|
시장보고서
상품코드
2086868
양자 위협은 이미 도래 : ‘Q-Day’를 앞두고, 타사 암호화 기술에 대한 대응 현황을 평가하기 위한 기업 구매자 가이드, 제1부 - 현황 및 전략적 지침Quantum Risk Is Already Here: An Enterprise Buyer´s Guide to Assessing Third-Party Cryptographic Readiness Before Q-Day, Part 1 - Situation and Strategic Guidance |
||||||
이 IDC Perspective에서는 제3자에 의한 포스트 양자 대응의 필요성에 대해 다루고 있습니다. 기업 데이터 보안에 대한 양자 위협은 미래의 위험이 아니라, 제3자 공급업체의 전체 포트폴리오에서 점차 커지고 있는 현재의 과제입니다. 'Harvest now, decrypt later(HNDL)' 공격은 벤더가 현재 암호화하고 있는 데이터를 수집하여, 양자 컴퓨터가 실용화된 후에 소급하여 복호화하려는 시도입니다. 또한, IDC가 HNDL과 관련된 인증 계층의 위협으로 제시한 'Trust now, forge later(TNFL)'이란, 공격자가 현재 서명된 벤더 산출물을 수집한 뒤, 향후 조직이나 규제 당국이 진품과 구별할 수 없도록 출처 기록을 소급하여 위조하는 것을 의미합니다. NIST가 2024년 8월에 3개의 PQC 표준을 최종 확정했으며, CISA가 2026년 1월에 연방 조달 지침을 발간하고, NIST IR 8547이 2030년 이후부터 양자 공격에 취약한 비대칭 알고리즘의 사용을 권장하지 않으며, 2035년 이후부터는 사용을 금지할 것을 제안하고 있는 점에 비추어 볼 때, 규제 환경의 변화에 따라, PQC로의 전환은 단순한 계획 단계에서 공급업체에 맡길 수 없는 제3자에 대한 규정 준수 의무로 전환되었습니다.
이 보고서는 기업의 구매 담당자를 대상으로 작성된 2부로 구성된 ‘IDC Perspective’ 시리즈의 제1부입니다. 본고에서는 타사 공급업체의 전체 포트폴리오에 걸쳐 PQC 준비 현황 평가 프로그램을 전개하기 위한 전략적 및 위협적 맥락을 제시하고 있습니다. 여기에는 HNDL 및 TNFL이라는 위협 차원, 모스카의 부등식을 기반으로 한 공급업체 우선순위 지정 프레임워크, 새롭게 부상하고 있는 양자 보안 태세 관리(QSPM) 및 양자 TRiSCM 운영 모델, 또한 성숙한 조달 프로그램에서 채택하고 있는 5가지 양자 거버넌스 차원과 신뢰성 KPI가 포함됩니다. 양자 위험은 이미 현실이 되었습니다. ‘Q-Day’를 앞두고, 제3자 암호화 기술에 대한 대응 준비를 입증하기 위한 공급업체용 가이드, 2부 - 평가 프레임워크 및 도입 가이드(IDC #, 곧 공개 예정)에서는 48개의 질문으로 구성된 타사 양자암호화 준비 상태 평가 프레임워크가 제공됩니다. 암호화 및 인증 양쪽 모두에서 신뢰할 수 있는 전환 체계를 입증하지 못하는 공급업체는 귀사의 제3자 포트폴리오에 있어 정량화할 수 없는 중대한 위험 요소가 됩니다. 이는 공식적인 규제가 도입되기 전에 규제 당국이나 이사회로부터 설명을 요구받는 경우가 점점 더 늘어날 것이라는 위험입니다.
'귀사의 제3자 공급업체 포트폴리오에는 두 개의 시계가 동시에 작동하고 있습니다. 첫 번째는 'HNDL 시계'입니다. 벤더가 현재 양자 공격에 취약한 알고리즘으로 암호화하고 있는 데이터는 10년 이내에 해독될 가능성이 있으며, 사후에 재암호화할 수는 없습니다. 두 번째는 'TNFL 시계'입니다. 벤더가 현재 양자 공격에 취약한 키로 서명하고 있는 모든 데이터는 양자 컴퓨팅이 암호 기술 분야에서 실용화될 경우 공격자가 악용할 수 있는 공격 대상을 확대하게 됩니다. 두 시계 모두 멈출 수 없으며, 또한 이는 판매자만의 문제도 아닙니다. 왜냐하면 위험에 노출된 것은 귀사의 데이터이며, 규제 당국에 대한 설명 책임을 지는 것도 귀사이기 때문입니다. Philip D. Harris 씨(CISSP, CCSK, IDC 거버넌스·리스크 및 컴플라이언스 솔루션 부문 리서치 디렉터)는 "유일한 합리적인 대응책은 제3자에 의한 PQC 평가를 향후 프로그램이 아닌, 벤더 리스크 관리 프레임워크에 추가해야 할 가장 시급한 요소로 취급하고, 규제 당국으로부터 『왜 대응하지 않았는가』라는 설명을 요구받기 전에 거버넌스, 평가 인프라, 그리고 지속적인 모니터링의 기반을 구축하는 것입니다."라고 밝혔습니다.
This IDC Perspective discusses the need for third-party post-quantum readiness. The quantum threat to enterprise data security is not a future risk - it is a present liability that is compounding across your third-party vendor portfolio. Harvest now, decrypt later (HNDL) attacks are collecting data that your vendors encrypt today for retroactive decryption once quantum computers mature. Trust now, forge later (TNFL) - introduced by IDC as the authentication-layer counterpart to HNDL - describes adversaries harvesting signed vendor artifacts currently to retroactively forge provenance records that your organization and your regulators cannot distinguish from authentic ones. With NIST finalizing three PQC standards in August 2024, CISA issuing federal procurement guidance in January 2026, and NIST IR 8547 proposing to deprecate quantum-vulnerable asymmetric algorithms after 2030 and disallow them after 2035, the regulatory landscape has converted PQC migration from a planning exercise into a third-party compliance obligation you cannot defer to your vendors.This document is part 1 of a two-part IDC Perspective series for enterprise buyers. It establishes the strategic and threat context for deploying a PQC readiness assessment program across your third-party vendor portfolio - including the HNDL and TNFL threat dimensions, Mosca's inequality vendor prioritization framework, emerging Quantum Security Posture Management and Quantum TRiSCM operating models, and the five quantum governance dimensions and trust KPIs that mature buyer programs are adopting. Quantum Risk Is Already Here: An Enterprise Buyer's Guide to Assessing Third-Party Cryptographic Readiness Before Q-Day, Part 2 - Assessment Framework and Deployment Guide (IDC #, forthcoming) delivers the complete 48-question Third-Party Quantum Encryption Readiness Assessment Framework. Vendors that cannot demonstrate a credible migration posture across both encryption and authentication represent material, unquantified risk in your third-party portfolio - risk that regulators and boards will increasingly require you to account for before formal mandates arrive."Two clocks are running simultaneously across your third-party vendor portfolio. The first is the HNDL clock: Data your vendors encrypt currently under quantum-vulnerable algorithms is potentially readable within a decade, and it cannot be re-encrypted retroactively. The second is the TNFL clock: Every artifact your vendors sign currently under a quantum-vulnerable key extends the attack surface adversaries will exploit once quantum computing reaches cryptographic relevance. Neither clock can be paused, and neither is your vendor's problem alone - because the data at risk is yours, and the regulatory accountability is yours. The only rational response is to treat third-party PQC assessment not as a future program but as the most time-sensitive addition to your vendor risk management framework - and to build the governance, assessment infrastructure, and continuous monitoring foundations before your regulators ask you to explain why you did not," says Philip D. Harris, CISSP, CCSK, research director, Governance, Risk, and Compliance Solutions at IDC.