Software

[Weekpick Cloud] Cloud Security Framework Unified... Ministry of the Interior and Safety to Migrate 50 Public Systems to Private Cloud

IT DAILY ·

[Photo: Pixabay]

✦ AI Summary

The National Intelligence Service unveiled a roadmap to unify public cloud security classifications under CSO and to fully overhaul the CSAP upper, middle, and lower tiers into Confidential (C), Sensitive (S), and Open (O).

The Ministry of the Interior and Safety has begun migrating 50 public information systems to private cloud and plans to complete the process sequentially by the first quarter of 2027.

The U.S. state of Virginia announced a responsibility framework for large data centers exceeding 25 megawatts (MW), tightening permitting procedures and requiring operators to directly bear the costs of expanding power infrastructure.

Changes in domestic public cloud policy and regulatory trends surrounding overseas data centers were presented together. The National Intelligence Service announced the direction of a overhaul of national cloud computing security policy through "Cyber Summit Korea (CSK 2026)." It also unveiled a roadmap to unify public cloud security ratings under CSO.

The National Intelligence Service decided to fully unify the existing CSAP upper, middle, and lower tiers into Confidential (C), Sensitive (S), and Open (O), in line with the National Security System for Public-Sector Information and Communications Infrastructure (N2SF) standard. Accordingly, C-tier systems must be configured as public-private partnership (PPP) clouds. S-tier systems may use external private clouds, but must satisfy the requirement to configure dedicated hardware for data systems. O-tier systems may be operated in a form that is logically separated from private systems.

The National Intelligence Service also unveiled a roadmap to reorganize into a single NIS verification system. In line with this restructuring direction, the Ministry of the Interior and Safety has begun full-scale migration of 50 public information systems to private cloud.

Overseas, Virginia was cited as a contrasting case. The U.S. state of Virginia, the world's largest concentration of data centers, announced an administrative framework that significantly tightens permitting and cost responsibility for large data centers.

The security standard overhaul is being promoted around improvements to key security standards, while maintaining the domestic-location requirement for data systems and, on the premise of ensuring cyber defense operations, allowing operating management systems to be located overseas and allowing management personnel to be located overseas as well. Under the encryption policy, use of international standard encryption such as AES will be allowed in addition to National Intelligence Service-verified cryptographic modules (KCMVP), and equipment introduction requirements will be expanded to include products certified under the Common Criteria (CC), among others.

Certification procedures will be integrated into a single NIS verification system, replacing the dual-track process of Ministry of Science and ICT CSAP certification and National Intelligence Service security verification. The grace period for implementation is expected to be about 1 year, and existing CSAP certification will remain valid for the remainder of its term. The maximum remaining period for recognition of existing CSAP certification is up to 5 years.

The revision also introduces exceptions. Subscriptions to domestic and overseas commercial generative AI services that process only public information will be excluded from security verification, and physical AI cloud infrastructure tied to special-purpose equipment such as robots will also be excluded from security verification.

The Ministry of the Interior and Safety is moving ahead in earnest with the migration of 50 administrative and public information systems to private cloud. This measure follows the "AI government infrastructure governance and innovation promotion direction" announced in February. The ministry cited the use of private-sector technology and resources and the strengthening of public infrastructure safety management systems as the purpose of the initiative.

This migration is an early implementation measure to accelerate the phased transition of systems in connection with the 2030 schedule to shut down the National Information Resources Service. The Ministry of the Interior and Safety first selected 50 agency websites and simple information-provision systems that can be migrated quickly without a separate Information Strategy Plan (ISP). Thorough pre-migration testing will be carried out for the selected systems.

The ministry plans to complete migration of these systems sequentially by the first quarter of 2027. It will also provide support measures to ease the financial burden on the agencies involved in the migration. The government included system migration costs and private cloud usage fees through 2027 after the transition within the scope of support.

The Ministry of the Interior and Safety plans to reflect the N2SF information system security classifications (C, S, O) next year. It also plans to select systems for migration to private cloud by reflecting the security classifications. In addition, it plans to continue expanding the scope of the project through consultations with relevant agencies.

The U.S. state of Virginia officially announced the "Data Center Responsibility Framework." Virginia, a dense hub of data centers, introduced the regulatory framework to block side effects stemming from rapid infrastructure growth. Virginia Governor Abigail Spanberger said that despite the rapid expansion of the data center industry, there had been a lack of clear adjustment plans regarding the impact on residents' electricity bills, water resources, air, and quality of life. She added that operators would be held to strict accountability.

The framework targets large data centers exceeding 25 megawatts (MW). Virginia decided to abolish the existing "by-right" system that had applied to these facilities. Instead, it strengthened the permitting process for large facilities by requiring review and approval by local authorities.

Virginia decided to restrict non-disclosure agreements (NDA) during the development process. The move aims to disclose development information transparently to residents. It also plans to reduce data centers' dependence on diesel and gas generators and encourage a shift to clean energy.

Virginia also took into account the fact that infrastructure build-out costs are rising as large centers increase in number. Accordingly, it stipulated that the costs of expanding power infrastructure such as transmission and distribution networks must be directly borne by data center operators. The goal is to prevent costs from being passed on through higher electricity bills for ordinary households and small businesses.

About 13% of global operational data center capacity is concentrated in the Northern Virginia area. That region continues to face rising electricity costs and environmental concerns, and accordingly residents' acceptance of new construction fell sharply from 69% in 2023 to 35% this year.

Source: IT DAILY · Kwon Young-seok
Original: https://www.itdaily.kr/news/articleView.html?idxno=241762

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.