Public Cloud Restrictions Eased, but Companies Following Government Guidance May Be Left in the Lurch
IT DAILY · · 3 views
✦ AI Summary
The National Intelligence Service has formalized a direction to unify the existing Cloud Security Assurance Program (CSAP) upper, middle, and lower tiers into a C·S·O (confidential, sensitive, open) framework, reflecting the National Network Security Framework (N2SF).
The NIS also set criteria for allowing overseas locations for the operating and management system of public cloud systems, as well as criteria for allowing the introduction of international standard encryption (AES) and equipment certified under the Common Criteria (CC).
However, the overhaul plan is not yet finalized, and the NIS said there are still procedures to gather industry feedback.
The National Intelligence Service has formalized a direction to unify the existing Cloud Security Assurance Program (CSAP) upper, middle, and lower tiers into a C·S·O (confidential, sensitive, open) framework, reflecting the National Network Security Framework (N2SF). It also formalized a policy to completely overhaul the security verification system for private clouds used in the public sector. The NIS has set criteria for allowing overseas locations for the operating and management system of public cloud systems, as well as criteria for allowing the introduction of international standard encryption (AES) and equipment certified under the Common Criteria (CC).
However, the NIS says the overhaul plan is not yet finalized. The agency said there are still procedures to gather industry feedback.
Authorities said the adjustment is intended to respond to the rapidly changing AI era and to create a flexible security policy aligned with global standards. By contrast, the reaction from domestic cloud service providers (CSPs) has reportedly been close to bewilderment. Industry watchers say the overhaul could weaken a key barrier that has kept overseas Big Tech out of the public market.
The backlash from the domestic industry cannot simply be reduced to 'anti-foreign products' or 'protectionism for local firms.' Since public-sector cloud adoption guidelines were established in 2016, domestic CSPs have responded to meet the government's requirement for 'physical network separation.' In the process, domestic CSPs built dedicated data centers for public use, deployed dedicated hardware and security equipment, and obtained CSAP certification as well.
Even after that, domestic CSPs have spent considerable money and manpower every year to maintain and renew CSAP certification. Yet the public cloud market expansion promised by the government has remained sluggish for years. As a result, some companies gave up their certification because of the burden of maintaining it.
Only recently had the public market begun to warm up when a fire broke out last year at the National Information Resources Service (NIRS). That incident accelerated the Ministry of the Interior and Safety's disaster recovery (DR) infrastructure project and its project to shift public-facing services to private clouds, and it raised expectations in the domestic industry that some of the investment could be recouped. But at this point, the government is pushing ahead with an overhaul in the name of 'regulatory easing,' and the change is having the effect of opening a path for global Big Tech.
Domestic operators have already made massive investments and built systems to fit existing regulations and certification structures. At the heart of the backlash from domestic companies is the perception of an 'uneven playing field,' and domestic operators have borne the burden of infrastructure investments worth hundreds of billions of won to respond to government regulations. In addition, as the existing tier system is changing from upper, middle, and lower to C·S·O, domestic companies must also bear the additional cost of redesigning their certification-response systems to match the new standard.
By contrast, new overseas operators can enter the market by using existing overseas control planes without establishing new domestic infrastructure. Foreign companies had been barred from entering the market by the existing regulatory barriers, but with this overhaul they can now enter without bearing redesign costs. Accordingly, there are concerns that the revision will create reverse discrimination against foreign companies relative to domestic firms.
Procedural issues are also being raised. According to industry sources, the NIS disclosed the broad outline of the overhaul plan before a closed-door briefing, and there was insufficient prior discussion with domestic operators. Industry sources also said that the NIS's process for gathering opinions from domestic operators was inadequate.
Some interpret this move as a possible bargaining chip amid trade pressure from the United States and others. However, even if the reality that the government must consider market opening for external trade and security diplomacy reasons is unavoidable, there are calls that the burden of market opening should not be shifted onto the domestic industry, which has complied with national security guidelines for the past 10 years.
Security standards in the public market need to be applied fairly, regardless of whether a company is domestic or foreign. Since the NIS has said that the feedback-gathering process is still ongoing, the government should prepare measures to offset the upfront investment burden on domestic companies before expanding entry paths for global firms, and it should also prepare a realistic grace period for domestic companies to transition. Otherwise, it will be difficult to draw future investment and support from companies because of a loss of policy credibility.
Source: IT DAILY · Kwon Young-seok
Original: https://www.itdaily.kr/news/articleView.html?idxno=241785
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.