FSC Korea Eases Rules for Cloud Computing and Network Separation in Financial Industry

South Korea's FSC (Financial Services Commission) has unveiled plans to relax its cloud computing and network separation rules for financial institutions, in order to support ongoing digital transformation efforts in the industry.
Exclusive with CMC Head of Greater China Biyi Cheng: Necessity as the Mother of Invention – Evolution in Derivative Trading
In a notice, the FSC said the financial industry has been experiencing difficulties in adopting and using new digital technologies as a result of excessively strict data security rules for the use of cloud computing and network separation.
To lessen the difficulties in adopting cloud computing, the FSC said it will introduce changes to ease the process firms must undertake to assess the level of work significance by introducing a detailed set of standards, taking into account examples from overseas. Such assessments are required for approval to use cloud computing services.
In addition, the number of criteria firms have to use when conducting a soundness and stability assessment on cloud service providers will be reduced from 141 to 54 criteria, to address concerns regarding overlapping and burdensome items. Cloud service providers will only need to be assessed against 16 criteria for non-essential types of work, i.e. back office functions.
A separate set of assessment standards will be introduced for assessing SaaS businesses. The assessment criteria used for cloud service providers are "not readily fit" for assessing SaaS applications, the FSC said.
Separate standards for business continuity plans and safety assurance measures will be introduced for non-essential types of work, documentary submission requirements will be relaxed to reduce redundancy, and a requirement for firms to report their use of cloud computing for essential work within seven business will be changed to an ex post facto reporting requirement.
On the network separation rules – which currently require physical network separation and prohibit logical network separation through virtualisation technology – the FSC will introduce exemptions for development and test servers which do not hold personal data, for work that is not relevant to electronic financial transactions and does not involve information about customers and their transactions, and for the use of SaaS applications in an internal company network.
"The uniform application of the physical network separation rule across all financial sectors without making distinctions for disparities between different companies and types of work has been impeding the level of efficiency for the development and testing types of work and posing difficulties in making use of innovative technologies," the FSC said.
Over the medium to long term, the FSC will also relax the network separation rules for some financial companies such as asset managers that do not necessarily hold information about their customers but focus solely on managing their assets. The regulator will first conduct a review of the accountability and security oversight at such firms.
The FSC said it will revise the Enforcement Decree of the Electronic Financial Transactions Act and its supervisory regulation with a view to implementing the rule amendments starting in 2023.
The regulator will also prepare a revision to the guideline on the use of cloud computing services in the financial sector to help provide specific procedures and standards for reference.
Starting in May 2022, a joint support team comprising regulators and industry groups will commence operating to provide interpretations on the rule changes to "facilitate early adaptation to the improved system", the FSC said.
In H2 this year, the FSC will also establish an internal data protection deliberation body, which will be tasked with carrying out inspections on financial firms' internal control mechanisms.
Subscribe Now

