Tektronix TIF 2026
This page was machine-translated and may differ from the original. View original

Cyber threats require two-factor authentication and access security policies.

Google 우선 소스Published2022.04.07 12:00

▲Key supplementary requirements by stage


The Ministry of Science and ICT announced measures to counter cyber threats.
Request for abnormal behavior inspection system check

The government has urged proactive measures, including double authentication with high security strength such as biometric authentication and system checks for abnormal behavior, stating that there is no system area or user that is safe from cyber threats.

The Ministry of Science and ICT, in collaboration with the Korea Internet & Security Agency, analyzed recent cyber threat trends and announced response measures for domestic companies on the 7th to enable Korean companies to systematically and preemptively respond to changes in the work environment, such as remote work becoming routine in the wake of COVID-19, and to cyber threats that are becoming increasingly sophisticated and organized.

Accordingly, it was revealed that in the initial infiltration stage, two-factor authentication such as highly secure biometric authentication must be introduced, and when accessing the remote work system, a security policy that allows access only through pre-approval and designated terminals and IPs must be applied.

He also mentioned the need to apply policies such as tracking employee account activity history and monitoring for abnormal signs by utilizing AI and big data-based technologies.

In the internal network penetration stage, it was revealed that two-factor authentication such as designating an administrator terminal for access to important servers and biometric authentication must be applied, monitoring for abnormal use such as accessing the server with an account different from the initial access account must be strengthened, and inspections must be strengthened for malicious code execution and log deletion behaviors that are mainly used in internal network attacks.

In the data leak stage, it was mentioned that access rights, export policies, and usage policies should be managed differentially by user, data, and usage behavior, and an AI-based continuous monitoring system should be introduced to monitor and block accounts with large volumes and repetitive exports, and to manage access history, such as abnormal behavior attempting to access data or servers without prior approval.

In addition, as cyberattacks are rapidly evolving due to rapid digital transformation, it is a time when meticulous security management at the corporate level is very necessary. He said that it is important to join 'C-TAS 2.0', which allows real-time sharing of cyber threat information, to quickly check threat information and take measures in advance, and to regularly check security vulnerability information such as SW through the 'Vulnerability Information Portal' and supplement the system.

Kim Jeong-sam, Director General of Information Protection Network Policy at the Ministry of Science and ICT, said, “As cyber threat techniques are rapidly becoming more sophisticated and intelligent, targeting vulnerabilities in the recent spread of non-face-to-face interactions and rapid digital transformation, it is time for companies to conduct meticulous security activities, such as regular checks at the manager level, to prevent security breaches from occurring due to insufficient basic security management.” He added, “In addition, we urge companies to actively utilize various information security services, such as C-TAS 2.0 subscription, My Server Caretaker, and cyber crisis response simulation training, to protect their valuable information assets from cyber threats that are becoming more intelligent and sophisticated by the day.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
강정규 기자