Download presentation
Presentation is loading. Please wait.
4
1
5
1 2013 BSA Global Cloud Computing Scorecard
6
2
7
2
8
2 Article 23 (Enhancement of Reliability) ① Cloud computing service providers shall do their best to enhance the quality, performance, and information protection level of their computing service. ② The Minister of Science, ICT, and Future Planning may encourage cloud computing service providers to comply with the Standards for Quality and Performance Level and Information Protection that he determines and publishes (including administrative, physical, and technical protection measures) with regard to their cloud computing service. ③ The Minister of Science, ICT, and Future Planning shall listen to the opinions of the Korea Communications Commission to publish Standards for the Quality and Performance Level of Cloud Computing Service pursuant to Paragraph 2. Article 25 (Notification of security incidents) ① Cloud computing service providers shall notify the service users without delay in cases falling under any of the following: (……) ② Cloud computing service providers shall immediately notify the Minister of Science, ICT, and Future Planning in cases falling under any of Paragraph 1, Subparagraph 2. ③ Upon being notified or informed of the relevant fact pursuant to Paragraph 2, the Minister of Science, ICT, and Future Planning may take the necessary actions to prevent the spread or recurrence of damage or recovery. ④ The Presidential Decree shall set forth the matters required for notification and actions under Paragraphs 1 ~ 3.
9
2 Article 27 (Protection of User-related Information) ① Cloud computing service providers shall neither provide any user-related information to a third party nor use the information for purposes other than the provision of services without the user’s consent unless the submission is ordered by a court or a warrant is issued by a judge. This shall apply to all third parties provided with the user-related information by cloud computing service providers. ② Cloud computing service providers shall notify and obtain consent from the users concerning the following when intending to provide the user-related information to a third party or use the information for purposes other than the provision of the services (this shall also apply to cases wherein any of the following is changed):…… Article 29 (Liability for Damage Compensation) The users may claim from cloud computing service providers compensation for damages they inflicted on the users through acts in violation of the provisions of this Act. In such case, cloud computing service providers shall not be exempted from responsibility unless they prove that they committed no intentional or negligent errors. Cloud computing service providers shall immediately notify the Minister of Science, ICT, and Future Planning in cases falling
11
1
12
2
13
2
14
2
15
2 This standard defines Information security framework for cloud service providers which are classified into governance, management processes and technology processes. And this standard provides Information security guidelines that should be considered in order to provide secure cloud service by cloud service provider.
17
1 Security Management Security Technologies Security Business Development of conditions for security-embedded cloud service Voluntary enhancement of security level by cloud service providers Development of infrastructure for safe cloud service Enhancing capabilities for the protection of cloud service users or addressing infringement accidents Development of core security technologies for global cloud service Development of cloud security framework Development of core source technologies for cloud computing security Enhancement of industrial competitiveness of cloud service security Development of technological support center for cloud security Creation of new cloud security markets Proactive introduction of cloud service between public and private sectors Development of cloud security personnel or enhancement of their understanding
18
1
19
1
20
1 Cloud Service Provider Security as a Service (SecaaS) (Web Firewall, DB encryption, Security Management etc.) development SME-1 SME-2 SME-3 Cloud Security Consulting
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.