[Exclusive] Foreign Cloud Firms Gain Easier Access to S. Korea's Public Market

NIS Eases Security Standards
Allows 'Logical Separation' for Control and Operation Systems
Gathering Opinions... To Be Implemented in Second Half of Next Year

Photo Image
Revisions to National Cloud Security Guidelines

The government is significantly easing entry barriers to the domestic public market for foreign cloud operators. As domestic cloud security policies have escalated into digital trade conflicts with countries like the United States, and demand for cloud computing has surged dramatically due to artificial intelligence (AI) transformation, the government has moved toward openness.

According to industry sources on September 2, the National Intelligence Service (NIS) has drawn up a revision plan for the 'National Cloud Computing Security Guidelines' and has begun gathering feedback from the government and industry stakeholders. The NIS plans to officially announce the revised guidelines as early as this month and fully implement them in the second half of next year after a grace period.

The core change is the relaxation of the physical separation principle. Previously, it was required that all areas constituting a cloud service—not only the server areas where actual public sector data is stored and processed, but also the control plane (control and management systems) necessary for cloud operations—be physically separated within South Korea.

The revision relaxes the requirement only for the control plane from physical separation to logical separation. Logical separation secures safety by compartmentalizing areas through software methods such as access control, encryption, and virtualization. As a result, the path opens for cloud service providers (CSPs) to conduct public cloud business in South Korea even while locating their control and management systems in overseas regions (multiple data centers). Management can also be conducted by foreign personnel.

However, the area where data itself is stored and processed remains untouched. The principle that data, along with the servers processing it, must be physically separated within South Korea (tenant separation) is maintained. The basic framework of this revision is to make operation and control flexible while keeping data bound within the country.

The scope of certification for security equipment (hardware and solutions) is also being expanded. Until now, only equipment that passed domestic Common Criteria (CC) certification could be used in the public cloud. The revision expands this to international CC certification, allowing security equipment that received international CC certification overseas to be used in South Korea's public cloud as well.

Previously, the U.S. pointed to South Korea's cloud security standards as non-tariff trade barriers and exerted trade pressure, demanding an expansion of the CC certification scope and the relaxation of physical separation requirements. This revision is interpreted as a measure that accepts a significant portion of those demands.

Photo Image
ⓒ Getty Images Bank

Positions among domestic and foreign CSPs were split over the revision. Foreign companies maintain the stance that despite some revised clauses, they may still face business difficulties given that physical separation remains in place for the most sensitive data processing area. On the other hand, domestic firms express concern that a path has suddenly opened for foreign CSPs to enter the public market as a substantial part of the regulations has been opened.

Kim Seung-joo, member of the Security Special Committee under the Presidential National AI Strategy Committee and professor at Korea University's Graduate School of Information Security, said, “At a stage where new cloud standards are being established in line with the NIS's N2SF security framework, the demands of domestic and foreign companies are conflicting.” Kim added, “In a situation where speed is required for the cloud transformation of public information systems, the task is to gather broad opinions from suppliers and consumers and provide clear, detailed guidelines.”

· This article was translated using AI and was published after final review by the reporter.