Part 16
디지털 인프라 거버넌스 참고자료
본문 인용은 각 챕터에 표시하고, 전체 참고자료는 이 부록에서 출처별로 확인한다.
CLOUDAI
목차참고자료
가이드 작성에 참고한 클라우드·AI 표준, 규제, 벤더 공식 문서와 사례 자료를 정리한다.
-
AWS, "AWS multi-account strategy for your AWS Control Tower landing zone", AWS 공식 문서
-
AWS Prescriptive Guidance, "Building a Cloud Center of Excellence within your organization", Rishi Singla 외
-
AWS Well-Architected Framework, "Governance"(Security Pillar)
-
Microsoft, "Cloud Adoption Framework — Govern"(5 Disciplines), "Align responsibilities across teams"(RACI)
-
Google Cloud, Resource Hierarchy & Organization Policy Service 공식 문서
-
FinOps Foundation, "FinOps Framework 2026", "FinOps Maturity Model", Vasilio Markanastasakis
-
Center for Internet Security(CIS), CIS Benchmarks 공식 자료
-
Wiz, "What CIS Benchmarks Are" · CloudQuery, "Cloud Governance Framework: 4-Step Design Guide" · SecurEnds, "Enforcing Least Privilege in Cloud Environments" · Lumenalta, "Cloud governance checklist" · AmpcusCyber, "ISO 27001 Mapping with Security Standards"
-
AI セーフティ・インスティテュート(日本AISI), "CAIO 설치·AI 거버넌스 실무 매뉴얼"(2026-03-17)
-
宮脇峻平(Algomatic), "AI 거버넌스 입문"(2026-06-18)
-
NIST, "AI Risk Management Framework"(nist.gov/itl/ai-risk-management-framework)
-
EU, "Artificial Intelligence Act"(artificialintelligenceact.eu)
-
ISO/IEC 42001 국제규격, コーピー(Corpy) AI 안전성 평가 프로토콜 실장 가이드(2026-05)
-
OWASP, "AI Security Verification Standard(AISVS) 1.0"(2026)
-
n-okutomi(Qiita), "생성AI 보안 입문 — 기업에서 일어나는 리스크와 중대 인시던트"(2026-07-12)
-
Anthropic 공식, "Agent Identity: a new access model for autonomous, team-wide AI"(2026-06-24)
-
Google Cloud, "Configure semantic governance policies"(Gemini Enterprise Agent Platform 문서)
-
Microsoft, Entra Agent ID / Agent 365 거버넌스 GA 발표(2026-07-07)
-
KAG Claude Enterprise 전사 롤아웃 사례(2026-07-03)
면책: 이 가이드는 업계 표준과 공개 자료를 종합한 일반 지침이며, 법률 자문이나 특정 규제 인증에 대한 공식 확인을 대체하지 않는다. 회사의 실제 업종·규모·규제 환경에 맞춘 세부 정책은 법무·컴플라이언스 부서와 함께 최종 확정하라.
이 챕터의 출처
- 01AWS Well-Architected Framework — 보안 거버넌스 ↗Amazon Web Services
- 02AWS Well-Architected Framework — Security Pillar ↗Amazon Web Services
- 03AWS Organizations 모범 사례 ↗Amazon Web Services
- 04AWS Control Tower 문서 ↗Amazon Web Services
- 05AWS IAM 보안 모범 사례 ↗Amazon Web Services
- 06AWS 클라우드 재무 관리 ↗Amazon Web Services
- 07AWS Cloud Center of Excellence 구축 ↗Amazon Web Services
- 08
- 09Microsoft Zero Trust 지침 ↗Microsoft
- 10Microsoft Cloud Security Benchmark ↗Microsoft
- 11Microsoft Responsible AI Standard ↗Microsoft
- 12
- 13Google Cloud 리소스 계층 ↗Google Cloud
- 14Google Cloud Organization Policy Service ↗Google Cloud
- 15Google Cloud IAM 사용 권장사항 ↗Google Cloud
- 16Google Cloud 보안 기반 가이드 ↗Google Cloud
- 17Google Cloud Semantic Governance 정책 개요 ↗Google Cloud
- 18FinOps Framework ↗FinOps Foundation
- 19FinOps 성숙도 모델 ↗FinOps Foundation
- 20FOCUS 사양 ↗FinOps Foundation
- 21FinOps for AI ↗FinOps Foundation
- 22CIS Benchmarks ↗Center for Internet Security
- 23ISO/IEC 42001:2023 — AI 매니지먼트 시스템 ↗International Organization for Standardization
- 24NIST AI Risk Management Framework 1.0 ↗National Institute of Standards and Technology
- 25Regulation (EU) 2024/1689 — EU AI Act ↗European Union
- 26OWASP Agentic AI Security Initiative ↗OWASP Foundation
- 27일본 AI 사업자 가이드라인 ↗일본 경제산업성·IPA/AISI
- 28Anthropic — 제품 전반의 에이전트 격리와 아이덴티티 ↗Anthropic