Tving said on Thursday it conducted a Security Improvement Program (SIP) with Amazon Web Services (AWS) to assess and improve its cloud security level.
SIP is a programme that analyses actual cloud usage environments to identify security vulnerabilities and improvement tasks and to establish a tailored roadmap.
The assessment applied security control standards from the Center for Internet Security (CIS), the U.S. National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and AWS foundational security best practices.
Based on the findings, Tving will strengthen its security framework in five areas: identity and access management (IAM), detection capabilities, infrastructure protection, data protection, and incident response and automation.
It will inspect externally exposed assets and excessively granted access privileges and build integrated governance based on AWS Organizations to centrally manage multiple AWS accounts. It will also enhance its threat response process to detect anomalies in real time and automatically take required actions.
Tving is also reviewing AWS security services such as AWS Network Firewall, Amazon GuardDuty, AWS Security Hub and Amazon Inspector in stages and is expanding the scope of their application.
SIP will not stop at a one-time assessment and will be accompanied by workshops, expert sessions and regular rechecks. Tving plans to regularly assess its cloud security level and continually reflect assessment results and improvements.
A Tving official said, "By using AWS's SIP, we are systematically inspecting our overall cloud environment and carrying out identified improvement tasks step by step." The official added, "Through regular checks and continuous improvement, we will create an environment where customers can use the service with peace of mind."