[Photo: Shutterstock]

The Korea AI Cloud Industry Association on Tuesday issued a statement on the National Intelligence Service's push to revise the national cloud computing security guide in line with the National Network Security Framework (N2SF). It shared industry views it has collected so far.

The association's CSP subcommittee said it held a meeting last month to hear industry opinions, seeing the guideline revision as an issue with major ripple effects on domestic CSPs' existing investment and the public cloud business environment.

Domestic CSPs said they generally agree with applying security measures in a differentiated way depending on data importance and risk level, and with the policy direction of expanding the use of cloud and AI in the public sector. They stressed that if investments made under existing government policy and security standards are not sufficiently recognised during the introduction of new standards, it would create burdens from additional system building and revalidation.

According to additional written feedback collected by the association after the meeting, opinions were submitted on linking existing investments and certification systems with the new system, clarifying the scope of entities subject to security requirements, ensuring fairness in applying the system between domestic and foreign providers, and providing sufficient preparation time and a phased transition plan.

Domestic CSPs have repeatedly stressed that if existing cloud security certifications and build-and-operation systems are not sufficiently recognised under the new system, reinvestment and revalidation for identical or similar items could occur. They said this could increase corporate cost burdens and extend service transition periods. They proposed considering a plan to recognise existing certification results and build-and-operation systems as much as possible and to focus verification on items that are changed or added under the revised guideline.

Domestic CSPs also requested that the revision clearly present security requirements and the scope of application for each system that makes up a cloud service. They said requirements and separation-and-protection standards should be set out in detail by component, considering not only major cloud infrastructure such as servers, storage, networks, security and virtualisation, but also GPU-based AI infrastructure and AI service environments.

They said if related standards are not clear, interpretations could differ among public institutions, verification bodies and CSPs, causing confusion in service design, building and verification.

Domestic CSPs said fairness between domestic and foreign providers should also be ensured as cloud security systems accommodate international standards and diverse service operating methods. They said the new system should be applied based on actual security levels and the ability to manage and control services, regardless of a provider's nationality or size. They also proposed that security performance, fairness in applying the system and the competitiveness of Korea's cloud industry should be considered together so that infrastructure building and certification investments made by domestic CSPs to comply with existing government security policy do not work against them after the system changes.

Companies also requested that detailed guidelines be sufficiently provided so the revised standards can be applied stably in the field, and that a preparation period be guaranteed to check service structures and operating systems. They said if the system is implemented while detailed application standards remain unclear, CSP service design and productisation could be delayed, and additional system changes and cost burdens could occur. They proposed providing sufficient guidance on detailed explanations and verification procedures alongside the revision and preparing a phased transition plan to link existing certifications and operating systems to the new system.

The association said it plans to hold follow-up subcommittee meetings and in-depth talks with participating companies, in addition to the CSP subcommittee meeting and written feedback collection.

Keyword

#National Intelligence Service #N2SF #Korea AI Cloud Industry Association #CSP #GPU
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.