Skip to main content

Function Specification Document

※ Last updated: 2026-07-29

RFP Notation Standards

NotationmeaningDescription
RequiredCommon Evaluation CriteriaEssential evaluation features that are fundamentally included in the RFP
specializationDifferentiation ItemsDocument Security 6's unique features provide an advantage over competitors.Recommendation to Add Evaluation Criteria to the RFP
SelectionAdditional ItemsFeatures proposed optionally based on customer requirements

Major CategoryMid-categorySubcategoryDetailed DescriptionNoteRFP notation
Document EncryptionSupport for various encryption policiesSelective EncryptionUsers can select and encrypt personal security documents, access target/permission setting security documents, regulatory security documents, and classification security documents.You can select and encrypt various security documents according to customer requirements.
Automatic Encryption | Forced EncryptionAutomatically enforces encryption under certain conditions according to the security policy set by the administrator.SAVE, SAVE AS, will be applied when closing.
Exception settings for forced encryptionYou can set forced encryption exception permissions under certain conditions.Detailed settings are available.
Simple EncryptionApply simple encryption to the unsupported Application file.You can perform basic encryption regardless of the file extension.
Document Permission ControlCategory-based permissionsEnterprise CategorySet up category-based security policies that apply organization-wide.
Forced CategoryEnhance category-based security settings through forced permissions.
Role-based permissionsWarrior GradeSet up a tiered security policy that applies organization-wide.
Forced RatingEnhance role-based security settings through enforced permissions.
Group/User Based PermissionsDocument-level permissionsYou can manage permissions by document unit for groups/users.
Forced AuthorizationGrants forced permissions to a specific group/user.
User Permission SettingsUser-Group Specific Policy SettingsYou can set security policies by user or group.Manage from the Console.
Category-Grade Policy SettingsYou can control permissions based on categories and ratings.Example: View, Edit, Print, Decrypt Permission Settings
Access ControlRead-Edit-Output-Decryption PermissionsSupports detailed settings by permission for reading, editing, outputting, and decryption.Includes constructor permissions and exception settings.
Output Permission ControlYou can set output permissions by user, group, category, and rating.
Block Virtual Printer OutputPrevents unauthorized printing using a virtual printer when outputting files.
Usage period and frequency limitsAutomatically destroys when the number of views/prints and the validity period exceed.
Edit ControlCopy & Paste Direction ControlCopy-Paste BlockPrevents copying/pasting the contents of security documents into regular documents.
Permission-based Copy-PasteCopying/pasting is possible depending on the permissions of the security document being copied.
Screen Capture ControlScreen Capture PreventionControls the content of security documents to prevent screen capture.
Creating Secure Files for External TransmissionCreating Secure Files for External TransmissionCreates a simple encrypted secure file (EXE) that can be executed without installing a client program (Clientless).
Security Document ProtectionTracking of Exported Security DocumentsUser-group specific markingInsert markings such as user/group information, output time, ownership, etc. into the output document.Example: Employee Number, Name, Department, IP Address, etc. Output
General Document MarkingYou can insert print markings not only in security documents but also in regular documents.
Offline Login PolicyOffline permission setting supportUser-Department Permission SettingsYou can set separate permissions for users/departments even in offline mode.If not set, the latest online login permissions will be automatically applied.
Policy-based permission actionsRecently, the permissions operate according to the online login policy or a separately designated policy.For example: You can set permission restrictions such as reading, editing, and output.
Batch EncryptionLocal Document EncryptionDocument Scanning and Batch EncryptionYou can scan regular documents on your local PC and encrypt them in bulk.Select the target document and proceed with encryption.
User-Department Level EncryptionYou can set encryption policies by user and department.Administrator settings and schedule-based encryption are available.
Document Type ManagementRegistering ExtensionsYou can register and manage the types of documents (extensions) to which encryption is applied.
Target Document Search and ProcessingSearch for the specified target document and proceed with batch encryption processing.You can select targets and apply encryption based on the search results.
Agent ProtectionProcess ProtectionPrevent Forced TerminationProtects against forcibly terminating the process.A blocking notification is displayed when attempting to terminate a process in Task Manager.
Process HidingHides specific processes to prevent external access.
Module Tampering PreventionAnti-tamperingPrevents arbitrary tampering of process modules and executable files.Administrator approval is required.
Deletion LimitApproval-Based Deletion ControlRestrict users from arbitrarily deleting the program, and deletion is only possible with administrator approval.A warning window will be displayed when attempting to delete.
Visibility/TrackingWeb ConsoleUser MonitoringRecords and analyzes user activity logs such as document viewing, editing, and printing to detect and track user activities. (InfoLineage)Scheduled Items
Document Distribution VisualizationVisualize the distribution and use of documents by user and business system graphically.Scheduled Items
Hidden InformationVisualize the distribution and use of documents containing hidden information graphically.Scheduled Items
MLS Support (N2SF)Rating AssignmentCSO grade designationManual rating can be specified through the right-click menu of the mouse.Provides the ability to assign C/S/O grades through right-clicking the mouse.
Automatic Grade Assignment Upon CompletionWhen saving or closing the document, the system automatically assigns a security level predetermined by the administrator's policy without user confirmation.Applies to both regular documents and security documents, and the grade can only be changed to a higher grade.
Manual Assignment of Grades at ClosureWhen closing the document, display the security level selection window, allowing the user to select the security level of the document directly.Documents without a grade show all allowed grades, while documents with a grade only display the same or higher grades. If canceled, the grade will not be applied.
Grade CheckDocument Properties Window Security Level DisplayIn the explorer, right-click on the file → Properties → You can check the security level applied to the document as read-only in the "Security Level" tab.Supports both regular documents and secure documents. By default, the grade name and label name are displayed, and the display items can be selected through administrator settings. It is only displayed when logged in.
Multi-Environment SupportSupport for Various OSWindows OSSupports Windows 10, 11 (64bit) environments.
Mac OSSupports Mac OS environment.Supports reading DRM documents in read-only mode, connecting MIP documents to MS Office, and converting general documents to MIP.
Batch Conversion ToolSCFinder Search and ConversionMFT-based searchProvides fast file search using the Master File Table.
Search by Document TypeSupports search by document type for General/DRM/MIP.
Batch conversionBatch conversion processing is provided for the retrieved documents.
Convenience FeaturesFolder EncryptionEncrypt the Application document in the folder.
Whitelist-based transformationConvert only specific documentsDS_MIP_DOC_CONV_WHITE_LIST provides policy-based 1:1 mapping conversion.
Zero Trust SecurityUser Authentication ManagementSHIELD ID Unified LoginSecurity365 login authentication supports integrated login for Security365, Azure ActiveX (MS365), and SCI.
AzureAD-EntraID SSOProvides automatic SSO login in Windows AD Join + Hybrid environment.
SCI SSOSupports Single Sign-On through SCI Server ID.
EntraID SSOSupports SSO login through EntraID.
PKCE Authentication (Public Client Login)You can complete Security365 authentication with just a browser login even in environments where authentication information cannot be distributed to user PCs.The authentication method is automatically determined according to the administrator policy settings. The authentication information is securely stored on the PC and can be used offline without re-logging during the validity period.
Customizing the Login UISupports branding for the SHIELD ID login page.
Force Logout on User DeactivationAutomatically logs out when the user is deactivated.
MFA Authentication SupportSupports various MFA authentication based on conditions to enhance user authentication.
Zero Trust PolicyApplies a zero trust-based security policy.
visibilityReportingUser-specific patch status, login status, installation status, decryption status, print status, document export status, and users with release permissions are provided.Scheduled Items
Document Security Orchestration (MIP Support)File Encryption/DecryptionMIP encryption methodSupports MIP encryption compatible with Microsoft 365.
Encryption-Decryption Timing ManagementManages the encryption/decryption timing through the ZTCAP policy.
Document Automatic Conversion and Integrated ControlBidirectional Automatic ConversionSupports bidirectional automatic conversion between MIP documents and DRM encryption documents according to the ZTCAP policy.
Right-click conversionSupports mutual conversion between DRM documents, MIP documents, and regular documents through right-clicking the mouse.
Batch Conversion of FoldersSupports batch DRM conversion and batch MIP conversion through right-clicking the mouse in the folder, and allows for saving and viewing batch conversion logs.
Transformation Log Save - QueryYou can save and view batch conversion logs.
Cloud Download Document ConversionAutomatically converts when downloading from OneDrive, SharePoint, and Teams.
Teams Copilot Upload Document ConversionWhen attaching security documents in the Copilot tab of the Teams app, they are automatically converted on the user's PC before being uploaded to the cloud.Supports file attachment, drag-and-drop, and paste methods. The targets are Word, Excel, PowerPoint documents, and PDFs, while Teams web, mobile, and chat, board uploads are excluded.
Automatic conversion when viewing the documentAutomatic conversion according to the ZTCAP policy is provided at the time of document viewing.Local/SharePoint Path Support
Maintain document ownership during conversionEven if the MIP document is converted to a DRM document and then converted back to a MIP document, the original owner of the MIP document remains unchanged.The original owner permissions are preserved even if another user performs the conversion. If the MIP label is deleted, the owner information is not retained.
Check the reason for conversion failureIf the document conversion fails, you can check the failed documents in the conversion results list and see which policy and reason caused the failure through the detail view.The list of policies is displayed in order of priority, and the policy that determined the outcome is highlighted. The evaluation results of conditions, exclusions, and decision factors for each policy are provided in Korean.
Conversion Progress Guide at Document EndWhen closing the document, if multiple documents are converted and graded simultaneously, the processing status for each file will be displayed in the progress notification window.Each file displays a conversion in progress, success, or failure status, and once all tasks are completed, the confirm button is activated and will automatically close after 5 seconds. The window cannot be closed during the operation.
Icon SupportDRM Document IconSupports DRM document icons.
MIP Document IconDistinguish and display MIP document icons in the explorer. Classification (Label) / Protection (Protect)
CSO grade iconDisplays the overlay icon for C/S/O grade documents.
MIP Document ManagementDelete MIP LabelProvides MIP label deletion through the right-click menu.
MIP Icon ControlYou can control the display/hide of the MIP icon.
Third-party Tenant MIP Document Viewing Confirmation GuideWhen opening a document protected by MIP labels from another company, a confirmation window is displayed, allowing the user to choose whether to view it or not.It is displayed when you double-click in the explorer or select it in the Office open dialog. This does not apply when opening via drag and drop or from the recent documents list.
Cloud Integrated ManagementUpload ControlAutomatic Conversion | UploadAutomatically converts when uploading from local to OneDrive/SharePoint.
Conversion Progress Warning DialogDisplays a user notification window during bulk file processing.Up to 10 windows
Backup of the original fileAutomatically backs up the original file upon upload.
Upload Blocking (Grade-Based Selective Blocking)When uploading documents to cloud storage such as OneDrive/SharePoint, it blocks the upload of documents that are classified as restricted.The level to be blocked is specified by the administrator in the conditional policy. Microsoft Office documents and PDFs are supported.
Replace the guide fileThe blocked document has been replaced with a notice file, allowing the process of uploading multiple documents at once to either stop midway or complete without errors.The notification file name is "original_name_blocked.txt". When uploading a folder, if there is a blocked document, the original folder remains on my PC as it is.
Upload Result NotificationWhen the upload task is complete, the results for each file (moved/blocked/error) will be displayed in one window.If there are no blocks or errors, no notifications will be displayed.
Download ControlAutomatic Conversion | DownloadOneDrive/SharePoint → Automatically converts when downloaded locally.
Document Control by PathLocal PathProvides control over the general path document.
OneDrive PathProvides control over OneDrive path documents. (Limited)
SharePoint PathProvides control over SharePoint path documents.
Adobe ControlBrowser Authentication Not UsedProvides an option to bypass Adobe authentication.