This study analyzes the structural limitations of the current pricing system for fair compensation of information security services and proposes institutional measures for improvement. The pricing system for information security services is still largely operated under the pricing logic of general software projects, raising concerns over the outflow of skilled professionals and the deterioration of service quality. This study finds that the current Software Development Cost Estimation Guide, when applied to information security services, relies heavily on direct labor costs and therefore fails to reflect the qualitative characteristics of such services as independent pricing variables. It also examines the limitations of the public procurement bidding structure, in which reduced budgets caused by bid savings and additional response costs from elevated cyber crisis alert levels place excessive burdens on contractors. Based on this analysis, this study proposes the establishment of a separate pricing guideline for information security services and the inclusion of an information security service category in the budget preparation guidelines issued by the Ministry of Economy and Finance. It also suggests clarifying Article 19 of the Act on Contracts to Which the State Is a Party to include specification changes and changes in the scope of work within design changes, thereby strengthening the legal basis for fair compensation for additional tasks.
한국어
본 연구는 정보보호 서비스 적정 대가 산정 체계의 구조적 한계를 분석하고 이를 개선하기 위한 제도적 방안을 모색하고자 한다. 정보보호 서비스의 대가 산정 체계는 여전히 일반 SW 사업의 산정 논리에 종속되어 운영됨에 따라 숙련된 인력의 이탈과 서비스 품질저하라는 악순환이 우려되는 상황이다. 이에 본 연구는 현행 「SW사업 대가산정 가이드」가 정보보호 서비스에 적용될 때 인력 단가를 중심으로 한 체계에 의해 서비스의 질적 특성이 독립적인 산정 변수로 반영되기 어렵다는 점을 확인했다. 나아가 정보보호 서비스 관점에서 현행 공공조달 입찰 구조의 한계를 분석하고 사이버위기경보 격상으로 인한 추가 대응업무와 비용이 계약상대자의 부담을 가중시키는 문제를 확인하였다. 본 연구는 이와 같은 분석을 기반으로 정보보호 서비스 대가산정을 위한 별도의 가이드라인 제정과 기획재정부 「예산안 편성 및 기금운용계획안 작성 세부지침」상 정보보안 서비스 항목 신설을 통한 서비스 가치 기반의 산정 체계로의 전환 필요성을 제시하였다. 또한 「국가계약법」 제19조 설계변경의 범위에 규격변경 및 과업내용의 변경이 포함됨을 명확히 하여 추가 과업에 대한 적정 대가 지급의 법적 근거를 강화해야 한다.
목차
<요약> Ⅰ. 서론 Ⅱ. 정보보호 서비스의 개념 및 범위 Ⅲ. 정보보호 서비스 대가 산정 체계의 구조적 한계 Ⅳ. 제도적 개선 방안 Ⅴ. 결론 참고문헌 【Abstract】