The Ministry of Science and ICT is set to overhaul the cybersecurity framework for the ministry and its affiliated and subordinate agencies. [Photo: Shutterstock]

South Korea's Ministry of Science and ICT will overhaul the cybersecurity framework for the ministry and its affiliated and subordinate agencies. It will subdivide security systems based on the importance of work-related information and apply separate security standards to new technology areas such as AI and cloud computing. It will also codify procedures to preserve evidence held by outside contractors when security incidents occur.

On Sept. 15, government and industry sources said the ministry issued an administrative notice of a partial revision to its Basic Information Security Guidelines incorporating the changes. The move follows the National Intelligence Service's revision in May of the National Cybersecurity Basic Guidelines.

It will also rename the guidelines to the Ministry of Science and ICT Basic Cybersecurity Guidelines from the Ministry of Science and ICT Basic Information Security Guidelines. The revised guidelines apply not only to the ministry but also to its affiliated agencies and subordinate institutions.

One of the biggest changes is the introduction of the National Network Security Framework (N2SF). Each agency must classify information it handles by work function into three levels. Until now, security for public institutions has centered on separating internal networks from internet networks. Under the revision, agencies will manage work-related information by dividing it into Classified, Sensitive and Open levels in line with NIS guidelines.

Open-level domains or information systems may communicate with the external internet or be placed on the external internet as long as they do not violate security control standards. The existing principle of separating and operating internal networks and institutional internet networks remains. While adding N2SF-related provisions, the revision also requires security measures including separation of internal and internet networks, blocking unauthorized intrusion, blocking internet access for internal-network information systems and secure data transfer between networks.

Each agency will carry out the actual work of classifying information levels. As work content and held data differ by agency, each one must identify its work functions and classify information into classified, sensitive and open levels based on that. The revision also adds a provision allowing agencies to raise an information security level when the importance or impact of a breach increases as different information is combined.

◆ Beyond network separation to information-level security...AI and cloud standards made more specific

The ministry also revised security rules for the AI era. Under the revision, each agency is required to establish and implement separate security measures when building or operating AI systems. When preparing the measures, agencies should seek to use relevant guidelines such as the AI Security Guidebook distributed by the NIS.

Projects to build information and communications networks or information systems using AI are newly included in the scope of security reviews. The scope also includes projects subject to N2SF, projects linked to other agencies' networks and systems, construction of large-scale backup and disaster recovery centers, online maintenance in national disaster and crisis situations, and the construction and introduction of space systems.

The revision also specifies standards for public institutions' use of private cloud services. Each agency must use private cloud services included in the list of services eligible for adoption under the National Cybersecurity Basic Guidelines. It adds to security standards whether data is stored and managed in information systems located in South Korea and whether they are managed by personnel based in South Korea.

It also strengthens the responsibilities of cloud providers. When an agency contracts with a private cloud provider, it must include terms requiring the provider to actively cooperate with the NIS and the user agency on security monitoring and incident investigations and on preventing and responding to cyberattacks, to respond to hacking incidents or outages and to prevent recurrence. Private cloud providers are required to assume security management responsibility for the cloud areas used by the agency at a level equivalent to that of government agencies.

The revision also includes as cooperation targets contractors carrying out IT projects for the ministry and its affiliated and subordinate agencies, as well as developers, manufacturers and suppliers of information systems and information security systems, cloud providers, telecommunications operators and information and communications service providers. If these businesses receive requests for cooperation and support from the NIS director, such as fact-finding or submission of materials related to cybersecurity work, they must comply unless they have just cause.

It also specifies the responsibilities of private companies that supply commercial software. When an agency introduces commercial software, contracts must specify that the agency may request corrective actions from the manufacturer or seller if security vulnerabilities are found in the product. Manufacturers are obligated to fix vulnerabilities once they become aware of them in products used by end users. It also includes provisions allowing agencies to request technical support from manufacturers and suppliers when vulnerabilities are found through technical support letters of commitment or agreements among the ordering party, supplier and manufacturer. A separate provision is added requiring corrective actions for commercial software with vulnerabilities in line with such contract terms.

The revision requires continuous monitoring of authentication and access histories to detect anomalous activity and take steps such as warnings, additional authentication, access restrictions or blocking as needed. Authentication and access logs, including successful or failed logins, access IP addresses and access times, must be kept for at least 1 year. Multi-factor authentication will be applied to administrator-privilege authentication except in unavoidable cases.

It also requires information system managers to prepare measures such as backup systems to prevent leakage of stored log records. If storage devices such as hard disks and SSDs are removed from or reinstalled in terminals or servers, agencies must manage the history and store removed devices in designated locations.

◆ Stronger evidence preservation for intrusions...security scope expanded to space systems

The revision also strengthens evidence preservation procedures after cyber intrusion incidents. Under current guidelines, affected agencies must preserve evidence in affected systems until the cause is identified and are prohibited from arbitrarily deleting or formatting related data. Under the revision, if outside contractors hold some or all incident evidence, agencies must immediately notify those contractors to prohibit data deletion and formatting. The measure aims to prevent situations where evidence disappears because outside contractors arbitrarily initialize systems or remove related data during investigations.

It also strengthens grounds for investigations when incidents occur in the cloud. Agencies using the cloud may take necessary steps, such as forming a joint investigation team with an investigative body to demand preservation and submission of materials from the service provider or to conduct on-site inspections. If the investigative body is the NIS, a new provision allows it to take necessary steps including fact-finding and verification, submission of materials and on-site inspections of cloud providers.

The revision also expands the scope of security management to the space sector. It sets out asset identification and security management for components of space systems including satellites, ground stations, satellite networks, communications facilities and related software. It requires security measures for interconnection sections among ground stations, satellite networks and satellites, and calls for advance reviews of cybersecurity threats that may arise when introducing and operating space systems such as low Earth orbit satellite communications.

The guideline revision does not mean agencies will immediately complete the transition of their security systems. To apply N2SF in practice, follow-up work is needed to reclassify each agency's work and data and then overhaul information systems, network structures and access control systems accordingly.

In particular, applying the changes in the field is expected to take some time because agencies must subdivide work-related information into classified, sensitive and open categories and then reconfigure systems and domains accordingly. Security reviews and improvements to contract frameworks will also need to proceed in parallel as AI and cloud adoption expands.

"This revision reflects the introduction of N2SF and changes reflecting new environments such as AI in line with the revision of the National Cybersecurity Basic Guidelines," it said. "We plan to 추진 security system transition work 단계적으로 in line with the introduction of AI systems and improvements to the data classification system."

Keyword

#Ministry of Science and ICT #N2SF #National Intelligence Service #AI Security Guidebook #Space systems
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.