FSS-Distributed "IT Security Self-Inspection Checklist"
One of 12 Items Rated "Inadequate"
Pages for Former Employee Information Lookup and Foreign Account Registration
Deleted

As banks and credit card companies wrapped up urgent inspections in response to the Financial Supervisory Service's request for a security review of the financial sector, BNK Kyongnam Bank was found to have rated some items as "inadequate."



[Exclusive] BNK Kyongnam Bank Flags One Security Check Item as "Inadequate"; Fixes Some Webpage Vulnerabilities View original image

According to the "IT Security Self-Inspection Checklist" submitted by BNK Kyongnam Bank to the office of Park Seong-hoon of the People Power Party, a member of the National Assembly's Political Affairs Committee, the bank rated one of the 12 inspection items as "inadequate."


The FSS had previously shared a list of attacker IP addresses it had obtained with the entire financial sector and urgently asked institutions to complete their own security inspections and address any deficiencies by October 8. It also distributed a checklist of 12 items to financial companies, including whether they had blocked the shared attacker IP addresses, whether there had been any intrusion attempts or damage involving those IP addresses, and whether their real-time security monitoring systems were operational.


The item rated "inadequate" concerned checking and verifying whether authentication and authorization functions were missing and whether access-control vulnerabilities existed in external systems, such as webpages. The remaining 11 items were all rated "adequate."


BNK Kyongnam Bank said it conducted an urgent inspection of all pages on external systems that ordinary users and others could access without logging in. It added that the inspection also identified some pages that required users to log in but had inadequate security measures.


The bank said it had regularly inspected vulnerabilities, including those related to authentication and access control, in its electronic financial infrastructure once a year and in its public-facing websites twice a year. It had also identified and managed externally exposed assets through the Financial Security Institute and its own attack surface management (ASM) tool, but added that the tool made it difficult to determine whether ordinary users could access those assets.


This means that the bank's existing inspection tools alone were not sufficient to determine whether externally exposed systems could be accessed. The findings revealed a need to improve the access-control inspection framework for externally exposed assets.


According to the "Statement of Reasons for Unremediated Issues" submitted by BNK Kyongnam Bank, the bank deleted or improved some pages found to be inadequate during the inspection. It completed the removal of a webpage related to searches for information on former employees and a page for registering foreign nationals' accounts via mobile web. On October 6, it introduced an additional authentication step on a page related to the online management status of retirement pension accounts.



The FSS plans to compile and analyze the inspection results and share them with the Financial Services Commission. Based on the results, the FSC will conduct on-site inspections of financial companies deemed to require further examination, and plans to incorporate commonly identified vulnerabilities into regulatory improvements. An FSC official said, "We plan to conduct on-site inspections where further examination is deemed necessary and improve regulations, focusing on vulnerabilities commonly found to be inadequate."


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing