Application security company Sparrow announced on the 5th that its SaaS-based application security vulnerability analysis solution, 'Sparrow Cloud,' has passed the security review by the National Intelligence Service.
Sparrow, which supplied Sparrow Cloud to Geumcheon-gu Facility Management Corporation and Korea Road Traffic Authority, plans to actively target the public sector market following the successful security review.
National and public institutions must adopt cloud services certified with Cloud Service Security Authentication Program (CSAP) to minimize security threats when using private cloud computing services. Depending on the system's importance, in addition to CSAP, a security review by the National Intelligence Service may be required. SaaS must comply with common security standards as well as additional security requirements such as secure authentication and access authorization, application of encryption protocols like TLS, and audit log management.
Sparrow Cloud is a cloud service that analyzes security vulnerabilities in applications and is the only service in Korea to provide source code analysis (SAST), open source analysis (SCA), and web vulnerability analysis (DAST) all together. It has obtained CSAP certification, confirming its stability and reliability. It supports network separation policies optimized for user institutions to ensure safe use.
Sparrow has completed the National Intelligence Service security review so that national and public institutions requiring strict security can adopt Sparrow Cloud to inspect software vulnerabilities. It also meets additional security requirements such as authentication, access control, encryption, and audit logging. As a result, institutions can continuously inspect vulnerabilities and ensure software safety with only usage fees, without separate construction and maintenance costs.
Jang Ilsu, CEO of Sparrow, said, "As the government promotes the use of private SaaS, Sparrow Cloud has once again proven its security by passing the National Intelligence Service's strict security review." He added, "We will actively support public institutions to build a secure software supply chain with Sparrow Cloud."
© The Asia Business Daily(www.asiae.co.kr). All rights reserved.


