Security

Interview: “Zero Trust Also Works in HR”

IT DAILY ·

이명화 스콥정보통신 인사팀장

✦ AI Summary

Zero trust is the principle of trusting no one and verifying every time, and it includes user safety checks, device safety checks, and allowing only the minimum necessary privileges.

SCOPE Information and Communications applied this principle to HR as well, presenting role-based privilege grants and privilege reallocation during personnel changes and resignations.

HR head Lee Myung-hwa said long tenure alone cannot preserve trust and privileges, and that rather than suspecting people, standards and procedures should be systematized.

An interview article in IT Daily, "Zero Trust Also Works in HR," raises the conventional idea that trust is built on tenure, then points out that cybersecurity is operated on the principles of zero trust. The essence of zero trust is to trust no one and verify every time, and its security measures include checking user safety and device safety. Its access-control principle is to allow only the minimum necessary privileges, and privileges are re-evaluated when circumstances change.

From those security principles, SCOPE Information and Communications drew hints for organizational management. The point of application is not to suspect or monitor people, but to apply it to HR in the form of granting privileges by job and role. It also connects to a flow that checks whether the existing privilege structure remains appropriate when personnel changes occur and when employees leave.

That perspective is reflected in the words of Lee Myung-hwa, head of HR at SCOPE Information and Communications. Lee presents the view that HR is about turning trust into a system. After serving as head of HR at a domestic home appliance company and as CEO of an affiliate in a group, Lee joined SCOPE Information and Communications, and the interview theme is zero trust applied to people.

In response to a question about what led HR at a security company to apply zero trust to people management, Lee Myung-hwa, head of HR at SCOPE Information and Communications, explained that work at a security company is about implementing the scope and level of trust through technology. He argued that risk can be reduced through a privileges- and procedures-based operation rather than an organization that relies on trust.

Lee Myung-hwa said that SCOPE Information and Communications' network security does not automatically trust all subsequent activity after allowing a single login. He added that the company continuously checks the situation and adjusts privileges based on the results.

He said the same principle can be applied to people management. He connected HR management to the idea that the core of security work is not treating trust as a fixed value, but continuously checking it and adjusting privileges.

Lee Myung-hwa said that long tenure alone cannot justify the current appropriateness of existing trust and privileges. Citing the possibility of changes in job duties, responsibilities, and the organizational environment, he explained that trust and privileges should not be maintained on tenure alone and that criteria and procedures should be established to reflect those changes.

He said this does not mean suspecting people. Rather, he said, trust criteria and procedures need to be systematized so employees can work with peace of mind.

The speaker said a situation arose in which the company needed to check and respond to the handling of information by an employee scheduled to leave. He said the specific details would not be disclosed. Through this process, he said, the company came to recognize that vague trust in long-serving employees can become a source of organizational risk.

As a result, the company specified when to adjust access privileges for employees scheduled to leave and also specified the procedure for returning information assets, he explained. The speaker said this measure was not aimed at any particular individual, but intended to reduce structural risks that can arise in any organization.

He then explained the access-control principle of zero trust using network access control (NAC), one of the company’s flagship products. He said NAC identifies the person connecting, verifies the device being used, checks whether the device is in a normal state, and then allows access to resources only when conditions are met.

He linked people management to a similar principle as NAC. He explained that it is not possible to allow access to all information and systems merely because someone has joined the company, that privileges must be granted according to the job, and that privileges must also be reviewed when roles change.

He outlined how this is applied in actual organizational operations, citing the granting of minimum privileges by job, re-examining whether those privileges are needed when personnel changes occur, promptly revoking unnecessary information access rights during leave or resignation, separating duties for critical tasks, and establishing mutual-check structures among employees handling critical tasks. He said privileges and procedures should not become overly concentrated in any one individual.

He then said the common goal of technology and HR is to create a trustworthy environment and procedures. He also pointed to communication and feedback as the first of two important factors in real-world operations.

The speaker said checking after a problem occurs is too late, and that early recognition of small signals is necessary. To that end, he said it is necessary to make an effort to talk frequently with employees regardless of rank, and that evaluation should not end with a single year-end results report. He also explained that the process of mutual feedback on strengths and areas for improvement is more important than the evaluation form itself.

He noted that transitions within an organization need systematic management. As examples of transition points, he cited joining, leaving, and personnel changes. He also pointed out that while many companies place importance on onboarding procedures, offboarding management is often relatively loose.

Accordingly, he said resignation should be seen from a process perspective and confirmed according to set procedures. He listed handover, the return of information assets, and the revocation of system access rights as items to be checked during the resignation process. He also stressed that this process should avoid relying on goodwill and instead include the verification procedures an organization needs.

Asked whether employees might feel that the company does not trust them, the speaker said that a careful approach is needed on that point. He explained that the meaning of zero trust-based HR management is not continuous suspicion of employees or surveillance of their behavior. He also said that when applied to people, clear and fair standards are important, and that if privileges are opaque or evaluation criteria are opaque, comparisons can create resentment, which in turn can lead to distrust within the organization.

Regarding changes in employee training in the AI era, he first raised the need to disclose to members the composition of the necessary privileges for each specific role, and to transparently disclose evaluation and growth criteria to members. The goal is advance sharing of standards and a commitment to comply with them together, which is different from surveillance, where members are observed without their knowledge. The effect of clear rules is to create a fair environment for the many conscientious employees.

On the role of employee training from this perspective, he said it must be assumed that required competencies change as rank and role change. Accordingly, the direction of employee training needs to include the need for both AI use and security education, and it needs to be designed to match the different competency requirements of each rank and role.

The competencies needed by new hires are early mastery of the basics of the company, products, and work. The competencies needed by practitioners are job expertise and collaboration skills. The competencies needed by managers and leaders are drawing out members' capabilities and creating collaboration across organizations.

In this process, he said it is necessary to avoid company-led, one-way notification-style training. Instead, it should identify training needs through regular conversations with employees, while also identifying the capabilities the organization needs through everyday communication. He said it is important to recognize that communication and training are inseparable.

He said the role of training is to make up for identified skill gaps, and that curricula should continuously reflect the needs that have been identified. In addition, he said the condition for a training program to be complete is that it must extend to confirming on-the-ground effectiveness.

He explained that the AI transition is creating new challenges in how people and privileges are managed, and that as AI becomes more common, the importance of security as a premise in employee training is increasing. He said that if employees enter a company’s sales information or customer information into an external generative AI service for convenience at work, serious problems can arise, so AI-use training needs to be provided together with security training. He added that employee training should include both how to use AI well and how to use AI safely.

He also explained that the content of training needs to change. In the past, training centered on conveying knowledge needed by the company, but now much information can be searched through AI, he said. Accordingly, he said that going forward, the ability to define problems and ask appropriate questions matters more than the amount of knowledge one possesses, and that the ability to verify AI results and then apply them to work is also a necessary competency.

He explained that these principles apply equally to the use of AI in HR work such as recruitment and evaluation. AI can assist judgment, but it cannot take responsibility for the outcome, he said. The final party responsible is a person, he added.

Regarding the influence of his experience as a head of HR at a large company and as a CEO of an affiliate, the speaker said that he learned the importance of systems at a large company. He said that once an organization grows in size, it is impossible to run it based on individual capability alone, and that he came to appreciate the need for clear systems for hiring, evaluation, promotion, and training.

He said that after serving as CEO of an affiliate, his perspective on HR systems changed. He explained that HR systems are not ends in themselves, but tools for business performance and organizational growth. He added that he came to recognize that it is just as important to create an environment in which good people can demonstrate their capabilities as it is to select good people.

He said this awareness has become the current standard for system design. He explained that when designing systems now, he considers both whether they support employee growth and whether they contribute to the company’s competitiveness.

As a one-line definition of "zero trust HR," the speaker presented HR management that turns trust into a system. He explained that building a good organizational culture requires more than unconditional trust; each member needs a clear role, and privileges corresponding to that role are necessary. He also said that when circumstances change, roles and privileges must be rechecked, and procedures are needed to correct them if problems arise. He explained that these standards help employees work with peace of mind and that the same principle applies in security. He added that if policies and procedures are properly established, the burden on individual employees of taking on unnecessary responsibility and risk is reduced. He then said the goal is not to control people, but to create an environment in which employees and the company can trust each other.

For other HR professionals wrestling with similar organizational-culture issues, he advised against first introducing a grand system. The speaker said he reconsidered the meaning of zero trust at SCOPE Information and Communications, and that zero trust-based HR management is not a single large-scale system. Instead, he explained, it should begin with the habit of regularly rechecking whether current privileges and procedures are appropriate.

Communication was cited as an essential foundation for such operations. The speaker said he tries to talk openly and frequently with employees, and that if conversations are possible at the stage of small problems, they can be resolved before they grow into bigger ones.

He also said that, for both people and systems, trust cannot be completed with a single grant. Accordingly, he presented the principle that continuous checks and changes tailored to the situation are necessary, defining trust as a process rather than a premise.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241251

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.