'Workplace Barriers' Blocking Public AX... DaaS Evolving Beyond Virtual PCs Into AI Execution Infrastructure
TECHWORLD ·
✦ AI Summary
There were discussions that applying generative AI and AI agents to administrative work in public AX requires changes to the existing network separation environment and fine-grained management of data access and usage permissions.
DaaS was raised as a foundation linking work data, AI, and security policies beyond a virtual PC for remote work, and for public work networks, data classification aligned with N2SF and access control were presented as tasks.
There were also views that public work network DaaS requires refinement of the scope of responsibility between institutions and service providers, service quality, budget and procurement systems, legal definitions, and an integrated management window.
The public sector's AI transformation (AX) is expanding beyond simply adopting models to a broader overhaul of the work environment. In the public sector, concerns have been raised that changing the existing network separation environment is a prerequisite for applying generative AI and AI agents to administrative work. It has also been pointed out that fine-grained management of data access and usage permissions is needed to apply generative AI and AI agents to administrative work.
Against this backdrop, DaaS is being discussed as a foundation linking work data, AI, and security policies, moving beyond the scope of a virtual PC for remote work. However, to apply DaaS to public work networks, data classification aligned with the National Network Security System (N2SF) was presented as a prerequisite. Revising access control was also mentioned as a task.
In addition, clarifying the scope of responsibility between agencies and service providers, improving service quality, and reorganizing budget and procurement systems were presented as prerequisites for applying DaaS to public work networks. This led to a broader view that the workplace overhaul task for public AX and the task of refining DaaS deployment in public work networks should be addressed together.
These points were discussed at a policy forum titled 'DaaS Institutionalization Strategy for Innovation in Public Work Environments in the AI Era,' held on the 6th at the National Assembly Library. The forum took as its discussion topics the workplace overhaul task for public AX and the task of refining DaaS deployment in public work networks. The event was co-hosted by lawmakers Lee Gwang-hee of the Democratic Party of Korea and Kim Dae-sik of the People Power Party, along with the DaaS Support Subcommittee of the Korea AI Cloud Industry Association, and was organized by the Korea AI Cloud Industry Association.
Kim Yong-jin, a professor in the Department of Business Administration at Sogang University, said DaaS should not be viewed as a mere PC virtualization project. He explained that in the AX phase, AI's role expands from search and document drafting to judgment and execution support.
Professor Kim explained that as the scope of AI support widens in this way, the important foundation in the AX phase is the connection between data and business systems. In that sense, DaaS should be seen not simply as virtualization, but as an infrastructure that links data and business systems.
He said business data needed to be managed centrally. He also explained that access rights should be separated by classification such as confidential, sensitive, and public, and that usage history should also be differentiated.
Professor Kim said that if rights and usage history are separated by classification in this way, AI functions such as retrieval-augmented generation (RAG), document summarization and analysis, and civil complaint response can be used in a controlled environment. He added that DaaS is a prerequisite for AI adoption, and that AI is the path to recouping DaaS investment costs.
He said the spread of AI agents would make access control even more important. He explained that while existing generative AI only responds to user questions, AI agents can access applications, files, and business systems and perform tasks directly.
Choi Baek-jun, CEO of Tilron and chair of the DaaS Support Subcommittee of the Korea AI Cloud Industry Association, said that as AI's actual execution of work expands, data and desktop access permissions need to be managed more precisely. He proposed using DaaS as the method.
CEO Choi Baek-jun said that AI needs access to data, platforms, and desktops to perform work. He added that control is needed in the form of separating permissions by user and department and limiting the scope of data AI can access.
He said that in defense, medical, and personal information areas, separate work environments are needed for the safe use of AI. He also raised the view that changes to the existing security framework are necessary to expand public DaaS.
The existing network separation has played a role in blocking external attacks by separating the Internet network from the business network. However, CEO Choi pointed out that this traditional network separation constrains the use of AI, SaaS, and cloud services.
Park Gi-beom, executive director at Monitor Lab, explained that costs are rising and management burdens are increasing due to the separate operation of Internet-use and business-use PCs. He said a transition to zero trust is needed, based on continuously verifying user, device, and data conditions, rather than uniformly separating networks.
Executive Director Park explained that the principle of zero trust is to prohibit absolute trust and verify continuously. He also said that he views DaaS as an infrastructure service capable of efficiently applying the National Network Security System.
It was then pointed out that to apply N2SF in actual operations, management of the flow after data creation is needed, not just data classification. The concern raised was that it is necessary to go beyond data classification management and address the entire lifecycle flow.
Kim Jong-pil, CEO of Inotium, said that while carrying out N2SF tasks, he found cases in which data classification and cloud usage criteria did not align even in DaaS deployment environments. As a result of these cases, a separate dedicated network was added, and he explained that governance is needed to track the entire process of data creation, storage, use, transfer, and disposal.
CEO Kim said that technical protection measures are ready. However, he pointed out that links to institutions and guidelines are lacking. Accordingly, he argued that an AI classification and user final-decision structure is needed.
As alternatives, CEO Kim proposed using rule-based classification, intelligent engines, and an internal large language model (LLM). The proposed approach is based on step-by-step data classification. For items that are difficult to judge, the structure was presented so that the person in charge makes the final confirmation.
The scope of security was presented as extending beyond data to include access permissions. It was further expanded to the infrastructure supply chain. Because internal operations are difficult to directly verify when external products are used, security checks for external products were presented as something needed from the supply stage.
Moon Hyung-wook, vice president at KTNF, emphasized integrated verification of hardware, firmware, security solutions, and cloud services. He said this is an issue that no single company can solve on its own. He added that the answer needs to be found through teamwork across the industry.
Even after establishing a security foundation, necessary elements and selection criteria remain for actual institutional DaaS adoption. DaaS adoption is not determined by security infrastructure alone, and the deployment method and operating entity differ by Internet network, business network, and required security level, so these must be judged separately.
Lee Jong-hoon, executive director at KT Cloud, explained that based on current operating cases, the Internet-network usage model is public DaaS. He also said that, based on current operating cases, the business-network model is a private environment set up within an institution's data center or within a cloud service provider (CSP)-dedicated area.
When the operating structure changes, the division of responsibilities between the institution and the CSP becomes necessary. Because the management domain of a cloud service provider (CSP) expands to servers, storage, and virtualization solutions in DaaS, responsibility in the event of a disruption or security incident must be clearly defined at the contract stage.
Service quality standards need to be differentiated from ordinary cloud services. Even if servers operate normally, that alone does not guarantee suitability for business use, and if access is delayed or sessions are unstable, it becomes difficult to use the service for work.
Lee Jong-hoon of KT Cloud proposed reflecting provisioning speed, session responsiveness, login success rate, and user support time in the service level agreement (SLA). These indicators are the kind of metrics that users can directly feel.
The discussion began with the question that there is a lack of concrete standards and guidelines for using DaaS in public work networks. The executive director said there are insufficient concrete standards and guidelines for using DaaS in public work networks, and added that in DaaS, whether actual users can use the service is more important than whether the server is alive.
Accordingly, it was pointed out that operational standards need to be reflected in the system. For such reflection, opinions were presented that legal definitions need to be reviewed, and that the budget system and procurement system also need to be reviewed.
Jung Jun-hwa, legislative researcher at the National Assembly Research Service, suggested that it is necessary to review whether DaaS should be seen as a combination of existing SaaS, PaaS, and IaaS, or as a separate service type. He also said that if it is defined as a separate policy target, the concept of DaaS needs to be clearly defined in relevant laws and regulations. In addition, there was a proposal that the budget structure should also shift from equipment purchases to subscription-based service fees.
Along with this, because several agencies are involved in related work, including the Ministry of Science and ICT, the Ministry of the Interior and Safety, the National Intelligence Service, and the Public Procurement Service, a proposal was also raised to establish an integrated window connecting demand institutions and suppliers.
Researcher Jung said that clarifying the DaaS concept is necessary to promote DaaS. He said budget allocation is needed, and explained that an integrated management window is necessary. He also viewed it as necessary to promote a package-style roadmap including pilot projects.
In administrative settings, opinions were raised that the work characteristics of each institution should be taken into account. It was pointed out that DaaS effects may differ between institutions with a lot of mobile work and office-centered institutions. The possibility of differences in the cost structure of DaaS between institutions with a lot of mobile work and office-centered institutions was also mentioned.
Sohn Seong-ju, director of the Public Service Innovation Division at the Ministry of the Interior and Safety, explained that work styles and work environments differ by institution. He said a simple comparison between existing PCs and DaaS costs is difficult. He also explained that in addition to cost, mobility, work convenience, and actual value in use need to be reviewed together.
Director Sohn Seong-ju said it is necessary to review DaaS adoption measures that take into account each institution's work purpose and usage environment. He said that regarding security issues, the ministry plans to consult with related agencies such as the National Intelligence Service.
Meanwhile, the expanding role of public DaaS is shifting from support for remote work to an AI-based work environment. The transition to N2SF is also gaining momentum. Accordingly, there are calls to flesh out standard models and data management. There is also a need to tailor responsibility and quality standards to public work settings, and the extent to which standard models, data management, and responsibility and quality standards are refined is expected to determine whether the approach spreads.
Source: TECHWORLD · Kim Seung-gi
Original: https://www.epnc.co.kr/news/articleView.html?idxno=407837
References
This article was produced with the help of an automated content generation algorithm.
Source: TECHWORLD
View originalThis article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.