National Intelligence Service Updates Cloud Policy for AI Era

By BAEK SEO HYUN Posted : September 17, 2026, 16:20 Updated : September 17, 2026, 16:20

The National Intelligence Service (NIS) is revamping its national cybersecurity policies, including cloud, network, and software vulnerability management, to align with the rise of artificial intelligence (AI). The updates aim to support AI utilization in the public sector and enhance responses to AI security threats.


On September 17, the NIS opened the Cyber Summit Korea 2026 at COEX in Seoul, where it unveiled the direction for revising national cybersecurity and AI security policies.


First established 14 years ago, the 'National Cloud Computing Security Guidelines' will be updated to reflect changes in AI and cloud technology environments. Security standards applied when introducing private clouds in the public sector will also be improved to align with international standards and technological advancements.


The cloud rating system will shift from a focus on systems to data. Currently categorized by importance as high, medium, or low, the revised guidelines will classify data based on the National Network Security Framework (N2SF) into confidential (C), sensitive (S), and public (D) information.


Exceptions for cloud validation will be established for new technology services like AI. This includes cases where only public information is processed, such as in public institutions, or cloud services tied to specialized equipment like medical robots.


The cloud security validation system will also be restructured. Instead of relying on evaluations and certifications from the Ministry of Science and ICT, the NIS plans to integrate and operate a verification system centered on its own assessments.


By 2028, the NIS aims to establish a national vulnerability database, collecting information on vulnerabilities in commercial and open-source software distributed domestically and internationally. A system for reporting, addressing, and disclosing vulnerabilities will undergo pilot testing this year before being expanded to national public institutions by 2028.


The network security framework will transition from a focus on network separation to the N2SF. This will enhance the security level application system based on the revised national cybersecurity guidelines established in May.


Additionally, the NIS is developing security policies specifically for AI. Last year, it launched the National AI Security Center to address AI security threats. In the first half of this year, the NIS surveyed over 290 national and public institutions regarding AI implementation and security management, conducting security assessments and validation activities (red teaming) for 17 of those institutions.





* This article has been translated by AI.

Copyright ⓒ Aju Press All rights reserved.