RESOURCE GUIDE · V2.0.0

Part 16

디지털 인프라 거버넌스 참고자료

본문 인용은 각 챕터에 표시하고, 전체 참고자료는 이 부록에서 출처별로 확인한다.

BOUNDARY경계
ACCESS권한
COST비용
RISK리스크

CLOUDAI

발행
버전
2.0.0
작성
801 PLANET
기술 검토
최종 검토
공개 출처
28
목차참고자료
  1. Part 0–2가이드 허브·공통 원리
  2. Part 3계정·조직
  3. Part 4IAM
  4. Part 5FinOps
  5. Part 6클라우드 보안
  6. Part 7AI 사용·자산
  7. Part 8에이전트 접근 통제
  8. Part 9AI 비용
  9. Part 10AI 리스크
  10. Part 11–12운영 모델·로드맵
  11. Part 13통합 컴플라이언스
  12. Part 14실행 체크리스트
  13. Part 15용어집
  14. Part 16참고자료
    1. 클라우드 — 업계 표준·공식 문서
    2. AI — 업계 표준·규제·2차 자료

가이드 작성에 참고한 클라우드·AI 표준, 규제, 벤더 공식 문서와 사례 자료를 정리한다.

클라우드 — 업계 표준·공식 문서
  • AWS, "AWS multi-account strategy for your AWS Control Tower landing zone", AWS 공식 문서

  • AWS Prescriptive Guidance, "Building a Cloud Center of Excellence within your organization", Rishi Singla 외

  • AWS Well-Architected Framework, "Governance"(Security Pillar)

  • Microsoft, "Cloud Adoption Framework — Govern"(5 Disciplines), "Align responsibilities across teams"(RACI)

  • Google Cloud, Resource Hierarchy & Organization Policy Service 공식 문서

  • FinOps Foundation, "FinOps Framework 2026", "FinOps Maturity Model", Vasilio Markanastasakis

  • Center for Internet Security(CIS), CIS Benchmarks 공식 자료

  • Wiz, "What CIS Benchmarks Are" · CloudQuery, "Cloud Governance Framework: 4-Step Design Guide" · SecurEnds, "Enforcing Least Privilege in Cloud Environments" · Lumenalta, "Cloud governance checklist" · AmpcusCyber, "ISO 27001 Mapping with Security Standards"

AI — 업계 표준·규제·2차 자료
  • AI セーフティ・インスティテュート(日本AISI), "CAIO 설치·AI 거버넌스 실무 매뉴얼"(2026-03-17)

  • 宮脇峻平(Algomatic), "AI 거버넌스 입문"(2026-06-18)

  • NIST, "AI Risk Management Framework"(nist.gov/itl/ai-risk-management-framework)

  • EU, "Artificial Intelligence Act"(artificialintelligenceact.eu)

  • ISO/IEC 42001 국제규격, コーピー(Corpy) AI 안전성 평가 프로토콜 실장 가이드(2026-05)

  • OWASP, "AI Security Verification Standard(AISVS) 1.0"(2026)

  • n-okutomi(Qiita), "생성AI 보안 입문 — 기업에서 일어나는 리스크와 중대 인시던트"(2026-07-12)

  • Anthropic 공식, "Agent Identity: a new access model for autonomous, team-wide AI"(2026-06-24)

  • Google Cloud, "Configure semantic governance policies"(Gemini Enterprise Agent Platform 문서)

  • Microsoft, Entra Agent ID / Agent 365 거버넌스 GA 발표(2026-07-07)

  • KAG Claude Enterprise 전사 롤아웃 사례(2026-07-03)

면책: 이 가이드는 업계 표준과 공개 자료를 종합한 일반 지침이며, 법률 자문이나 특정 규제 인증에 대한 공식 확인을 대체하지 않는다. 회사의 실제 업종·규모·규제 환경에 맞춘 세부 정책은 법무·컴플라이언스 부서와 함께 최종 확정하라.

CITATIONS · PRIMARY FIRST

이 챕터의 출처

  1. 01
  2. 02
  3. 03
  4. 04
    AWS Control Tower 문서Amazon Web Services
  5. 05
  6. 06
  7. 07
  8. 08
  9. 09
  10. 10
  11. 11
  12. 12
  13. 13
  14. 14
  15. 15
  16. 16
  17. 17
  18. 18
    FinOps FrameworkFinOps Foundation
  19. 19
  20. 20
    FOCUS 사양FinOps Foundation
  21. 21
    FinOps for AIFinOps Foundation
  22. 22
    CIS BenchmarksCenter for Internet Security
  23. 23
    ISO/IEC 42001:2023 — AI 매니지먼트 시스템International Organization for Standardization
  24. 24
    NIST AI Risk Management Framework 1.0National Institute of Standards and Technology
  25. 25
  26. 26
  27. 27
    일본 AI 사업자 가이드라인일본 경제산업성·IPA/AISI
  28. 28