Cloud Security Guideline Overhaul Raises Fears of Discrimination Against Domestic CSPs, Sovereignty Erosion
IT DAILY ·
✦ AI Summary
As the government pushed ahead with a revision proposal for the "National Cloud Computing Security Guidelines," domestic CSPs raised concerns over violations of national data sovereignty and discrimination.
The National Intelligence Service unveiled a plan in a closed-door briefing to significantly ease public-market regulations, and the revision proposal included separating the data plane and control plane, specifying AES, and expanding international CC certification.
The CSP industry criticized the move as a standards change that would benefit foreign operators only, and called for equal regulatory treatment for domestic and foreign companies, a sufficient grace period, and industry participation.
As the government pushes ahead with a revision to the "National Cloud Computing Security Guidelines," domestic CSPs have publicly raised concerns over violations of national data sovereignty and serious discrimination. The article focuses on moves to revise the "National Cloud Computing Security Guidelines."
In this regard, the Cloud Service Provider division of the Korea Artificial Intelligence Cloud Industry Association held a media briefing on the 7th, where those concerns were reaffirmed. The industry criticized the government's unilateral push to ease regulations, saying there had been no thorough fact-finding study on the impact on the sector and no process for gathering opinions.
Meanwhile, the key barrier to entry in the public cloud market is the Cloud Security Assurance Program (CSAP). The National Intelligence Service is working on revising the security guidelines.
Accordingly, the CSAP system is being folded into and transitioned to the CSO rating system (C, S, O) based on the National Network Security Framework (N2SF). The existing CSAP rating structure was high, medium, and low, and the mapping is high to C, medium to S, and low to O.
The National Intelligence Service recently held a closed-door briefing for industry officials and unveiled a plan to revise the guidelines in a direction that would significantly ease regulations in the public market. The announcement of that revision plan sparked a major backlash.
According to industry officials, the core of the revision proposal is the separation of the "data plane" and the "control plane" in public cloud systems. The "data plane" is the area for actual data storage and processing, while the "control plane" is the area for managing and controlling overall system resources.
Under the plan, the data plane would be required to remain physically located in South Korea, while foreign or overseas region operations would be allowed for the control plane as long as it is logically separated. At the center of the revision direction presented by the National Intelligence Service is this allowance for separating the data processing area from the management and control area.
The policy also includes language specifying AES, an international cryptographic standard, in addition to the National Intelligence Service-validated cryptographic module (KCMVP). It also expands requirements for introducing security equipment from domestic CC certification to international CC certification.
Across the domestic CSP industry, the released revision proposal drew concerns. The biggest issue cited by domestic CSPs was serious discrimination against local providers, with the background being that they have invested massive capital over more than 10 years in line with government guidelines.
Until now, domestic CSPs have made preemptive investments to meet the public zone's strict physical network-separation requirements. They have built dedicated data centers for public use, introduced dedicated hardware, and secured dedicated operations personnel. An official from Company A in the CSP division said domestic firms had endured massive infrastructure investments to meet government standards.
By contrast, if the revision proposal is adopted, global big tech companies could enter the public market without investing in domestic infrastructure and could reuse existing overseas control planes. In that case, global big tech would receive preferential treatment when entering the public market, while domestic firms would have to completely redesign and relocate their existing network-separation architectures to respond to the changed framework. As a result, domestic firms would bear enormous sunk costs for the transition.
In response, an official from Company A in the CSP division said loosening standards only for new foreign entrants amounts to discrimination. He also criticized the move, saying it was not about global big tech adapting to regulations but about the government changing regulations to widen the entry path for foreign companies.
If the control plane is located overseas, account management, VM control, portal and console operations, and API calls would be carried out abroad, and the associated transfer of metadata to overseas data centers would also be unavoidable, potentially leading to weakened data sovereignty and a loss of security control. This raised a national-security issue directly tied to state security.
It was also pointed out that under the U.S. CLOUD Act, data disclosure can be demanded for security-related reasons, and that foreign companies have difficulty refusing U.S. government requests for data disclosure. An official from Company B in the CSP division, citing MS transparency report cases, warned that under the CLOUD Act there is always a risk that customer data could be transferred to foreign governments.
There were also concerns that if a failure occurs in an overseas control plane, domestic regulators would face limits in investigating the cause, potentially creating a vacuum in control. An official from Company B in the CSP division warned that domestic firms are subject to strong government audits and sanctions in the event of outages, but if an overseas control plane fails, the National Intelligence Service and the Ministry of Science and ICT may be unable to determine the cause, creating a serious gap in control.
The government is promoting "national AI self-reliance" as a policy goal. To this end, it is investing budget in an "independent foundation model (indigenous model)," "public-sector specialized AI," and "expansion of national AI computing resources," while emphasizing AI sovereignty as an overall government stance.
However, controversy has also emerged over the mismatch with such government policy. Public cloud is the root infrastructure on which AI actually runs, and there are concerns that if this market is opened to foreign companies, domestic AI infrastructure could become dependent on foreign providers.
In addition, the possibility that the public GPU market could also become dependent on foreign suppliers has been raised as an issue. An official from Company C in the CSP division said that investing budgets to achieve national AI self-reliance while moving cloud infrastructure to global companies is self-contradictory, and warned that dependence on foreign ecosystems could spread across public GPU resources and the broader data infrastructure.
Along with these concerns, the demands set out were equal regulation and assurance of a sufficient grace period.
The domestic CSP industry is presenting the application of equal standards to global companies and the guarantee of a sufficient preparation period as key demands in connection with opening the public market. It is also calling for parallel protection and support measures for domestic CSPs and the security industry in line with public-market opening.
The industry is demanding that overseas operators entering the domestic public market be required to build the control plane physically and logically in South Korea on the same terms as domestic firms. It is also calling for the abolition of unfair exemption clauses, and an official from Company D in the CSP division stressed that security standards in the public market should be applied equally regardless of whether an operator is domestic or foreign.
As for the implementation schedule, it opposes unilaterally forcing through a rollout in the second half of next year. It is asking for a sufficient grace period to redesign the architecture, and an official from Company D in the CSP division also said the government should avoid unilaterally finalizing and announcing standards.
In the process of establishing detailed standards, the industry is calling for guaranteed participation from domestic companies in the drafting of detailed guidelines and explanatory materials. An official from Company D in the CSP division stressed the need for joint discussions with the domestic industry when preparing the detailed plan, and also urged the government to preserve data sovereignty and prepare a realistic roadmap and complementary measures that domestic companies can follow.
Source: IT DAILY · Kwon Young-seok
Original: https://www.itdaily.kr/news/articleView.html?idxno=241451
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.