IT °Å¹ö³Í½º, ÅëÁ¦, º¸¾È ±×¸®°í º¸Áõ ¾÷°èÀÇ ±Û·Î¹ú ¸®´õ
 
 
HOME > Ä¿¹Â´ÏƼ > ¼­Æò & ¹ø¿ª¹°
  ÅëÁ¦¸¦ Áø´ÜÇϱâ Àü¿¡ ´øÁ®¾ß ÇÒ 5°¡Áö Áú¹® By Brian Barnier, CGEIT
  ±Û¾´ÀÌ : ½ÅÀÎö     ³¯Â¥ : 11-06-13 01:20     Á¶È¸ : 2672     Ãßõ : 9     Æ®·¢¹é ÁÖ¼Ò

Ask Five Questions Before Assessing Your Controls

ÅëÁ¦¸¦ Áø´ÜÇϱâ Àü¿¡ 5°¡Áö Áú¹®À» Ç϶ó.

 

By Brian Barnier, CGEIT

@ISACA Relevant Timely News Volume 12: 8 June 2011

À§Çè ¹× ÅëÁ¦ Áø´ÜÀº ±âº»ÀûÀÎ ¼ö´ÜµéÀÌ´Ù. ¸ðµç »ç¶÷ÀÌ ±×°ÍµéÀ» ÀÌ¿ëÇÏ°í, ´ëºÎºÐ »ç¶÷µéÀÌ ±×°Íµé°ú ½Î¿î´Ù. ¾î¶² ÄÁÆÛ·±½º¿¡ °¡¼­ ´Ù¼¸ »ç¶÷¿¡°Ô ¹°¾îº¸¸é ±× ¸íĪ Á¶Â÷ Á¦ °¢°¢À̶ó´Â »ç½ÇÀ» ¹ß°ßÇÒ °ÍÀÌ´ÙÀ§Çè ¹× ÅëÁ¦ ÀÚ°¡ Áø´Ü, À§Çè ÅëÁ¦ ÀÚ°¡ Áø´Ü, ÅëÁ¦ ÀÚ°¡ Áø´Ü µî. ÀÌ·¯ÇÑ Áø´ÜµéÀº ÁÖ¿ä ¼±Çà Á¶°ÇµéÀÌ ÃæÁ·µÇÁö ¾ÊÀ¸¸é ½±°Ô ¾µ¸ð ¾ø°Å³ª È¥¶õ¸¸ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù.
 
ÀÌ·¯ÇÑ ¹®Á¦¸¦ ÇÇÇϱâ À§Çؼ­, ¿©·¯ºÐ ½º½º·Î ´ÙÀ½ ´Ù¼¸ °¡Áö Áú¹®À» ´øÁ®¾ß ÇÑ´Ù:
 

1.     ¿ì¸®´Â ¡°ºñÁî´Ï½º¸¦ ¾Ë°í¡± Àִ°¡? ¸¹Àº Áø´ÜÀÌ ÀÌ¹Ì ¾Ë·ÁÁø À§Çè, ÅëÁ¦ ±×¸®°í °áÇԵ鿡¸¸ ÃÊÁ¡À» ¸ÂÃá´Ù; ±×·¯ÇÑ Áø´ÜÀº Àß µå·¯³ªÁö ¾ÊÀº °áÇÔµé°ú (ÇØ´ç ÅëÁ¦µéÀÌ ±¸ÇöµÈ) ±Ù¿øÀûÀÎ (¾÷¹«) ÇÁ·Î¼¼½º ³»ÀÇ °áÇÔÀ» °£°úÇÑ´Ù.

2.     ¼³°èµÇ°í ±¸ÇöµÈ ÅëÁ¦µéÀ» À¯µµÇÏ´Â À§Çè Æò°¡°¡ ¾ó¸¶³ª ¹ÏÀ» ¸¸ÇÑ°¡? Áø´ÜÀº ȯ°æ ¹× ±â¾÷ ¿ª·® Æò°¡, ½Ã³ª¸®¿À ºÐ¼®, ±Ùº» ¿øÀÎ ºÐ¼®, ÀÇÁ¸¼º ºÐ¼®, ÅëÁ¦ ¼³°è, ±×¸®°í ÅëÁ¦ ±¸Çö µîÀ» Æ÷ÇÔÇÑ À§Çè Æò°¡ ¹× ´ëó¿¡ À־ÀÇ Á¤»óÀûÀ¸·Î ¿Ï·áµÈ ¾Õ¼± ÀýÂ÷µé¿¡ Á¿ìµÈ´Ù. ±×·¯ÇÑ ¼±Çà ÀýÂ÷µéÀÌ ºñÁ¤»óÀûÀ̶ó¸é, À߸øµÈ ÅëÁ¦µéÀ» Áø´ÜÇÏ°í °ü·Ã ÁöÀû »çÇ׵鵵 °ÅÀÇ ¹«ÀǹÌÇÒ °¡´É¼ºÀÌ ÀÖ´Ù.

3.     Áø´Ü ÁֱⰡ Çö½ÇÀÇ º¯È­¿Í º¸Á¶¸¦ ¸ÂÃß°í Àִ°¡? À§Çè¿¡ ´ëÇÑ º¯È­°¡ (ȯ°æ ±×¸®°í ÇÁ·Î¼¼½º, ȤÀº ÅëÁ¦) Æò°¡ Áֱ⺸´Ù ´õ ÀÚÁÖ ¹ß»ýÇϸé, ±× ¶§ÀÇ Æò°¡´Â ½ÇÁúÀûÀÎ À§ÇèÀ» ³õÄ¥ °ÍÀÌ´Ù. ¿¹¸¦ µé¾î, ¿©·¯ºÐÀÇ IT ȯ°æÀÌ ¸î °³¿ù ¸¶´Ù º¯ÇÑ´Ù¸é, »ç¾÷ ¿¬¼Ó¼º Å×½ºÆ® ÁֱⰡ IT ȯ°æ º¯È­ Áֱ⿡ ¸ÂÃçÁ®¾ß ÇÑ´Ù±×·¸Áö ¾Ê´Â °ÍÀº À߸øµÈ ½Å·Ú°¨À» °®°Ô ÇÑ´Ù.

4.     ÅëÁ¦ Áø´ÜÀÌ ½ÇÁúÀûÀ¸·Î ÅëÁ¦( ÀÚü)¿¡ ÃÊÁ¡À» ¸ÂÃß¾ú´ÂÁö ȤÀº ÅëÁ¦ Áø´ÜÀÌ Á¤Ã¥, ÀýÂ÷ ¶Ç´Â ±ÔÁ¤µé ¼Ó¿¡ ¾î¿ì·¯Á® Àִ°¡? Á¤Ã¥µéÀÇ Á¸Àç ¿©ºÎ¿¡ ´ëÇÑ ¡°±×¸°green¡± µî±ÞÀº Á¤»ó ±Ëµµ¸¦ ¹þ¾î³­ Á¶°ÇÀ» °¨ÁöÇÏ°í ±× Á¤º¸¿¡ ´ëÇÏ¿© Á¶Ä¡ÇÒ ¼ö ÀÖ´Â ÅëÁ¦¸¦ ½ÃÇèÇÏ´Â °Í°ú´Â °Å¸®°¡ ¸Ö´Ù.

5.     Áø´ÜÀÌ À§Çè °ü¸®ÀÇ ÀÏ»óÀû ÀÌ¿ë¿¡ ´ëÇÑ ÁÖÀÇ·ÂÀ» ¾àÇÏ°Ô ÇÏÁö´Â ¾Ê´Â°¡? (ȯ°æ ¶Ç´Â ºñÁî´Ï½º ¿ª·® º¸´Ù´Â) ÅëÁ¦¿¡ ´ëÇÑ Áöü ½Ã°£ ¹× ºÎ°¢Àº Á¶Á÷µé·Î ÇÏ¿©±Ý À§Çè °ü¸®¸¦, ±Ùº» ¿øÀÎÀ» Ä¡À¯ÇÏ´Â ºÎ°¡°¡Ä¡Àû °ü¸® ±â´ÉÀ̶ó±â º¸´Ù´Â, ÀÏÁ¾ÀÇ ¡°ÀÏȸ¼º bandage¡± º¸Áõ ±â´ÉÀ¸·Î °£ÁÖÇÏ°Ô ÇÏ´Â °æÇâÀÌ ÀÖ´Ù.

 
À§Çè ¶Ç´Â ÅëÁ¦ Áø´ÜÀÌ À§¿¡ ±â¼úÇÑ ÇÔÁ¤¿¡ ºüÁø´Ù¸é, ¾Æ¸¶µµ º¸´Ù À¯¿ëÇÑ À§Çè °ü¸® È°µ¿µé¿¡ ´ëÇÑ ÀÚ¿ø ÁýÁßÀ» ÈåÆ®·¯¶ß¸®°í ±×¸®°í À߸øµÈ º¸ÁõÀ» ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ ÇÔÁ¤µéÀº ½É°¢ÇÑ ¼ÕÇظ¦ À¯µµÇÑ´Ù. ÅëÁ¦°¡ ¹®¼­ »óÀ¸·Î ¼ö¿ëÇÒ ¼ö ÀÖ¾úÀ» ¶§(¿ªÀÚ ÁÖ: Áï ¹®¼­ »óÀ¸·Î´Â ÅëÁ¦°¡ ÀûÀýÇÏ´Ù°í ÆǴܵǾúÀ» ¶§) ¹ß»ýÇÑ µ¥ÀÌÅÍ À¯½Ç, »ç±â, ³×Æ®¿öÅ© Áß´Ü, ·Îº¸-»çÀÌ´×(robo-signings: ¹æ´ëÇÑ ¾çÀÇ ¹®¼­¿¡ ´ëÇØ ³»¿ë °ËÅäµµ ¾Ê°í »çÀÎÇÏ´Â °Í) ±×¸®°í ±âŸ ´Ù¸¥ ¹®Á¦Á¡µéÀ» »ý°¢ÇØ º¸¶ó. ¹°·Ð, Áø´Ü ¹× Å×½ºÆ®´Â ÀǹÌÀÖ´Â Á¶Ä¡°¡ ÃëÇØÁöµµ·Ï ¹Ýµå½Ã ÀûÀýÈ÷ ¾ö°ÝÇÏ°Ô Àû¿ëµÇ¾î¾ß¸¸ ÇÑ´Ù. ÁÁÀº ¼Ò½ÄÀº (±×¸®Çϸé) ÀÌ·¯ÇÑ ¹®Á¦Á¡µéÀÌ ºñ±³Àû ¼Õ½±°Ô Ä¡À¯µÈ´Ù´Â Á¡ÀÌ´Ù.
 
ÀÌ ±ÛÀº °ð ¹ß°£µÉ ºê¶óÀ̾ð ¹Ù´Ï¾îÀÇ Ã¥(±ÝÀ¶ ȸ»ç¸¦ À§ÇÑ ¿ÀÆÛ·¹ÀÌ¼Ç À§Çè ÇÚµåºÏ)¿¡¼­ °¢»öµÇ¾ú´Ù.
 
Brian Barnier, CGEIT, is a principal at ValueBridge Advisors, where he analyzes trends and advises/mentors business and IT leaders to help them accelerate business performance improvement, including risk management. In the past, he has held business, IT and risk roles. Barnier teaches, speaks and researches widely. He can be reached at brian@valuebridgeadvisors.com.

ÀÇ°ß¾²±â

¹øÈ£ Á¦¸ñ ±Û¾´ÀÌ ³¯Â¥ Á¶È¸ Ãßõ
¹ø¿ª¿¡ ´ëÇÑ º¯ (1) ½ÅÀÎö 07-03-24 7828 17
38 ¿£ÅÍÇÁ¶óÀÌÁîÀÇ °³³ä ½ÅÀÎö 13-01-08 2402 8
37 ÅëÁ¦¸¦ Áø´ÜÇϱâ Àü¿¡ ´øÁ®¾ß ÇÒ 5°¡Áö Áú¹® By Brian Barnier, CGEIT ½ÅÀÎö 11-06-13 2673 9
36 Ŭ¶ó¿ìµå ÄÄÇ»ÆÃ, ¹ý±Ô ±×¸®°í µ¥ÀÌÅÍ º¸¾È À§Çè¿¡ °üÇÑ ÀÔ¹® By Carl Cadregari, and Alfonzo Cutaia, Esq (4) ½ÅÀÎö 11-05-31 5441 20
35 Àü»ç À§Çè °ü¸®¿¡¼­ÀÇ IT ½Ã³ª¸®¿À ºÐ¼® By Urs Fischer, CISA, CRISC, CPA Swiss ½ÅÀÎö 11-05-04 5290 11
34 º¸¾ÈÀÇ °¡Ä¡´Â ¹«¾ùÀΰ¡? By Steven J. Ross, CISA, CISSP, MBCP ½ÅÀÎö 11-04-17 3233 10
33 º¸¾È Á¤Ã¥À» ÀÛ¼ºÇÏ´Â ¹æ¹ý: ³×Æ®¿öÅ© º¸¾È Á¤Ã¥ ¸Å´º¾ó by Paul R. Meynen ½ÅÀÎö 11-03-25 3579 14
32 ¼ÒÇÁÆ® IT °Å¹ö³Í½º By Kazuhiro Uehara, CGEIT, CISA, CIA, PMP, and Sayaka Akino, CISA ½ÅÀÎö 11-01-31 3522 13
31 IS °³¹ß ÇÁ·ÎÁ§Æ®¿¡¼­ À§Çè °ü¸®¸¦ À§ÇÑ ¡®¿ä±¸»çÇ× ÁïÈZ¡¯ °ü¸® by Sachidanandam Sakthivel ½ÅÀÎö 11-01-20 3456 12
30 ÇÑ°¡Áö Áß¿äÇÑ Áú¹® by Steven J. Ross ½ÅÀÎö 11-01-11 3184 13
29 ¼­ºñ½º °¡¿ë¼º°ú ÀçÇØ º¹±¸ by Steven J. Ross ½ÅÀÎö 11-01-05 4572 13
28 ISO/IEC 38500 ¿¡ ±â¹ÝÇÑ IT °Å¹ö³Í½ºÀÇ ±Ùº» by Haris Hamidovic ½ÅÀÎö 10-12-02 5110 15
27 IT À§Çè ºÐ¼® – ºü¶ß¸°¡°A¡± By Eric J. Brown and William A. Yarberry Jr., ½ÅÀÎö 10-11-08 3766 20
26 Ŭ¶ó¿ìµå ÄÄÇ»ÆÃÀÇ ÇöȤ (Cloudy Daze) by Steven J. Ross ½ÅÀÎö 10-03-03 3936 16
25 IT °Å¹ö³Í½º¸¦ ÇÑ Â÷¿ø ²ø¾î¿Ã¸®±â À§ÇÑ 5°¡Áö ÆÁ By Brian Barnier ½ÅÀÎö 10-01-22 3340 14
24 ¿ä¾à: ¸Å·ÂÀÖ´Â ÀüÇâÀû °Å¹ö³Í½º ¸ÅÇÎ À̴ϼÅƼºê By ISACA (¹ø¿ªÀÚ Ãßõ) ½ÅÀÎö 09-08-10 3626 13
 1  2  3