Naver Cloud said on Tuesday it has launched DSAC (DB & Server Access Control), an integrated security service that controls access to databases (DB) and servers and automatically records and manages work histories.
The company said DSAC is a cloud-native security solution that integrates access-rights management, work-history logging and audit functions for servers and databases that handle personal information, and provides integrated support for personal-information processing functions.
It is offered in a SaaS format that can be used immediately from a console without building a separate solution. The company stressed that a proxy server is automatically created and deleted, enabling detailed control of which servers and databases each user can access without separate account management.
Under the Personal Information Protection Act and its enforcement decree, and standards for measures to ensure the safety of personal information, businesses that handle personal information must meet a legal obligation to keep access records for related systems for at least 1 year and preserve the history of changes to access rights for at least 3 years.
But there has been no cloud-native access control service that meets domestic regulations, so companies have mainly relied on separately adopting external solutions.
Kim Jae-dong (김재동), Naver Cloud's chief information security officer, said, "This service differs from existing methods in that companies can set up an access-control environment directly in a cloud console without a complex installation and configuration process." He said, "We will continue to roll out security services that provide practical help, so that all companies, regardless of size, can enjoy a high level of security by reducing the time and cost burden of meeting legal obligations."