A Comprehensive Analysis of Security Measures for MyData in South Korea Based on AHP
摘要
With the full launch of Korea’s MyData service in January 2022, data subjects as individuals have gained the right to data portability, which allows them to access, transfer, delete, and utilize their personal credit information proactively. Data subjects can demand that financial institutions holding their personal credit information transmit the data to MyData operators. Then, the MyData operators can manage the received data efficiently and provide various services to the data subjects by analyzing the relevant data. In the MyData ecosystem, large amounts of data are transmitted over the Internet; thus, sufficient security is required protect these data. Thus, this paper introduces various security mechanisms applied to South Korea’s MyData services, e.g., secure authentication methods, data transmission via standard APIs, mutual authentication between organizations, and secure communication. However, due to the concentration of data within the MyData operators, ineffective security measures could result in a significant data breach compromising large amounts of personal credit information. Thus, this study also analyzes the priority of security measures to enhance the security of MyData operators through Analytic Hierarchy Process (AHP) empirical analysis. The results indicate that it is critical to prioritize protecting the large volume of data from external exposure and reinforce infrastructure security against external hacking threats.