|
 |
|
|
±Û¤ÓÀ¯Á¾±â ¿µ±¹ BCI(Business Continuity Institute) Çѱ¹´ëÇ¥, Deloitte ¾ÈÁøÈ¸°è¹ýÀÎ ±â¾÷¸®½ºÅ©ÀÚ¹®º»ºÎ Manager |
|
ÃÖ±Ù ±Û·Î¹ú±â¾÷ÀÇ Â÷º°ÈµÈ °æÀï·ÂÈ®º¸¸¦ À§ÇÑ ¼ÒÀ§ SCM2.0 Àü·«ÀÌ Ä¡¿ÇÏ´Ù. »ï¼º°æÁ¦¿¬±¸¼ÒÀÇ ÃÖ±Ù ¿¬±¸º¸°í¼¿¡ ÀÇÇÏ¸é ±Û·Î¹ú±â¾÷µéÀº ÀüÅëÀûÀ¸·Î´Â Àç°í°¨Ãà¿¡ ÃÊÁ¡À» ¸ÂÃá SCM(Supply Chain Management, °ø±Þ¸Á°ü¸®) 1.0À» ¹ÙÅÁÀ¸·Î ÇßÀ¸³ª ÃÖ±Ù¿¡´Â Â÷º°Àû °æÀï·ÂÈ®º¸¸¦ °Ü³ÉÇÑ Â÷¼¼´ë SCM(Àϸí SCM 2.0)À» ¾Õ´ÙÅý ÃßÁø ÁßÀÌ´Ù. SCM 1.0ÀÌ ±â¾÷ ÀÔÀå¿¡¼ 'ºñ¿ëÀý°¨(Àç°í°¨Ãà)'À» Ãß±¸ÇÏ´Â ¹Ý¸é SCM 2.0Àº ź·Â, ±×¸°, °í°´ÁöÇâ µîÀ» Ãß±¸Çϸç 'À¯¿¬¼º È®º¸(building resilience)'¸¦ Áß½ÃÇÏ´Â °ÍÀÌ Â÷ÀÌÁ¡ÀÌ´Ù.
Áï SCM 1.0¸¸À¸·Î´Â ÃÖ±Ù µé¾î ±Þº¯ÇÏ´Â ±Û·Î¹ú »ý»ê·¹°·ù·À¯Åë ȯ°æ ¼Ó¿¡¼ Áö¼ÓÀûÀÎ °æÀï·Â È®º¸°¡ ¾î·Á¿î ½ÇÁ¤À̶ó´Â °ÍÀ» º¸¿©ÁÖ°í ÀÖ´Ù. ƯÈ÷ ź·ÂÀû SCM, Áï ±Û·Î¹ú°ø±Þ¸Á(°ø±ÞüÀÎ)ÀÇ À§±â°ü¸®Ã¼Á¦ ±¸ÃàÀº Á¦Á¶, À¯Åë¾÷¿¡¼ ¸®½ºÅ©°ü¸®¿Í BCP Ãø¸é¿¡¼ »ó´çÈ÷ Áß¿äÇϸç Åë»ó SCMÀÌ °íµµÈµÉ¼ö·Ï °ø±Þ¸ÁÀÇ À§±â´ëÀÀ·ÂÀº Ãë¾àÇØÁö´Â °æÇâÀÌ ½ÉȵȴÙ.
Á¦Á¶È¸»çµéÀÌ JIT(Just-In-Time) µîÀ¸·Î ´ëÇ¥µÇ´Â °¨·®°æ¿µ(lean operations/man agement)À» ³»¼¼¿ö Àç°í ¹× Áߺ¹ÅõÀÚ¸¦ ȸÇÇÇÑ °á°ú À§±â°¡ ¹ß»ýÇßÀ» °æ¿ì ´ëó°¡ ½±Áö ¾ÊÀº »óȲÀÌ ¹ß»ý(ź·Â¼ºÀÇ ¾àÈ)ÇÒ °¡´É¼ºÀÌ Ä¿Á³´Ù. ƯÈ÷ ±Û·Î¹úȰ¡ ÁøÃ´µÇ¸é¼ ¿¹±âÄ¡ ¸øÇÑ ¼ö¿äº¯µ¿, Çù·Â¾÷ü µµ»ê, ÀÚ¿¬ÀçÇØ, Å×·¯ µî °æ¿µÀ§±âÀÇ ¹ß»ýºóµµ¿Í Ãæ°Ý, ¿µÇâ°ú ÆÄ±«·ÂÀÌ Áõ´ëÇÏ¸é¼ ÀÌÀü¿¡ ¸®Áú¸®¾ðÆ® ¿£ÅÍÇÁ¶óÀÌÁî(Resilient Enterprise: Overcoming Vulnerability for Competitive Advantage)¿¡¼µµ ¼Ò°³µÈ »ç·ÊÀÎ 2000³â ÃÊ °°Àº À§±â»óȲÀ» ¸Â¾Ò´ø ³ëŰ¾Æ¿Í ¿¡¸¯½¼ÀÌ À§±â°ü¸®·ÂÀÇ Â÷ÀÌ·Î ÀÎÇØ Èñºñ°¡ °¥·È´ø »ç·Ê°¡ ´ëÇ¥ÀûÀÌ´Ù.
Áö³ È£¿¡¼ ¾ð±ÞÇÑ GMÀÇ ¸®½ºÅ©°ü¸®»ç·Ê¿¡¼µµ °Á¶ÇÑ °Í°ú °°ÀÌ À§±â ¸ð´ÏÅ͸µ ü°è¸¦ ±¸ÃàÇÏ´Â °ÍÀº ¹°·Ð ºñ»ó°èȹ ¹× ¼±Åà °¡´ÉÇÑ ´ë¾ÈÀ» ÁغñÇÔÀ¸·Î½á °ø±Þ¸ÁÀÇ Ãë¾à¼º°ú À§±â¸¦ ¼±Á¦ÀûÀ¸·Î °ü¸®ÇÒ ¼ö ÀÖ´Â Áغñ´Â ¾Æ¹«¸® °Á¶Çصµ Áö³ªÄ¡Áö ¾Ê´Â´Ù. ½ÇÁ¦·Î °ø±Þ¸ÁÀÇ À§±â´Â ³ªºñÈ¿°ú·Î ÀÎÇØ ±â¾÷°æ¿µ¿¡ Ä¡¸íÀûÀÎ ¼ÕÇØ¸¦ ³¢Ä¥ ¼ö ÀÖÀ¸¹Ç·Î ü°èÀûÀÎ ½Å¼Ó ´ëÀÀ°ú Çù·Â¾÷ü°£ °øÁ¶°¡ ÇʼöÀûÀÌ´Ù.
|
 |
|
|
|
|
±Û·Î¹ú±â¾÷ÀÇ À§±â´ëÀÀ·ÂÀ» °ÈÇϱâ À§ÇØ À¯¿¬¼ºÀ» º¸°ÇÏ´Â ¹æÇâÀ¸·Î ±âÁ¸ °ø±Þ¸ÁÀ» Àç¼³°èÇÏ´Â °ÍÀÌ Áß¿äÇÏ°í ¿¹ÃøÇÏÁö ¸øÇÑ ¼ö¿äº¯µ¿¿¡ ´ëóÇϱâ À§ÇØ 'ź·ÂÀû °è¾à', '»ý»êóÀÇ ´Ù¾çÈ' µîÀ¸·Î °ø±Þ¸ÁÀÇ À¯¿¬¼º È®º¸ÇÏ°í ¼Ò¼ö °ø±Þ¾÷ü¿¡ ´ëÇÑ ³ôÀº ÀÇÁ¸µµ·Î ÀÎÇØ ¹ß»ýÇÒ ¼ö ÀÖ´Â Ãæ°ÝÀ» ÁÙÀ̱â À§ÇØ ´Ù¼ö °ø±Þ¾÷ü¸¦ Ȱ¿ëÇÏ°í °ø±Þ¾÷ü°£ ±ä¹ÐÇÑ Çù·ÂÀ» À¯ÁöÇÏ´Â °ÍÀ» ±Ç°íÇÏ´Â °ÍÀº BCP¿¡¼ Áß¿äÇÑ ¿ä¼Ò Áß ÇϳªÀÎ Á¦3ÀÚ ºñÁî´Ï½º¿¬¼Ó¼º È®º¸(3rdpartyBusiness Continuity)¿Íµµ ÀϸƻóÅëÇÑ´Ù.
ÇÑ Á¶Á÷ÀÇ Àü»çÀû ¸®½ºÅ©°ü¸® ü°è´Â ºñÀü°ú Á¶Á÷ÀÇ ¸ñÀû/¸ñÇ¥¶ó´Â ÃÖ»óÀ§´Ü°èºÎÅÍ ¸®½ºÅ© ´ëÀÀ¸Å´º¾ó°ú Á¶±â°æº¸½Ã½ºÅÛ, ´ë½Ãº¸µå µî ¸Å´º¾ó°ú ½Ã½ºÅÛÀ̶ó´Â ÃÖÇÏÀ§ ü°è·Î Á¤¸®ÇÒ ¼ö ÀÖ´Ù. ¹°·Ð ÀÌ·¯ÇÑ Ã¼°è¿¡ ´ëÇÑ Á¤ÀÇ´Â ÇϳªÀÇ ¸ð¹ü»ç·ÊÀ̰í Á¤´äÀº ¾Æ´Ï¸ç ±× Á¶Á÷ÀÇ ºñÁî´Ï½º ÇàÅÂ, ¼º°Ý, Á¶Á÷¹®È¿¡ µû¶ó º¯°æ Àû¿ëÀÌ ÇÊ¿äÇÏ´Ù. ¤ý¸®½ºÅ©°ü¸® Á¤Ã¥(Policy) : Á¶Á÷ ºñÀü, Á¶Á÷ ¸ñÀû/¸ñÇ¥ ¹Ý¿µ ¤ý¸®½ºÅ©°ü¸® µµÀÔ/°ü¸® Àü·«(Strategy) : µµÀÔ¿øÄ¢, Áö¹è±¸Á¶, ´ëÀÀÀü·«, ¿î¿µÀü·« Æ÷ÇÔ ¤ý¸®½ºÅ©°ü¸® ÀýÂ÷(Process) : (¼ø¼) ¸®½ºÅ©ÀνÄ, ¸®½ºÅ©Æò°¡, KRI(Key Risk Indicator Áֿ丮½ºÅ©ÁöÇ¥) µµÃâ, ¸ð´ÏÅ͸µ ¹× º¸°í, ¸®½ºÅ©´ëÀÀ ¤ý¸Å´º¾ó/½Ã½ºÅÛ(Response Plan - Manual, System): KRI´ëÀÀ ¸Å´º¾ó, ¸®½ºÅ© ´ëÀÀ¸Å´º¾ó, ERM ½Ã½ºÅÛ * ¸»¹Ì¿¡ ±â¼úÇÑ BS 31100¿¡¼ ¼Ò°³ÇÑ Risk Management Framework ±¸¼º¿ä¼Òµµ Âü°í
|
 |
|
|
|
|
±×·¯¸é ÀÌ·¯ÇÑ ±¸¼º¿ä¼Ò/ü°è ÇÏ¿¡¼ ERM ü°è¼ö¸³À» À§ÇÑ ¼öÇàÀýÂ÷¿Í °£´ÜÇÑ ¹æ¹ýÀ» ¾Ë¾Æº¸ÀÚ. ´ëü·Î ¼öÇàÀýÂ÷´Â ¸®½ºÅ©ÀνÄ(Risk Identification) > ¸®½ºÅ©Æò°¡(Risk Assessment) > ¸®½ºÅ© ´ëÀÀ(Risk Response Strategy/Res ponse Plan, KRI ¼±Á¤/ÃßÃâ Æ÷ÇÔ) > ¸ð´ÏÅ͸µ(Monitoring) ÀÇ »ý¸íÁÖ±â(lifecycle)Çü½ÄÀ¸·Î º¸°í ÀÖÀ¸¸ç ´õ ±¸Ã¼ÀûÀ¸·Î ³ª¿Çغ¸¸é ´ÙÀ½°ú °°´Ù. (ERM ÄÁ¼³ÆÃ ¼öÇà¹æ¹ý·Ð¿¡¼ ÁøÇàÇÏ´Â ¼öÁØ/¼º¼÷µµ Æò°¡(maturity level)¿Í ÇöȲºÐ¼® µîÀÇ ºÎºÐÀº ¿©±â¼ ¼³¸íÇÏÁö ¾Ê´Â´Ù.) ¤ý¸®½ºÅ©ÀÎ½Ä - ¸®½ºÅ© À¯´Ï¹ö½º/¸Ê(Risk Universe/Map)µî Á¤ÇüÈµÈ ¸®½ºÅ© Ç®(Risk Pool, À§Çè¿©·¯¿ä¼Ò)À» ±â¹ÝÀ¸·Î ºÎ¼ ÀÎÅͺä, ¼³¹®À» ÅëÇØ ÇØ´ç Á¶Á÷¿¡¼ Àü»çÀû ¿µÇâ°ú Ãæ°ÝÀ¸·Î ¹ßÀüµÉ °¡´É¼ºÀÌ ÀÖ´Â Ãë¾àÇÑ ¸®½ºÅ©¸¦ ÃßÃâ ¤ý¸®½ºÅ©Æò°¡ - ¸®½ºÅ© ´ëÀÀ ÀÌÀüÀÇ ÃѸ®½ºÅ©(Total or Inherent Risk)¿Í ¸®½ºÅ© ´ëÀÀ ¼öÁØÀ» Æò°¡ÇØ Â÷°¨ÇÑ ÀÜ¿©¸®½ºÅ©(Residual Risk)¸¦ °áÁ¤Çϸç ERM µµÀÔ µî Àü·«¼ö¸³À» ÅëÇØ Ãß°¡ÀûÀÎ ´ëÀÀ¹æ¾È ¼ö¸³À¸·Î ÀÎÇØ ÃÖÁ¾ ¼ö¿ë °¡´ÉÇÑ ÀÜ¿©¸®½ºÅ©(Acceptable Residual Risk) ¼öÁØÀ» ÆÄ¾Ç, Á¶Á÷ÀÌ ¸ñÇ¥·Î ÇÏ´Â Çã¿ëÄ¡(tolerable level, threshold)¸¦ ³Ñ¾î¼´Â °æ¿ì ÇØ´ç ºÎºÐ¿¡ ´ëÇØ ´ëÀÀ¹æ¾ÈÀ» ¼ö¸³ÇÏ´Â ´ë»ó ±âÁØ ¸¶·Ã, Áï °ü¸®´ë»óÀÇ ¿ì¼±¼øÀ§È ¤ý¸®½ºÅ©´ëÀÀ - ºñ»ó´ëÃ¥À§¿øÈ¸ Æ÷ÇÔ ´ëÀÀÁ¶Á÷±¸¼º ¹× ´ëÀÀ¸Å´º¾ó ÀÛ¼º, Æò»ó½Ã ¸®½ºÅ©°ü¸® ÀýÂ÷¿Í ºñ»ó½Ã À§±â°ü¸®ÀýÂ÷(Crisis Management Procedure) (ÁöÇ¥µ¥ÀÌÅÍ ¼öÁý µî KRI ÃßÃâ Æ÷ÇÔ) ¤ý¸ð´ÏÅ͸µ - ÇÙ½ÉÀ§Çè¿ä¼Ò(Key risk)¿¡ ´ëÇÑ ÁýÁß ºÐ¼® ¹× ¸ð´ÏÅ͸µ À§ÇÑ ÁöÇ¥ µµÃâ ÈÄ À§±â ½Ã ÀÇ»ç°áÁ¤ Áö¿øÇÏ´Â Dashboard Çü½ÄÀÇ ½Ã½ºÅÛ ±¸¼º, Á¶±â°æº¸½Ã½ºÅÛ(EWS, Early Warning System) µî
|
 |
|
|
|
|
´ÙÀ½Àº ±Û·Î¹ú ¸®½ºÅ© Á߿伺(Risk Importance)°ú °ü¸®³À̵µ(Discomfort Risk is Being Managed Appropriately) °£ÀÇ °ü°è¸¦ ³ªÅ¸³»ÁÖ°í ÀÖ´Ù. (Ãâó: Excellence in Risk Management 2007 º¸°í¼by MARSH, RIMS) °¢ ±â¾÷ÀÇ ¸®½ºÅ©°ü¸®´ã´çÀÚ¸¦ ´ë»óÀ¸·Î ÇÑ ¼³¹®Á¶»ç¸¦ ÅëÇØ ´Ù·ïÁö°í ÀÖ´Â ¸®½ºÅ©°¡ Áß¿äÇϸ鼵µ À̸¦ ´ëÀÀ, °ü¸®ÇϱⰡ ¸Å¿ì ¾î·Á¿î ºÐ¾ß°¡ ±×¸²¿¡¼ »¡°£»öÀ¸·Î Ç¥½ÃµÈ ¿ìÃø»ó´Ü¿¡ À§Ä¡ÇÑ ¿µ¿ªÀ¸·Î Àü»çÀû¸®½ºÅ©¿Í BCP, À§±â°ü¸®ºÐ¾ß°¡ ´«¿¡ ¶è´Ù.
Á¶»ç¿¡¼µµ ¾Ë ¼ö ÀÖµíÀÌ Àü»çÀû¸®½ºÅ©°ü¸®´Â ´ë»ó ÀÚüµµ Áß¿äÇÒ »Ó ¾Æ´Ï¶ó ½ÇÁ¦ÀûÀ¸·Î ¿î¿µ°ú °ü¸®°¡ ¸Å¿ì ¾î·Æ°í Á¤´äÀÌ ¾ø¾î¼ ´Ù¾çÇÑ »ê¾÷¿¡¼ ÁøÇàÇϰí ÀÖ´Â ¸ð¹ü½Çõ»ç·Ê(best practice) µéÀ» °è¼Ó º¥Ä¡¸¶Å· ÇÏ´Â Áö¼ÓÀûÀÎ ³ë·ÂÀÌ ¸Å¿ì Áß¿äÇÏ´Ù. ´ÙÀ½ È£, Àü»çÀû¸®½ºÅ©°ü¸®(ERM)¿Í BCP Á¦4ºÎ¿¡¼´Â ½ÇÁ¦ ±Û·Î¹ú±â¾÷ÀÇ ¸î¸î »ç·Ê¸¦ ¼Ò°³ÇÏ¸é¼ Áö±Ý±îÁö °Á¶ÇؿԴø ERM ±¸¼º¿ä¼Ò¿Í ü°è, °ü·Ã À̽´µéÀÌ ¾î¶»°Ô À¯±âÀûÀ¸·Î ±¸ÇöµÇ¾î ¿î¿µ, °ü¸®µÇ°í ÀÖ´ÂÁö¸¦ ¾Ë¾Æº»´Ù.
¸®½ºÅ©°ü¸® practice¸¦ Á¤ÇüÈ, Ç¥ÁØÈÇÑ ¸î°¡Áö ÁÁÀº Ç¥Áع®¼¸¦ ¼Ò°³ÇÑ´Ù. 1) 2006³â¿¡ ¹ß°£µÈ È£ÁÖ±Ô°Ý AS/NZS 4360: The Risk Management Standard 2) 2008³â ¿µ±¹±Ô°Ý BS 31100: Code of Practice for Risk Management, PAS(Publicly Available Specification)¸¦ Áö³ª DPC(Draft for Public Comment) ´Ü°è¸¦ °ÅÄ¡°í ÀÖÀ¸¸ç, ÇϹݱâ Áß¿¡ ÃÖÁ¾±Ô°ÝÈ µÉ ¿¹Á¤) * BS 31100¿¡¼ Á¤ÀÇÇϰí ÀÖ´Â Risk Management Framework ±¸¼º¿ä¼Ò¸¦ °£´ÜÈ÷ ¤¾îº¸¸é ´ÙÀ½°ú °°´Ù. ¤ý¸®½ºÅ©°ü¸® ¹®È Risk Management Culture ¤ý¸®½ºÅ© °¡¹ö³Í½º(±¸Á¶/Á¶Á÷ Æ÷ÇÔ) Risk Governance ¤ý¸®½ºÅ©°ü¸® Àü·« Risk Management Strategy ¤ý¸®½ºÅ© ¼ºÇâ Risk Appetite ¤ý¸®½ºÅ©°ü¸® Á¤Ã¥ Risk Management Policy ¤ý¸®½ºÅ©, ¿µÇ⠺зù ¹× ÃøÁ¤ Risk and Impact Categorization and measurement - Àü»çÀû ¸®½ºÅ© ±¸¼ºÀ» ½ÃÀå, ½Å¿ë, ¿î¿µ, ÇÁ·ÎÁ§Æ®, À繫, Àü·«, ÆòÆÇ ¸®½ºÅ©·Î Å©°Ô ±¸ºÐ - ¿µÇâ ±¸ºÐÀº À繫Àû, ÀÎÀû, ¼ºñ½º, °í°´, ÁÖÁÖ(ÀÌÇØ°ü°èÀÚ), ÅõÀÚÀÚ, Á¦Ç°, ¹ý·ü/±ÔÁ¦Áؼö, ÆòÆÇ°ú ºê·£µå·Î ºÐ·ù ¤ý¿ªÇÒ°ú Ã¥ÀÓ Role & Responsibility ¤ýÈÆ·Ã/±³À° Training ¤ý¸®½ºÅ©°ü¸® µµ±¸ Risk Management Tools - ¾÷¹«¿î¿µ Practice, ±â¼ú Techniques, ÅÛÇø´ Template, ¹®¼ Documents, ½Ã½ºÅÛ/¼Ö·ç¼Ç Systems, Àü¹®°¡ Á¶¾ð Advices ·Î ´Ù¾ç ¤ý(´ë³»¿Ü) º¸°í (Internal / External) Reporting ¤ý °æ¿µÁø °ËÅä Review |