OTT platform adopts AWS Security Improvement Program to strengthen access management and threat response
South Korean OTT platform Tving is overhauling its cloud security infrastructure to align with global standards, tapping Amazon Web Services' security program to conduct a comprehensive review of its cloud environment. The initiative aims to bolster both service stability and customer data protection.
Tving announced Friday that it is upgrading its security framework by leveraging AWS's Security Improvement Program, or SIP — a cloud security diagnostic and enhancement program that starts from a customer's actual cloud usage environment and targets long-term security capability building through customized roadmaps, collaboration and implementation support.
The assessment draws on security control benchmarks from the global security organization CIS, the cybersecurity framework developed by the US National Institute of Standards and Technology, and AWS foundational security best practices to diagnose security levels across the cloud environment and identify specific areas for improvement. The SIP engagement is part of Tving's broader push to strengthen its information security framework.
Tving is reinforcing its cloud security posture across five areas: identity and access management, detection capabilities, infrastructure protection, data protection, and incident response and automation. The company plans to improve visibility across its cloud environment, systematically manage access privileges and external exposure points, and enable rapid detection of and response to anomalies.
To that end, Tving will conduct a comprehensive review of its cloud environment by incorporating domestic and international security standards and global guidelines, building a management framework grounded in global security best practices to respond flexibly to a rapidly shifting security landscape.
The company will also proactively audit externally exposed assets and overly permissive access rights to minimize security gaps and misconfigurations. It plans to further develop its threat response process to detect anomalies in real time and automatically execute necessary countermeasures, with a focus on accelerating response times when security events occur and automating repetitive tasks.
In addition, Tving is expanding its use of AWS native security services, including AWS Network Firewall, which monitors network traffic within the cloud and blocks malicious traffic; Amazon GuardDuty, which intelligently detects signs of threats; AWS Security Hub, which consolidates alerts and security status from multiple security services in one place; and Amazon Inspector, which automatically scans systems for vulnerabilities.
"We are using AWS's SIP to systematically review our entire cloud environment and are executing identified improvement tasks in a phased manner," a Tving official said. "Through regular assessments and continuous improvement, we will build an environment where customers can use our service with confidence."
ko@heraldcorp.com