
■ AS-IS
□ Overview of Monitoring Practices for Information Security Project Procurement
In accordance with Article 10 of the Information Security Industry Act, joint public-private monitoring is conducted for national and public institutions to establish fair
procurement practices. The monitoring process examines whether appropriate budgets are reflected, compliance is ensured, and corrective measures are requested when
necessary.
○ Review of advance specifications (RFI) for information security projects to check compliance with relevant laws and take corrective actions if needed.
○ Operation of a reporting center for unfair practices in information security project procurement to receive and handle complaints.
○ Operation of a working committee to investigate unfair or unreasonable practices.
- Monitoring of Procurement Practices in Information Security Projects
To establish fair procurement practices in the information security industry, joint public-private monitoring is conducted in accordance with Article 10 of the Information
Security Industry Act. This includes monitoring whether proper project cost estimation (e.g., avoiding overestimation, adjusting excessive manpower requirements), and
requirements for introducing certified security products are being followed. If violations are found, corrective actions are requested.
□ Major Improvement Cases
- Proper Cost Estimation for Security Projects (Adjusting Overestimation)
- Issue: Budgets for additional requirements in security projects were not properly estimated.
※ Cost estimation for information security services (e.g., control services) must follow the SW Project Cost Estimation Guide.
- Improvement: Budget levels were adjusted, and requests for reduction of excessive estimates were reflected, completing negotiations on overestimation.
- Proper Cost Estimation for Information Security Consulting (Adjusting Manpower Requirements)
- Issue: In proposals from procuring agencies, manpower input was limited to IT support technicians only, without allocating IT consultants, resulting in improper cost estimates.
※ According to the SW Cost Estimation Guide, IT consultants (information security consultants) must be assigned.
- Improvement: Agencies were requested to include not only IT support staff but also IT consultants in manpower requirements, and public notices reflected these improvements.
- Security Product Adoption Requirements (Improving Conditions for Certified Products)
- Issue: Agencies required both CC (Common Criteria) certification with excessive assurance levels (EAL4) and GS (Good Software) certification, creating redundancy.
※ For government procurement, CC certification is already required under national technical certification rules, and GS certification is unnecessary.
- Improvement: Requirements were streamlined to avoid redundancy, GS certification was removed, and excessive assurance levels (EAL) were relaxed.