시장보고서
상품코드
2092431

Measuring What Matters : 고객에게 필수적인 사이버 보안 지표 플랫폼 구축

Measuring What Matters: Building the Cybersecurity Metrics Platform Your Customers Can´t Live Without

발행일: | 리서치사: 구분자 IDC | 페이지 정보: 영문 33 Pages | 배송안내 : 즉시배송

    
    
    



가격
PDF (Single User License) help
PDF 보고서를 1명만 이용할 수 있는 라이선스입니다. 인쇄는 가능하며 인쇄물의 이용 범위는 PDF 이용 범위와 동일합니다.
US $ 7,500 금액 안내 화살표 ₩ 11,173,000
※ 부가세 별도
한글목차
영문목차
※ 본 상품은 영문 자료로 한글과 영문 목차에 불일치하는 내용이 있을 경우 영문을 우선합니다. 정확한 검토를 위해 영문 목차를 참고해주시기 바랍니다.

사이버 보안 지표에 관한 총 2회 시리즈 중 두 번째 편인 이 IDC Market Perspective에서는 공급업체가 구축, 제공 및 수익화할 수 있는 데이터 기반의 3계층 구조(거버넌스, 관리, 운영)로 구성된 지표 프레임워크를 정의하고 있습니다. 전 세계의 조직들은 경영진, 이사회 및 운영 팀에 유용한 형태로 사이버 보안 위험을 측정하지 못하고 있으며, AI의 부상으로 인해 이러한 격차는 더욱 확대되고 있습니다. 기술 제공업체와 서비스 제공업체에게 있어, 이는 GRC 및 사이버 보안 시장에서 가장 중요한 차별화 기회 중 하나가 될 것입니다. AI는 적대적인 공격을 가속화하는 것과 적절한 거버넌스 없이 사내에 AI를 도입하는 것, 이 두 가지 측면에서 위협 상황을 재편하고 있습니다. 이러한 측면들은 모두 기존의 사이버 보안 지표로는 파악되지 않습니다. 섀도우 AI 탐지부터 에이전틱 AI 거버넌스, SaaS에 통합된 AI의 가시화에 이르기까지, AI 고유의 위험 측정 기능을 플랫폼에 통합한 제공업체는 모든 산업 분야와 조직 규모에 걸쳐 중요하면서도 아직 해결되지 않은 고객의 요구를 충족시킬 수 있을 것입니다. 본 자료에서는 섀도우 AI, 규제 준수 체계, 에이전틱 AI의 위험, 모델의 지적 재산권 보호, 그리고 SaaS에 통합된 AI를 포괄하는 전용 AI 위험 지표를 활용하여 3단계 프레임워크를 확장하고 있습니다. 원어민 수준의 AI 거버넌스 기능을 갖춘 GRC 플랫폼을 도입하고, 지표를 비즈니스 리스크와 연계하며, 투명성이 높고 검증된 인사이트를 활용해 대상자별 의사결정을 지원하는 조직이야말로, 오늘날 AI가 주도하는 위협 및 규제 환경에서 자신 있게 주도적인 입지를 구축할 수 있을 것입니다. "AI 시대는 조직이 사이버 보안 위험을 측정하는 방식에 대한 근본적인 재검토를 요구합니다. AI 시스템이 거버넌스, 측정, 설명 책임 없이 운영되고 있음에도 불구하고, 이사회에 방화벽 차단 건수만 보고하는 것은 더 이상 용납될 수 없습니다. 통합된 인텔리전스 플랫폼을 기반으로 구축되고, 모든 대상 수준에서 AI 특유의 위험을 포착하도록 확장된 데이터 기반 지표는 더 이상 모범 사례에 그치지 않습니다. 이는 비즈니스에 있어 필수 요건입니다."라고 IDC의 거버넌스, 리스크, 컴플라이언스 솔루션 담당 리서치 디렉터인 필립 해리스(Philip Harris) 씨는 말했습니다.

이그제큐티브 스냅샷

  • 주요 사항
  • 권장되는 대응 방안

새로운 시장 동향과 시장 역학

  • 역설적인 구조 : 사이버 보안 지표가 오해받는 이유
  • 이사회까지 책임이 미친다 : 현 상황을 더 이상 용납할 수 없는 이유
  • 3가지 장벽, 1가지 사각지대 : 지표의 괴리가 해소되지 않는 이유
  • 기존 지표가 가져온 것과 가져오지 못한 것
  • 패치 수 집계에서 쉬운 표현으로 : 조직이 실제로 필요로 하는 것
  • 무기로 활용되고, 제대로 관리되지 않는 : AI의 두 가지 새로운 위험 요소
    • 데이터 기반 지표
      • 데이터 기반 지표의 특성
      • 지표를 수립할 때 고려해야 할 요소
        • 위험에 대한 이해
        • 데이터 수집의 일관성
        • 데이터 분석
        • 결과 해석
        • 이해관계자에 대한 배려
        • 의사결정 지원
        • 모니터링 및 최적화
        • 프로세스 및 지침 수립

기술 공급업체/서비스 제공업체를 위한 조언

  • 데이터 기반 지표에 필요한 요소
  • GRC 플랫폼의 역할
  • 인텔리전스 패브릭이 제공하는 기능
  • 패브릭이 실현하는 것
    • 대상자에 맞는 적절한 지표
      • 거버넌스 지표
        • 대상층
        • 카테고리 및 상세 정보
      • 관리 지표
        • 대상자
        • 카테고리 및 상세 정보
      • 운용 지표
        • 대상 독자
        • 카테고리 및 상세 정보
    • 장점

참고 자료

  • 관련 조사
  • 요약
KSM

This IDC Market Perspective, part 2 of a two-part series on cybersecurity metrics, defines a data-driven, three-tier metrics framework (governance, managerial, and operational) that providers can build, deliver, and monetize. Organizations worldwide are failing to measure cybersecurity risk in ways that serve their executives, boards, and operational teams, and the emergence of AI has widened that gap. For technology providers and service providers, this represents one of the most significant differentiation opportunities in the GRC and cybersecurity market.AI is reshaping the threat landscape on two fronts: accelerating adversarial attacks and deploying AI internally without adequate governance. Neither dimension is captured by traditional cybersecurity metrics. Providers that embed AI-specific risk measurement capabilities, from shadow AI detection to agentic AI governance and SaaS-embedded AI visibility, into their platforms will address a critical, unmet customer need across every industry and organization size.This document extends the three-tier framework with dedicated AI risk metrics covering shadow AI, regulatory compliance posture, agentic AI risk, model IP protection, and SaaS-embedded AI. Organizations that implement GRC platforms with native AI governance capabilities, align metrics to business risk, and empower audience-specific decision-making with transparent, validated insights will be best positioned to lead with confidence in today's AI-driven threat and regulatory environment."The age of AI demands a fundamental rethink of how organizations measure cybersecurity risk. Reporting firewall blocks to boards while AI systems operate without governance, measurement, or accountability is no longer acceptable. Data-driven metrics, built on a consolidated intelligence platform and extended to capture AI-specific risk at every audience level, are no longer a best practice. They are a business imperative," says Philip Harris, research director, Governance, Risk, and Compliance Solutions, IDC.

Executive Snapshot

  • Key takeaways
  • Recommended actions

New Market Developments and Dynamics

  • Built in reverse: Why cybersecurity metrics are misunderstood
  • Accountability reaches the boardroom: Why the status quo can no longer be tolerated
  • Three barriers, one blind spot: Why the metrics gap has persisted
  • What traditional metrics delivered, and what they didn't
  • From patch counts to plain language: What organizations actually need
  • Weaponized and ungoverned: AI's two new risk dimensions
    • Data-driven metrics
      • Qualities of data-driven metrics
      • Elements to consider in crafting metrics
        • Understanding the risks
        • Aligning data collection
        • Analyzing the data
        • Interpreting the results
        • Considering the stakeholders
        • Empowering decision-making
        • Monitoring and optimizing
        • Establishing processes and guidelines

Advice for the Technology Supplier/Services Provider

  • What is needed for data-driven metrics
  • The role of GRC platforms
  • What the intelligence fabric provides
  • What the fabric enables
    • Appropriate metrics by audience
      • Governance metrics
        • Audience
        • Categories and details
      • Managerial metrics
        • Audience
        • Categories and details
      • Operational metrics
        • Audience
        • Categories and details
    • Benefits

Learn More

  • Related research
  • Synopsis
샘플 요청 목록
0 건의 상품을 선택 중
목록 보기
전체삭제
문의
원하시는 정보를
찾아 드릴까요?
문의주시면 필요한 정보를
신속하게 찾아드릴게요.
02-2025-2992
email
문의하기