레이블이 Compliance인 게시물을 표시합니다. 모든 게시물 표시
레이블이 Compliance인 게시물을 표시합니다. 모든 게시물 표시

2015년 4월 29일 수요일

How important is email archiving? Just ask Hilary

최근에 개인메일을 사용한 힐러리 사건을 이메일게이트(EmailGate)라고 표현합니다. 개인적으로 보관하는 것은 자료들이 보호받지 못하고 향후 참조될 수 없어서 문제라고 하고, 클라우드를 사용하든지 다양한 디바이스를 사용하던지 하나의 레퍼지토리에 저장해서 조회, 검색할 수 있어야 한다고 합니다.

IDC에서도 회사의 60% 중요정보들이 이메일에 저장되어 있어 중요하지만, 개인적인 USB이나 개인저장소에 저장되어 있다고 합니다.

디바이스가 다양해 지고 저장의 영역이 모호해지면서 자동 아카이빙(automated archiving) 영역도 필요해보입니다.

==========================================

Hilary Clinton’s announcement of her candidacy for the Democrat nomination for the US presidency in a youtube video highlighted the increasing importance of social media in the modern world, but it was in marked contrast to her cavalier approach to emails in her time as US Secretary of State.
An article in the New York Times in March revealed Clinton had preferred to use her personal email address instead of her official .gov government e-mail address when she was Secretary of State between 2009 and 2013.


The National Archives and Records Administration (NARA) described this unusual situation as a “serious breach” of federal practices and the duty to preserve emails from government officials.
Using her private account meant Clinton’s emails were not protected, were not preserved for future reference and were unsearchable by the State Department. Unsurprisingly, this has raised questions over how a high ranking government official was able to make such exclusive use of her personal account for sensitive, work-related emails.
While Clinton’s case is unlikely to be unique, it is sufficiently high profile to help focus people’s attention on the significance of email to businesses and administrations. According to IDC, 60 per cent of critical information is stored in emails and many of them are generated and stored in USB keys or personal devices.
The onus is on companies and organisations to manage their employees’ emails to ensure they are accessible securely from anywhere and on any device, anytime. But as employees use new devices or share data in new ways, organisations need to stay on top of those developments and incorporate new forms of data into their governance plans. Otherwise, important data sources will be left unprotected and inaccessible.
The best way to ensure vigilant monitoring and data collection is through a single virtual repository that captures and stores data, whether it’s archived or backed up, in the public or private cloud, from all types of devices. With such a repository, data can be fully searched from a single location and deduplicated. The result is better control of applications, processes and data workflows across the organisation.
Very few companies or organisations, large or small, think to protect emails even though they contain documents and information of the utmost importance. But given their significance, they really ought to ensure emails are protected and accessible, especially for legal and information management purposes.
From a legal standpoint, it is essential to maintain the integrity of emails that need to be retained for a statutory period for legal and compliance reasons. It is also crucial that the proper information management structure is in place to organise data in a consistent and sustainable manner so emails can be properly archived and the information they contain can be easily accessed.
Automated archiving is a simple way to achieve those goals, to protect the sustainability of a company or organisation and to safeguard its image. The fall out from Hilary Clinton’s “Emailgate” demonstrates that organisations often don’t realise their internal information management strategy is ineffective, or even non-existent, until something bad happens.

Organisations need to think about the cost, risk and exposure implications of their information management strategy.
Nobody wants to be the poster child for the next Emailgate. Starring in negative headlines in the media is the worst way to discover there’s something wrong with your information management strategy, especially when it can be so easily prevented.


Read more: http://www.itproportal.com/2015/04/29/how-important-is-email-archiving-just-ask-hilary/#ixzz3YkjGm8xh

2015년 3월 4일 수요일

힐러리 국무장관 시절 개인 이메일 사용 ‘논란’

회사에서도 개인 이메일을 이용하여 업무상 이메일을 보내는 것을 회사차원에서 금지해야 합니다. 중요 메일이 누락될 수 있고, 미래에 위험에 대비하여야 합니다.

=================================================

미국 유력 차기 대권주자인 힐러리 클린턴 전 국무장관이 장관 재직 시절 정부기관이 발급한 이메일계정 대신 개인 이메일 계정을 썼다가 구설수에 올랐다.

뉴욕타임스는 클린턴 전 장관이 국무장관으로 재직하는 동안 개인 이메일 계정을 이용했고, 업무상 이메일을 국무부 서버에 저장해야 한다는 규정도 지키지 않았다고 3일(현지시간) 보도했다. 국무장관으로서 타국 지도자들과 주고받은 민감한 정보가 담긴 이메일이 별도의 보안조치가 돼있지 않은 개인 계정을 통해 오갔다는 뜻이다. 보안전문가들은 “개인 계정에는 보안 문제가 있을 수 있다”고 지적했다.

더구나 클린턴 전 장관은 이메일을 국무부 서버에 저장하지도 않았던 것으로 알려져 미국판 ‘사초 폐기’ 논란이 일고 있다. 미국 연방법은 연방 관리들이 주고받은 이메일들을 국가기록물로 간주하고 의회 위원회 구성원들이나 사학자, 언론인 등이 찾아볼 수 있도록 보관하도록 돼 있다. 기밀이나 민감한 내용만 여기서 제외된다. 

제이슨 배런 전 국립문서기록보관소(NARA) 소송담당 국장은 “장관급 인사가 의사소통 채널로 개인 이메일을 이용하도록 기관이 허용했다는 것은 상상하기 어려운 시나리오다”라고 말했다. 다른 국무장관들도 업무에 개인 이메일을 사용한 적은 있었지만, 클린턴 전 장관처럼 정부 이메일 계정을 만들지도 않고 임기 내내 개인 이메일만 사용한 경우는 거의 없었다고 배런 전 국장은 설명했다. 

2013년 초 물러난 클린턴 전 장관은 지난해 10월에야 국무부의 기록 제출 요청을 받고, 수만 페이지에 달하는 개인 이메일들을 검토한 뒤 5만5000페이지 분량의 업무상 이메일을 국무부에 넘겼다. 클린턴 전 장관 측은 “규칙을 지켰다”고 답했을 뿐 개인 이메일을 이용한 이유에 대해서는 설명하지 않았다.

2013년 9월 9일 월요일

[특별기고] 기업 보안 담당자, 컴플라이언스 이슈 따라잡기

[특별기고] 기업 보안 담당자, 컴플라이언스 이슈 따라잡기
등록 : 13-09-09 07:39 , 데일리시큐 길민권기자 , mkgil@dailysecu.com
관련 법률 항상 주목하고 관련 내용 잘 알고 있어야!
대한민국은 전세계에서 정보보호와 관련 법규가 가장 엄격하고 구체적인 것인 나라 중에 하나로 알려져 있다. 이러한 환경 속에서 기업 보안 담당자는 항상 컴플라이언스에 대해서 부족한 부분이 있다고 생각이 들 수 밖에 없으며 최근에 떠오르는 이슈에 대해서 항상 민감할 수 밖에 없게 된다. 컴플라이언스, 즉 법률은 기업 내의 법무 담당자만의 역할이라고 생각할 수 있겠지만 정보보호와 관련해서 실제 기업 보안담당자가 법률을 준수해야 되는 책임을 질 수 밖에 없기 때문에 관련 법률을 항상 주목하고 관련 내용을 잘 알고 있어야 한다.(사진. SK컴즈 송재훈 매니저)

기업의 보안 담당자가 정보보호와 관련된 컴플라이언스를 잘 파악하고 준수를 하기 위해서 제일 먼저 해야 하는 것은 현재 본인이 담당하고 있는 기업이 온라인 및 오프라인에서 매진하고 있는 사업이 무엇인지 파악을 하는 것이다. 두가지 모두를 파악해야 되는 이유는 온라인 또는 오프라인 사업이 메인이어서 반대쪽 분야에서 어떤 사업을 하고 있는지 잘 모르고 있는 경우가 있기 때문이다. 그리고 오랫동안 보안 업무를 수행하고 있는 기업 보안 담당자라고 하더라도 정보통신망법, 개인정보보호법 외에는 잘 모르거나 신경을 쓰지 않는 부분이 있다.

하지만 좀 더 자세히 파악을 하게 되면 실제로 기업이 사업을 하기 위해서 준수해야 되는 법률이 생각보다 많으며, 이러한 법률 가운데에는 기업 보안 담당자가 고려해야 되는 내용인 정보보안, 정보시스템 운용 또는 좀 더 넓게 내부 통제와 관련된 부분을 찾아 낼 수 있는 경우가 있다. 예를 들어 만약 기업이 전자상거래를 하는 기업이라고 한다면 대표적인 법률은 아마도 “전자상거래 등에서의 소비자보호에 관한 법률”일 것이며, 이 법률에서는 전자상거래와 관련된 정보시스템의 로그 보관 기관 및 항목에 대해서 규정을 하고 있다는 것을 알 수 있을 것이다.

기업이 준수해야 되는 법률 중에 기업 보안담당자가 관심있게 봐야 하는 법률을 선정한 후에 해야 되는 내용은 관련 법률과 시행령, 시행규칙, 고시 또는 모범규준, 가이드 및 해설서를 참고를 해서 정확한 내용이 무엇인지 좀 더 상세하게 파악을 하는 것이다.  우선 현재 공표된 법률의 경우에는 “국가법령정보센터”에서 쉽게 관련 정보를 구할 수 있으며, 가이드 및 해설서의 경우에는 “한국인터넷진흥원”, “보호나라”, “개인정보 종합지원포탈” 이나 해당 법률과 관련된 공공기관의 홈페이지에서 찾을 수 있다.

이렇게 정보를 확인하고 수집을 하더라도 일반적으로 법률 전문가가 아닌 기업 보안 담당자는 법률의 해석에 어려움을 겪을 수 밖에 없게 된다. 이러한 경우에는 우선 관련 법률의 제1조인 목적이나 제개정 사유를 참고를 해서 해석을 하고, 법률에서 특별히 대상을 제한하는 용어를 사용하지 않았다면 보수적으로 해석을 하는 것이 맞을 것이다. 간혹 관련 법규에 따라서 적용해야 되는 내용이 다른 경우나 상충되는 경우가 있는데 이러한 경우에는 법률이나 해설서 등에 설명되어져 있는 타 법률간의 관계를 잘 읽어볼 필요가 있다.

특히 법률의 준수 대상에 대해서는 기존에는 정보시스템에 주로 한정이 되어 있던 것이 개인정보보호와 관련된 내용이 강화되면서 수탁사에 대한 위탁사의 감독과 같은 조항이 추가되어 수탁사까지 준수 대상으로 고려를 하여야 한다. 최근 여러 법률에서 정보보호와 관련된 내용을 다루고 있어 서로 상충 또는 중복 되는 부분이 있어서 해석에 어려움이 있다면 기업 내의 법무 담당자나 외부의 자문 변호사 또는 관련 공공기관에 문의를 하여 도움을 받는 것이 좋다.

법률에 대한 검토가 완료가 되었다면 실제로 담당하고 있는 기업에서 현재 준수를 하고 있는지 준수를 하고 있지 못하면 어떻게 준수를 해야 될 것인지에 대해서 대책을 마련하고 현업과 협의를 하여야 한다. 대책은 다음과 같이 세가지 정도를 마련할 수 있을 것이며 어떤 대책을 선택할지는 현업과 협의 후에 의사결정권자의 결정 후 수행을 하면 될 것이다.

첫번째 대책으로는 법률을 준수를 하기에는 너무 많은 인력, 시간 또는 비용이 소요되며 해당 사업이 큰 이익을 내지 못한다면 해당 사업에서 철수하는 것이다. 두번째 대책으로는 법률을 준수해야 되는 조직 또는 시스템을 최소한으로 축소하는 것이다. 예를 들어 최근에 이슈가 된 PC 망분리의 경우에는 개인정보처리시스템, 개인정보취급자를 최소화함으로써 법률을 준수하기 위해서 소요되는 비용을 최소화할 수 있게 된다. 세번째는 법률을 준수해야 되는 사업이 기업의 핵심 사업이어서 조직이나 시스템 등이 큰 경우로써 이러한 경우에는 우선 순위를 정해서 계획을 마련을 하고 이행을 하는 것이다.

이렇게 준수하고 있는 법률이 자주 변경이 되지 않는다면 기업 보안 담당자로서는 좋은 일이지만 정보통신망법의 경우에는 상당히 자주 바뀌는 법률이기 때문에 항상 어떻게 변경이 되는지에 대해서 알고 있어야 한다. 아직 국회에서 통과가 되지 않은 개정안의 경우라고 한다면 “대한민국 국회” 홈페이지에서 관련 법령에 대해서 검색을 하게 되면 현재 국회에서의 진행 경과를 알 수 있다. 이러한 법률은 통과되고 필요한 경우 시행규칙이나 고시까지 나오는 경우에는 다소 시간이 걸리기 때문에 사전에 유관 부서에 알려서 준비를 할 수 있도록 하는 것도 중요하다.

또한 현재 가장 이슈가 많이 되고 있는 정보통신망법과 개인정보보호와 관련되는 내용의 경우 관련 판례와 개인정보 분쟁 조정 사례를 파악을 하면 업무에 많은 도움이 될 수 있다. 판례의 경우에는 언론 보도에 난 요약된 정보만으로는 도움이 되지 않는 경우가 있기 때문에 대한민국 법원 대국민서비스 홈페이지에서 판결과 관련해서 검색을 해서 공개된 판결문을 다운로드 하여 읽어보거나 국가법령정보센터에서도 판례 페이지를 읽어 보면 실제 업무를 하면서 생각했던 것과는 다르게 법원에서 법률을 해석하는 경우를 발견할 수도 있게 되는데 이러한 경우에는 기존에 수립했던 대책 중에 누락이 되거나 한 부분이 없는지 다시 한번 점검을 해볼 필요가 있다.

컴플라이언스와 관련해서는 누구도 정확하게 답을 줄 수는 없지만 기업 보안 담당자가 이 분야에 대해서 경험과 지식이 많게 되면 Business Diabler라는 인식이 차츰 Enabler로 바꿀 수 있을 것으로 생각이 들며 그렇게 된다면 기업 내에서 기업 보안 담당자에 대한 인식도 개선이 될 것으로  기대해 본다.

글. SK커뮤니케이션즈 보안문화팀 송재훈 매니저

2013년 1월 27일 일요일

[기사] 8 Steps to Effective Data Compliance






출처 : http://www.business2community.com/strategy/8-steps-to-effective-data-compliance-0382976


컴플라이스언스가 서서히 국내에서도 도입되고 있습니다. 기사에서도 언급하듯이 컴플라이언스 준수를 못했을 경우의 충격을 고려한다면 빨리 도입해야 할 것입니다. 그러데 어떻게 준비할까요? 여기에서 제시하는 8가지 단계를 적용해보시죠.

1. 필요한 법적 요구사항들 정리

2. 컴플라이언스 절차 준비

3. 필요한 데이타 솔루션을 확보

4. 자체적으로 감사실시

5. 보안강화

6. 재난에 대비

7. 작은 이슈도 챙기자

8. 자체 감사를 지속적으로



8 Steps to Effective Data Compliance




If you were to write down a list of your organization’s vital functions, in order of importance, where would data compliance appear? Far too many organizations push data compliance towards the bottom of the list. Considering the potential damage non-compliance can cause, you need to start pushing it back to the top of your priorities.

  1.     Assess Your Regulatory Requirements

The first step may seem obvious but you’d be surprised at how many organizations implement procedure and buy equipment before reviewing their data compliance requirements. Especially in less regulated industries. It’s a simple step; it’s an easy one to miss too.

  2.     Set/Edit Data Compliance Procedure

Once you have reviewed your requirements you need to address policy. Every member of staff from the top down should be aware of their individual responsibilities. The most common data compliance problem isn’t a lack of procedure; it’s individual errors or confusion over requirements.

  3.     Identify Appropriate Data Solutions

At the same time, you need to make sure you have the appropriate hardware and software to retain your data. You should assess your data backups and email archiving capabilities and ensure they provide the appropriate space and security. It’s also important to check on your ability to present data. A lot of businesses get into difficulty with data they have but can’t access.

  4.     Self-Audit Regularly

The key to data compliance is self-audit, you need to set a schedule and stick to it. They are vital in identifying gaps and highlighting best practice. The more you audit, the better your compliance.

  5.     Keep Security Up-to-Date

Data security isn’t just about locking the door to the server room. You need to stay on top of your security and encryption software and keep it up to date. That means following trends and reviewing industry changes. Not just clicking ‘update software’ once a week.

  6.     Be Disaster Ready

Last years East Coast Superstorm in the US demonstrated just how unpredictable the weather can be. You can’t afford to assume your data is secure in one location. The most comprehensive data compliance strategies include disaster recovery. Because you just never know when disaster will strike.

  7.     Don’t Ignore Minor Issues

Data compliance is a broad term; it’s easy to think of it as an organizational issue only. But all it takes is one misplaced document or one security breach to cause real problems. Don’t let minor issues grow; tackle them as soon as they’re identified.

  8.     Self-Audit Regularly

That’s not a typo. The key to data compliance really is self-audit and it never stops.

Read more at http://www.business2community.com/strategy/8-steps-to-effective-data-compliance-0382976#PQZIycf4mh2pQsVi.99