South Korea Cloud Security Assurance Program (CSAP)
Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Audit
Per CSAP: Five-Year Review and Recertification + Record Retention + KISA cooperation.
- KR CSAP evidence for KRCSAP-4
- KISA audit + sovereignty partial
Certification
Per South Korea CSAP (KISA): cloud security assurance certification. Requirements include (a) CSAP tiers (Standard + Simplified) + (b) IaaS + SaaS + DaaS + AI cloud certifications + (c) initial assessment + recertification + (d) KISA audit.
- KR CSAP evidence for KRCSAP-1
- KISA audit + sovereignty partial
Cloud Security
Per CSAP: security controls including admin + physical + technical + data classification + encryption + access control + monitoring.
- KR CSAP evidence for KRCSAP-2
- KISA audit + sovereignty partial
Continuity and Change Management
Services shall maintain documented business continuity and disaster recovery plans aligned to defined RTO and RPO targets, with failover sites within Korea, regular testing, and customer-facing service level commitments.
- BCP and DR plan
- RTO RPO matrix per service tier
- DR test reports including full failover
- DR site location attestation within Korea
- Customer communication runbook
- Tabletop tests substituted for live failover
- RTO RPO not validated against customer SLAs
- Cross-border DR not addressed where prohibited
All changes to certified production environments shall follow documented change management procedures including risk assessment, testing, approval by authorised parties, scheduled deployment windows, and rollback plans.
- Change management policy
- CAB minutes
- Sample change records with risk assessments
- Emergency change procedure
- Change success rate metrics
- Automated deployments bypass CAB without standard change template
- Rollback never tested
- Emergency changes account for high percentage of total
Cryptography and Access Control
Data at rest and in transit shall be protected using cryptographic algorithms approved by the Korean cryptographic module validation programme (KCMVP), with key lifecycle managed in hardware security modules certified to required levels.
- Approved algorithm inventory referencing KCMVP
- HSM certification documents
- Key management policy with rotation schedules
- Key ceremony records
- TLS configuration scans showing only approved ciphers
- Non-KCMVP algorithms permitted for legacy compatibility
- Customer managed keys not supported where claimed
- Key rotation overdue
Access to administrative interfaces and customer data shall require multi-factor authentication, role-based access control with least privilege, periodic access reviews, and just-in-time elevation for privileged operations.
- Identity provider configuration with MFA enforcement
- RBAC role catalogue with assigned permissions
- Quarterly user access review evidence
- Privileged access management workflow logs
- Joiner mover leaver process documentation
- Service accounts excluded from MFA
- Reviews approved without examination
- PAM bypass routes via emergency accounts not monitored
Data Protection and Privacy
Customer data shall be classified according to sensitivity, with handling, storage, and transmission controls matched to classification, and government customer data treated with the highest level of protection.
- Data classification policy
- Data flow diagrams with classification overlay
- DLP configuration and alert log
- Customer data inventory
- Disposal certificates for end-of-life media
- Backups inherit lower classification than primary data
- DLP rules generate too many false positives and are ignored
- Test data extracted from production without masking
Where certified services process personal information of Korean data subjects, the provider shall comply with PIPA obligations on lawful basis, data minimisation, retention limits, data subject rights, and cross-border transfer restrictions.
- Privacy policy in Korean
- Lawful basis documentation per processing activity
- Data subject request handling procedure
- Cross border transfer impact assessment
- Privacy officer designation
- Cross border transfer mechanisms unclear
- Retention schedules inconsistent across systems
- Data subject requests handled outside SLA
Data Sovereignty
Per CSAP: domestic data storage + sovereignty per Korean law + restrictions on cross-border.
- KR CSAP evidence for KRCSAP-3
- KISA audit + sovereignty partial
Logging, Vulnerability and Incident Management
Cloud service providers shall maintain documented incident response procedures with defined severity tiers, notification to affected government customers and KISA within prescribed timeframes, and post incident review with corrective actions.
- Incident response plan
- Severity classification matrix
- Annual tabletop and live exercise reports
- Notification templates for KISA and customers
- Post incident review reports with action tracking
- KISA notification timing not defined
- Customer contact list outdated
- Lessons learned not closed
Security-relevant events shall be logged with sufficient detail to support investigation, retained for periods aligned to government customer requirements (minimum one year), and monitored via 24/7 security operations.
- Logging architecture covering OS, network, app, identity
- Retention configuration showing minimum periods
- SOC runbooks and shift handover logs
- Sample alert tickets with triage timestamps
- Log integrity protection via WORM or signing
- Application logs not centralised
- Retention shorter than government customer needs
- SOC tickets lack root cause analysis
Vulnerabilities shall be identified through regular scanning, prioritised by severity and exposure, and remediated within timeframes specified in policy, with emergency patching procedures for critical zero day issues.
- Vulnerability management policy with SLAs
- Scanner configurations and credentialed scan evidence
- Patch deployment records with success rates
- Risk acceptance log for deferred patches
- Zero day response timeline
- Scans authenticated only partially
- Container images not scanned in registry
- Legacy systems excluded without compensating controls
Physical and Network Security
Certified services shall implement logical network segmentation isolating public sector tenant data from non-certified environments, with stateful firewall, intrusion prevention, and DDoS protection at perimeter and inter-zone boundaries.
- Network architecture diagram with VLAN and security zone overlay
- Firewall rule base with justifications
- IPS and DDoS configuration snapshots
- Penetration test reports targeting segmentation
- Annual review minutes of firewall rules
- Flat networks within tenant boundary
- Excessive any-any rules
- DDoS protection not exercised in tests
Data centres hosting certified services shall implement layered physical access controls, environmental monitoring, fire suppression, and power redundancy, with all infrastructure components located within Republic of Korea borders for public sector workloads.
- Data centre location attestation within Korea
- Physical access control system logs
- CCTV coverage map and retention configuration
- Environmental monitoring dashboards
- Fire suppression and power redundancy test records
- Disaster recovery site outside Korea
- Visitor logs not retained for required period
- Environmental alerts not routed to operations team
Policy, Risk and Personnel
Personnel with access to certified environments shall undergo background verification, sign confidentiality agreements, complete role-specific security training, and have access removed promptly upon role change or termination.
- Background check policy and completed records
- Signed confidentiality and security agreements
- Annual security awareness training completion
- Role-based training for privileged personnel
- Termination checklist showing access revocation
- Contractor background checks weaker than employees
- Training completion rates below target
- Termination access revocation delayed beyond same day
Providers shall maintain a documented information security policy framework approved by senior management, with policies, standards, and procedures covering all CSAP control domains and reviewed at least annually.
- Approved policy register with version control
- Senior management approval signatures
- Annual review minutes
- Policy exception register
- Policy communication and acknowledgement records
- Policies not aligned to latest CSAP version
- Exception register dormant indicating either no exceptions or no tracking
- Acknowledgements not collected from contractors
Providers shall conduct annual information security risk assessments covering assets within the certification scope, with risks treated through controls or formally accepted by management, and the risk register reviewed periodically.
- Risk assessment methodology
- Annual risk assessment report
- Risk register with treatment plans
- Management acceptance records for residual risk
- Quarterly risk review minutes
- Risk register inherited year over year without re-assessment
- Treatments not linked to project plans
- Threat landscape input from threat intelligence missing
Scope and Certification
Certified providers shall undergo annual surveillance audits and full recertification on the prescribed cycle, with non-conformities remediated within timeframes set by KISA and material changes notified for impact assessment.
- Current CSAP certification certificate
- Annual surveillance audit reports
- Non-conformity remediation evidence
- Material change notifications submitted to KISA
- Internal audit programme covering CSAP scope
- Material changes not notified
- Surveillance findings repeated year over year
- Internal audits not independent of operations
Providers shall publish a shared responsibility matrix clearly distinguishing provider, customer, and joint obligations for each control area, with guidance for government customers on secure configuration.
- Shared responsibility matrix per service
- Customer security guide
- Default secure configuration documentation
- Customer onboarding security briefing materials
- Customer security event notification SLA
- Matrix not updated when service features change
- Customer guide written in English only without Korean translation
- Default configurations insecure out of the box
Cloud service providers seeking CSAP certification shall determine applicable service category (SaaS, IaaS, PaaS, DaaS) and tier (Standard or Simplified for SaaS), with scope boundaries documented and presented to KISA at engagement initiation.
- Service description document with tier rationale
- System architecture diagrams covering certified scope
- Service inventory with mapping to CSAP categories
- Customer commitments document
- KISA scope confirmation correspondence
- Multiple services bundled into single certification incorrectly
- Standard vs Simplified tier mismatch with target government users
- Scope boundary diagrams not updated after architectural changes
Secure Development and Tenancy
SaaS providers shall demonstrate logical isolation between government tenant data and other tenants, with controls preventing data leakage through shared services, caches, search indexes, or backup systems.
- Tenancy model architecture documentation
- Tenant isolation test results
- Cache and search index segregation evidence
- Backup tenant scoping documentation
- Bug bounty or third party assessment focused on tenant isolation
- Cross-tenant indexes for analytics
- Backup restoration testing without tenant scoping
- Shared admin tools that view cross-tenant data without audit
Software supporting certified services shall be developed with security activities integrated at each lifecycle phase, including threat modelling, secure coding standards, code review, application security testing, and dependency management.
- Secure SDLC policy
- Threat models for high risk components
- SAST and DAST scan results
- Software composition analysis reports
- Developer security training records
- Threat models stale after major releases
- SCA findings not tracked to remediation
- Pre-prod environments lack scanning
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the South Korea Cloud Security Assurance Program (CSAP) framework page.