Skip to content

Evidence request lists

South Korea Cloud Security Assurance Program (CSAP)

Evidence request list. 23 controls, 23 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Audit

KRCSAP-4
Audit, Recertification, KISA Cooperation

Per CSAP: Five-Year Review and Recertification + Record Retention + KISA cooperation.

Artefacts an auditor will ask for
  • KR CSAP evidence for KRCSAP-4
Where this commonly fails
  • KISA audit + sovereignty partial

Certification

KRCSAP-1
CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)

Per South Korea CSAP (KISA): cloud security assurance certification. Requirements include (a) CSAP tiers (Standard + Simplified) + (b) IaaS + SaaS + DaaS + AI cloud certifications + (c) initial assessment + recertification + (d) KISA audit.

Artefacts an auditor will ask for
  • KR CSAP evidence for KRCSAP-1
Where this commonly fails
  • KISA audit + sovereignty partial

Cloud Security

KRCSAP-2
Cloud Security Controls

Per CSAP: security controls including admin + physical + technical + data classification + encryption + access control + monitoring.

Artefacts an auditor will ask for
  • KR CSAP evidence for KRCSAP-2
Where this commonly fails
  • KISA audit + sovereignty partial

Continuity and Change Management

CSAP-BCP-09
Business continuity and disaster recovery

Services shall maintain documented business continuity and disaster recovery plans aligned to defined RTO and RPO targets, with failover sites within Korea, regular testing, and customer-facing service level commitments.

Artefacts an auditor will ask for
  • BCP and DR plan
  • RTO RPO matrix per service tier
  • DR test reports including full failover
  • DR site location attestation within Korea
  • Customer communication runbook
Where this commonly fails
  • Tabletop tests substituted for live failover
  • RTO RPO not validated against customer SLAs
  • Cross-border DR not addressed where prohibited
CSAP-CHG-10
Change management

All changes to certified production environments shall follow documented change management procedures including risk assessment, testing, approval by authorised parties, scheduled deployment windows, and rollback plans.

Artefacts an auditor will ask for
  • Change management policy
  • CAB minutes
  • Sample change records with risk assessments
  • Emergency change procedure
  • Change success rate metrics
Where this commonly fails
  • Automated deployments bypass CAB without standard change template
  • Rollback never tested
  • Emergency changes account for high percentage of total

Cryptography and Access Control

CSAP-CRYP-04
Cryptographic controls and key management

Data at rest and in transit shall be protected using cryptographic algorithms approved by the Korean cryptographic module validation programme (KCMVP), with key lifecycle managed in hardware security modules certified to required levels.

Artefacts an auditor will ask for
  • Approved algorithm inventory referencing KCMVP
  • HSM certification documents
  • Key management policy with rotation schedules
  • Key ceremony records
  • TLS configuration scans showing only approved ciphers
Where this commonly fails
  • Non-KCMVP algorithms permitted for legacy compatibility
  • Customer managed keys not supported where claimed
  • Key rotation overdue
CSAP-IAM-05
Identity and access management

Access to administrative interfaces and customer data shall require multi-factor authentication, role-based access control with least privilege, periodic access reviews, and just-in-time elevation for privileged operations.

Artefacts an auditor will ask for
  • Identity provider configuration with MFA enforcement
  • RBAC role catalogue with assigned permissions
  • Quarterly user access review evidence
  • Privileged access management workflow logs
  • Joiner mover leaver process documentation
Where this commonly fails
  • Service accounts excluded from MFA
  • Reviews approved without examination
  • PAM bypass routes via emergency accounts not monitored

Data Protection and Privacy

CSAP-DATA-14
Data classification and protection

Customer data shall be classified according to sensitivity, with handling, storage, and transmission controls matched to classification, and government customer data treated with the highest level of protection.

Artefacts an auditor will ask for
  • Data classification policy
  • Data flow diagrams with classification overlay
  • DLP configuration and alert log
  • Customer data inventory
  • Disposal certificates for end-of-life media
Where this commonly fails
  • Backups inherit lower classification than primary data
  • DLP rules generate too many false positives and are ignored
  • Test data extracted from production without masking
CSAP-PRIV-20
Privacy and personal information protection

Where certified services process personal information of Korean data subjects, the provider shall comply with PIPA obligations on lawful basis, data minimisation, retention limits, data subject rights, and cross-border transfer restrictions.

Artefacts an auditor will ask for
  • Privacy policy in Korean
  • Lawful basis documentation per processing activity
  • Data subject request handling procedure
  • Cross border transfer impact assessment
  • Privacy officer designation
Where this commonly fails
  • Cross border transfer mechanisms unclear
  • Retention schedules inconsistent across systems
  • Data subject requests handled outside SLA

Data Sovereignty

KRCSAP-3
Data Sovereignty, Domestic Storage

Per CSAP: domestic data storage + sovereignty per Korean law + restrictions on cross-border.

Artefacts an auditor will ask for
  • KR CSAP evidence for KRCSAP-3
Where this commonly fails
  • KISA audit + sovereignty partial

Logging, Vulnerability and Incident Management

CSAP-INC-07
Incident response and breach notification

Cloud service providers shall maintain documented incident response procedures with defined severity tiers, notification to affected government customers and KISA within prescribed timeframes, and post incident review with corrective actions.

Artefacts an auditor will ask for
  • Incident response plan
  • Severity classification matrix
  • Annual tabletop and live exercise reports
  • Notification templates for KISA and customers
  • Post incident review reports with action tracking
Where this commonly fails
  • KISA notification timing not defined
  • Customer contact list outdated
  • Lessons learned not closed
CSAP-LOG-06
Logging and security monitoring

Security-relevant events shall be logged with sufficient detail to support investigation, retained for periods aligned to government customer requirements (minimum one year), and monitored via 24/7 security operations.

Artefacts an auditor will ask for
  • Logging architecture covering OS, network, app, identity
  • Retention configuration showing minimum periods
  • SOC runbooks and shift handover logs
  • Sample alert tickets with triage timestamps
  • Log integrity protection via WORM or signing
Where this commonly fails
  • Application logs not centralised
  • Retention shorter than government customer needs
  • SOC tickets lack root cause analysis
CSAP-VUL-08
Vulnerability and patch management

Vulnerabilities shall be identified through regular scanning, prioritised by severity and exposure, and remediated within timeframes specified in policy, with emergency patching procedures for critical zero day issues.

Artefacts an auditor will ask for
  • Vulnerability management policy with SLAs
  • Scanner configurations and credentialed scan evidence
  • Patch deployment records with success rates
  • Risk acceptance log for deferred patches
  • Zero day response timeline
Where this commonly fails
  • Scans authenticated only partially
  • Container images not scanned in registry
  • Legacy systems excluded without compensating controls

Physical and Network Security

CSAP-NET-03
Network segmentation and boundary protection

Certified services shall implement logical network segmentation isolating public sector tenant data from non-certified environments, with stateful firewall, intrusion prevention, and DDoS protection at perimeter and inter-zone boundaries.

Artefacts an auditor will ask for
  • Network architecture diagram with VLAN and security zone overlay
  • Firewall rule base with justifications
  • IPS and DDoS configuration snapshots
  • Penetration test reports targeting segmentation
  • Annual review minutes of firewall rules
Where this commonly fails
  • Flat networks within tenant boundary
  • Excessive any-any rules
  • DDoS protection not exercised in tests
CSAP-PHYS-02
Physical and environmental security

Data centres hosting certified services shall implement layered physical access controls, environmental monitoring, fire suppression, and power redundancy, with all infrastructure components located within Republic of Korea borders for public sector workloads.

Artefacts an auditor will ask for
  • Data centre location attestation within Korea
  • Physical access control system logs
  • CCTV coverage map and retention configuration
  • Environmental monitoring dashboards
  • Fire suppression and power redundancy test records
Where this commonly fails
  • Disaster recovery site outside Korea
  • Visitor logs not retained for required period
  • Environmental alerts not routed to operations team

Policy, Risk and Personnel

CSAP-HR-12
Personnel security

Personnel with access to certified environments shall undergo background verification, sign confidentiality agreements, complete role-specific security training, and have access removed promptly upon role change or termination.

Artefacts an auditor will ask for
  • Background check policy and completed records
  • Signed confidentiality and security agreements
  • Annual security awareness training completion
  • Role-based training for privileged personnel
  • Termination checklist showing access revocation
Where this commonly fails
  • Contractor background checks weaker than employees
  • Training completion rates below target
  • Termination access revocation delayed beyond same day
CSAP-POL-19
Information security policy framework

Providers shall maintain a documented information security policy framework approved by senior management, with policies, standards, and procedures covering all CSAP control domains and reviewed at least annually.

Artefacts an auditor will ask for
  • Approved policy register with version control
  • Senior management approval signatures
  • Annual review minutes
  • Policy exception register
  • Policy communication and acknowledgement records
Where this commonly fails
  • Policies not aligned to latest CSAP version
  • Exception register dormant indicating either no exceptions or no tracking
  • Acknowledgements not collected from contractors
CSAP-RIA-18
Risk assessment and management

Providers shall conduct annual information security risk assessments covering assets within the certification scope, with risks treated through controls or formally accepted by management, and the risk register reviewed periodically.

Artefacts an auditor will ask for
  • Risk assessment methodology
  • Annual risk assessment report
  • Risk register with treatment plans
  • Management acceptance records for residual risk
  • Quarterly risk review minutes
Where this commonly fails
  • Risk register inherited year over year without re-assessment
  • Treatments not linked to project plans
  • Threat landscape input from threat intelligence missing

Scope and Certification

CSAP-AUD-15
Audit and certification maintenance

Certified providers shall undergo annual surveillance audits and full recertification on the prescribed cycle, with non-conformities remediated within timeframes set by KISA and material changes notified for impact assessment.

Artefacts an auditor will ask for
  • Current CSAP certification certificate
  • Annual surveillance audit reports
  • Non-conformity remediation evidence
  • Material change notifications submitted to KISA
  • Internal audit programme covering CSAP scope
Where this commonly fails
  • Material changes not notified
  • Surveillance findings repeated year over year
  • Internal audits not independent of operations
CSAP-CUST-17
Customer responsibility and shared model documentation

Providers shall publish a shared responsibility matrix clearly distinguishing provider, customer, and joint obligations for each control area, with guidance for government customers on secure configuration.

Artefacts an auditor will ask for
  • Shared responsibility matrix per service
  • Customer security guide
  • Default secure configuration documentation
  • Customer onboarding security briefing materials
  • Customer security event notification SLA
Where this commonly fails
  • Matrix not updated when service features change
  • Customer guide written in English only without Korean translation
  • Default configurations insecure out of the box
CSAP-SCOPE-01
Service scope and tier determination

Cloud service providers seeking CSAP certification shall determine applicable service category (SaaS, IaaS, PaaS, DaaS) and tier (Standard or Simplified for SaaS), with scope boundaries documented and presented to KISA at engagement initiation.

Artefacts an auditor will ask for
  • Service description document with tier rationale
  • System architecture diagrams covering certified scope
  • Service inventory with mapping to CSAP categories
  • Customer commitments document
  • KISA scope confirmation correspondence
Where this commonly fails
  • Multiple services bundled into single certification incorrectly
  • Standard vs Simplified tier mismatch with target government users
  • Scope boundary diagrams not updated after architectural changes

Secure Development and Tenancy

CSAP-SAAS-16
SaaS specific isolation and tenancy

SaaS providers shall demonstrate logical isolation between government tenant data and other tenants, with controls preventing data leakage through shared services, caches, search indexes, or backup systems.

Artefacts an auditor will ask for
  • Tenancy model architecture documentation
  • Tenant isolation test results
  • Cache and search index segregation evidence
  • Backup tenant scoping documentation
  • Bug bounty or third party assessment focused on tenant isolation
Where this commonly fails
  • Cross-tenant indexes for analytics
  • Backup restoration testing without tenant scoping
  • Shared admin tools that view cross-tenant data without audit
CSAP-SDLC-11
Secure software development lifecycle

Software supporting certified services shall be developed with security activities integrated at each lifecycle phase, including threat modelling, secure coding standards, code review, application security testing, and dependency management.

Artefacts an auditor will ask for
  • Secure SDLC policy
  • Threat models for high risk components
  • SAST and DAST scan results
  • Software composition analysis reports
  • Developer security training records
Where this commonly fails
  • Threat models stale after major releases
  • SCA findings not tracked to remediation
  • Pre-prod environments lack scanning
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the South Korea Cloud Security Assurance Program (CSAP) framework page.