RISS 학술연구정보서비스

검색

인기 검색어

    다국어 입력

    http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

    변환된 중국어를 복사하여 사용하시면 됩니다.

    예시)
    • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
    • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
    닫기

    국가 클라우드 컴퓨팅 보안 가이드라인과 글로벌 프레임워크와의 비교를 통한 정보보안 책임 구조 분석

    한글로보기

    https://www.riss.kr/link?id=T17395463

    • 0

      상세조회
    • 0

      다운로드
    서지정보 열기
    • 내보내기
    • 내책장담기
    • 공유하기
    • 오류접수
    인용문이 복사되었습니다.

    부가정보

    다국어 초록 (Multilingual Abstract) kakao i 다국어 번역

    With the rapid expansion of cloud adoption in both the public and private sectors, and the growing prevalence of hybrid and multi-cloud architectures, the “shared responsibility model” has become a common reference for allocating security and operational duties among cloud service providers (CSPs), customer organizations, and third parties. However, high-level descriptions of shared responsibility in guidelines and certification schemes often leave practical “control gaps” in which ownership of key security controls is unclear, overlapping, or fragmented. Misconfigurations, over-privileged identities, and unmonitored SaaS or backup services in recent incidents illustrate that such gaps can be directly linked to real-world breaches. This study conceptualizes these control gaps from a shared responsibility perspective and examines how they appear in Korea’s national cloud security guidance compared with major international frameworks.
    The research employs a structured document review and qualitative comparative analysis. First, it defines a multidimensional analytical matrix that crosses service models (IaaS, PaaS, SaaS), deployment models (public, private, hybrid, multi-cloud), security control domains (governance and organization; infrastructure and network; virtualization and platform; data and application; identity and access management; logging, monitoring, and incident response), and responsible entities (customer organization, CSP, third party). Using this matrix, the study maps and compares security controls across Korea’s national cloud computing security guideline and cloud security certification scheme, and overseas indicators including NIST and NSA/CISA guidance, FedRAMP, DoD SRG, CSA Cloud Controls Matrix, and ISO/IEC 27017/27018. The analysis is further interpreted through the lens of zero trust architecture, focusing on identity- and log-centric controls.
    The results show that the Korean guideline functions effectively as a minimum baseline checklist for public agencies, but offers limited explicit modeling of which party holds primary, shared, or supporting responsibility for individual controls, especially in complex hybrid and multi-cloud settings. In contrast, overseas frameworks tend to provide more granular control catalogues, explicit role–control mappings, and, in many cases, risk- and maturity-based models that can guide stepwise improvement.
    The study identifies notable control gaps around hybrid and multi-cloud governance, SaaS and backup services, third-party managed security and integrated monitoring, and zero-trust-related identity and logging controls. It suggests complementing the national guideline with responsibility matrices and maturity-oriented checklists derived from international frameworks to reduce control gaps and strengthen cloud security governance in the public sector.
    번역하기

    With the rapid expansion of cloud adoption in both the public and private sectors, and the growing prevalence of hybrid and multi-cloud architectures, the “shared responsibility model” has become a common reference for allocating security and oper...

    With the rapid expansion of cloud adoption in both the public and private sectors, and the growing prevalence of hybrid and multi-cloud architectures, the “shared responsibility model” has become a common reference for allocating security and operational duties among cloud service providers (CSPs), customer organizations, and third parties. However, high-level descriptions of shared responsibility in guidelines and certification schemes often leave practical “control gaps” in which ownership of key security controls is unclear, overlapping, or fragmented. Misconfigurations, over-privileged identities, and unmonitored SaaS or backup services in recent incidents illustrate that such gaps can be directly linked to real-world breaches. This study conceptualizes these control gaps from a shared responsibility perspective and examines how they appear in Korea’s national cloud security guidance compared with major international frameworks.
    The research employs a structured document review and qualitative comparative analysis. First, it defines a multidimensional analytical matrix that crosses service models (IaaS, PaaS, SaaS), deployment models (public, private, hybrid, multi-cloud), security control domains (governance and organization; infrastructure and network; virtualization and platform; data and application; identity and access management; logging, monitoring, and incident response), and responsible entities (customer organization, CSP, third party). Using this matrix, the study maps and compares security controls across Korea’s national cloud computing security guideline and cloud security certification scheme, and overseas indicators including NIST and NSA/CISA guidance, FedRAMP, DoD SRG, CSA Cloud Controls Matrix, and ISO/IEC 27017/27018. The analysis is further interpreted through the lens of zero trust architecture, focusing on identity- and log-centric controls.
    The results show that the Korean guideline functions effectively as a minimum baseline checklist for public agencies, but offers limited explicit modeling of which party holds primary, shared, or supporting responsibility for individual controls, especially in complex hybrid and multi-cloud settings. In contrast, overseas frameworks tend to provide more granular control catalogues, explicit role–control mappings, and, in many cases, risk- and maturity-based models that can guide stepwise improvement.
    The study identifies notable control gaps around hybrid and multi-cloud governance, SaaS and backup services, third-party managed security and integrated monitoring, and zero-trust-related identity and logging controls. It suggests complementing the national guideline with responsibility matrices and maturity-oriented checklists derived from international frameworks to reduce control gaps and strengthen cloud security governance in the public sector.

    더보기

    목차 (Table of Contents)

    • Ⅰ. 서론 01
    • A. 연구 배경 및 필요성 01
    • 1. 디지털 전환과 클라우드 도입 확산 01
    • 2. 하이브리드·멀티 클라우드 환경의 보안 복잡성 01
    • 3. 클라우드 책임 공유 모델의 한계 02
    • Ⅰ. 서론 01
    • A. 연구 배경 및 필요성 01
    • 1. 디지털 전환과 클라우드 도입 확산 01
    • 2. 하이브리드·멀티 클라우드 환경의 보안 복잡성 01
    • 3. 클라우드 책임 공유 모델의 한계 02
    • 4. 최근 클라우드 보안 사고 사례와 정책적 시사점 02
    • B. 연구 목적 및 연구 방향 04
    • 1. 책임 공유 모델 관점에서의 통제 공백 규명 04
    • 2. 국내·외 지표 비교를 통한 문제점 도출 04
    • 3. 정책·기술 관점을 통합한 분석 프레임 제시 04
    • 4. 연구 결과의 활용 방향 및 기대 효과 제시 05
    • C. 연구 범위 및 대상 05
    • 1. 기술적 범위 05
    • 2. 보안 범위 05
    • 3. 정책·지표 범위 06
    • 4. 연구의 한계 06
    • D. 연구 방법 및 논문의 구성 07
    • 1. 문헌 조사 및 선행 연구 분석 방법 07
    • 2. 책임 공유 모델 관점의 분석 틀 적용 방법 07
    • 3. 국가·해외 클라우드 보안 지표 비교 분석 방법 07
    • 4. 논문의 전체 구성 및 전개 흐름 07
    • Ⅱ. 클라우드 컴퓨팅 및 보안 이론 08
    • A. 클라우드 컴퓨팅 개요 08
    • 1. 클라우드 서비스 모델 정의 및 특징 08
    • 2. 서비스 모델의 구조와 특징 11
    • 3. 배포 모델 유형 16
    • 4. 가상화 및 컨테이너 기반 클라우드 인프라 구조 22
    • B. 클라우드 책임 공유 모델 23
    • 1. 책임 공유 모델의 개념 23
    • 2. 주요 CSP별 책임 범위 비교 24
    • 3. 서비스·배포 모델별 책임 매트릭스 구조화 24
    • 4. 조직·CSP·제3자의 역할 구분 25
    • C. 클라우드 보안 위협 및 통제 기본 개념 26
    • 1. 클라우드 환경의 주요 보안 위협 분류 26
    • 2. 가상화·컨테이너·네트워크 계층의 보안 이슈 26
    • 3. 데이터 수명 주기별 보안 요구사항 27
    • 4. 인증·권한·관리·감사 통제의 기본 구조 28
    • D. 제로 트러스트 보안 아키텍처 개요 28
    • 1. 제로 트러스트의 등장 배경과 보안 패러다임 변화 28
    • 2. 제로 트러스트의 핵심 원칙 29
    • 3. 클라우드 환경에서 적용 가능한 주요 요소 29
    • 4. 책임 공유 모델과의 연계 30
    • Ⅲ. 선행 연구 및 기술·정책 동향 31
    • A. 클라우드 보안 위협 및 취약점 연구 동향 31
    • 1. 서비스 모델별(IaaS/PaaS/SaaS) 위협 분석 연구 31
    • 2. 하이브리드·멀티 클라우드 보안 이슈 관련 연구 34
    • 3. 통합 관제·로그 분석·침해 대응 관련 연구 동향 35
    • B. 책임 공유 모델 및 통제 공백 관련 연구 37
    • 1. 책임 공유 모델 정의 및 확장 모델 제안 연구 37
    • 2. 책임 불명확성으로 인한 사고·사례 분석 연구 37
    • 3. 통제 공백 분석 프레임워크 제안 동향 38
    • C. 클라우드 보안 기술·솔루션·특허 동향· 40
    • 1. CSP 보안 서비스 및 관리·통제 자동화 기술 40
    • 2. 컨테이너·가상화 환경 보안 및 접근통제 기술 41
    • 3. 아이덴티티 관리·단말 보안·AI 기반 보안 기술 43
    • D. 국내·외 클라우드 보안 표준 및 가이드라인 동향 46
    • 1. 국내 클라우드 보안 관련 법·제도·지침·인증제 동향 46
    • 2. 국제표준 및 글로벌 프레임워크 동향 46
    • 3. NIST, ENISA, CISA 등 주요국 정책 프레임 동향 47
    • 4. 정책·지표 중심 기존 연구 및 한계 정리 47
    • Ⅳ. 선행 연구 및 기술·정책 동향 48
    • A. 클라우드 보안 위협 및 취약점 연구 동향 48
    • 1. 분석 대상 국내 국가 클라우드 컴퓨팅 보안 가이드라인 개요 48
    • 2. 비교 대상 해외 지침·표준·인증제 선정 기준 49
    • 3. 책임 공유 모델 관점의 비교 프레임 구성 50
    • 4. 비교 관점 정의 50
    • B. 국내 가이드라인의 책임 구조 분석 51
    • 1. 통제 영역 및 세부 통제 항목 구성 분석 51
    • 2. 책임 주체별 역할 및 범위 분석 52
    • 3. 공공·민간 클라우드 도입 시 적용 사례 및 한계 52
    • C. 해외 가이드라인 및 인증제도의 책임 구조 분석 53
    • 1. 미국 NIST·FedRAMP 등 클라우드 보안 프레임워크 구조 53
    • 2. 유럽 ENISA, EU 관련 클라우드 보안 지침 분석 54
    • 3. 국제표준과 기타 주요국 지침 개관 54
    • 4. 책임 공유 모델 관점에서 본 해외 지표의 특징 55
    • D. 책임 공유 모델 기반 국내·외 지표 비교 및 통제 공백 논의 56
    • 1. 통제 항목 커버리지 및 깊이 비교 56
    • 2. 책임 배분·역할 정의의 명확성 비교 56
    • 3. 위험 관리·보안 성숙도 평가 지표 비교 57
    • 4. 문헌·지표 수준에서 도출되는 통제 공백 및 시사점 58
    • Ⅴ. 결론 59
    • A. 연구 결과 요약 59
    • B. 학문적·실무적 시사점 61
    • C. 연구 한계 및 향후 연구 과제 62
    • 부록 A. 국·내외 지표 64
    • 부록 B. 통제 항목 매핑표 88
    • 참고 문헌 92
    • Abstract 98
    더보기

    분석정보

    View

    상세정보조회

    0

    Usage

    원문다운로드

    0

    대출신청

    0

    복사신청

    0

    EDDS신청

    0

    동일 주제 내 활용도 TOP

    더보기

    주제

    연도별 연구동향

    연도별 활용동향

    연관논문

    연구자 네트워크맵

    공동연구자 (7)

    유사연구자 (20) 활용도상위20명

    이 자료와 함께 이용한 RISS 자료

    나만을 위한 추천자료

    해외이동버튼