Where 15 Years of Physical Network Separation Hit Its Limit
Ask anyone working inside a Korean public institution whether they have used generative AI on their work PC, and the answer is almost always the same: "I move to the internet-connected PC to do that." Files must pass through a network-linkage server and wait for approval, and half a day disappears in the process.
Physical network separation has been the default for Korean public sector and financial security for more than 15 years. The benefit was clear — it eliminated external intrusion paths outright. But the cost was equally real.
That is the context behind N2SF (National Network Security Framework), the reorganized policy that Korea's National Intelligence Service consolidated from what was previously discussed as MLS (Multi-Level Security). The governing principle shifted from "cut the network" to "protect according to grade."
How N2SF Works: Classify First, Then Protect Accordingly
The core of N2SF fits into three letters. Business functions and data are classified as C (Classified), S (Sensitive), or O (Open), and protection levels are applied differentially by grade.
Moving from "block everything" to "classify, then control" places N2SF squarely alongside zero trust principles. Instead of trusting a single perimeter, every access request is evaluated against user, device, and data grade.
The pilot projects selected under KISA's demonstration program reveal the practical priorities. Generative AI in the work environment, external cloud-based collaboration, and remote and mobile work environments appear repeatedly — a clear signal of where institutions feel the most pressure.
What This Actually Requires at the System Level
The policy documents read simply. Implementation does not. Consider four stages.
Stage 1 — Identify and classify business functions and data. Most organizations stall here. Surprisingly few can answer "how many business functions does your institution have?" Cross-referencing business inventories, system inventories, and table inventories to separate what is actually in use from what has been abandoned must come first.
Stage 2 — Map data flows and define control points between grades. Once grades exist, every point where data crosses between them must be found: batch interfaces, API calls, report downloads, even screen captures. Flows moving from S down to O require de-identification or an approval step.
Stage 3 — Redesign authentication, access control, and logging. IAM consolidation, device authentication (MDM and certificates), data exfiltration controls (DLP), and audit log retention policies all need to be rebuilt around the grade structure. A permission model where "logging in reveals everything" cannot support grade separation.
Stage 4 — Assign grades at the screen and function level in existing systems. This is where redevelopment scope gets decided. If a single screen mixes C-grade and O-grade fields, the screen must be split or the fields individually masked. These judgments translate directly into engineering effort.
What Buyers and Implementers Should Calculate in Advance
The failure patterns are consistent.
What This Means for Private Enterprises
N2SF targets the public sector, but its design vocabulary transfers directly to manufacturing and logistics companies that have held onto closed networks.
The typical case: a company wants to analyze production line data with AI, but the plant network is fully sealed and no one can touch it. What is needed is not a decision to open the network — it is deciding which data belongs to which grade first. Classify equipment control commands as C, production and quality data as S, and aggregated KPIs as O, and a workable architecture emerges: KPI analysis runs in the cloud, production data passes through an on-premise gateway, and the control layer stays closed.
Drawing on our MES, WMS, and ERP implementation experience, POLYGLOTSOFT supports the engineering work of translating classification results into working systems — screen- and function-level permission matrices, interface control points derived from data flow maps, IAM and audit log redesign, and scoping the redevelopment driven by grade separation. If network separation reform is approaching and you are unsure where to start with your existing systems, [contact us](/en/support/contact) with your current architecture. We will come back with a prioritized plan and an effort estimate.
