Security

Naver Cloud Launches Integrated DB and Server Access Control Service to Support Regulatory Compliance

TECHWORLD ·

[Photo: Naver Cloud]

✦ AI Summary

Naver Cloud has launched a cloud security service called DB & Server Access Control (DSAC).

DSAC provides DB and server access control, work history logging, and audit functions in the form of SaaS.

It automatically creates proxy servers inside a customer's virtual network to control server and DB access paths through a single gateway.

Naver Cloud has launched a cloud security service. The service, unveiled on the 22nd, is called DB & Server Access Control (DSAC). Naver Cloud provides access control and activity log management for DBs and servers in a single service.

DSAC is a SaaS service. It covers access-rights management, work history logging, and audit functions for servers and DBs that handle personal data. Through this, users can manage everything from DB and server access rights to work histories in an integrated way.

DSAC works by automatically creating proxy servers inside a customer's virtual network. At the same time, access paths to servers and DBs are controlled through a single gateway. Naver Cloud said this structure provides access control, logging, and auditing together.

According to personal data protection regulations, data handlers must retain access logs for relevant systems for a certain period of time. They are also required to retain access-rights change histories for a certain period of time. Naver Cloud said DSAC also supports building access control systems related to personal data protection.

Through DSAC, Naver Cloud supports cloud-based one-stop management of log creation, retention, and retrieval. As a result, it supports the establishment of log management systems, and there is no need to build separate security solutions. It is a service that allows management tasks required under personal data protection regulations to be handled in the cloud.

A key feature of the service is reduced separate deployment work. It is configured so that proxy servers are automatically created when an administrator activates the cloud console service. It also allows control over each user's access scope through a function that sets which servers and DBs each user can access.

This structure makes it possible to control each user's access scope without a separate account management system. Naver Cloud determined that it can reduce the burden of separate management servers, deployment work, and specialized personnel that were previously needed when introducing external access control solutions.

The service automatically logs operations performed on servers and DBs. If the logs include sensitive personal data such as resident registration numbers or card information, masking is applied at the storage stage. It also provides log management functions linked with existing Naver Cloud services.

Access and work histories are handled through integration that requires no separate configuration. Access and work histories can be viewed in real time and retained for long periods. In addition, it detects anomalies such as after-hours access and large-scale queries. This creates a structure in which access control, log management, and anomalous behavior checks are handled in a single cloud environment.

Kim Jae-dong, Chief Information Security Officer (CISO) at Naver Cloud, said the new security service can build an access control environment immediately from the cloud console without complex installation or configuration procedures. He added that the approach is intended to ease the time and cost burden associated with meeting legal obligations, and said the company plans to continue expanding its security services.

Source: TECHWORLD · Kim Seung-gi
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407310

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.