구두 답변 · 2020-10-05 · 국회 14

공공 조달 교육 및 IT 허점 대응

AI 거버넌스 및 규제 공공 부문 AI 논쟁도 2 · 온건한 질의

의원이 정부 공무원의 조달 프로세스 교육 및 IT 통제 허점 문제를 질의했으며, 정기적인 교육이 있는지, 시스템적 문제가 있는지를 주목했습니다. 정부는 감사 보고서가 지적한 IT 통제 약점을 인정하고, 정부 IT 시스템이 복잡하고 분산되어 있으며 수동으로 권한을 조정하면 오류가 발생하기 쉽다고 설명했습니다. 현재 Smart Nation and Digital Government Group에서 자동화 개선을 추진하고 오류를 줄이기 위해 새로운 도구를 단계적으로 배포하고 있습니다.

핵심 요점

  • Procurement training for officers
  • IT privilege management gaps
  • Drive automation improvements
정부 입장

감사 의견 존중, 시스템 자동화 추진

질의 입장

교육 및 시스템적 허점에 주의

정책 신호

정부 IT 시스템 자동화 추진

“Actions have been taken at the whole-of-Government level to address the gaps identified.”

참여자 (3)

전문 번역(한국어)

Hansard 원문 · 2026-05-02

25번 의원 Alex Yam이 부총리 겸 재무부장관에게, 감사원장 보고서에서 매년 지적하는 약점들을 감안할 때, (a) 정부의 조달 절차 준수를 위해 공무원들이 적절한 교육과 감시를 받도록 어떻게 보장하는지, (b) 입찰 담당 공무원들이 최신 규정과 절차를 숙지하기 위해 정기적으로 재교육 과정에 참석해야 하는지 여부에 대해 질문하였습니다.

26번 의원 량롱화가 부총리 겸 재무 부장관에게, 최근 감사원 보고서에서 반복적으로 나타나는 정보 기술 통제 결함을 감안할 때, 공공 서비스에 내재된 체계적 문제가 있는지, 그리고 이러한 약점을 해결하기 위해 어떤 효과적인 조치를 취할 것인지에 대해 질문했습니다.

재무부 제2부장 (Indranee Rajah 여사) (부총리 겸 재무부장관 대리) : 의장님, 저에게 제25번과 제26번 질문에 함께 답변할 수 있도록 허용해 주시기를 간청합니다.

의장: 좋습니다. 말씀해주십시오.

Indranee Rajah 여사 : 먼저, 감사원장 보고서에서 언급한 대로 모든 기관들이 감사 의견을 매우 중요시하며 개선을 위해 노력하고 있음을 각 의원님들께 보장합니다. 정부 차원에서 발견된 부족분을 메우기 위한 조치를 이미 취해 왔습니다.

의장님, 2019/2020 회계연도의 감사원장 보고서는 정보기술 통제에 약점이 있음을 지적하고 있으며, 구체적으로는 첫째, 특권 사용자 활동의 검토, 둘째, 계정 및 사용자 접근 권한의 관리가 포함됩니다. 이러한 문제들은 이전 보고서에서도 제기된 바 있습니다.

배경을 제공하기 위해, 정부의 정보기술 시스템은 단계적으로 구축되었으며, 1980년대에 각 부처가 처음 IT 시스템을 구축하면서 시작되었고 이후 모든 부처 및 새로 설립된 부처와 프로젝트 사무실로 확대되었음을 먼저 설명하겠습니다.

그 후 IT 시스템은 여러 해 동안의 요구 사항을 보다 효율적으로 충족시키기 위해 지속적으로 업그레이드, 업데이트 또는 교체되었습니다. 따라서 우리는 현재 2,000개 이상의 정부 IT 시스템을 보유하고 있으며, 이러한 시스템들은 다양한 공급업체에 의해 다양한 기술로 개발되었습니다. 각 시스템은 자체 사용자 활동 로그 및 접근 권한 관리 방식을 가지고 있습니다. 접근 제어가 시스템 간 연동되지 않기 때문에, 공무원이 다른 부처로 발령났을 때 여러 시스템에서 수동으로 조정하여 만료된 권한을 취소하고 새 권한을 생성해야 합니다. 수동 조정에 의존하면 오류가 발생하기 쉽습니다.

스마트 네이션 및 디지털 정부 그룹 (SNDGG)은 프로세스를 간소화하고 오류를 줄이기 위한 자동화 시스템을 개발하고 있습니다. 2,000개 이상의 시스템에 구현해야 하므로 전면 확산에는 시간이 필요합니다.

첫째, 우리는 특권 사용자 활동의 검토를 자동화하고 있습니다. SNDGG는 일부 기관과 함께 시범 프로젝트를 시작했으며, 이 도구는 2021년 1월부터 단계적으로 배포될 것입니다. 2022년 12월 이전에 높은 우선순위 시스템에 대한 완전한 구현을 완료하고, 2023년 12월 이전에 모든 시스템을 적용할 것으로 예상됩니다.

둘째, 우리는 계정 및 사용자 접근 권한 관리를 자동화하고 있습니다. SNDGG는 기관 직원의 발령 및 역할 변경을 알림으로써 더 이상 필요하지 않은 사용자 계정을 수동으로 삭제하는 것을 용이하게 하는 솔루션 세트를 제공했습니다. 이 시스템에 접속한 38개 기관 중 5개가 감사원장 사무실의 감사를 받았으며, 계정 및 접근 권한 관리 측면에서 오류가 발견되지 않았습니다.

SNDGG는 현재 이 솔루션을 업그레이드하고 있으며, 향후 인사 기록이 직원 발령 또는 역할 변경으로 업데이트되면 시스템은 불필요한 계정을 자동으로 삭제하고 접근 권한을 검토할 것입니다. 이 시스템은 2023년 12월 이전에 800개의 높은 우선순위 시스템을 적용하고, 2024년 12월 이전에 모든 나머지 시스템을 적용할 계획입니다.

공무원들이 번거로운 수동 작업에서 해방되면, 기계가 대체할 수 없는 네트워크 보안 및 데이터 보호 작업에 더 집중할 수 있습니다. SNDGG는 공무원에 대한 교육을 강화했으며, 강력한 ICT 거버넌스 및 보안 통제의 중요성을 강조하고 올바른 습관과 경각심을 배양하였습니다. 모든 공무원은 매년 네트워크 및 데이터 보안 인식 교육을 받아야 합니다.

다음으로 조달 및 계약 관리에 대해 언급하겠습니다. 반복적으로 나타나는 오류는 IT 및 건축과 같은 보다 복잡한 조달 유형, 그리고 단일 입찰 가격의 적절성 평가 및 긴급 계약 변경 관리와 같이 직접적이지 않은 상황에서 주로 발생합니다. 이러한 복잡한 상황에 대처하려면 기술 기술뿐만 아니라 경험과 판단력이 필요하며, 이는 장기적인 축적을 필요로 합니다.

이를 위해 최근 몇 년 동안 우리는 조달 관리 측면에서 공무원의 역량 구축을 강화해 왔습니다. 첫째, 입찰 평가 및 승인과 같은 핵심 분야의 교육을 강화했으며, 교육 내용은 감사 의견의 학습 포인트 및 모범 사례를 포함합니다. 둘째, 내년 초에 승인 권한 보유자에게 추가 지침을 제공할 예정입니다. 셋째, 2018년부터 조달 프로세스에 참여하는 모든 공무원은 필수 전자 학습 모듈을 완료해야 하며, 정기적으로 보수 교육을 받고 새로운 정책 및 실천을 업데이트해야 합니다.

또한 우리는 건축 및 IT 조달 및 계약 관리 능력 구축을 강화하고 있습니다. 이러한 분야는 더욱 전문적이며 더 깊은 기술 지식을 필요로 합니다. 건축 및 건설청 (BCA)은 공무원이 건축 계약을 관리하도록 교육하기 위한 능력 틀을 수립하고 있습니다. 재무부와 BCA는 지난해 변경 주문 관리 및 사기성 입찰 식별에 대한 실질적인 조언을 제공하는 모범 사례 지침을 발표했습니다. 거버넌스를 강화하기 위해 우리는 일련의 거버넌스 지표에 따라 기관의 계약 관리 성과를 추적할 것입니다. 마찬가지로 GovTech는 IT 조달 능력 틀을 수립하고 있으며 전자 학습 모듈을 개발하고 있으며, 내년에 완료될 것으로 예상됩니다.

이러한 업무를 더욱 추진하기 위해, 재무부는 공무원 학원과 함께 올해 재정 및 조달 학원을 공동 설립했으며, 이는 공무원의 재정, 조달 및 계약 관리 기술을 향상시키기 위한 것입니다. 학원은 BCA, GovTech 등의 기술 기관과 협력하여 정규 교육뿐만 아니라 실무자 공유 및 멘토링과 같은 비정규 학습을 추진할 것입니다. 학원은 또한 공무원의 지속적인 학습을 지원하여 재정, 조달 및 계약 관리 정책 및 실천의 발전을 따라잡을 수 있도록 합니다.

재정 역량 배양 측면에서, 재정 공무원은 거버넌스 및 내부 통제 내용을 포함하여 정부 재무 절차의 기초 지식을 다루는 입직 과정에 참석해야 합니다. 이정표 프로젝트, 포럼 및 공유 회의를 통해 경력 전반에 걸쳐 이러한 지식을 지속적으로 강화하고 업데이트합니다. 유사한 조치는 공공 서비스의 더 넓은 범위에서 인식을 높이고 있으며, 예를 들어 재정 공무원이 아닌 사람들을 대상으로 하는 재정 과정에 관련 내용을 포함하는 것과 같습니다. 재무부는 또한 정기적으로 기관의 고위 관리진에게 공공 문책의 중요성을 강조하는 브리핑을 제공합니다.

요약하면, 공무원은 자신의 행동 및 결정에 대해 책임을 져야 하며, 여기에는 업무 수행 과정에서 높은 수준의 준수를 유지하는 것이 포함됩니다. 우리는 공공 서비스의 고위 리더십에 큰 기대를 가지고 있으며, 그들은 공공 자원 관리자의 책임을 부여받았으며, 그들의 조직 내에서 강력한 거버넌스 및 책임을 유지해야 합니다. 이러한 기대사항은 리더십 및 책임의 형태로 각 부처 및 법정 기관의 고위 리더십에 명확히 전달됩니다. 우리는 성과 평가에서 이러한 기대사항에 따라 리더십을 평가하며, 성과가 좋지 않은 경우 더 낮은 등급을 받을 것입니다. 사건의 성질과 원인에 따라 적절한 징계 조치가 취해질 수 있습니다.

마지막으로, 공공 문책은 정부의 최우선 과제임을 각 의원님들께 보장합니다. 감사원장 보고서에 언급된 기관들은 오류에 대한 추가 조사를 진행하고 있습니다. 공공 서비스의 고위 리더십은 발견된 문제를 해결하고, 근본 원인을 제거하며, 향후 재발을 방지하기 위해 노력할 책임이 있습니다.

의장 : 질서. 질의 시간 종료. 교통부장관 Josephine Teo의 해명.

오후 1시 31분

[의사 규칙 제22(3)조에 따라, 의제상 제29-32, 41-60, 63-68, 70-84, 86-90, 92-106 및 108번 질문에 대한 서면 답변은 부록에 기재되어 있습니다. 제27-28, 33-40, 61-62, 69, 85, 91 및 107번 질문은 2020년 10월 6일 의회 회의 논의로 연기되었습니다.]

영어 원문

SPRS Hansard 원본 기록 · 수집일: 2026-05-02

25 Mr Alex Yam asked the Deputy Prime Minister and Minister for Finance in view of the weak links highlighted annually in the Auditor-General's Reports (a) how does the Civil Service ensure that officers are adequately trained and supervised to meet the Government's procurement processes; and (b) whether officers handling tenders have to attend regular refresher courses to stay abreast with new regulations and processes.

26 Mr Liang Eng Hwa asked the Deputy Prime Minister and Minister for Finance in view of the recurring lapses in IT controls highlighted in the latest Auditor-General's Report, whether there are inherent systemic issues within the public service and what effective measures will be taken to address the weaknesses.

The Second Minister for Finance (Ms Indranee Rajah) (for the Deputy Prime Minister and Minister for Finance) : Mr Speaker, Sir, may I have your permission to answer Question Nos 25 and 26 together, in my response?

Mr Speaker : Yes, please.

Ms Indranee Rajah : Let me first assure Members that, as mentioned in the Auditor-General’s reports, all the agencies take the audit observations seriously and are committed to making improvements. Actions have been taken at the whole-of-Government level to address the gaps identified.

Mr Speaker, the Auditor-General’s Report for FY 2019/2020 highlighted weaknesses in IT controls, specifically in the areas of: first, review of privileged users’ activities; and second, management of account and user access rights. These observations were raised in previous Reports.

To provide some context, I should first explain that the Government IT systems were built over time, beginning from when we first built IT systems in Ministries back in 1980s and eventually extending to all Ministries and also new Ministries and programme offices.

Since then, the IT systems have been upgraded, refreshed or replaced to be more effective and efficient to cater to the requirements over the years. Consequently, we now have more than 2,000 Government IT systems built over the years, by different vendors and using different technologies. Each system has its way of logging user activities and of managing who can access the system. As the access controls are not linked across systems, when an officer moves to another portfolio, it requires a chain of manual adjustments to different systems, to remove obsolete access rights and create new access rights for the officer. The reliance on manual adjustments is prone to human errors.

The Smart Nation and Digital Government Group or SNDGG is developing systems that will automate the processes involved and minimise errors. It will take some time to fully implement the solutions across the whole-of-Government because we need to implement the automated process in more than 2,000 IT systems.

First, we are automating the review of privileged users’ activities. SNDGG has started a pilot with some agencies and the tool will be progressively deployed from January 2021. This will be fully implemented for high-priority systems by December 2022 and all remaining systems by December 2023.

Second, we are automating the management of account and user access rights. SNDGG has made available a solution which can alert agencies to staff movements and role changes so that they can manually remove the user accounts that are no longer required. Five of the 38 agencies that have onboarded this system were audited by AGO and no lapses pertaining to account and user access rights management were found.

SNDGG is in the midst of enhancing this solution, so that it can trigger automatic removal of unneeded user accounts and review of user access rights, once the staff movement or role change is updated in the HR records. This system will be implemented for 800 high-priority systems by December 2023 and all remaining systems by December 2024.

When officers are freed up from manual tasks, they are better able to focus on aspects of cyber-security and data protection that cannot be replicated by a machine. SNDGG has stepped up efforts to educate public officers on the importance of strong ICT governance and security controls, and to have the right habits and instincts. All public officers are required to undergo annual cyber and data security awareness training.

Next, on procurement and contract management, the recurrent lapses tend to be for more complex types of procurement – such as IT and construction, and in less straightforward cases, such as assessing price reasonableness for single bids and managing urgent contract variations. Navigating these complexities require not only technical skills but experience and judgment which require long-term efforts to build up.

To address this, we have been stepping up efforts in recent years to strengthen the competencies and capabilities of Public Officers in managing the procurement process. First, we are stepping up training of officers in key areas such as evaluation and approval of tenders. The training covers learning points from audit observations and good practices. Second, we will be providing additional guidance to approving authorities, which will be available from early next year. Third, since 2018, we have required all officers who are involved in procurement processes to complete a compulsory e-learning module. These are supplemented with regular refreshers and updates on new policies and practices.

In addition, we are also stepping up efforts to strengthen construction and IT procurement and contract management capabilities, which are more specialised areas requiring deeper technical know-how. The Building and Construction Authority or BCA is developing a competency framework to train public officers in managing construction contracts. MOF and BCA issued a good practice guide last year, containing practical advice on the management of variation orders and how to spot fraudulent quotes. To enhance governance, we will track agencies’ performance in contract management, based on a set of governance indicators. Similarly, GovTech is working on a competency framework for IT procurement and developing an e-learning module that will be ready next year.

To take these efforts forward further, MOF and the Civil Service College jointly established the Finance and Procurement Academy this year to better equip Public Officers with finance, procurement and contract management skills. The academy will work with technical agencies such as BCA and GovTech to not only conduct formal training, but also promote informal learning such as through practitioner sharing and mentorships. It will also support officers in continual learning to keep abreast of developments in finance, procurement and contract management policies and practices.

In the area of developing finance capabilities, finance officers today are required to attend induction courses that cover the fundamentals of Government financial procedures, including on governance and internal controls. These are reinforced and refreshed at milestone programmes, forums and sharing sessions throughout the officers’ career. Similar efforts are also undertaken to raise awareness of these concepts more widely across the Public Service. For example, they are incorporated into finance courses targeted at non-finance officers. MOF also conducts regular briefings to agencies’ senior management to emphasise the importance of public accountability.

In conclusion, let me say public officers are expected to be accountable for their actions and decisions, and this includes maintaining high standards of compliance with guidelines and procedures as they perform their duties. We place high expectations on the senior leadership of the Public Service, who are entrusted to be stewards of public resources. They must uphold strong governance and accountability in their organisations. These expectations are spelt out in the form of leadership competencies and responsibilities, which are conveyed to all senior Public Service leaders in Ministries and Statutory Boards. We evaluate our leaders against these expectations as part of their performance reviews and those who fall short will be rated less favourably. Depending on the nature and cause of the incident, appropriate disciplinary action may be taken as well.

So, finally, let me assure Members that public accountability remains a top priority for the Government. Where warranted, agencies mentioned in the Auditor-General’s report are conducting further investigation into the lapses. The senior leadership of the Public Service is accountable and committed to addressing the lapses identified, resolving the problem at the root and preventing future recurrence.

Mr Speaker : Order. End of Question Time. Clarification by Minister Josephine Teo.

1.31 pm

[Pursuant to Standing Order No 22(3), Written Answers to Question Nos 29-32, 41-60, 63-68, 70-84, 86-90, 92-106 and 108 on the Order Paper are reproduced in the Appendix. Question Nos 27-28, 33-40, 61-62, 69, 85, 91, and 107 have been postponed to the sitting of Parliament on 6 October 2020.]

같은 주제 더 보기