÀÌ ÃæÁ·µÇÁö ¾ÊÀ¸¸é ½±°Ô ¾µ¸ð ¾ø°Å³ª È¥¶õ¸¸ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù.
 
ÀÌ·¯ÇÑ ¹®Á¦¸¦ ÇÇÇϱâ À§Çؼ­, ¿©·¯ºÐ ½º½º·Î ´ÙÀ½ ´Ù¼¸ °¡Áö Áú¹®À» ´øÁ®¾ß ÇÑ´Ù:
 

1.     ¿ì¸®´Â ¡°ºñÁî´Ï½º¸¦ ¾Ë°í¡± Àִ°¡? ¸¹Àº Áø´ÜÀÌ ÀÌ¹Ì ¾Ë·ÁÁø À§Çè, ÅëÁ¦ ±×¸®°í °áÇԵ鿡¸¸ ÃÊÁ¡À» ¸ÂÃá´Ù; ±×·¯ÇÑ Áø´ÜÀº Àß µå·¯³ªÁö ¾ÊÀº °áÇÔµé°ú (ÇØ´ç ÅëÁ¦µéÀÌ ±¸ÇöµÈ) ±Ù¿øÀûÀÎ (¾÷¹«) ÇÁ·Î¼¼½º ³»ÀÇ °áÇÔÀ» °£°úÇÑ´Ù.

2.     ¼³°èµÇ°í ±¸ÇöµÈ ÅëÁ¦µéÀ» À¯µµÇÏ´Â À§Çè Æò°¡°¡ ¾ó¸¶³ª ¹ÏÀ» ¸¸ÇÑ°¡? Áø´ÜÀº ȯ°æ ¹× ±â¾÷ ¿ª·® Æò°¡, ½Ã³ª¸®¿À ºÐ¼®, ±Ùº» ¿øÀÎ ºÐ¼®, ÀÇÁ¸¼º ºÐ¼®, ÅëÁ¦ ¼³°è, ±×¸®°í ÅëÁ¦ ±¸Çö µîÀ» Æ÷ÇÔÇÑ À§Çè Æò°¡ ¹× ´ëó¿¡ À־ÀÇ Á¤»óÀûÀ¸·Î ¿Ï·áµÈ ¾Õ¼± ÀýÂ÷µé¿¡ Á¿ìµÈ´Ù. ±×·¯ÇÑ ¼±Çà ÀýÂ÷µéÀÌ ºñÁ¤»óÀûÀ̶ó¸é, À߸øµÈ ÅëÁ¦µéÀ» Áø´ÜÇÏ°í °ü·Ã ÁöÀû »çÇ׵鵵 °ÅÀÇ ¹«ÀǹÌÇÒ °¡´É¼ºÀÌ ÀÖ´Ù.

3.     Áø´Ü ÁֱⰡ Çö½ÇÀÇ º¯È­¿Í º¸Á¶¸¦ ¸ÂÃß°í Àִ°¡? À§Çè¿¡ ´ëÇÑ º¯È­°¡ (ȯ°æ ±×¸®°í ÇÁ·Î¼¼½º, ȤÀº ÅëÁ¦) Æò°¡ Áֱ⺸´Ù ´õ ÀÚÁÖ ¹ß»ýÇϸé, ±× ¶§ÀÇ Æò°¡´Â ½ÇÁúÀûÀÎ À§ÇèÀ» ³õÄ¥ °ÍÀÌ´Ù. ¿¹¸¦ µé¾î, ¿©·¯ºÐÀÇ IT ȯ°æÀÌ ¸î °³¿ù ¸¶´Ù º¯ÇÑ´Ù¸é, »ç¾÷ ¿¬¼Ó¼º Å×½ºÆ® ÁֱⰡ IT ȯ°æ º¯È­ Áֱ⿡ ¸ÂÃçÁ®¾ß ÇÑ´Ù±×·¸Áö ¾Ê´Â °ÍÀº À߸øµÈ ½Å·Ú°¨À» °®°Ô ÇÑ´Ù.

4.     ÅëÁ¦ Áø´ÜÀÌ ½ÇÁúÀûÀ¸·Î ÅëÁ¦( ÀÚü)¿¡ ÃÊÁ¡À» ¸ÂÃß¾ú´ÂÁö ȤÀº ÅëÁ¦ Áø´ÜÀÌ Á¤Ã¥, ÀýÂ÷ ¶Ç´Â ±ÔÁ¤µé ¼Ó¿¡ ¾î¿ì·¯Á® Àִ°¡? Á¤Ã¥µéÀÇ Á¸Àç ¿©ºÎ¿¡ ´ëÇÑ ¡°±×¸°green¡± µî±ÞÀº Á¤»ó ±Ëµµ¸¦ ¹þ¾î³­ Á¶°ÇÀ» °¨ÁöÇÏ°í ±× Á¤º¸¿¡ ´ëÇÏ¿© Á¶Ä¡ÇÒ ¼ö ÀÖ´Â ÅëÁ¦¸¦ ½ÃÇèÇÏ´Â °Í°ú´Â °Å¸®°¡ ¸Ö´Ù.

5.     Áø´ÜÀÌ À§Çè °ü¸®ÀÇ ÀÏ»óÀû ÀÌ¿ë¿¡ ´ëÇÑ ÁÖÀÇ·ÂÀ» ¾àÇÏ°Ô ÇÏÁö´Â ¾Ê´Â°¡? (ȯ°æ ¶Ç´Â ºñÁî´Ï½º ¿ª·® º¸´Ù´Â) ÅëÁ¦¿¡ ´ëÇÑ Áöü ½Ã°£ ¹× ºÎ°¢Àº Á¶Á÷µé·Î ÇÏ¿©±Ý À§Çè °ü¸®¸¦, ±Ùº» ¿øÀÎÀ» Ä¡À¯ÇÏ´Â ºÎ°¡°¡Ä¡Àû °ü¸® ±â´ÉÀ̶ó±â º¸´Ù´Â, ÀÏÁ¾ÀÇ ¡°ÀÏȸ¼º bandage¡± º¸Áõ ±â´ÉÀ¸·Î °£ÁÖÇÏ°Ô ÇÏ´Â °æÇâÀÌ ÀÖ´Ù.

 
À§Çè ¶Ç´Â ÅëÁ¦ Áø´ÜÀÌ À§¿¡ ±â¼úÇÑ ÇÔÁ¤¿¡ ºüÁø´Ù¸é, ¾Æ¸¶µµ º¸´Ù À¯¿ëÇÑ À§Çè °ü¸® È°µ¿µé¿¡ ´ëÇÑ ÀÚ¿ø ÁýÁßÀ» ÈåÆ®·¯¶ß¸®°í ±×¸®°í À߸øµÈ º¸ÁõÀ» ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ ÇÔÁ¤µéÀº ½É°¢ÇÑ ¼ÕÇظ¦ À¯µµÇÑ´Ù. ÅëÁ¦°¡ ¹®¼­ »óÀ¸·Î ¼ö¿ëÇÒ ¼ö ÀÖ¾úÀ» ¶§(¿ªÀÚ ÁÖ: Áï ¹®¼­ »óÀ¸·Î´Â ÅëÁ¦°¡ ÀûÀýÇÏ´Ù°í ÆǴܵǾúÀ» ¶§) ¹ß»ýÇÑ µ¥ÀÌÅÍ À¯½Ç, »ç±â, ³×Æ®¿öÅ© Áß´Ü, ·Îº¸-»çÀÌ´×(robo-signings: ¹æ´ëÇÑ ¾çÀÇ ¹®¼­¿¡ ´ëÇØ ³»¿ë °ËÅäµµ ¾Ê°í »çÀÎÇÏ´Â °Í) ±×¸®°í ±âŸ ´Ù¸¥ ¹®Á¦Á¡µéÀ» »ý°¢ÇØ º¸¶ó. ¹°·Ð, Áø´Ü ¹× Å×½ºÆ®´Â ÀǹÌÀÖ´Â Á¶Ä¡°¡ ÃëÇØÁöµµ·Ï ¹Ýµå½Ã ÀûÀýÈ÷ ¾ö°ÝÇÏ°Ô Àû¿ëµÇ¾î¾ß¸¸ ÇÑ´Ù. ÁÁÀº ¼Ò½ÄÀº (±×¸®Çϸé) ÀÌ·¯ÇÑ ¹®Á¦Á¡µéÀÌ ºñ±³Àû ¼Õ½±°Ô Ä¡À¯µÈ´Ù´Â Á¡ÀÌ´Ù.
 
ÀÌ ±ÛÀº °ð ¹ß°£µÉ ºê¶óÀ̾ð ¹Ù´Ï¾îÀÇ Ã¥(±ÝÀ¶ ȸ»ç¸¦ À§ÇÑ ¿ÀÆÛ·¹ÀÌ¼Ç À§Çè ÇÚµåºÏ)¿¡¼­ °¢»öµÇ¾ú´Ù.
 
Brian Barnier, CGEIT, is a principal at ValueBridge Advisors, where he analyzes trends and advises/mentors business and IT leaders to help them accelerate business performance improvement, including risk management. In the past, he has held business, IT and risk roles. Barnier teaches, speaks and researches widely. He can be reached at brian@valuebridgeadvisors.com.

ÀÇ°ß¾²±â

¹øÈ£ Á¦¸ñ ±Û¾´ÀÌ ³¯Â¥ Á¶È¸ Ãßõ
¹ø¿ª¿¡ ´ëÇÑ º¯ (1) ½ÅÀÎö 07-03-24 8231 17
38 ¿£ÅÍÇÁ¶óÀÌÁîÀÇ °³³ä ½ÅÀÎö 13-01-08 2543 8
37 ÅëÁ¦¸¦ Áø´ÜÇϱâ Àü¿¡ ´øÁ®¾ß ÇÒ 5°¡Áö Áú¹® By Brian Barnier, CGEIT ½ÅÀÎö 11-06-13 2788 9
36 Ŭ¶ó¿ìµå ÄÄÇ»ÆÃ, ¹ý±Ô ±×¸®°í µ¥ÀÌÅÍ º¸¾È À§Çè¿¡ °üÇÑ ÀÔ¹® By Carl Cadregari, and Alfonzo Cutaia, Esq (4) ½ÅÀÎö 11-05-31 5998 20
35 Àü»ç À§Çè °ü¸®¿¡¼­ÀÇ IT ½Ã³ª¸®¿À ºÐ¼® By Urs Fischer, CISA, CRISC, CPA Swiss ½ÅÀÎö 11-05-04 5800 11
34 º¸¾ÈÀÇ °¡Ä¡´Â ¹«¾ùÀΰ¡? By Steven J. Ross, CISA, CISSP, MBCP ½ÅÀÎö 11-04-17 3370 10
33 º¸¾È Á¤Ã¥À» ÀÛ¼ºÇÏ´Â ¹æ¹ý: ³×Æ®¿öÅ© º¸¾È Á¤Ã¥ ¸Å´º¾ó by Paul R. Meynen ½ÅÀÎö 11-03-25 3805 14
32 ¼ÒÇÁÆ® IT °Å¹ö³Í½º By Kazuhiro Uehara, CGEIT, CISA, CIA, PMP, and Sayaka Akino, CISA ½ÅÀÎö 11-01-31 3680 13
31 IS °³¹ß ÇÁ·ÎÁ§Æ®¿¡¼­ À§Çè °ü¸®¸¦ À§ÇÑ ¡®¿ä±¸»çÇ× ÁïÈZ¡¯ °ü¸® by Sachidanandam Sakthivel ½ÅÀÎö 11-01-20 6879 12
30 ÇÑ°¡Áö Áß¿äÇÑ Áú¹® by Steven J. Ross ½ÅÀÎö 11-01-11 3436 13
29 ¼­ºñ½º °¡¿ë¼º°ú ÀçÇØ º¹±¸ by Steven J. Ross ½ÅÀÎö 11-01-05 9187 13
28 ISO/IEC 38500 ¿¡ ±â¹ÝÇÑ IT °Å¹ö³Í½ºÀÇ ±Ùº» by Haris Hamidovic ½ÅÀÎö 10-12-02 5249 15
27 IT À§Çè ºÐ¼® – ºü¶ß¸°¡°A¡± By Eric J. Brown and William A. Yarberry Jr., ½ÅÀÎö 10-11-08 4168 20
26 Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÇ ÇöȤ (Cloudy Daze) by Steven J. Ross ½ÅÀÎö 10-03-03 4096 16
25 IT °Å¹ö³Í½º¸¦ ÇÑ Â÷¿ø ²ø¾î¿Ã¸®±â À§ÇÑ 5°¡Áö ÆÁ By Brian Barnier ½ÅÀÎö 10-01-22 3486 14
24 ¿ä¾à: ¸Å·ÂÀÖ´Â ÀüÇâÀû °Å¹ö³Í½º ¸ÅÇÎ À̴ϼÅƼºê By ISACA (¹ø¿ªÀÚ Ãßõ) ½ÅÀÎö 09-08-10 3755 13
 1  2  3