|
시장보고서
상품코드
2104478
Beyond Check the Box(형식적인 대응을 넘어) : AI 위험, 양자 위협, 규제 요건 및 조직의 실정에 부합하는 보안 프레임워크 선정Beyond Check the Box: Choosing a Security Framework Built for AI Risk, Quantum Threat, Regulatory, and Your Organization´s Reality |
||||||
본 IDC Perspective는 크게 변화한 상황을 반영하기 위해 프레임워크 선정에 관한 IDC의 기본 지침을 업데이트한 것입니다. 구체적으로는 2024년에 NIST CSF 2.0의 적용 범위가 확대되고, ' 거버넌스(Govern)' 기능이 추가된 점, 2025년 1월부터 DORA가 EU 내 약 22,000개의 금융 기관에 적용되기 시작한 점, 그리고 2024년 3월에 PCI DSS v4.0이 기존 규격을 폐지한 점을 들 수 있습니다. 보안 프레임워크 선정은 단순한 기술적 체크리스트가 아니라, 리스크 관리상의 의사결정입니다. 2022년 이후 프레임워크 전략을 재검토하지 않은 조직은, 이용 가능한 선택지나 그 선택을 제약(혹은 촉진)할 가능성이 있는 규제상의 의무에 대해, 시대에 뒤떨어진 전제를 바탕으로 운영되고 있을 가능성이 높습니다. 2022년에는 최우선 고려 사항으로 존재하지 않았던 두 가지 기준이, 현재는 명확한 주의를 요하게 되었습니다. AI 도입으로 인해 모델 포이즌링, 프롬프트 인젝션, 에이전트형 시스템의 위험과 같은 새로운 공격 표면이 생겨났습니다. 이에 대응하여 NIST는 2025년 12월에 ‘사이버 AI 프로파일’ 초안을 발표했습니다. 또한, 포스트 양자 암호화(PQC)는 이론적 우려 사항에서 운영상의 필수 사항으로 전환되고 있으며, NIST는 2024년 8월에 3가지 PQC 표준을 최종 확정했고, 규제 당국도 전환 기한을 설정하고 있습니다. 이 두 가지 고려 사항을 지금 당장 프레임워크 선정 과정에 반영하는 조직은, 이를 미래의 과제로만 취급하는 조직보다 훨씬 유리한 입장에 서게 될 것입니다. "적절한 보안 프레임워크는 현재의 보안 위험뿐만 아니라 미래에 발생할 수 있는 위험도 적절히 관리하기 위한 중요한 요소입니다."라고 IDC의 사이버 보안 GRC 솔루션 담당 리서치 디렉터인 필 해리스(Phil Harris) 이사는 말했습니다. "2026년의 상황에서는 조직이 AI 거버넌스와 포스트 양자 암호화에 대한 대응 준비를 미래의 과제가 아닌 최우선 평가 기준으로 검토해야 합니다. 우수한 GRC 기술에 기반한 체계적이고 기준에 입각한 접근 방식을 채택하는 조직은 오늘날의 상황에 적합할 뿐만 아니라, 위협 및 규제 환경의 변화에 맞춰 진화할 수 있는 충분한 탄력성을 갖춘 프레임워크를 선택하게 될 것입니다."
This IDC Perspective updates IDC's foundational guidance on framework selection to reflect a materially changed landscape: NIST CSF 2.0 expanded scope and added a Govern function in 2024; DORA became applicable to approximately 22,000 EU financial entities in January 2025; and PCI DSS v4.0 retired the legacy standard in March 2024. Security framework selection is a risk management decision, not a technical checklist. Organizations that have not revisited their framework strategy since 2022 are likely operating against outdated assumptions about both the available options and the regulatory obligations that may constrain - or drive - their choice.Two criteria that did not exist as first-order considerations in 2022 now demand explicit attention. AI adoption has introduced new attack surfaces - model poisoning, prompt injection, and agentic system risks - for which NIST published a draft Cyber AI Profile in December 2025. Post-quantum cryptography (PQC) has moved from theoretical concern to operational imperative, with NIST finalizing three PQC standards in August 2024 and regulators establishing migration deadlines. Organizations that embed both considerations into their framework selection process now will be substantially better positioned than those that treat them as future-state concerns."The right security framework is a critical factor in adequately managing security risks not only present today but also risks that could appear in the future," says Phil Harris, research director, Cybersecurity GRC Solutions at IDC. "The 2026 landscape demands that organizations evaluate AI governance and post-quantum cryptography readiness as first-order criteria, not future-state considerations. Organizations that apply a structured, criteria-driven approach, supported by capable GRC technology, will make framework choices that are the right fit today and resilient enough to evolve as the threat and regulatory landscape continues to change."