[Photo: ChatGPT]

A certification system that evaluates reliability and stability when private cloud providers offer services to public institutions will be unified into a single verification framework aligned with the National Intelligence Service’s National Network Security Framework (N2SF) from the second half of 2027.

As a result, the Ministry of Science and ICT’s Cloud Security Assurance Program (CSAP) will be abolished and the cloud security certification system will be integrated into the N2SF framework.

The overhaul is expected to somewhat lower entry barriers for private cloud providers seeking certification compared with CSAP. This is expected to relatively expand room for global cloud providers to operate in the public market.

The National Intelligence Service on Wednesday shared details of the cloud security certification policy overhaul and future plans at a cyber security summit event at COEX.

Under the overhaul, CSAP, which consists of high, medium and low grades, will be replaced by the N2SF framework based on grades C (Classified), S (Sensitive) and O (Open) promoted by the National Intelligence Service.

With the introduction of N2SF, the security environment for public institutions will move away from a uniform network separation structure. The core is to allow less important information to be made public on the internet. Data in the O grade among C, S and O can be disclosed on the internet. '

N2SF’s C, S and O security grades are broadly similar to CSAP’s high, medium and low system, but the security standards required for each grade differ.

In particular, for the S grade, which corresponds to CSAP’s medium grade, certification can be obtained without physical network separation if a public-sector-only data infrastructure is in place. This is expected to be an opportunity for global cloud companies as well.

Under CSAP’s data localization criteria, all grades required all systems and operating personnel to be located in South Korea to obtain certification. Under N2SF, the S and O grades allow operating management systems and operating personnel to be located overseas on the premise of ensuring cyber security activities. Under N2SF, international standard encryption such as AES can also be used for the S and O grades, in addition to verified encryption modules required under the encryption module validation system.

From companies’ perspective, this reduces various burdens associated with obtaining S and O grade certification. As physical network separation is not required to obtain S and O grade certification, global companies can target more substantial public infrastructure than under CSAP.

Under the CSAP framework, global firms only hold low-grade certification that can be obtained without network separation, so their presence in the public cloud market has not been significant. Industry participants point out that using global cloud providers for systems that fall under CSAP’s low grade is expensive and often not necessary.

The National Intelligence Service is expected to announce implementation of the new security verification system in the second half of 2027.

Even if the certification policy is overhauled, the existing CSAP validity period of 5 years will be maintained. Companies holding CSAP will be granted eligibility to comply with public security standards within the validity period even after switching to the N2SF framework.

The N2SF framework also introduces exception rules. Exceptions include domestic and overseas commercial generative AI (LLM) services that handle only public information, and cloud services tied to equipment for specific purposes such as medical robotic arms and patrol robot dogs.

Keyword

#N2SF #CSAP #National Intelligence Service #Ministry of Science and ICT #COEX
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.