Tving said on Tuesday it is strengthening its security system based on zero-trust principles, including access and privilege management and incident response.
Zero trust is a security approach that does not inherently trust users or devices and continuously verifies access privileges. Tving is applying four principles to its service and cloud environments: access verification, least privilege, assumed breach and continuous verification.
It applied authentication token verification across all app and web services and implemented forced updates for older versions of its app. It also subdivided system and service access permissions by task and strengthened access controls by managing permission scope and validity periods.
In its cloud environment, it enabled real-time detection of anomalous activity and alerts when abnormal access occurs. It is also reviewing incident response procedures for different scenarios.
It also carried out measures to protect customer information. It replaced app signing keys and digital rights management (DRM) keys and improved its login and session verification structure. It switched its password storage algorithm to one based on bcrypt.
It moved sensitive information in code to a separate management system and built a system that automatically blocks it at the source-code storage stage. It applied an endpoint detection and response (EDR) solution to all employees' PCs.
Tving plans to expand the scope of simulated hacking and vulnerability assessments to include cloud accounts and permission areas and is reviewing the introduction of a bug bounty programme. It is also pushing to apply AI-based security threat detection and blocking technology.
A Tving official said, "We are upgrading our access and privilege management and incident response system based on zero-trust principles." The official added, "We will also continue investing in next-generation security technologies such as AI-based threat detection."