The financial authorities are expanding the scope of emergency easing of network separation regulations to enhance security vulnerability assessments using artificial intelligence (AI) in the financial sector. The second round of testing will increase participation and selection size to include the second financial sector and electronic financial service providers, aiming to bolster their AI security capabilities.
On September 3, the Financial Services Commission (FSC) held its fifth meeting of the 'Frontier AI Response Team' led by Yu Young-jun, Director of Digital Finance Policy, alongside the Financial Supervisory Service and the Financial Security Institute, where they finalized the details of the 'Second Emergency Easing Measures for Network Separation Regulations.'
The second round of testing will include a total of 75 companies, an increase of 26 from the 49 companies that participated in the first round held in June. The actual selection size will also expand from 10 to 15 companies.
The application criteria for financial companies will be relaxed from 'total assets of 10 trillion won or more and 1,000 or more employees' to 'total assets of 2 trillion won or more and 300 or more employees.' However, to ensure accountability and independence in information security, only financial companies where the Chief Information Security Officer (CISO) does not hold concurrent duties in other IT sectors will be eligible. A total of 59 companies meet this criterion.
Separate criteria will be applied to electronic financial service providers to broaden participation opportunities. They must have annual electronic financial transaction amounts exceeding 2 trillion won and electronic financial service-related revenue constituting more than 10% of total revenue. The same requirement regarding the CISO's concurrent duties will apply. Sixteen electronic financial service providers meet these criteria.
Selected financial companies and electronic financial service providers will establish alternative control measures for network separation and utilize Frontier AI and security software as a service (SaaS) to detect and improve security vulnerabilities in their IT systems.
The FSC plans to evaluate the security capabilities and AI utilization of the applying companies through a private technical advisory group this month, and will issue a one-year temporary non-objection opinion on network separation regulations after reporting to the FSC on October 7.
This initiative aims to enhance the defensive capabilities of the financial sector amid increasing risks of cyberattacks utilizing AI. A uniform application of network separation regulations could hinder the use of external AI services for security purposes, so the regulations will be temporarily eased for financial companies that meet certain security requirements.
The government intends to quickly determine the timing and selection size for a third round of testing based on the application status and results from the first and second rounds. If additional demand is confirmed, further emergency easing measures for network separation regulations will be considered, or the possibility of institutionalizing them will be explored.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.