시장보고서
상품코드
2086858

Measuring What Matters : AI 시대의 데이터 기반 사이버 보안 지표 프레임워크

Measuring What Matters: A Data-Driven Cybersecurity Metrics Framework for the Age of AI

발행일: | 리서치사: 구분자 IDC | 페이지 정보: 영문 34 Pages | 배송안내 : 즉시배송

    
    
    



가격
PDF (Single User License) help
PDF 보고서를 1명만 이용할 수 있는 라이선스입니다. 인쇄는 가능하며 인쇄물의 이용 범위는 PDF 이용 범위와 동일합니다.
US $ 7,500 금액 안내 화살표 ₩ 11,173,000
※ 부가세 별도
한글목차
영문목차
※ 본 상품은 영문 자료로 한글과 영문 목차에 불일치하는 내용이 있을 경우 영문을 우선합니다. 정확한 검토를 위해 영문 목차를 참고해주시기 바랍니다.

사이버 보안 지표에 관한 2부작 시리즈의 두 번째 편인 이번 IDC Perspective에서는 데이터에 기반한 3단계 지표 프레임워크(거버넌스, 관리, 운영)를 제시하여, 조직이 기업의 모든 수준에서 핵심 요소를 측정할 수 있도록 지원합니다. 사이버 보안 지표는 오랫동안 오해받아 왔으며, 기술적·운영적 지표로 보고되어 왔지만, 경영진이나 이사회가 필요로 하는 것은 비즈니스 성과와 직접적으로 연결되는 전략적이고 위험 기반의 인사이트력입니다. AI의 부상은 두 가지 측면에서 지표의 중요성을 근본적으로 변화시켰습니다. 공격 측면에서는 AI를 악용한 공격이 규모, 고도화, 속도 면에서 가속화되고 있어, 감지 및 대응에 할애할 수 있는 시간이 줄어들고 있습니다. 방어 측면에서는 조직이 제품, 서비스, 의사결정에 AI를 도입하는 속도가 거버넌스의 대응 속도를 앞지르고 있어, 기존의 지표 프레임워크로는 포착하도록 설계되지 않았던 새로운 유형의 기업 리스크가 발생하고 있습니다. 본 자료에서는 3계층 프레임워크를 확장하여, 섀도 AI, 규제 준수 체계, 에이전트형 AI 리스크, 모델의 지적재산권 보호, SaaS에 통합된 AI를 포괄하는 AI 리스크 전용 지표를 제시하고 있습니다. 원생 AI 거버넌스 기능을 갖춘 GRC 플랫폼을 도입하고, 지표를 비즈니스 리스크와 연계하며, 투명성이 높고 검증된 인사이트력을 바탕으로 대상자별 의사결정을 지원하는 조직이야말로, 오늘날 AI가 주도하는 위협 및 규제 환경 속에서 자신 있게 주도적인 입지를 구축할 수 있을 것입니다. IDC의 거버넌스·리스크 및 컴플라이언스 솔루션 담당 리서치 디렉터인 필립 해리스(Philip Harris) 씨는 "AI 시대에는 조직이 사이버 보안 위험을 측정하는 방식에 대해 근본적인 재검토가 요구되고 있습니다. AI 시스템이 거버넌스, 측정, 설명 책임 없이 운영되고 있음에도 불구하고, 이사회에 방화벽 차단 건수만 보고하는 것은 더 이상 용납될 수 없습니다. 통합된 인텔리전스 플랫폼을 기반으로 구축되고, 모든 대상 수준에서 AI 특유의 위험을 포착하도록 확장된 데이터 기반 지표는 더 이상 모범 사례에 그치지 않습니다. 이는 비즈니스상 필수 요건입니다.”라고 말했습니다.

주요 요약

  • 주요 사항
  • 권장되는 대응 방안

상황 개요

  • 역방향으로 구축된 시스템: 사이버 보안 지표가 오해받는 이유
  • 이사회까지 확대된 책임성: 현 상태를 더 이상 용납할 수 없는 이유
  • 세 가지 장벽, 하나의 사각지대: 지표 격차가 지속된 이유
  • 기존 지표가 제공한 것과 제공하지 못한 것
  • 패치 수에서 평이한 언어로: 조직이 실제로 필요로 하는 것
  • AI가 가져온 두 가지 새롭고 시급한 차원
  • 데이터 기반 지표
    • 데이터 기반 지표의 특성
    • 지표 수립 시 고려해야 할 요소
      • 위험에 대한 이해
      • 데이터 수집의 일관성 확보
      • 데이터 분석
      • 결과 해석
      • 이해관계자 고려
      • 의사결정 역량 강화
      • 모니터링 및 최적화
      • 프로세스 및 지침 수립

기술 구매 담당자를 위한 조언

  • 데이터 기반 지표에 필요한 요소
  • GRC 플랫폼과 인텔리전스 패브릭의 역할
  • 패브릭이 리스크 레지스터에 제공하는 가치
  • 패브릭이 가능하게 하는 것
  • 대상별 적절한 지표
    • 이사회를 위한 지표
    • 이사회를 위한 지표란?
    • 이사회를 위한 지표가 아닌 것
    • 대상 독자
    • 카테고리 및 상세 정보
  • 경영 지표
    • 대상 독자
    • 카테고리 및 상세 정보
  • 운용 지표
    • 대상 독자
    • 카테고리 및 상세 정보
  • 장점

참고 자료

  • 관련 조사
  • 요약
LSH 26.07.20

This IDC Perspective, Part 2 of a two-part series on cybersecurity metrics, presents a data-driven, three-tier metrics framework, governance, managerial, and operational, that enables organizations to measure what matters at every level of the enterprise. Cybersecurity metrics have long been misunderstood, reported as technical operational measures when what executives and board members need are strategic, risk-based insights tied directly to business outcomes.The emergence of AI has fundamentally changed the metrics imperative on two fronts. On the offensive side, AI-weaponized attacks are accelerating in scale, sophistication, and speed, compressing the time available to detect and respond. On the defensive side, organizations are deploying AI into products, services, and decision-making faster than governance can keep pace, creating a new class of enterprise risk that traditional metrics frameworks were never designed to capture.This document extends the three-tier framework with dedicated AI risk metrics, covering shadow AI, regulatory compliance posture, agentic AI risk, model IP protection, and SaaS-embedded AI. Organizations that implement GRC platforms with native AI governance capabilities, align metrics to business risk, and empower audience-specific decision-making with transparent, validated insights will be best positioned to lead with confidence in today's AI-driven threat and regulatory environment."The age of AI demands a fundamental rethink of how organizations measure cybersecurity risk. Reporting firewall blocks to boards while AI systems operate without governance, measurement, or accountability is no longer acceptable. Data-driven metrics, built on a consolidated intelligence platform and extended to capture AI-specific risk at every audience level, are no longer a best practice. They are a business imperative," says Philip Harris, research director, Governance, Risk, and Compliance Solutions, IDC.

Executive Snapshot

  • Key takeaways
  • Recommended actions

Situation Overview

  • Built in reverse: Why cybersecurity metrics are misunderstood
  • Accountability reaches the boardroom: Why the status quo can no longer be tolerated
  • Three barriers, one blind spot: Why the metrics gap has persisted
  • What traditional metrics delivered, and what they didn't
  • From patch counts to plain language: What organizations actually need
  • AI has introduced two new and urgent dimensions
  • Data-driven metrics
    • Qualities of data-driven metrics
    • Elements to consider in crafting metrics
      • Understanding the risks
      • Aligning data collection
      • Analyzing the data
      • Interpreting the results
      • Considering the stakeholders
      • Empowering decision-making
      • Monitoring and optimizing
      • Establishing processes and guidelines

Advice for the Technology Buyer

  • What is needed for data-driven metrics
  • The role of GRC platforms and the intelligence fabric
  • What the fabric adds to the risk register
  • What the fabric enables
  • Appropriate metrics by audience
    • Board of directors metrics
    • What board of directors metrics are
    • What board of directors metrics are not
    • Audience
    • Categories and details
  • Managerial metrics
    • Audience
    • Categories and details
  • Operational metrics
    • Audience
    • Categories and details
  • Benefits

Learn More

  • Related research
  • Synopsis
샘플 요청 목록
0 건의 상품을 선택 중
목록 보기
전체삭제
문의
원하시는 정보를
찾아 드릴까요?
문의주시면 필요한 정보를
신속하게 찾아드릴게요.
02-2025-2992
email
문의하기