TVING Reinforces Security Framework with Zero Trust to Prevent Data Leaks
Access Verification, Least Privilege, Breach Assumption, and Continuous Verification
Advancing AI Security Monitoring and Cloud Permission Assessment
On September 23, TVING announced that it is making every effort to strengthen security by applying a 'Zero Trust'-based security system across its services and cloud environment.
Zero Trust is a security principle that assumes no access is trusted by default and continually verifies users, devices, and permissions. TVING has established four core principles: thorough access verification, least privilege, breach assumption, and continuous verification.
To enable thorough access verification, TVING has implemented authentication token verification across all applications and web interfaces and enforced mandatory updates for outdated app versions. The company is also considering the implementation of technology to detect and block tampered apps. In line with the least privilege principle, access rights to systems and services are subdivided by job function, and the scope and validity period of permissions are strictly managed, thereby strengthening the access control framework.
Furthermore, TVING is refining its incident response processes by assuming potential breaches and evaluating response systems for various scenarios. For continuous verification, the company has set up a system that can detect abnormal activity in the cloud environment in real time and send alerts when irregular access is detected.
As follow-up measures to advance its security framework, TVING plans to validate the introduction of credential management tools and source code analysis/vulnerability management solutions, as well as broaden the scope of penetration testing and vulnerability assessments to include cloud account and permissions domains. The company is also exploring the adoption of a bug bounty program in conjunction with enhancing scenario-based incident response protocols. Regarding the establishment of next-generation security systems, TVING is reinforcing integrated cloud security inspection processes and applying AI-based threat detection and blocking technologies to improve its real-time response capabilities.
To further reinforce its core security areas, TVING has transferred secret information in code to a dedicated management system and established automated blocking and abnormal access detection at the source code storage stage. Next-generation endpoint detection and response (EDR) solutions have also been deployed across all employee PCs. In addition, to better protect customer data, TVING has replaced all app signing keys and DRM keys, and enhanced the architecture for login and session validation. The password storage algorithm has been switched to a bcrypt-based system.
Hot Picks Today
Micron Holds the Fate of Semiconductor Stocks After Chuseok, Could Trigger a New Rally for Samsung Electronics and SK hynix [Weekend Money]
- "450,000 Deaths Expected by Early Next Year"... World's Worst-Ever El Nino Forecast Spurs Global Alarm
- She Was Not Punished for Drunk Driving... Court Rules Woman Who Drove to Escape Sexual Assault Not Criminally Liable
- Saudi Arabia, Turkey, and Pakistan Discuss Joint Response as Houthi Attacks Intensify
- Who Is the Woman Next to Ivanka? Trump’s Granddaughter Who Sang in Chinese for Xi Jinping 9 Years Ago
A TVING spokesperson said, "We are prioritizing the protection of customer data, continuously reviewing our security systems, and enhancing our security posture to ensure that improvements translate to practical actions. In accordance with Zero Trust principles, we will continue to advance our access and permission management, elevate our breach response systems, and invest in next-generation security technologies, such as AI-based threat detection, to create a safer service environment."
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.