¾Æ·¡ÀÇ ³»¿ëÀº COBIT Mapping - Overviewof International IT Guidance, 2nd Edition °¡¿îµ¥ ÀϺΠ¹ßÃéÇÏ¿© ¹ø¿ªÇÑ °ÍÀÔ´Ï´Ù.
PRINCE2 (Projects in Controlled Environments: ÅëÁ¦µÈ ȯ°æÇÏ¿¡¼ ÇÁ·ÎÁ§Æ®µé)
DOCUMENT TAXONOMY (¹®¼ ºÐ·ù)
Projects in Controlled Environments(PRINCE)´Â ¼º°øÀûÀÎ ÇÁ·ÎÁ§Æ®¸¦ PRINCE2¸¦ °¡Áö°í °ü¸®ÇÑ´Ù´Â Á¡¿¡¼ ¹ßÇàµÈ È¿°úÀûÀÎ ÇÁ·ÎÁ§Æ® °ü¸®¸¦ À§ÇÑ ±¸Á¶Àû ¸Þ¼Òµå(method)¸¦ Á¦°øÇÑ´Ù. ±×°ÍÀº ¿µ±¹ÀÇ OGC(Office of Government Commerce: Á¤ºÎ»ó¹«±¹, ¿ì¸®³ª¶óÀÇ Á¶´Þû¿¡ ÇØ´çµÈ´Ù°í ÇÔ)¿¡ ÀÇÇØ ¹ßÇàµÇ¾ú´Ù. PRINCE2´Â ¾î¶°ÇÑ ÇüÅÂÀÇ ÇÁ·ÎÁ§Æ®¿¡µµ Àû¿ëµÉ ¼ö ÀÖ´Ù.
ISSUER (¹ßÇàÀÚ)
PRINCE2´Â Á¤º¸ ½Ã½ºÅÛ »Ó¸¸ÀÌ ¾Æ´Ï¶ó ¸ðµç ÇÁ·ÎÁ§Æ®µé¿¡ ´ëÇÏ¿© ÇÁ·ÎÁ§Æ® °ü¸®¿¡ °üÇÑ Çâ»óµÈ ¾È³»¼¸¦ ¿øÇÏ´Â »ç¿ëÀÚ ¿ä±¸¿¡ ºÎÀÀÇÏ¿© 1996³â¿¡ ¹ßÇàµÇ¾ú´Ù. PRINCE ¸Þ¼Òµå´Â OGCÀÇ Àü½ÅÀÎ Central Computer and Telecommunications Agency (CCTA)¿¡ ÀÇÇØ 1989³â óÀ½ È®¸³µÇ¾ú´Ù. OGC°¡ ÀÌ ¸Þ¼Òµå¸¦ Áö¼ÓÀûÀ¸·Î Áö¿øÇÏ°í °³¹ßÇÏ°í ÀÖ´Ù.
GOAL OF THE GUIDANCE (¾È³»¼ÀÇ ¸ñÇ¥)
PRINCE2ÀÇ ¸ñÇ¥´Â ÇÁ·ÎÁ§Æ®¿¡¼ ÇÊ¿ä·Î ÇÏ´Â Æø³Ð°í ´Ù¾çÇÑ ±ÔÀ² ¹× È°µ¿µéÀ» ¸Á¶óÇÏ´Â ÇÁ·¹ÀÓ¿öÅ©¸¦ °¡Áö°í ÇÁ·ÎÁ§Æ® °ü¸® ¸Þ¼Òµå¸¦ Á¦°øÇÏ´Â °ÍÀÌ´Ù. PRINCE2 Àü¹Ý¿¡ °ÉÄ£ ÃÊÁ¡Àº ÇÁ·ÎÁ§Æ®¿¡ ´ëÇÑ Å¸´ç¼º°ú ºñÁî´Ï½º Á¤´ç¼ºÀ» ±â¼úÇÏ´Â ºñÁî´Ï½º ÄÉÀ̽º(business case)¿¡ °üÇÑ °ÍÀÌ´Ù. ºñÁî´Ï½º ÄÉÀ̽º´Â Ãʱâ ÇÁ·ÎÁ§Æ® ¼³Á¤(setup)ºÎÅÍ ¼º°øÀû ¸¶¹«¸®±îÁö ¸ðµç ÇÁ·ÎÁ§Æ® °ü¸® ÇÁ·Î¼¼½ºµéÀ» Á¶Á¾ÇÑ´Ù.
ISO/IEC 17799:2005
¹®¼ ºÐ·ù
Á¤º¸ º¸¾È °ü¸®¸¦ À§ÇÑ ½Ç¹« ±ÔÁ¤ÀÎ ISO/IEC 17799:2005 ´Â ±¹Á¦ Ç¥ÁØÀÌ´Ù.
¹ßÇàÀÚ
ÀÌ ±¹Á¦ Ç¥ÁØÀº ±¹Á¦ Ç¥ÁØ ±â±¸(ISO)¿Í ±¹Á¦ ÀüÀÚ±â¼ú Çùȸ(International Electrotechnical Commission: IEC)°¡ ¼³¸³ÇÑ ÇÕµ¿ ±â¼ú À§¿øȸ(a joint technical committee, ISO/IEC JTC 1)¿¡¼ ÃâÆÇÇÏ¿´´Ù. ÀÌ Ç¥ÁØÀÇ ¿ª»çÀû ¿øõÀº ¿µ±¹ Ç¥ÁØÀÎ BS 7799-1À̸ç, ÀÌÀÇ ÇÙ½É ºÎºÐµéÀÌ ISO/IEC 17799:2005 Á¤º¸ ±â¼ú- Á¤º¸ º¸¾È °ü¸®¸¦ À§ÇÑ ½Ç¹« ±ÔÁ¤ÀÇ °³¹ß¿¡ äÅõǾú´Ù. BS 7799´Â ¿µ±¹ Ç¥ÁØ Çùȸ¿¡¼ °³¹ßÇÏ°í ¹ß°£ÇÏ¿´´Ù. Ãʱ⠿µ±¹ Ç¥ÁØÀº µÎ °³ÀÇ ºÎºÐÀ¸·Î ¹ßÇàµÇ¾îÁ³´Ù.
• BS 7799 Part 1: Á¤º¸ ±â¼ú—Á¤º¸ º¸¾È °ü¸®¸¦ À§ÇÑ ½Ç¹« ±ÔÁ¤
• BS 7799 Part 2: Á¤º¸ º¸¾È °ü¸® ½Ã½ºÅÛ—»ç¿ë ¾È³»¼°¡ µ¿¹ÝµÈ ¸í¼¼
Ç¥ÁØ ¹× ¾È³»¼ ¹ßÇà ¸ñÇ¥
ISO/IEC 17799:2005ÀÇ ¸ñÇ¥´Â Á¶Á÷³» Á¤º¸ º¸¾ÈÀ» ±¸ÇöÇÒ Ã¥ÀÓÀÖ´Â ´ç»çÀڵ鿡°Ô Á¤º¸¸¦ Á¦°øÇÏ´Â °ÍÀÌ´Ù. ÀÌ°ÍÀº Á¶Á÷°£ »óÈ£°ü°è¿¡¼ Á¤º¸ º¸¾È¿¡ °üÇÑ ½Å·Ú¼ºÀ» ÁõÁø½ÃÅ°±â À§ÇÏ¿© Á¶Á÷ ³»¿¡ º¸¾È Ç¥ÁØ°ú °í³ª¸® ½Ç¹«¸¦ °³¹ßÇÏ°í À¯Áö°ü¸®Çϱâ À§ÇÑ ¸ð¹ü ½Ç¹«·Î½á º¸¿©Áú ¼ö ÀÖ´Ù. ÀÌ°ÍÀº 11°³ÀÇ ÁÖ¿ä Ç¥Á¦ ÇÏ¿¡ 133°³ÀÇ º¸¾È ÅëÁ¦ Àü·«À» Á¤ÀÇÇÑ´Ù. ÀÌ Ç¥ÁØÀº À§Çè °ü¸®ÀÇ Á߿伺À» °Á¶ÇÏ¸ç ±×¸®°í ±â¼úµÈ ÁöħÀ» ¸ðµç°¡ ¾Æ´Ï¶ó °ü·Ã ÀÖ´Â °Í¸¸À» ±¸ÇöÇÏ¿©¾ß¸¸ ÇÏ´Â °ÍÀ» ºÐ¸íÈ÷ ¹àÈ÷°í ÀÖ´Ù.
PMBOK (Project Management Body of Knowledge, ÇÁ·ÎÁ§Æ® °ü¸® Áö½Ä °³¿ä)
¹®¼ ºÐ·ù
PMBOK °¡À̵å´Â ¡®ÇÁ·ÎÁ§Æ® °ü¸® (Àü¹®) Á÷¾÷¿¡ ÀÖ¾î¼ Áö½ÄÀÇ °³¿ä¡¯·Î½á ±â¼úµÇ¾ú´Ù. PMBOK´Â ¹Ì±¹ Ç¥ÁØ ANSI/PMI 99-001-2004ÀÌ´Ù.
¹ßÇàÀÚ
PMI(Project Management Institute: ÇÁ·ÎÁ§Æ® °ü¸® Çùȸ)¿¡ ÀÇÇØ ¹ß°£µÈ PMBOK °¡À̵å´Â ÇÁ·ÎÁ§Æ® °ü¸®¿¡ °ü½ÉÀÖ´Â »ç¶÷µéÀ» À§ÇÑ ±âº»ÀûÀÎ ÂüÁ¶¹®ÇåÀÌ´Ù.
¾È³»¼ ¸ñÇ¥
PMBOK °¡À̵åÀÇ ¿ì¼± ¸ñÀûÀº ÀϹÝÀûÀ¸·Î ¿ì¼ö ½Ç¹«·Î½á ÀÎÁ¤¹Þ´Â ÇÁ·ÎÁ§Æ® °ü¸® Áö½ÄÀÇ ºÎºÐ ÁýÇÕÀ» ÆľÇÇÏ´Â °ÍÀÌ´Ù. ¶ÇÇÑ, PMBOK °¡À̵å´Â ÇÁ·ÎÁ§Æ® °ü¸®¸¦ Åä·ÐÇÏ°í, Àú¼úÇÏ°í Àû¿ëÇϱâ À§ÇÑ °øÅë »çÀüÀ» Á¦°øÇÏ°í Àå·ÁÇÑ´Ù.
ITIL (IT Infrastructure Library : Á¤º¸±â¼ú ÀÎÇÁ¶ó±¸Á¶ ¶óÀ̺귯¸®)
¹®¼ ºÐ·ù
ITILÀº 8±ÇÀÇ ½Ã¸®Áî·Î µÇ¾îÀÖÀ¸¸ç °íÇ°ÁúÀÇ IT ¼ºñ½º¸¦ Àü´ÞÇϱâ À§ÇÏ¿© IT ¼ºñ½º °ü¸®¸¦ À§ÇÑ ÀÏ°üµÇ°í Á¾ÇÕÀûÀÎ ¸ð¹ü ½Ç¹«·Î½á ºÒ¸°´Ù. ºñ·Ï ´ÜÀÏ Á¤ºÎ ±â°ü¿¡ ÀÇÇØ ÀÛ¼ºµÇ°í ¹ßÇàµÇ¾úÁö¸¸, ÀÌ°ÍÀº Ç¥ÁØÀº ¾Æ´Ï´Ù. 8±ÇÀÇ Ã¥ Á¦¸ñÀº ´ÙÀ½°ú °°´Ù:
• Software Asset Management (¼ÒÇÁÆ®¿þ¾î ÀÚ»ê °ü¸®)
• Service Support (¼ºñ½º Áö¿ø)
• Service Delivery (¼ºñ½º Àü´Þ)
• Planning to Implement Service Management (¼ºñ½º °ü¸®¸¦ ±¸ÇöÇϱâ À§ÇÑ °Ôȹ¼ö¸³)
• ICT Infrastructure Management (Á¤º¸ ¹× Åë½Å ±â¼ú ÀÎÇÁ¶ó±¸Á¶ °ü¸®)
• Application Management (¾ÖÇø®ÄÉÀÌ¼Ç °ü¸®)
• Security Management (º¸¾È °ü¸®)
• Business Perspective (ºñÁî´Ï½º °üÁ¡)
¹ßÇàÀÚ
ITIL ¸ðÀ½Àº Áß¾Ó ÄÄÇ»ÅÍ ¹× Åë½Å±¹(CCTA: Central Computer and Telecommunications Agency), Áö±ÝÀÇ ¿µ±¹ »ó¹«¼º(British Office of Government Commerce), ¿¡¼ ¹ßÇàÇÏ¿´´Ù. OGC°¡ ¿µ±¹ Á¤ºÎ ³»¿¡ IT ÀÚ¿øÀÇ È¿À²ÀûÀÌ°í È¿°úÀûÀÎ ÀÌ¿ëÀ» À§ÇÑ ¹æ¹ý·ÐÀ» °³¹ßÇÒ °ÍÀ» À§ÀÓ¹Þ¾Ò´Ù.
¹ßÇà ¸ñÇ¥
ITIL ¸ñÇ¥´Â ¼ºñ½º °ü¸®¸¦ À§ÇÏ¿© º¥´õ-µ¶¸³Àû Á¢±Ù ¹æ¹ýÀÇ °³¹ßÀÌ´Ù. ÀÌ·¯ÇÑ °³¹ß¿¡ ´ã°ÜÀÖ´Â Á¤½ÅÀº ³ôÀº Ç°ÁúÀÇ IT ¼ºñ½º¿¡¼ ÀÇÇØ °ü¸®µÇ¾î¾ß¸¸ ÇÑ´Ù´Â ³ô¾ÆÁø IT ÀÇÁ¸¿¡ ´ëÇÑ ÀνÄÀÎ °ÍÀÌ´Ù.
COBIT (Control Objectives for Information and relative Technology: Á¤º¸ ¹× °ü·Ã ±â¼úÀ» À§ÇÑ ÅëÁ¦ ¸ñÀû)
¹®¼ ºÐ·ù
COBITÀº IT °Å¹ö³Í½º, ÅëÁ¦ ±×¸®°í º¸ÁõÀ» À§ÇÑ ÀϹÝÀûÀ¸·Î ¹Þ¾Æµé¿©Áö´Â ¸ð¹ü ½Ç¹«·Î½á ºÐ·ùµÉ ¼ö ÀÖ´Â ¹®¼µéÀÇ ¸ðÀ½À¸·Î »ó¡µÈ´Ù.
¹ßÇàÀÚ
COBITÀÇ ÃÊÆÇÀº 1996³â¿¡ Á¤º¸½Ã½ºÅÛ °¨»ç ¹× ÅëÁ¦ Àç´Ü(ISACF: Information Systems Audit and Control Foundation)¿¡ ÀÇÇØ ¹ßÇàµÇ¾ú´Ù. 1998³â 2¹ø° Áõº¸ÆÇÀº Ãß°¡ÀûÀÎ ÅëÁ¦ ¸ñÀû°ú ±¸Çö µµ±¸ ¼¼Æ®(set)¿Í ÇÔ²² ¹ßÇàµÇ¾ú´Ù. 2000³â ITGI¿¡ ÀÇÇؼ ¹ßÇàµÈ ¼Â° ÆÇÀº °æ¿µÀÚ Áöħ°ú ¸î°¡Áö »õ·Î¿î »ó¼¼ ÅëÁ¦ ¸ñÀûÀÌ Ãß°¡µÇ¾ú´Ù. 2005³â¿¡ ITGI´Â COBIT ³»¿ëÀÇ ¿ÏÀüÇÑ °³Á¤À» ¸¶Ä¡°í, ÇöÇà ¹öÀüÀÎ COBIT 4.0À» ¹ßÇàÇÏ¿´´Ù.
ÃâÆÇ ¸ñÇ¥
COBIT ¹Ì¼Ç: ºñÁî´Ï½º Ã¥ÀÓÀÚ, IT Àü¹®°¡ ±×¸®°í º¸Áõ Àü¹®°¡¿¡ ÀÇÇÑ ÀÏ»óÀûÀÎ ÀÌ¿ëÀ» À§Çؼ º¸ÆíÀûÀ¸·Î ¹Þ¾Æµé¿©Áö´Â Á¤º¸ ±â¼ú ÅëÁ¦ ¸ñÀû¿¡ ´ëÇÑ ±ÇÀ§ÀÖ°í, ÃÖ½ÅÀÇ ±×¸®°í ±¹Á¦ÀûÀÎ ¸ðÀ½(set)À» Á¶»çÇÏ°í, °³¹ßÇÏ°í ¼±ÀüÇÏ°í ÃËÁø½ÃÅ°´Â ÀÏ