Earticle

현재 위치 Home 검색결과

결과 내 검색

발행연도

-

학문분야

자료유형

간행물

검색결과

검색조건
검색결과 : 15
No
1

7,300원

본 연구는 트럼프 2기(2025~) 행정부의 사이버 전략이 미국과 유럽연합(EU)의 관계를 어떠한 방식으로 재구성하고 있는지를 기술–규범–안보의 삼중축 복합체제 관점에서 분석한다. 기존 연구는 미국의 기술·산업 중심 전략과 EU의 규범·제도 중심 전략을 각각 독립적으로 다루는 경향이 강해, 두 행위자의 상호작용이 충돌·조정·병존이 중첩된 구조로 나타나는 현상을 충분히 설명하지 못했다. 이에 본 연구는 기술–산업, 규범–데이터, 군사–방위의 세 축이 상호구속적으로 작동하는 복합체제를 분석틀로 설정하고, 트럼프2기 전략 변화와 EU의 대응을 구조적으로 비교하였다. 분석 결과, 미국은 규제완화와 민간 중심 모델을 강화함으로써 기술패권과 경제안보를 결합한 산업·기술 중심 전략을 재가속화하고 있다. 반면 EU는 GDPR, NIS2, AI Act 등 규범·책임성 기반 접근을 유지하면서도 기술주권과 전략적 자율성을 강화하는 규범적 실용주의로 변화하고 있다. 이러한 상이한 전략 구조는 기술–산업 축에서는 경쟁을, 규범–데이터 축에서는 제도적 긴장을, 군사–방위 축에서는 제한적 조정을 동시에 낳으며, 결과적으로 미국–EU 사이버 관계는 단일한 협력이나 대립이 아니라 구조적 병존체제로 전개된다. 본 연구의 기여는 첫째, 기존의 단일 축 분석을 넘어 기술–규범–안보 삼중축 복합체제를 통해 미–EU 전략 상호작용의 작동 원리를 재구성한 데 있으며, 둘째, 이러한 구조적 변화가 한국의 기술·규범·안보 전략에 요구하는 다층적 선택 조건을 제시한 데 있다. 특히 한국은 미국 중심 기술·안보 질서와 EU 중심 규범·데이터 질서가 병존하는 환경에서 균형·분화·중개 전략을 결합하는 방식으로 실효적 전략 공간을 확보할 필요가 있다. 본 연구는 복합안보 시대의 미–EU 디지털 질서를 설명하고 중견국의 전략적 선택을 분석하는 데 중요한 이론적·정책적 함의를 제공한다.

This study examines how the cyber strategy of Trump’s second administration (2025– ) is reshaping relations between the United States and the European Union (EU) through the lens of a triple-axis complex regime of technology, norms, and security. Existing research tends to analyze the U.S. technology- and industry- centered approach and the EU’s norms- and institution-based strategy separately, leaving insufficient explanations for why U.S.–EU cyber interactions simultaneously display patterns of conflict, adjustment, and coexistence. To address this limitation, the study develops an analytical framework that conceptualizes cyber strategy as a complex regime in which the technology–industry, norms–data, and military–defense axes operate in a mutually constraining manner. The analysis demonstrates that the United States has reaccelerated an industry- and technology-centered strategy that closely links technological primacy with economic security by reinforcing deregulation and a private-sector-led model. By contrast, the EU has maintained a norms- and accountability-based approach—anchored in instruments such as the General Data Protection Regulation (GDPR), the revised Network and Information Security Directive (NIS2), and the AI Act—while simultaneously moving toward normative pragmatism that strengthens technological sovereignty and strategic autonomy. These divergent strategic logics generate competition along the technology–industry axis, institutional tension along the norms–data axis, and limited adjustment along the military–defense axis, resulting in a structural regime of coexistence rather than a single pattern of cooperation or confrontation. This study contributes by moving beyond single-axis analyses to reconstruct the logic of U.S.–EU strategic interaction through a triple-axis framework, and by highlighting the implications of this transformation for Korea’s strategic choices. In a context where a U.S.-centered technology–security order and an EU-centered norms–data order coexist, Korea faces the need to combine balancing, differentiation, and mediation strategies to secure effective strategic space.

2

국가 사이버보안 전략 수립과 개선을 위한 참조 모델 개발 KCI 등재

윤재석

한국융합보안학회 융합보안논문지 제16권 제4호 2016.06 pp.53-61

※ 기관로그인 시 무료 이용이 가능합니다.

4,000원

세계 많은 국가들은 사이버위협으로 인한 피해를 사전에 예방하고, 사고 발생 시 그 피해를 최소화하기 위해 국가차원의 사이버보안 전략을 수립하여 이행하고 있다. 그러나 국가 사이버보안 전략은 해당 국가가 처한 환경과 필요에따라 그 수준과 범위에 있어 상당한 편차를 보이고 있다. 어느 한 곳의 취약점은 전 세계적인 문제로 이어질 수 있다는점에서 국가 사이버보안 전략 수립을 지원하고 개선하기 위해 국제기구를 비롯한 관련 기구, 기관에서 다양한 지침서가개발되었다. 본 논문에서는 국가 사이버보안 전략 수립을 위해 발표된 각종 지침서를 분석하고, 주요 공통요소를 도출한 참조 모델을 제시하였다. 아울러 이를 우리나라 정책과 비교하여 미흡한 부분에 대한 보완대책을 제안하였다.

A number of countries have been developing and implementing national cybersecurity strategy to prevent damages caused by cyber threats and to minimize damages when they happened. However, there are a lot of differences and disparities in respective strategies with their own background and needs. A vulnerability in some places can be a global problem, so various guidelines have been developed by relevant organizations including international organizations to support the establishment of national cybersecurity strategies and improvement of them. In this paper, with analysis on the guidelines for the establishment of national cybersecurity strategies, reference model consisting of common elements of strategies was suggested. And several recommendations for the improvement measures for Korean national cybersecurity strategies were explained with a comparison of the reference model.

3

미국 사이버안보 전략의 경향 분석과 한국에의 함의 KCI 등재

배선하, 송민경, 김동희

한국융합보안학회 융합보안논문지 제23권 제2호 2023.06 pp.11-25

※ 기관로그인 시 무료 이용이 가능합니다.

4,800원

미국은 바이든 정부 취임 후 대규모 사이버 공격이 잇따라 발생하고, 사이버안보를 국가 최우선과제로 강조하 고 있으며, 미국뿐만 아니라 동맹 및 우방국의 사이버안보 강화를 위한 노력을 추진하고 있다. 특히, 2023년 3월 에는 국가 사이버안보 전략을 발표하였는데, 연방정부 및 주요기반시설 보호, 국제협력을 통한 사이버공간의 악의 적 행위자 및 위협국에 대한 추적 및 대가부과, 민간의 사이버보안 책임 강화 등을 골자로 하고 있다. 국가 사이 버안보 전략은 사이버안보의 최상위 지침으로 공공-민간뿐만 아니라 국외 정책 방향도 포함하고 있어 국제질서 에까지 영향을 미칠 것으로 예상된다. 한편, 우리나라는 2022년 새로운 정부가 출범하고, 2019년에 발간된 국가 사이버안보 전략의 개정이 필요한 상황이다. 또한, 최근 한-미 협력이 강화되고 있으며, 사이버안보는 한미 정상 회담에서 핵심의제로 다뤄지고 있다. 이에 본 논문에서는 바이든 정부의 사이버안보전략을 살펴보고, 기존의 트럼 프 정부와 어떻게 달라졌는지 그 특징과 시사점을 정성적·정략적 측면에서 분석하고자 한다. 정량적 분석을 위해 서는 텍스트 마이닝 기법 중 하나인 토픽모델링을 활용한다. 그리고 이러한 변화가 한-미 관계를 비롯해 우리나 라에 미치는 영향과 한국 사이버안보 정책에 주는 함의를 도출한다.

Since President Biden’s inauguration, significant cyberattacks have occurred several times in the United States, and cybersecurity was emphasized as a national priority. The U.S. is advancing efforts to strengthen the cybersecurity both domestically and internationally, including with allies. In particular, the Biden administration announced the National Cybersecurity Strategy in March 2023. The National Cybersecurity Strategy is the top guideline of cybersecurity and is the foundation of other cybersecurity policies. And it includes public-privates as well as international policy directions, so it is expected to affect the international order. Meanwhile, In Korea, a new administration was launched in 2022, and the revision of the National Cybersecurity Strategy is necessary. In addition, cooperation between Korea and the U.S. has recently been strengthened, and cybersecurity is being treated as a key agenda in the cooperative relationship. In this paper, we examine the cyber security strategies of the Trump and Biden administration, and analyze how the strategies have changed, their characteristics and implications in qualitative and quantitative terms. And we derive the implications of these changes for Korea’s cybersecurity policy.

4

독일 사이버안보 국가전략 : 안보화를 넘어 군사화로 KCI 등재

김주희

한독사회과학회 한독사회과학논총 제30권 제2호 2020.06 pp.3-32

※ 기관로그인 시 무료 이용이 가능합니다.

7,000원

본 연구는 독일의 사이버안보 전략이 안보화를 넘어 군사화로 이동하고 있다고 주장한다. 군사화는 안보화된 문제에 대응하기 위해 군사적 수단에 우선순위를 부여하는 극단화된 안보화를 말하며 관념적인 측면과 물질적인 측면 모두에서 발생한다. 군사화는 안보화된 문제 해결을 위한 다양한 대안들과 구별되는 익숙한 군사적 표현과 담론형성과 유지를 통해 발생할 뿐만 아니라 사이버안보 군 관련 조직을 형성하고 이를 실행하기 위한 제도적 측면을 통해 구체화된다. 2011년 이후 독립적인 사이버안보전략을 수립하고 주요기반시설에 대한 보안에 중점을 두며 군의 역할은 보충적인 역할로 제한했던 독일은 2016년 새로운 사이버안보전략을 통해 독일연방군의 적극적인 참여와 이를 위한 제도적 변화를 모색했다. 동시에 주요 정책결정자들의 사이버 위협 담론과 군사적 조치 도입을 정당화하는 담론이 동반되었다. 앞으로 국가 사이버안보의 발전 방향은 군사화의 심화를 예상할 수 있다는 점에서 국경에 근거한 영토성의 개념으로 담아낼 수 없는 사이버 공간의 위협에 대한 대응이 전통적 지정학 발상에 근거할 때 나타날 수 있는 과잉 안보화를 넘어 과잉 군사화로 향할 가능성에 대한 비판적 고려가 필요하다.

This study argues that German cybersecurity national strategy has been moving beyond security toward militarization. Militarization refers to an hyper-securitization that prioritizes military means to respond to security threats, and operates in both the ideational and material aspects. Militarization not only occurs through familiar military expressions and discourse formation and maintenance that is distinguished from various responses to solving security problems, but is also embodied through institutional aspects to form and implement cybersecurity-relevant organizations. Germany established an cybersecurity national strategy since 2011, focusing on security for critical infrastructure, and limits the role of the military to supplementary. However, Germany's new cybersecurity national strategy in 2016 sought active participation by the Bundeswehr(German Federal Forces) and institutional changes. At the same time, high-ranked policy-makers were accompanied by discourses of cyber threat that justified the utilization of military measures. The direction of the development of national cybersecurity can predict the deepening of militarization. It is necessary to critically consider the possibility of moving toward hyper-militarization beyond the hyper-securitization if countering the threat of cyberspace, which cannot be captured by the concept of territoriality, arose with traditional geopolitics.

5

인적정보(HUMINT) 역량 강화를 통한 사이버 안보위협 및 범죄대응전략 KCI 등재

정태진, 임준태

한국경찰연구학회 한국경찰연구 제13권 제4호 2014.12 pp.289-314

※ 기관로그인 시 무료 이용이 가능합니다.

6,400원

최근 들어 미국-중국, 유럽-러시아, 아랍-이스라엘간에 지속적인 사이버공격이 시도되고 있으며, 우리나라의 경우 북한에서 시도한 것으로 추정되는 심각한 사이버상의 테러 혹은 공격사례들이 확인되고 있다. 이와 같은 사이버테러나 관련범죄에 대한 효과적인 대응전략으로 인적정보수집(HUMINT) 역량을 강화해야 한다. 네트워 크상에서의 공격이기에 온라인상에서의 기술적인 대응만으로 위협세력이나 범죄집단을 통제할 수 있다는 안 일한 태도는 수정되어야 한다. 사이버 안보를 위협하는 대부분의 공격 배후에는 그러한 공격이나 범행을 계획하고 실행하는 ‘인간의 행위’가 있기 때문이다. 그들의 동향에 대한 정보를 사전에 제대로 파악하지 못한다면 지속적으로 사이버안보를 위협 하는 공격에 대해서 무방비 상태에 놓이게 되며, 피해가 야기된 이후, 사후 대응에 의존할 수 밖에 할 수 없다. 또한 인적 정보활동은 대체로 정보원(informant)이나 내부인의 협조로 이루어진다. 그러므로 충분한 인적정보 수집이 이루어지지 않는다면 완벽하게 사이버테러나 범죄를 사전에 감지, 차단할 수 없다. 그리고 인적정보 수집 역량을 강화하기 위해서는 전문인력채용, 사이버테러나 관련 범죄대응 기관들, 즉 각급 정보보안기관들 의 통합이나 협업, 해외정보수집 강화, 전문화 교육과정 등이 필요하다.

Recent intelligence reported that cyber-attacks have occurred between US and China, Europe and Russia, Arab and Israel while serious cyber-attacks occurred by north-Korea have been identified. In order to respond to cyber terror and its relevant crimes effectively, it is imperative to enhance the HUMINT (Human Intelligence). Existing counter measure of cyber-attacks focuses on technological response. However, technological response should not completely control the risky group and criminal organization. Beyond cyber-attacks on national security, there is a human behavior that makes a plan and commits the attacks and crimesWithout identifying those behaviors in advance, our cyber security system will be stayed in vulnerable. It has to depend on reactive response. HUMINT activities are mainly done through cooperation of informant or insider. Detection and interception of cyber-terror or crime cannot be done without sufficient HUMINT activities. It is imperative to cooperate among cyber-terror or cyber-crime response agencies in order to enhance the HUMINT capability. Thus, integration of intelligence or security agencies, enhancement of overseas intelligence capability and professional training are essential.

6

영국의 사이버 안보전략, 대응정책 그리고 사이버 안보법 KCI 등재

윤민우

한국경찰연구학회 한국경찰연구 제22권 제3호 2023.09 pp.161-182

※ 기관로그인 시 무료 이용이 가능합니다.

5,800원

오늘날 사이버 위협은 모든 국가안보위협과 관련된다. 현재 사이버 위협은 사이버 공간에서의 위협에만 한정되어 있지 않다. 사이버 공격을 통해 오프라인의 국가핵심기 반시설들에 대한 물리적 공격, 민주주의 사회에 대한 선거개입 등이 가능해졌다. 또한 사이버 공격은 국가의 내부분열과 사회혼란을 조장하기 위한 허위정보, 가짜뉴스, 영향 력 공작 등의 사이버 심리전 또는 인지전으로 진화하였다. 콜로니얼 파이프라인 공격, 쏠라윈즈 해킹, 지금도 진행 중인 러시아-우크라이나에서의 하이브리드 전쟁의 일환으 로서의 사이버전과 사이버 인지전 등이 그와 같은 사례들이다. 이 같은 사이버 위협을 일찍 인지한 미국, 영국, NATO 등 주요 선진국들은 이에 대응하기 위한 대응 체계와 방안들을 마련해오고 있다. 이에 비해 한국의 사이버 안보에 대한 대응은 상대적으로 미진한 상황이다. 사이버 안보의 필요성이나 위험성에 대한 대안을 요구하는 목소리도 있지만 아직 사이버 안보법의 입법도 이루어지지 않고 있고 사이버 안보위협에 대한 기술적, 인지적 대응역량 구축 역시 미흡한 실정이다. 특히 현재까지 한국의 사이버 안 보전략과 사이버 안보 대응체계는 민·관·군을 아우르는 통합전략과 체계, 그리고 관련 법률이 없다는 점은 주요한 한계점이다. 더욱이 이와 관련된 학문적 관심과 논의도 아 직까지 충분히 이루어지지 않고 있다. 따라서 이 연구는 영국의 사이버 안보대응 전략과 국가사이버안보 대응체계와 대응정책, 그리고 사이버 안보대응을 지원하기 위한 입 법 활동과 법률들에대해 사례분석하고 논의하였다. 영국과같은 사이버 안보대응선도 국들의 사례를 살펴봄으로서 국내 사이버안보 대응 전략, 정책, 그리고 관련 법률의 발전과 그 필요성 등을 논의하였다.

Today, cyber threats infiltrate all aspects of national security, extending beyond the boundaries of cyberspace. Cyberattacks have the potential to disrupt critical national infrastructure and interfere with democratic processes, such as elections. These cyber threats have evolved into hybrid threats, encompassing cyber psychological warfare, cognitive warfare, and disinformation campaigns that exploit internal divisions and sow societal unrest. Prominent examples include the Colonial Pipeline attack, the SolarWinds hacking incident, and the ongoing hybrid warfare between Ukraine and Russia. While countries like the United States and the United Kingdom have proactively developed and implemented cyber threat response systems and strategies, South Korea's response to cybersecurity has experienced delays. Although some propose alternative measures to address the risks associated with cybersecurity, practical policies and legislative efforts have proven insufficient. Consequently, there is a pressing need to foster academic interest and engage in discussions to address the shortcomings of counter-cybersecurity policies and laws. This study conducts an analysis of the cybersecurity strategies and countermeasures employed by the United Kingdom, including its national security strategy, national cybersecurity response system, and legislative activities. Drawing on the findings from this analysis, the study underscores the importance of recognizing cybersecurity as a threat at the level of hybrid warfare for the South Korean government. In the concluding discussion, the study proposes directions and strategies for cyber policy responses, emphasizing the importance of developing cyber threat response systems and cybersecurity legislation that align with the standards set by advanced countries like the United Kingdom. The contributions and policy implications of this study shed light on the critical issues at hand and offer guidance for future endeavors in the realm of cybersecurity.

7

Improvement of the Defense Planning and Management System to Implement ROK’s National Cybersecurity Strategy

정연오, Jin-Young Choi, Seunghyun Park

[NRF 연계] 한국국방연구원 The Korean Journal of Defense Analysis Vol.35 No.3 2023.09 pp.337-360

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

With the development of the Internet, cyberspace has expanded, which has ushered in several changes. These changes have significantly impacted the defense sector. The defense sector is changing from an existing weapon system-centered operation to a network-centered operation, and cyberspace is now recognized as the fifth strategic space, land, sea, air, and space. However, this expansion of cyberspace paradoxically increases its vulnerability to cyberattacks. Hacking groups have been causing damage through cyberattacks in many countries. Therefore, severalcountries are preparing countermeasures for cybersecurity at the national level. In 2019, the ROK announced its national cybersecurity strategy. However, in the case of the defense field, there are limitations in implementing the cybersecurity policy of the higher concept because it is closed and has specificity. Accordingly, this paper proposes the secure defense planning and management system (SPPBEES) so that the cybersecurity policy of the high concept is materialized as a strategy and leads to force reinforcement.

8

미국 사이버 안보전략, 정책, 그리고 법률의 발전 동향 및 시사점

윤민우

[NRF 연계] 가천대학교 법학연구소 가천법학 Vol.16 No.2 2023.06 pp.145-172

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

오늘날 사이버 안보의 위협은 모든 국가안보 사안과 관련되어 있다고 해도 과언이 아니다. 사이버 안보의 위협은 정부와 안보기관에서 대응해야 할 핵심적인 사안으로 부상하였다. 국내에서도 사이버 안보 강화를 위한 법령 제정에 대한 논의가 있어왔으며 2011년 사이버위협 대응을 위한 부처별 역할을 정립하는 등의 대응을 위한 ‘국가사이버 안보마스터 플랜’이 수립되었고, 비교적 최근인 2019년에는 ‘국가사이버안보전략’이 세워지는 등의 노력이 있어왔다. 그러나 이러한 노력들은 아직까지는 추상적인 수준에 머물고 있으며, 실제 사이버 안보 관련 입법으로 이어지지 못하였다는 점에서 한계가 있다. 따라서 한국은 사이버 공간을 통한 다양한 정보활동, 대테러위협, 해킹위협 등에 노출되어 있음에도 불구하고 사이버 위협 대상이 되는 주요시설과 취약시설에 대한 보안을 강화할 수 있는 법령이 상당히 취약하다. 반면 미국과 유럽 등 해외 주요 선진국들은 2000년대 초부터 국가적 차원에서 사이버위협에 대응하기 위한 체계들을 세우고, 정책을 개발하고, 그리고 법령들을 제정해왔다. 이러한 활동은 사이버 위협 컨트롤 타워 설립, 전담조직설치, 관련기관 및 조직에 대한 책임 및 역할 부여, 사이버 안보법 제정, 사이버안보 전략 수립 등의 다양한 법령과 전략, 그리고 정책의 수립 등을 포함한다. 복잡한 사이버 안보사안의 출현과 다양한 사이버 안보 위협주체들의 등장으로 더욱 위협적으로 변모하고 있는 안보환경 속에서 국내 사이버 안보 역량 강화를 위한 입법은 매우 시급하고 중요하다. 그러나 국내에서는 이러한 사이버 안보관련 입법에 대한 관심이나 논의는 아직까지 미흡한 실정이다. 이에 따라, 이 연구에서는 국내 사이버 안보관련 전략발전과 법령제정에 기여하기 위한 의도로 미국의 사이버 안보전략과 정책, 그리고 법률의 발전 동향을 살펴보았다. 이를 통해 이 연구는 국내 사이버 안보전략과 정책발전 그리고 관련 법령의 제정과 관련된 시사점을 제시하였다.

Today, the threat of cybersecurity is intricately linked to national security, making it a pressing concern for governments and security agencies. Consequently, ongoing discussions are taking place in South Korea regarding the enactment of laws to strengthen cybersecurity. Some efforts have already been made, such as the establishment of the 'National Cyber Security Master Plan' in 2011 and the introduction of the 'National Cyber Security Strategy' in 2019. However, despite these initiatives, the availability of significant and concrete legislation or policies that effectively address the substantial cybersecurity threats is limited. It is important to note that South Korea remains exposed to various cybersecurity risks, including influence operations, terrorist cyber propaganda, radicalization, and cyber technological attacks and hacking. In contrast, the United States has implemented comprehensive national-level cybersecurity policies and laws to safeguard sensitive information, national infrastructure, vulnerable facilities, and democratic election systems from various cyber threats. Recently, the Biden administration has recognized cyber security threats as one of the components of hybrid warfare and has constructed essential systems for national security protection. Several initiatives adopted by the Biden administration encompass the implementation of crucial cybersecurity policies and laws. It is crucial to understand the impact of enacting cybersecurity laws and establishing cybersecurity policies for the enhancement of national security in this rapidly evolving technology-driven interconnected security environment. However, there are substantial loopholes of cybersecurity in South Korea. To address those issues, this study aims to introduce the laws, strategies, and policies of cybersecurity in the United States. For doing so, it suggests some practical options for the development of cybersecurity strategies, policy practices, and the enactment of laws in South Korea.

9

미국 사이버 안보전략의 변화와 이론적 함의

장노순

[NRF 연계] 한국국가정보학회 국가정보연구 Vol.16 No.2 2023.12 pp.145-179

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사이버 안보위협은 기존의 안보전략과 관행으로 대응해 왔지만 전통적인 안보구조처럼 외부의 악의적 사이버활동을 효과적으로 예방하고 억제하지 못하고 있다. 사이버수단은 재래식 무기 혹은 핵무기와 전혀 다르게 은밀하고 저렴한 비용으로 개발되고, 비국가 행위자들도 손쉽게 활용하여 사이버 국제안보질서에 영향을 미칠 수 있다. 더욱이 사이버 보복과 응징은 사이버 확전의 위험을 감당해야 하는 딜레마를 조성한다. 하지만 최강대국인 미국은 오바마 행정부 이후 행정부와 국방부가 수정된 사이버전략을 공개하고 있다. 트럼프 행정부는 선제적 사이버공격전략을 공개 천명하였고, 사이버 위협을 방지하고 여타 안보위협을 해소하는 대체 방안으로 사이버 비밀공작을 적극 활용하겠다는 전략의 기조를 발표했다. 외교와 전쟁이 아닌 선제적 사이버 비밀공작은 ‘선제 방어’와 ‘지속적 관여’의 전략 개념으로 명확하게 드러났다. 미국의 새로운 전략은 이론적으로 전쟁에 미치지 못한 위협의 방식으로 상대방에게 비용을 누적시키면서도 확전의 위험을 선제공격의 피해국 역시 고려하도록 역이용하는 것이다. 또한 선제적 사이버 비밀공작은 비밀스런 행위이지만 자국의 의지와 의도를 신호 보내는 방식이고, 이를 통해 상호 용인되는 사이버 위협활동에 대해 상호 암묵적인 합의점을 도출할 수 있다는 것이다. 이점은 국제규범이 발달하지 못한 사이버공간에서 비밀공작을 통해 규범을 구축하는 방식으로 과거와는 전혀 다른 효과이다.

Cyber threats have been responded with the framework of traditional security strategies and practices, but the growing threat of cyberattacks from foreign countries could not be prevented and deterred effectively. Cyber weapons are different from kinetic forces or nuclear bombs, because they are developed secretly and inexpensively and non-state actors became a major player. In addition, cyber retaliation or punishment may create the cybersecurity dilemma in which cyber actions and reactions can escalate into cyber war that makes it hard for major states to protect their national interests. However, the Obama administration had changed the U.S. cyber deterrence strategy into proactive one. The Trump administration publicly announced that the U.S. has a strong will to eliminate any cyber threats in their origins and use a cyber tool to weaken security threats. As a preemptive strike, 'defend forward' and 'persistent engagement' are key elements in the U.S. DoD cyber strategy and Cyber Command's vision. Those preemptive cyber activities are conducted covertly and clandestinely. Although they impose political or economic costs upon an opponent, the offensive cyber operations force her to accept the burden without any open retaliation. The competing state also will be careful not to escalate cyber conflict. Consequently, the adversary as well as the U.S. adapt implicitly the limits of offensive cyber operations. International norms to curb malicious cyber activities can be constructed through the cyber preemptive strategy.

10

미국 사이버 안보전략의 등장과 발전: 역사적 전개와 사이버솔라리움보고서

변진석

[NRF 연계] 고려대학교 평화와 민주주의연구소 평화연구 Vol.30 No.1 2022.04 pp.41-76

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

미국은 1980년대부터 컴퓨터 정보보안정책을 시작한 이후 사이버 위협과 공격의 증가에 따라 사이버보안과 안보정책을 발전시키고 그러한 노력은 최근 사이버솔라리움보고서에서 제시된 사이버 안보전략으로 나타났다. 동 보고서에서 제시된 미국의 사이버 안보전략은 ‘다층적 사이버 억지’ 전략으로서 미국 자신의 사이버 시스템을 정비하여 사이버공격에 대응력을 강화하고, 국제적 연대를 구축하여, 사이버 적대세력이 미국을 공격하지 못하도록 한다는 개념이다. 그러한 미국의 사이버 안보전략에서 나타난 미국 정책의 특징을 간략하게 정리하면 다음과 같다. 첫째, 미국의 사이버 안보전략은 군사안보전략과 달리 정부와 민간부문의 협조에 기반을 둔 전 국가적 차원의 전략을 마련하고 추진하고 있다. 둘째, 과거의 방어적 전략에서 벗어나 공세적 전략, 즉 ‘선제적 방어’(forward defend)라는, 냉전 시기 군사전략에서 비롯된 개념에 기반을 둔 전략을 추진하고 있다. 셋째, 사이버 안보전략이 대응하고자 하는 사이버 위협, 사이버공격의 특성 때문에 미국은 국제적 규범의 확립, 사이버 위협의 추적과 무력화를 위하여 국제적 협력을 사이버 안보전략의 중요한 내용으로 하고 있다.

The US has pursued cybersecurity policy and strategies responding to cyber threats and attacks since its computer information security policy in the 1980s. The US efforts brought ‘Cyberspace Solarium Commission Report’ in March 2020. The Commission proposed ‘layered cyber deterrence’ as the US cybersecurity strategy. The strategy proposes to strengthens US domestic network for resilience to cyber threats and attacks and to impose costs on potential cyber adversaries along with international allies and partners so that they give up illegal activities. The features of the US cybersecurity strategy are: first, unlike its military security strategy, the US cybersecurity strategy is based on the cooperation with private sector; second, the US pursues ‘forward defend’ strategy unlike its defensive prior cybersecurity strategy; third, the US pursues to build international network of cybersecurity with which it can disrupt and neutralize cyber adversary.

11

독일 사이버안보 국가전략 형성의 국내적 요인

김주희

[NRF 연계] 한국유럽학회 유럽연구 Vol.39 No.1 2021.02 pp.91-118

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

본 연구는 독일의 사이버안보 국가전략의 형성요인은 무엇인지에 대한 분석을 시도한다. 사이버안보 분야는 새로운 위협에 적절히 대처하기 위해 총체적인 접근 즉, 다면적이고 다행위자적인 접근을 요구한다는 점에서 대부분의 신안보 접근에서 적용되고 있는 포괄적 접근이 독일적 맥락에서 포괄적 안보로 치환되어 독일적 특성을 배태한 개념이 되었음을 밝힌다. 또한 본 연구는 외부요인으로서 미・중경쟁이라는 국제체제 요인과 경제적 상호의존의 변화가 독일의 사이버안보국가전략은 내용과 방향성을 결정하는 데 중요하지만, 결정적인 요인은 국내적 요인으로 국가전략문화를 통해 구체화하였다. 독일 사이버안보 전략의 수립과 실행은 독일의 연방적 특성으로 인한 분권화된 구조는 결국 포괄적 접근과 총체적 접근에 있어 구조적인 어려움을 내포하고 있다는 점에서 독일의 포괄적안보는 이러한 어려움을 타파하기 위한 전략적 개념이다. 동시에 독일과 같은 분권화된 사례가 보여주는 전략과 정책형성의 복잡성은 실행기관의 전문성과 독립성을 통해 완화될 수 있다. 결국 독일은 구조적 약점을 보완함과 동시에 장점은 강화하는 전략을 형성했다. 동시에 미・중 경쟁으로 인한 양자택일 혹은 안보-경제 선택에 대한 대안 전략을 제공해줄 수 있다는 점에 한국적 함의가 있다.

This study attempts to analyze the factors that form the national cybersecurity strategy in Germany. The cybersecurity requires a holistic approach, that is, a multi-dimensional and multi-actors approach to adequately cope with emerging threats, so the comprehensive approach applied in the field of emerging security approaches has been embeded in the German context. In addition, this study shows that the international system factors such as US-China competition and changes in economic interdependence as external factors are significant in determining the content and direction of the German cybersecurity national strategy, but the determinant is a domestic factor which is embodied through the national strategic culture. Germany's Vernetzte Sicherheit(comprehensive security) is a strategic concept for overcoming these difficulties in that the decentralized structure due to the federal nature of Germany in the establishment and implementation of the German cybersecurity strategy poses structural difficulties in both comprehensive and holistic approaches. At the same time, the complexity of strategy and policy formation shown by decentralized examples such as Germany can be mitigated through the expertise and independence of the implementing agency. Finally, there are Korean implications in that Germany has formed a strategy that complements structural weaknesses and enhances its strengths, and at the same time this study can provide an alternative strategy for security- economic choices due to US-China competition.

12

일본의 사이버안보 수행체계와 전략

이상현

[NRF 연계] 국가안보전략연구원 국가안보와 전략 Vol.19 No.1 2019.03 pp.115-154

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

인공지능(AI), 사물인터넷(IoT), 빅데이터(Big Data) 등 사이버 공간에서 발생하는 기술혁신의 진전은 인류문명의 패러다임 전환을 가져옴과 동시에 이로 인해 초래되는 사이버 위협 또한 해를 거듭할수록 심각성이 더해지고 있다. 이 글은 최근 심각성을 더해가는 사이버 위협에 대해 이웃국가인 일본이 범정부적 차원에서 어떠한 수행체계와 전략을 마련하여 이에 대처하고 있는지를 살펴보는 것이다. 이를 위해 이 글은 일본의 사이버안보 수행체계가 정립되고 발전해 온과정을 기본법 시행 전과 기본법 성립과정 그리고 기본법 성립 이후로 나누어 살펴본 뒤, 일본의 중장기 사이버안보 전략인 「사이버시큐리티전략」에대한 분석을 통해 일본 사이버안보 전략의 특징을 도출해 낸다. 체계적인 사이버안보 수행체계의 정립과 국가사이버안보전략 수립이란숙제를 안고 있는 우리에게 있어 일본의 선도적 행보는 모범사례이자 사이버 위협 대응 능력 강화라는 차원에서 많은 시사점을 제공해 주고 있다.

Advances in technological innovation in cyberspace such as AI, IoT, and Big Data have led to a paradigm shift in human civilization. At the same time, cyber threats resulting from this are also becoming more serious over the years. This article examines what kind of implementation framework and strategy Japan has prepared to cope with cyber threats that are adding to the seriousness of recent years. To this end, this article examines the development process of the cyber security system in Japan before and after the implementation of the Cybersecurity Basic Act and derives the characteristics of cybersecurity strategy in Japan through analyzing the Cyber Security Strategy. For us, who are in the process of establishing and developing a systematic cybersecurity implementation framework, Japan’s leading actions provide many implications for strengthening cyber threat response capabilities.

13

사이버 안보위협의 성격과 통합적 대응의 전략적 의미

장노순, 조성권

[NRF 연계] 한국외국어대학교 국제지역연구센터 국제지역연구 Vol.20 No.5 2017.01 pp.185-208

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사이버 공간의 긍정적 및 부정적 양면성에도 불구하고 국가는 사이버안보와 사이버 공간에서 국민의 사생활을 보호하고 정보가 자유롭게 유통될 수 있는 환경을 만들어야 한다. 그러나 사이버 공간에서는 이제 국가의 정체성이 점차적으로 희박해지고 미래에는 더욱 희박해질 것이다. 왜냐하면 국가 정체성보다는 새로운 집단의식으로 무장한 비국가 행위자들의 활동 영역이 될 가능성 때문이다. 사이버안보관련 대내적인 대응의 심각한 도전은 사이버 위협에 대한 방어와 공격 이후의 복원을 위해 통합적이고 체계적인 대응 방식으로 기존의 통합방위법을 적용하기에 사이버 안보위협의 성격이 다르다는 점이다. 특히 사이버 위협의 성격과 공격의 결과가 물리적 군사 공격과 상당히 거리가 멀고, 사이버 위협에 대해 군의 사회적 개입이 초래하는 부정적 요소들을 쉽게 간과할 수 없다. 사이버 안보위협에 대한 대외 안보전략 역시 억지전략이나 선제공격전략 등 기존의 군사전략을 그대로 수용하기에 장애 요소들이 많다. 국가는 사이버안보의 효과적인 정책 실행을 위해 국내 조직, 법제화 및 전문인력 양성 방안을 마련해야 하고, 대외 안보전략 차원에서도 한국의 독자적인 역량을 갖추고 한미 안보협력을 위한 호혜적인 관계에서 추진돼야 한다.

Cyberspace can be used positively and negatively in the view of national security, but state should protect the security of cyberspace and the civil right to exchange information among the public. One of the most important challenges is that state identity in cyberspace is getting weaker and may be hard to distinguish it in the near future. In particular, nonstate actors are playing a critical role in threatening cybersecurity. Any cybersecurity policies are far from sufficient to achieve its purpose because of the distinctive features of cybersecurity threats. A comprehensive defense policy toward cybersecurity cannot be applied with the main ideas of the current comprehensive security law. The cyber attacks are considerably different from those of military forces and the military’s involvement of cyber accidents in nonmilitary areas may bring about social and political oppositions. South Korea’s comprehensive cybersecurity defense is required to setup the governmental organization for cyber emergency, to authorize governmental activities, and to train cyber warriors. In cybersecurity strategy, the Korean government should prepare for the framework of conciliatory and balanced cooperation between South Korea and America.

14

사이버안보 위협, 대응 전략 그리고 한국적 함의

장노순

[NRF 연계] 국가안보전략연구원 국가안보와 전략 Vol.19 No.2 2019.06 pp.1-36

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사이버 공간은 안보 위협 측면에서 확장성과 복잡성이 크게 강화된 특징을 보여준다. 이에 따라 사이버안보의 위협이 전략적 목적에 따라 전통적인 방식과 다르게 제기되고 있다. 사이버전, 사이버 강압전략, 사이버 첩보활동, 공급망선도전략은 대표적인 유형이고, 이에 대한 대응 전략으로 적극적 방어전략, 사이버 강압대응전략, 사이버 방첩전략, 공급망안보전략이강구되고 있다. 사이버전이나 사이버 첩보활동은 오랫동안 사이버안보 위협으로 강조되었고, 강압전략이나 공급망선도는 국제안보질서에 주요 위협방식으로 최근 대두되고 있다. 이런 상황에서 한국 정부는 금년 초에 ‘국가사이버안보전략’을 발표했다. 이 전략에서 사이버안보 위협에 대한 대응 기조는 종합적이고 포괄적인 내용을 담고 있지만 억제와 예방전략을 채택하고 있다. 하지만 억제전략의 효과는 공개 천명만으로는 기대하기 어렵고, 그에 따른 구체적인 실행 의지와 역량이 필요하고 구체적인 실행의 경험도담보되어야 한다. 국제사회와 우방국의 협조와 지원 없이는 매우 제한적인효과만을 기대할 수 있다. 즉, 국가사이버안보전략의 발표는 국내 정책과제도로 뒷받침되어야 하고, 대외적으로는 실질적인 대응 여건이 갖추어져야 한다.

Cyberspace has been facilitating the expansiveness and complexity of national security. Under such a condition, cybersecurity threats which differ from traditional ones can be made diversely for its strategic purposes such as Cyber warfare, cyber coercion, cyber espionage, and supply network dominance. The counter strategies to prevail over malicious cyber operations are developed and applied with active cyber defense, counter cyber coercion, cyber counterintelligence, and supply network security strategies, respectively. Early this year, South Korea revealed the National Strategy for Cybersecurity that is based on deterrence and prevention. But this strategy can be expected to achieve its aims only by domestically introducing the policies and laws that cope with cyber attacks and maintain government performance, and internationally demonstrating its capabilities and willingness to do with allies and partners.

15

사이버 안보위협과 사이버 방첩의 역할과 전략

장노순

[NRF 연계] 한국국가정보학회 국가정보연구 Vol.9 No.2 2016.12 pp.97-117

※ 협약을 통해 무료로 제공되는 자료로, 원문이용 방식은 연계기관의 정책을 따르고 있습니다.

원문보기

사이버 위협은 다양한 수준의 심각성과 위협의 방식으로 국가안보에 도전해오고 있다. 이런 사이버 안보위협은 크게 사이버 공격과 사이버 이용으로 구분이 된다. 전자는 자료, 네트워크 혹은 시설이 훼손, 마비, 파괴되는 결과를 초래하지만, 후자는 자료를 절취하는 사이버 첩보활동을 의미한다. 사이버 첩보활동은 국가안보 관련 기밀에서 개인 자료에 이르기까지 정보를 절취함으로써 국익과 국가안보에 치명적인 위협이다. 하지만 사이버 첩보활동은 사이버 범죄와 전통적인 첩보활동의특징을 포함하지만, 전통적인 안보위협과 비교하면 국제규범의 제약과 통제를 심각하게 받지 않고안보전략의 적용도 용이하지 않다. 특히 사이버 첩보활동은 사이버 공격을 사전에 준비하는 과정으로 이 두 유형의 위협을 구분하는 경계가 애매하다. 이런 이유로 사전에 탐지하여 예방하고 방어하는 활동이 중요하고, 사이버 방첩은 그와 같은 기능을 수행하는 국가 안보전략의 일환이다. 방어와억지 목적에 국한된 사이버 방첩은 사이버 공간의 특성상 불충분하기 때문에, 미국은 공세적 방첩활동을 적극 추진하고 있다. 마찬가지로 한국은 사이버 방첩의 조직, 전략, 법적 제도화를 체계화할필요성과 시급성에 주목해야 한다.

Cyber threats become a critical security issue with regard to their diverse levels of severity and methods. Cyber security threats can be divided into two types, cyber attack and cyber exploitation. The former is halting operations, disrupting network and destroying facilities, and the latter means cyber espionage. Cyber spying is hacking the network system to steal data on from personal backgrounds to deepest secrets. Such an activity in cyberspace makes states greatly vulnerable. Cyber espionage involves some elements of cybercrime and human intelligence. However, this sort of threats is not yet a subject of international norms, and traditional security strategies cannot be expected to achieve their goals in cyberspace. In particular, cyber spying is a requisite step necessary to make cyber attacks and the boundary between these two threats are blurred. Because of difficulties to prevent and deter cyber security threats, it should be put an emphasis on cyber counterintelligence prior to cyber deterrence, prevention, and defense. In recent years, America is eager to build up its offensive cyber capabilities. Our government also should reexamine the organization, strategy and law concerning to cyber counterintelligence.

 
페이지 저장