This page was machine-translated and may differ from the original. View original
Ministry of Science and ICT introduces zero trust, boosting security levels.
Zero Trust Principles Guidelines Announced
Separate and protect each resource… based on implicit distrust
Separate and protect each resource… based on implicit distrust
The Ministry of Science and ICT is introducing zero trust security at the national level.
The Ministry of Science and ICT announced that it had established the "Zero Trust Forum" comprised of domestic experts from academia, industry, and research in October of last year and had gathered opinions through global trend analysis, data review, and discussion sessions to establish the "Zero Trust Guideline 1.0" suitable for the domestic environment.
In addition, as announced in April with the Digital Platform Government Committee under the President, we plan to expand the newly established "Zero Trust Guideline 1.0" to each sector.
Zero Trust assumes that a network has already been compromised when a request for access to information systems or other devices is made. The security concept is 'Never Trust, Always Verify'.
This was decided based on the judgment that a transition to a new security model is urgent as non-face-to-face work becomes more active.
Previously, by granting implicit trust to network insiders, once an intruder had accessed an information system through collusion with an insider or theft of authority, they could access all protected objects, including internal servers, computing services, and data, without additional authentication, which could lead to data leaks to the outside for malicious purposes.
In contrast, the zero-trust security model separates and protects each resource, such as servers, computing services, and data, as separate, protected resources. This ensures that even if one resource is compromised, nearby resources remain protected. Furthermore, all access requests from users or devices are authenticated using a variety of information, in addition to IDs and passwords.
Zero Trust Guidelines 1.0 presents the following: basic concepts of zero trust, security principles, core principles, access control principles, detailed procedures for establishing an implementation plan, and an implementation reference model.
This guideline 1.0 will be available from July 10th on the websites of the Ministry of Science and ICT, KISA, and related organizations. Furthermore, we plan to continuously enhance the guideline by preparing the "Zero Trust Guideline 2.0" based on analysis of security effectiveness of future case studies and the changing environment.
In the second half of the year, the SGA Solutions Consortium and the Private Technology Consortium will implement a zero-trust security model in various environments, including telecommunications, finance, and the public sector, from June to December of this year. White hat hackers plan to apply a verification model consisting of attack scenarios to verify the security effectiveness before and after the introduction of zero trust.
Park Yoon-gyu, Second Vice Minister of the Ministry of Science and ICT, said, “In a time of paradigm shift where the security system must be transformed in a situation where networks are expanding into people’s daily lives and various industrial fields, we must find an alternative that is suitable for this situation.” He added, “The Ministry of Science and ICT will continue to supplement and improve the zero trust guidelines so that they can be of practical help to the government, public institutions, and companies, while supporting the spread of the zero trust security model to various fields through demonstration projects.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.

.png)













