Domestic CSPs Raise Concerns Over Cloud Security Overhaul, Warning of Stranded Investment Costs
IT DAILY ·
✦ AI Summary
As the National Intelligence Service pushes ahead with revisions to the 'National Cloud Computing Security Guidelines' tailored to the National Security Framework (N2SF), domestic cloud service providers (CSPs) voiced concerns.
While domestic CSPs agreed with the policy direction, they said reinvestment and revalidation costs could arise if existing investments and certifications are not sufficiently recognized under the new standard.
The CSP subcommittee under the association held a meeting on August 26 to review the impact of the revisions and the response measures needed, and plans to continue with additional meetings and roundtables.
As the National Intelligence Service pushes ahead with revisions to the "National Cloud Computing Security Guidelines" tailored to the National Security Framework (N2SF), domestic cloud service providers (CSPs) have voiced concerns about the draft revision. While they say they agree with the direction of the policy itself, they argue that infrastructure and certification costs already incurred to provide cloud services could arise again.
According to an announcement on the 2nd by the Korea Artificial Intelligence Cloud Industry Association, the CSP subcommittee under the association held a meeting on August 26 to discuss the guideline revisions. The meeting was organized to review the impact of the National Intelligence Service's push for the revisions and the response measures the industry needs.
The agenda included the impact the guideline revisions would have on the service delivery and operations of domestic CSPs. It also covered the revisions' effects on the industry ecosystem and the investment burden tied to policy changes.
Domestic CSPs said they agree with the policy direction of applying differentiated security measures based on data sensitivity and risk level. However, during the introduction of the new standard, they stressed the need to secure continuity for existing investments and continuity in the existing certification system.
Domestic CSPs have continued to invest in data centers, security facilities, and certifications for the purpose of providing cloud services to national and public institutions. However, as concerns have been raised that previous investments may not be sufficiently recognized under the new system, the industry is worried about the possibility of cost burdens from reinvestment and revalidation.
In response, domestic CSPs are proposing that existing certification results be recognized as much as possible, that build and operational systems be recognized to the greatest extent possible, and that verification should focus on the items changed through the guideline revisions. There is also growing consensus that clear standards are needed for on-site application.
Inside and outside the industry, opinions have been raised that major cloud infrastructure such as servers and storage, as well as AI service environments, need to be considered. There have also been calls for security requirements by component and for separation and protection standards. The association held a CSP subcommittee meeting on the 26th of last month and is also collecting written feedback.
With a policy of continuing follow-up efforts, the association plans to hold additional subcommittee meetings and in-depth roundtables with participating companies. Through these efforts, it plans to discuss ways to link existing certifications, the scope of security requirements, and the expected impact on service delivery and operations, while working to flesh out the industry's views.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241367
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.